Consent for facial recognition is valid only as a fully informed, freely given choice, which is very hard in public spaces; without it another lawful basis is needed. Using FRT must not cause detriment: for authentication an alternative such as a key code or another entrance should be offered (a gym requiring face scans for entry has no valid consent; offering a membership card makes explicit consent possible). The ICO's school case study adds that biometric cashless catering for pupils needs a DPIA first, explicit consent with a genuine alternative that brings no disadvantage (swipe cards, PINs or cash without longer waits or higher prices), a child-friendly privacy notice, bias testing and, in England and Wales, the Protection of Freedoms Act 2012 parental consent rules.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.