There are two operative components: cameras & software. They don't need to be on the same device or used by the same person. Increasingly, if the cameras exist, the "data" is likely to go through software at some point.
Facebook, Apple, Google or whatnot... they do facial recognition & other classification by default. Any publicly available pictures can be crawled & analysed by aggregators... or whoever wants to. Most people use services that analyse image content, make images public, or both.
These aren't just theoretical loopholes. There are tons and tons of private cameras out there. These will continue to "do facial recognition," or lead to it.
This can probably only be a ban on certain users: police... maybe some classes of regulatable businesses. This might be ok, but I don't get the impression decision makers know this.