DATA PROTECTION IMPACT ASSESSMENT (DPIA)
Facial Recognition Access Control and Member Engagement Analytics System
Version: 1.1
Assessment Date: June 2026
Review Date: June 2027
Controller:
YOURGYM LYTHAM LTD
Company Number:
10712961
Processor:
GHOST AI LTD
Company Number:
17017701
1. EXECUTIVE SUMMARY
YOURGYM LYTHAM LTD proposes to implement a facial recognition access control solution integrated with membership management, attendance tracking and member engagement analytics.
The system is designed to:
• Verify member identity.
• Control access to gym facilities.
• Prevent unauthorised access and membership sharing.
• Improve member convenience.
• Improve facility security.
• Support safeguarding and incident investigations.
• Support emergency occupancy management.
• Improve member engagement and retention.
• Improve operational efficiency.
The processing includes biometric data used for the purpose of uniquely identifying individuals and therefore constitutes special category personal data under Article 9 UK GDPR.
This DPIA has been completed in accordance with Article 35 UK GDPR and relevant guidance issued by the Information Commissioner's Office (ICO).
2. ORGANISATIONAL DETAILS
Data Controller
YOURGYM LYTHAM LTD
Company Number:
10712961
Registered Office:
Unit 8 St Georges Court
St Georges Park
Kirkham
Preston
Lancashire
PR4 2EF
Data Processor
GHOST AI LTD
Company Number:
17017701
Registered Office:
9 Cropper Close
Blackpool
FY4 5PU
3. DESCRIPTION OF PROCESSING
Enrolment
Members may voluntarily enrol in facial recognition through the Ghost membership application.
The enrolment process requires the member to upload a profile image (selfie).
The image is associated with the member account and securely transmitted to authorised access control devices.
Access control devices generate facial recognition templates used solely for authentication purposes.
Ghost does not store facial recognition templates.
Authentication
Members may access the facility using:
• Facial recognition.
• QR code.
• Membership card.
• Reception assistance.
The access control device authenticates the member and returns an access result.
Successful and unsuccessful authentication events generate access records.
Attendance Recording
Attendance records include:
• Member identifier.
• Date and time of entry.
• Date and time of exit where applicable.
• Facility attendance history.
Attendance Analytics
Attendance and membership information may be analysed to generate:
• Attendance history.
• Visit frequency.
• Days since last visit.
• New member engagement indicators.
• Retention indicators.
• Occupancy reporting.
• Peak attendance analysis.
• Class participation reporting.
• Purchase history reporting.
Attendance analytics are derived from attendance and membership records and not from biometric templates.
4. PURPOSES OF PROCESSING
The processing is undertaken to:
• Verify member identity.
• Control access to facilities.
• Prevent membership sharing.
• Prevent unauthorised access.
• Protect members, staff and property.
• Support safeguarding investigations.
• Support emergency evacuation management.
• Maintain occupancy awareness.
• Improve member engagement.
• Improve member retention.
• Improve operational planning.
• Improve service delivery.
5. CATEGORIES OF PERSONAL DATA
Personal Data
• Name.
• Membership number.
• Email address.
• Telephone number.
• Membership status.
• Profile photograph.
• Attendance history.
• Purchase history.
• Class attendance history.
• Payment status information.
• Access control records.
Special Category Data
Facial biometric templates used to uniquely identify members for access control purposes.
Biometric templates are generated and stored within authorised access control devices.
Ghost does not store biometric templates.
6. DATA FLOW
Member uploads profile image.
↓
Ghost securely stores profile image.
↓
Profile image securely transmitted to authorised access control device.
↓
Access control device generates facial recognition template.
↓
Member presents face.
↓
Device performs authentication.
↓
Authentication result returned.
↓
Access event created.
↓
Attendance record created.
↓
Attendance analytics generated.
7. CONTROLLER AND PROCESSOR RESPONSIBILITIES
Controller
YOURGYM LYTHAM LTD determines:
• Why personal data is processed.
• Which members are enrolled.
• How access control operates.
• Retention periods.
• Operational use of analytics.
• Member communications.
Processor
GHOST AI LTD provides:
• Membership management software.
• Data hosting.
• Attendance management.
• Analytics functionality.
• Technical support.
Processing is undertaken solely on documented instructions from the Controller.
A written Data Processing Agreement compliant with Article 28 UK GDPR is maintained between the parties.
8. LAWFUL BASIS
Article 6 UK GDPR
Article 6(1)(f) Legitimate Interests.
Legitimate interests include:
• Facility security.
• Prevention of fraud.
• Prevention of membership sharing.
• Protection of members and staff.
• Efficient operation of facilities.
• Improvement of member services.
A separate Legitimate Interests Assessment supports this lawful basis.
Article 9 UK GDPR
Article 9(2)(a) Explicit Consent.
Explicit consent is obtained before biometric authentication is enabled.
Members may withdraw consent at any time.
Alternative access methods remain available.
9. NECESSITY AND PROPORTIONALITY
The Controller operates a membership-based facility that requires reliable identity verification.
The gym operates extended and partially unattended opening periods, increasing the importance of secure access controls.
The Controller has identified risks associated with:
• Membership sharing.
• Unauthorised access.
• Lost credentials.
• Fraudulent use of memberships.
Alternative solutions were assessed.
Membership Cards
Can be lost, stolen or shared.
QR Codes
Can be transferred between individuals.
PIN Codes
Can be disclosed or observed.
Reception Verification
Requires staffing resources and is not suitable for all operating periods.
Facial Recognition
Provides enhanced identity assurance and reduces opportunities for membership misuse.
To ensure proportionality, facial recognition remains optional and alternative methods remain available.
10. DATA MINIMISATION
Ghost stores only data necessary to operate the service.
Ghost stores:
• Membership information.
• Profile photographs.
• Attendance records.
• Access events.
• Membership activity data.
Ghost does not store facial recognition templates.
Biometric templates are used solely for authentication and access control.
11. PURPOSE LIMITATION
Biometric processing is limited to:
• Identity verification.
• Access control.
• Prevention of membership sharing.
• Security management.
Biometric information is not used for:
• Marketing.
• Advertising.
• Sale to third parties.
• Behavioural profiling using biometric characteristics.
Attendance analytics are generated from attendance and membership records only.
12. ACCURACY AND FAIRNESS
Facial recognition functionality is provided through authorised access control devices.
The Controller and Processor have considered the potential for false acceptance, false rejection and demographic bias within facial recognition systems.
Alternative access methods remain available where facial recognition is unsuccessful.
Staff override procedures are available where required.
System performance and authentication failures shall be monitored and reviewed periodically.
13. RETENTION
Profile Photographs
Retained while membership remains active and only for as long as necessary for membership administration.
Biometric Templates
Deleted within 30 days of:
• Membership termination.
• Withdrawal of consent.
• Removal from access control enrolment.
Attendance Records
Retained for 12 months unless longer retention is required for legal, insurance or security purposes.
Membership Records
Retained in accordance with accounting, contractual and legal obligations.
14. INTERNATIONAL TRANSFERS
Personal data is hosted within the United Kingdom.
No routine international transfers of personal data are undertaken as part of the processing activity.
Should future international transfers become necessary, appropriate safeguards will be implemented in accordance with UK GDPR requirements.
15. TECHNICAL AND ORGANISATIONAL MEASURES
Technical Controls
• Encryption at rest.
• Encryption in transit.
• OVHcloud-hosted infrastructure protected by Cloudflare services.
• Role-based access control.
• Multi-factor authentication for infrastructure administration.
• System and operational audit logging.
• Secure API communications.
• Backup and recovery arrangements.
• Security monitoring.
Organisational Controls
• Staff training.
• Data protection policies.
• Access management procedures.
• Incident response procedures.
• Vendor management procedures.
• Annual compliance reviews.
16. INDIVIDUAL RIGHTS AND COMPLAINTS
Members may exercise their rights under UK GDPR including:
• Right of access.
• Right to rectification.
• Right to erasure.
• Right to restriction.
• Right to object.
• Right to data portability where applicable.
Members may withdraw consent to facial recognition at any time.
YOURGYM LYTHAM LTD maintains an internal data protection complaints procedure.
Individuals may submit complaints directly to the organisation regarding the processing of their personal data.
Individuals also retain the right to complain to the Information Commissioner's Office.
17. CHILDREN AND YOUNG PERSONS
Facial recognition enrolment is available only to members aged 18 years and over.
The system is not intended for use by children.
18. RISK ASSESSMENT
Risk: Unauthorised disclosure of profile photographs
Impact:
Medium
Likelihood:
Medium
Residual Risk:
Low
Risk: Compromise of biometric authentication systems
Impact:
High
Likelihood:
Medium
Residual Risk:
Low
Risk: Membership fraud and sharing
Impact:
Medium
Likelihood:
High without controls
Residual Risk:
Low
Risk: Algorithmic bias or inaccurate authentication
Impact:
Medium
Likelihood:
Medium
Residual Risk:
Low
Mitigations:
• Alternative access methods.
• Staff override procedures.
• Ongoing performance monitoring.
Risk: Function creep
Impact:
High
Likelihood:
Low
Residual Risk:
Low
Risk: Emergency management failures
Impact:
High
Likelihood:
Low
Residual Risk:
Low
19. DPIA REVIEW
This DPIA shall be reviewed:
• Annually.
• Following any material change to the system.
• Following any personal data breach.
• Following any significant change in processing activities.
• Following new regulatory guidance.
• Following implementation of new analytics functionality.
20. CONCLUSION
YOURGYM LYTHAM LTD has identified a legitimate requirement to implement secure access control and attendance management systems.
The processing of biometric information is limited to what is necessary to achieve the stated objectives.
Appropriate technical and organisational measures have been implemented to protect individuals and reduce risk.
Alternative access methods remain available to members who do not wish to use facial recognition.
The Controller concludes that the processing is lawful, necessary, proportionate and supported by appropriate safeguards.
No prior consultation with the Information Commissioner's Office is considered necessary.
21. APPROVAL
Data Controller
YOURGYM LYTHAM LTD
Name: ___________________
Position: ___________________
Signature: ___________________
Date: ___________________
Processor Acknowledgement
GHOST AI LTD
Name: ___________________
Position: ___________________
Signature: ___________________
Date: ___________________