DATA PROTECTION IMPACT ASSESSMENT (DPIA)

Facial Recognition Access Control and Member Engagement Analytics System

Version: 1.1
Assessment Date: June 2026
Review Date: June 2027

Controller:
YOURGYM LYTHAM LTD

Company Number:
10712961

Processor:
GHOST AI LTD

Company Number:
17017701

1. EXECUTIVE SUMMARY

YOURGYM LYTHAM LTD proposes to implement a facial recognition access control solution integrated with membership management, attendance tracking and member engagement analytics.

The system is designed to:

• Verify member identity.
• Control access to gym facilities.
• Prevent unauthorised access and membership sharing.
• Improve member convenience.
• Improve facility security.
• Support safeguarding and incident investigations.
• Support emergency occupancy management.
• Improve member engagement and retention.
• Improve operational efficiency.

The processing includes biometric data used for the purpose of uniquely identifying individuals and therefore constitutes special category personal data under Article 9 UK GDPR.

This DPIA has been completed in accordance with Article 35 UK GDPR and relevant guidance issued by the Information Commissioner's Office (ICO).

2. ORGANISATIONAL DETAILS

Data Controller

YOURGYM LYTHAM LTD

Company Number:
10712961

Registered Office:
Unit 8 St Georges Court
St Georges Park
Kirkham
Preston
Lancashire
PR4 2EF

Data Processor

GHOST AI LTD

Company Number:
17017701

Registered Office:
9 Cropper Close
Blackpool
FY4 5PU

3. DESCRIPTION OF PROCESSING

Enrolment

Members may voluntarily enrol in facial recognition through the Ghost membership application.

The enrolment process requires the member to upload a profile image (selfie).

The image is associated with the member account and securely transmitted to authorised access control devices.

Access control devices generate facial recognition templates used solely for authentication purposes.

Ghost does not store facial recognition templates.

Authentication

Members may access the facility using:

• Facial recognition.
• QR code.
• Membership card.
• Reception assistance.

The access control device authenticates the member and returns an access result.

Successful and unsuccessful authentication events generate access records.

Attendance Recording

Attendance records include:

• Member identifier.
• Date and time of entry.
• Date and time of exit where applicable.
• Facility attendance history.

Attendance Analytics

Attendance and membership information may be analysed to generate:

• Attendance history.
• Visit frequency.
• Days since last visit.
• New member engagement indicators.
• Retention indicators.
• Occupancy reporting.
• Peak attendance analysis.
• Class participation reporting.
• Purchase history reporting.

Attendance analytics are derived from attendance and membership records and not from biometric templates.

4. PURPOSES OF PROCESSING

The processing is undertaken to:

• Verify member identity.
• Control access to facilities.
• Prevent membership sharing.
• Prevent unauthorised access.
• Protect members, staff and property.
• Support safeguarding investigations.
• Support emergency evacuation management.
• Maintain occupancy awareness.
• Improve member engagement.
• Improve member retention.
• Improve operational planning.
• Improve service delivery.

5. CATEGORIES OF PERSONAL DATA

Personal Data

• Name.
• Membership number.
• Email address.
• Telephone number.
• Membership status.
• Profile photograph.
• Attendance history.
• Purchase history.
• Class attendance history.
• Payment status information.
• Access control records.

Special Category Data

Facial biometric templates used to uniquely identify members for access control purposes.

Biometric templates are generated and stored within authorised access control devices.

Ghost does not store biometric templates.

6. DATA FLOW

Member uploads profile image.

Ghost securely stores profile image.

Profile image securely transmitted to authorised access control device.

Access control device generates facial recognition template.

Member presents face.

Device performs authentication.

Authentication result returned.

Access event created.

Attendance record created.

Attendance analytics generated.

7. CONTROLLER AND PROCESSOR RESPONSIBILITIES

Controller

YOURGYM LYTHAM LTD determines:

• Why personal data is processed.
• Which members are enrolled.
• How access control operates.
• Retention periods.
• Operational use of analytics.
• Member communications.

Processor

GHOST AI LTD provides:

• Membership management software.
• Data hosting.
• Attendance management.
• Analytics functionality.
• Technical support.

Processing is undertaken solely on documented instructions from the Controller.

A written Data Processing Agreement compliant with Article 28 UK GDPR is maintained between the parties.

8. LAWFUL BASIS

Article 6 UK GDPR

Article 6(1)(f) Legitimate Interests.

Legitimate interests include:

• Facility security.
• Prevention of fraud.
• Prevention of membership sharing.
• Protection of members and staff.
• Efficient operation of facilities.
• Improvement of member services.

A separate Legitimate Interests Assessment supports this lawful basis.

Article 9 UK GDPR

Article 9(2)(a) Explicit Consent.

Explicit consent is obtained before biometric authentication is enabled.

Members may withdraw consent at any time.

Alternative access methods remain available.

9. NECESSITY AND PROPORTIONALITY

The Controller operates a membership-based facility that requires reliable identity verification.

The gym operates extended and partially unattended opening periods, increasing the importance of secure access controls.

The Controller has identified risks associated with:

• Membership sharing.
• Unauthorised access.
• Lost credentials.
• Fraudulent use of memberships.

Alternative solutions were assessed.

Membership Cards

Can be lost, stolen or shared.

QR Codes

Can be transferred between individuals.

PIN Codes

Can be disclosed or observed.

Reception Verification

Requires staffing resources and is not suitable for all operating periods.

Facial Recognition

Provides enhanced identity assurance and reduces opportunities for membership misuse.

To ensure proportionality, facial recognition remains optional and alternative methods remain available.

10. DATA MINIMISATION

Ghost stores only data necessary to operate the service.

Ghost stores:

• Membership information.
• Profile photographs.
• Attendance records.
• Access events.
• Membership activity data.

Ghost does not store facial recognition templates.

Biometric templates are used solely for authentication and access control.

11. PURPOSE LIMITATION

Biometric processing is limited to:

• Identity verification.
• Access control.
• Prevention of membership sharing.
• Security management.

Biometric information is not used for:

• Marketing.
• Advertising.
• Sale to third parties.
• Behavioural profiling using biometric characteristics.

Attendance analytics are generated from attendance and membership records only.

12. ACCURACY AND FAIRNESS

Facial recognition functionality is provided through authorised access control devices.

The Controller and Processor have considered the potential for false acceptance, false rejection and demographic bias within facial recognition systems.

Alternative access methods remain available where facial recognition is unsuccessful.

Staff override procedures are available where required.

System performance and authentication failures shall be monitored and reviewed periodically.

13. RETENTION

Profile Photographs

Retained while membership remains active and only for as long as necessary for membership administration.

Biometric Templates

Deleted within 30 days of:

• Membership termination.
• Withdrawal of consent.
• Removal from access control enrolment.

Attendance Records

Retained for 12 months unless longer retention is required for legal, insurance or security purposes.

Membership Records

Retained in accordance with accounting, contractual and legal obligations.

14. INTERNATIONAL TRANSFERS

Personal data is hosted within the United Kingdom.

No routine international transfers of personal data are undertaken as part of the processing activity.

Should future international transfers become necessary, appropriate safeguards will be implemented in accordance with UK GDPR requirements.

15. TECHNICAL AND ORGANISATIONAL MEASURES

Technical Controls

• Encryption at rest.
• Encryption in transit.
• OVHcloud-hosted infrastructure protected by Cloudflare services.
• Role-based access control.
• Multi-factor authentication for infrastructure administration.
• System and operational audit logging.
• Secure API communications.
• Backup and recovery arrangements.
• Security monitoring.

Organisational Controls

• Staff training.
• Data protection policies.
• Access management procedures.
• Incident response procedures.
• Vendor management procedures.
• Annual compliance reviews.

16. INDIVIDUAL RIGHTS AND COMPLAINTS

Members may exercise their rights under UK GDPR including:

• Right of access.
• Right to rectification.
• Right to erasure.
• Right to restriction.
• Right to object.
• Right to data portability where applicable.

Members may withdraw consent to facial recognition at any time.

YOURGYM LYTHAM LTD maintains an internal data protection complaints procedure.

Individuals may submit complaints directly to the organisation regarding the processing of their personal data.

Individuals also retain the right to complain to the Information Commissioner's Office.

17. CHILDREN AND YOUNG PERSONS

Facial recognition enrolment is available only to members aged 18 years and over.

The system is not intended for use by children.

18. RISK ASSESSMENT

Risk: Unauthorised disclosure of profile photographs

Impact:
Medium

Likelihood:
Medium

Residual Risk:
Low

Risk: Compromise of biometric authentication systems

Impact:
High

Likelihood:
Medium

Residual Risk:
Low

Risk: Membership fraud and sharing

Impact:
Medium

Likelihood:
High without controls

Residual Risk:
Low

Risk: Algorithmic bias or inaccurate authentication

Impact:
Medium

Likelihood:
Medium

Residual Risk:
Low

Mitigations:

• Alternative access methods.
• Staff override procedures.
• Ongoing performance monitoring.

Risk: Function creep

Impact:
High

Likelihood:
Low

Residual Risk:
Low

Risk: Emergency management failures

Impact:
High

Likelihood:
Low

Residual Risk:
Low

19. DPIA REVIEW

This DPIA shall be reviewed:

• Annually.
• Following any material change to the system.
• Following any personal data breach.
• Following any significant change in processing activities.
• Following new regulatory guidance.
• Following implementation of new analytics functionality.

20. CONCLUSION

YOURGYM LYTHAM LTD has identified a legitimate requirement to implement secure access control and attendance management systems.

The processing of biometric information is limited to what is necessary to achieve the stated objectives.

Appropriate technical and organisational measures have been implemented to protect individuals and reduce risk.

Alternative access methods remain available to members who do not wish to use facial recognition.

The Controller concludes that the processing is lawful, necessary, proportionate and supported by appropriate safeguards.

No prior consultation with the Information Commissioner's Office is considered necessary.

21. APPROVAL

Data Controller

YOURGYM LYTHAM LTD

Name: ___________________

Position: ___________________

Signature: ___________________

Date: ___________________

Processor Acknowledgement

GHOST AI LTD

Name: ___________________

Position: ___________________

Signature: ___________________

Date: ___________________