LEGITIMATE INTERESTS ASSESSMENT (LIA)

Facial Recognition Access Control and Member Engagement Analytics

Version: 1.0
Date: June 2026

Controller:
YOURGYM LYTHAM LTD

Company Number:
10712961

Supporting Processor:
GHOST AI LTD

Company Number:
17017701

1. PURPOSE OF THIS ASSESSMENT

This Legitimate Interests Assessment (LIA) has been completed in accordance with Article 6(1)(f) UK GDPR.

The purpose of this assessment is to determine whether the processing of personal data associated with the YourGym access control, attendance management and member engagement system is necessary for the legitimate interests pursued by the organisation and whether those interests are overridden by the rights and freedoms of affected individuals.

This assessment should be read alongside the associated Data Protection Impact Assessment (DPIA).

2. DESCRIPTION OF PROCESSING

The processing includes:

• Membership administration.
• Access control.
• Attendance monitoring.
• Occupancy reporting.
• Member engagement analytics.
• Retention analytics.
• Security monitoring.

Members may optionally enrol in facial recognition authentication.

Alternative access methods remain available, including QR code access, membership cards and staff assistance.

Attendance records are analysed to support member engagement, operational planning and service improvement.

3. PURPOSE TEST

What legitimate interests are being pursued?

YOURGYM LYTHAM LTD has identified the following legitimate business interests.

Facility Security

The gym operates a membership-based facility and has a legitimate interest in ensuring that only authorised individuals gain access.

The processing assists in protecting:

• Members.
• Staff.
• Visitors.
• Physical assets.

Prevention of Membership Fraud

The organisation has a legitimate interest in preventing:

• Membership sharing.
• Credential misuse.
• Unauthorised entry.

Traditional access methods such as cards, QR codes and PINs may be shared between individuals.

Identity verification reduces this risk.

Health and Safety

The organisation has a legitimate interest in maintaining accurate occupancy information to support:

• Emergency evacuation procedures.
• Incident response.
• Safeguarding activities.

Attendance records contribute to understanding who may be present within the facility at any given time.

Operational Efficiency

The organisation has a legitimate interest in providing efficient and reliable access management.

Automated access reduces:

• Administrative burden.
• Reception staffing requirements.
• Delays at facility entry points.

Member Engagement and Retention

The organisation has a legitimate interest in understanding attendance patterns to:

• Identify disengaged members.
• Offer support to members who have stopped attending.
• Improve member outcomes.
• Improve service delivery.

Attendance insights help ensure members obtain value from their membership and achieve their fitness objectives.

4. NECESSITY TEST

Is the processing necessary?

The organisation considered less intrusive alternatives.

Membership Cards

Cards may be:

• Lost.
• Stolen.
• Shared.

Cards do not reliably verify identity.

QR Codes

QR codes may be transferred between individuals.

The system cannot verify that the authorised member is physically present.

PIN Codes

PIN codes may be:

• Shared.
• Observed.
• Disclosed.

PIN codes do not provide reliable identity verification.

Manual Verification

Manual identity checks require staffing resources and are not suitable for all operating hours.

The gym operates extended and partially unattended access periods.

Facial Recognition

Facial recognition provides a more reliable method of identity verification.

The processing supports the legitimate aims identified while reducing opportunities for fraud and misuse.

The organisation considers the processing necessary and proportionate to achieve these objectives.

5. BALANCING TEST

What is the impact on individuals?

The processing involves:

• Membership information.
• Attendance records.
• Profile photographs.
• Biometric authentication.

Biometric processing has the potential to create a higher privacy impact than standard membership systems.

The organisation has therefore implemented additional safeguards.

Reasonable Expectations

Members joining a secure membership-based gym would reasonably expect:

• Identity verification.
• Access control measures.
• Attendance recording.
• Security monitoring.

Members are informed of the processing before enrolment.

No hidden or covert processing takes place.

Voluntary Participation

Facial recognition is optional.

Members may choose alternative access methods including:

• QR code.
• Membership card.
• Staff assistance.

Members are not required to use facial recognition in order to access the facility.

This significantly reduces the impact on individual privacy rights.

Transparency

Members receive:

• Privacy notices.
• Biometric processing information.
• Consent requests.
• Information regarding their rights.

The processing is transparent and clearly communicated.

Data Minimisation

Ghost stores:

• Membership information.
• Attendance records.
• Profile photographs.

Ghost does not store facial biometric templates.

Biometric templates are stored only within authorised access control devices and are used solely for authentication.

Attendance analytics are generated using attendance records rather than biometric characteristics.

Ability to Object

Members may:

• Withdraw consent.
• Object to processing where applicable.
• Request deletion where appropriate.
• Use alternative access methods.

Individuals retain meaningful control over participation.

Automated Decision Making

Attendance analytics may generate engagement indicators and retention insights.

These indicators assist staff decision-making.

No solely automated decisions producing legal or similarly significant effects are made using attendance analytics.

Members are able to challenge decisions affecting their membership.

6. SAFEGUARDS

The organisation has implemented the following safeguards.

Technical Safeguards:

• Encryption at rest.
• Encryption in transit.
• Secure cloud hosting.
• Multi-factor authentication.
• Audit logging.
• Role-based access controls.
• Secure API communications.

Organisational Safeguards:

• Staff training.
• Data protection policies.
• Data retention controls.
• Incident response procedures.
• Annual compliance reviews.

Privacy Safeguards:

• Optional facial recognition.
• Alternative access methods.
• Explicit consent.
• Transparent privacy notices.
• Defined retention periods.

7. OUTCOME

Having completed this assessment, YOURGYM LYTHAM LTD concludes that:

• The processing pursues legitimate business interests.
• The processing is necessary to achieve those interests.
• The interests are not overridden by the rights and freedoms of affected individuals.
• Appropriate safeguards have been implemented.
• The processing is fair, proportionate and transparent.

The organisation therefore considers Article 6(1)(f) UK GDPR to be an appropriate lawful basis for the processing described within this assessment.

8. APPROVAL

Completed By:

Name:

Position:

Signature:

Date:

Approved By:

Name:

Position:

Signature:

Date: