LEGITIMATE INTERESTS ASSESSMENT (LIA)
Facial Recognition Access Control and Member Engagement Analytics
Version: 1.0
Date: June 2026
Controller:
YOURGYM LYTHAM LTD
Company Number:
10712961
Supporting Processor:
GHOST AI LTD
Company Number:
17017701
1. PURPOSE OF THIS ASSESSMENT
This Legitimate Interests Assessment (LIA) has been completed in accordance with Article 6(1)(f) UK GDPR.
The purpose of this assessment is to determine whether the processing of personal data associated with the YourGym access control, attendance management and member engagement system is necessary for the legitimate interests pursued by the organisation and whether those interests are overridden by the rights and freedoms of affected individuals.
This assessment should be read alongside the associated Data Protection Impact Assessment (DPIA).
2. DESCRIPTION OF PROCESSING
The processing includes:
• Membership administration.
• Access control.
• Attendance monitoring.
• Occupancy reporting.
• Member engagement analytics.
• Retention analytics.
• Security monitoring.
Members may optionally enrol in facial recognition authentication.
Alternative access methods remain available, including QR code access, membership cards and staff assistance.
Attendance records are analysed to support member engagement, operational planning and service improvement.
3. PURPOSE TEST
What legitimate interests are being pursued?
YOURGYM LYTHAM LTD has identified the following legitimate business interests.
Facility Security
The gym operates a membership-based facility and has a legitimate interest in ensuring that only authorised individuals gain access.
The processing assists in protecting:
• Members.
• Staff.
• Visitors.
• Physical assets.
Prevention of Membership Fraud
The organisation has a legitimate interest in preventing:
• Membership sharing.
• Credential misuse.
• Unauthorised entry.
Traditional access methods such as cards, QR codes and PINs may be shared between individuals.
Identity verification reduces this risk.
Health and Safety
The organisation has a legitimate interest in maintaining accurate occupancy information to support:
• Emergency evacuation procedures.
• Incident response.
• Safeguarding activities.
Attendance records contribute to understanding who may be present within the facility at any given time.
Operational Efficiency
The organisation has a legitimate interest in providing efficient and reliable access management.
Automated access reduces:
• Administrative burden.
• Reception staffing requirements.
• Delays at facility entry points.
Member Engagement and Retention
The organisation has a legitimate interest in understanding attendance patterns to:
• Identify disengaged members.
• Offer support to members who have stopped attending.
• Improve member outcomes.
• Improve service delivery.
Attendance insights help ensure members obtain value from their membership and achieve their fitness objectives.
4. NECESSITY TEST
Is the processing necessary?
The organisation considered less intrusive alternatives.
Membership Cards
Cards may be:
• Lost.
• Stolen.
• Shared.
Cards do not reliably verify identity.
QR Codes
QR codes may be transferred between individuals.
The system cannot verify that the authorised member is physically present.
PIN Codes
PIN codes may be:
• Shared.
• Observed.
• Disclosed.
PIN codes do not provide reliable identity verification.
Manual Verification
Manual identity checks require staffing resources and are not suitable for all operating hours.
The gym operates extended and partially unattended access periods.
Facial Recognition
Facial recognition provides a more reliable method of identity verification.
The processing supports the legitimate aims identified while reducing opportunities for fraud and misuse.
The organisation considers the processing necessary and proportionate to achieve these objectives.
5. BALANCING TEST
What is the impact on individuals?
The processing involves:
• Membership information.
• Attendance records.
• Profile photographs.
• Biometric authentication.
Biometric processing has the potential to create a higher privacy impact than standard membership systems.
The organisation has therefore implemented additional safeguards.
Reasonable Expectations
Members joining a secure membership-based gym would reasonably expect:
• Identity verification.
• Access control measures.
• Attendance recording.
• Security monitoring.
Members are informed of the processing before enrolment.
No hidden or covert processing takes place.
Voluntary Participation
Facial recognition is optional.
Members may choose alternative access methods including:
• QR code.
• Membership card.
• Staff assistance.
Members are not required to use facial recognition in order to access the facility.
This significantly reduces the impact on individual privacy rights.
Transparency
Members receive:
• Privacy notices.
• Biometric processing information.
• Consent requests.
• Information regarding their rights.
The processing is transparent and clearly communicated.
Data Minimisation
Ghost stores:
• Membership information.
• Attendance records.
• Profile photographs.
Ghost does not store facial biometric templates.
Biometric templates are stored only within authorised access control devices and are used solely for authentication.
Attendance analytics are generated using attendance records rather than biometric characteristics.
Ability to Object
Members may:
• Withdraw consent.
• Object to processing where applicable.
• Request deletion where appropriate.
• Use alternative access methods.
Individuals retain meaningful control over participation.
Automated Decision Making
Attendance analytics may generate engagement indicators and retention insights.
These indicators assist staff decision-making.
No solely automated decisions producing legal or similarly significant effects are made using attendance analytics.
Members are able to challenge decisions affecting their membership.
6. SAFEGUARDS
The organisation has implemented the following safeguards.
Technical Safeguards:
• Encryption at rest.
• Encryption in transit.
• Secure cloud hosting.
• Multi-factor authentication.
• Audit logging.
• Role-based access controls.
• Secure API communications.
Organisational Safeguards:
• Staff training.
• Data protection policies.
• Data retention controls.
• Incident response procedures.
• Annual compliance reviews.
Privacy Safeguards:
• Optional facial recognition.
• Alternative access methods.
• Explicit consent.
• Transparent privacy notices.
• Defined retention periods.
7. OUTCOME
Having completed this assessment, YOURGYM LYTHAM LTD concludes that:
• The processing pursues legitimate business interests.
• The processing is necessary to achieve those interests.
• The interests are not overridden by the rights and freedoms of affected individuals.
• Appropriate safeguards have been implemented.
• The processing is fair, proportionate and transparent.
The organisation therefore considers Article 6(1)(f) UK GDPR to be an appropriate lawful basis for the processing described within this assessment.
8. APPROVAL
Completed By:
Name:
Position:
Signature:
Date:
Approved By:
Name:
Position:
Signature:
Date: