A camera at a shop entrance can be CCTV. A system that analyses faces to identify people is a different privacy proposition. UK data-protection law imposes a high bar when biometric data is processed for identification.
Facial Recognition Is Not Just Ordinary CCTV
Facial recognition technology analyses facial features to produce or compare biometric information. Where biometric data is processed for the purpose of uniquely identifying a person, it falls within the special-category data regime and requires both a lawful basis and a separate Article 9 condition.
The ICO says explicit consent is likely to be the most appropriate special-category condition in many biometric-recognition cases, although other conditions can apply depending on the circumstances.
Retail Use Has a High Privacy Bar
The ICO's current FRT guidance says private-sector deployments, including shopping centres, must be justified on their own merits. The controller should be able to demonstrate lawfulness, necessity and proportionality, and should consider whether a less intrusive method could achieve the same purpose.
The ICO specifically warns that it may be difficult to justify analysing images of large numbers of people to identify a small number of individuals where the need or public-interest justification is not realistic or proportionate.
Do Customers Have an Absolute Right to Refuse?
There is not a universal UK rule saying every shop must offer admission to a person who refuses facial recognition. Whether the retailer can rely on consent, legitimate interests or another legal basis — and what alternatives it must provide — depends on the system and the circumstances.
However, if the retailer relies on consent, the ICO says consent must be freely given and the person must have a genuine choice. Where a different lawful basis is used, the retailer must satisfy the applicable necessity, proportionality and transparency requirements.
Look for the Privacy Information at the Entrance
The controller should provide privacy information explaining matters such as who is processing the data, why it is being used, the lawful basis and relevant individual rights. A short sign at the entrance may form part of a layered approach, but it does not replace the broader transparency obligations.
What if You Believe the System Is Unlawful?
- Photograph or note the signage, where lawful and safe to do so.
- Record the retailer, location, date and approximate time.
- Save the privacy notice and any facial-recognition information on the retailer's website.
- Ask the retailer who the controller is and what lawful basis and special-category condition it relies on.
- Exercise your relevant UK GDPR rights, such as access or objection, where applicable.
- Complain to the retailer and then to the ICO if the concern is not resolved.
Don't Rely on the Police LFR Case Law as if It Directly Governs Retailers
The Court of Appeal's 2020 Bridges case concerned South Wales Police and law-enforcement use of live facial recognition. It is highly relevant to proportionality and public-space facial recognition, but it does not create a one-line rule that every private retailer using FRT is lawful or unlawful.
For retail, use the ICO's private-sector guidance and the facts of the particular deployment.
What This Means Practically
- Facial recognition can involve special-category biometric data.
- Retailers need a lawful basis and a separate Article 9 condition where required.
- Necessity and proportionality are central.
- There is no universal statutory "right to walk in without scanning" in every retail scenario.
- Document the deployment before challenging it.
Sources
- ICO — Facial recognition technology (FRT) and surveillance. ico.org.uk
- ICO — How to process biometric data lawfully. ico.org.uk
- ICO — AI and biometrics strategy update, 2026. ico.org.uk