Select Page

Facial Recognition legislation, Facewatch and Home Bargains and what it means for retailers

Sep 22, 2026 | CCTV, Commercial Security, Retail

The Call We Get After a Bad Month for Shoplifting

A store manager rings us after the third repeat-offender incident that month. Staff are rattled, the loss figures are climbing and someone on the management team has seen a rival retailer running facial recognition: can we just fit that here?

It’s a fair question, but the wrong first one. The real question isn’t whether the equipment can be installed – cameras and software are easy to buy. It’s whether you can lawfully run it and whether you’ve done the work that makes it defensible if something goes wrong. Get it wrong and the cost isn’t just a fine – it’s a wrongly accused customer confronted in front of other shoppers and a press story that outlasts the technical fix. That question follows a specific sequence set out across UK facial recognition legislation – and a 2025 case shows exactly what happens when a retailer skips it.

The Big Picture

  • Live facial recognition (LFR) scans camera footage in real time and matches faces against a watchlist – turning a face into biometric data, a stricter legal category than CCTV footage.
  • Police powers to use LFR and your powers as a retailer are separate legal questions. A court ruling on what the Metropolitan Police may do tells you nothing about what your store may do.
  • A 2025 wrongful-identification case involving Facewatch’s technology at Home Bargains shows precisely why the safeguards in this article exist.
  • Whether you can lawfully deploy LFR is answered by working through a defined sequence of legal-basis, necessity, documentation and governance questions.
  • For a lot of retail theft and access-control problems, a better-specified conventional CCTV System solves the underlying problem without the compliance burden of biometric processing.

What Went Wrong at Home Bargains – and Why It’s the Whole Point of This Article

In 2025, a shopper was reportedly wrongly matched against a retail watchlist by Facewatch‘s facial recognition system, deployed at Home Bargains among other retail sites, and was confronted in-store as a suspected shoplifter, according to widespread UK press coverage. The case was widely reported in the UK press and became a widely reported example of a facial recognition false positive – not an abstract statistic, but a real person, wrongly accused, in front of other customers.

First, the human-review failure. An LFR system produces a match. That match is intelligence, not evidence – a probability score, not a verified fact. Every credible compliance framework for this technology insists that no automated action is taken on an alert alone: a trained member of staff has to check the match, image quality and context and independently decide whether to act. When that step is thin or rushed, the system’s error becomes a public confrontation.

Second, the reputational cost. A story like this doesn’t stay contained to the store where it happened – it becomes a national talking point about the retailer, the vendor and facial recognition in retail generally, coverage and compliance sign-off after the fact does nothing to undo. The damage is done the moment the wrong person is stopped, not when a regulator later reviews the paperwork.

Step One: Confirm You’re Actually Dealing With Biometric Data

Not every camera-based system that claims to spot repeat offenders is facial recognition in the legal sense. Simple people-counting or heat-mapping technology, which doesn’t identify a specific individual, sits outside it.

It’s also worth distinguishing live facial recognition from retrospective facial recognition (RFR), which matches stored footage against a watchlist after the fact. RFR raises the same Article 9 and Data Protection Impact Assessment (DPIA) questions, just on a different timescale.

Genuine facial recognition – software that extracts a unique biometric template from a face to identify a specific person – is special category data under Article 9 of UK GDPR (the UK General Data Protection Regulation), triggering a stricter lawful-basis test, a mandatory impact assessment and a higher bar for getting it wrong. Ask the vendor what the system does before any money changes hands – marketing language isn’t a reliable guide.

Steps Two and Three: Do You Have a Lawful Basis and Does an Exception Apply?

Under Article 6 of UK GDPR, you need a lawful basis for processing personal data at all. For a retailer running LFR, the realistic option is legitimate interests – crime prevention is a recognised interest, but it has to pass a necessity and balancing test, not just be asserted. Consent is rarely workable, since you can’t meaningfully obtain it from every walk-in member of the public.

Because facial recognition is special category data, Article 6 alone isn’t enough. You also need a condition under Article 9 and DPA 2018 (the Data Protection Act 2018) Schedule 1 – the realistic route is Schedule 1, Part 2, paragraph 10 (preventing or detecting unlawful acts), requiring a written Appropriate Policy Document (APD) covering compliance measures and retention, kept for the processing period plus six months. If that condition isn’t genuinely satisfied, the honest answer is to stop here – and drafting or certifying it is a job for a data protection specialist or solicitor, not an installer.

Worth tracking: the Data (Use and Access) Act 2025 introduces a new “recognised legitimate interests” basis, simplifying the Article 6 test for purposes including crime prevention, once in force. That touches Article 6 only – it doesn’t remove the Article 9 special-category condition or the APD requirement above.

Step Four: Would Something Less Intrusive Do the Job Just as Well?

This is a common failure point for unlawful deployments. Is the watchlist genuinely limited to individuals connected to specific, documented unlawful acts or is it a general “known troublemakers” list built on suspicion? Is the scope matched to evidenced risk, rather than a blanket rollout?

The clearest precedent is the ICO (Information Commissioner’s Office) enforcement action against Serco Leisure in February 2024, over biometric fingerprint scanning used for staff attendance. The ICO found Serco couldn’t show the processing was necessary, because ID cards or fobs achieved the same purpose without touching biometric data. The same logic is likely to apply to facial recognition: if a non-biometric alternative – better CCTV, tighter Access Control, more visible staffing – would solve your problem, that weakens the case for biometric processing.

“Biometric data is wholly unique to a person, so the risks of harm in the event of inaccuracies or a security breach are much greater – you can’t reset someone’s face or fingerprint like you can reset a password.”
John Edwards, then Information Commissioner, on the Serco Leisure enforcement action, February 2024

Step Five: The DPIA Has to Exist Before You Switch Anything On

A Data Protection Impact Assessment (DPIA) is mandatory under Article 35 UK GDPR wherever processing is likely to result in high risk – and live facial recognition of the public is highly likely to meet that threshold. It must be completed before processing begins, not written up afterwards.

A proper DPIA documents the purpose, the necessity and proportionality assessment, the risks to individuals and the mitigating measures – the record that shows the risk was thought through in advance, not explained away afterwards. Where residual risk stays high even after mitigation, you’re required to consult the ICO before going live. A CCTV contractor can supply the technical facts, but shouldn’t present itself as certifying the document unless it genuinely has a qualified data protection specialist on staff.

Step Six: The Safeguards That Run Every Single Day

Getting the legal basis and the DPIA right is necessary but not sufficient. LFR needs live, ongoing governance – and this is where the Home Bargains incident traces back to. Retailers who avoid an incident like that treat the six safeguards below as standing operating procedure, not paperwork filed away and forgotten.

    • Written watchlist governance – inclusion and exclusion criteria, an evidence threshold before anyone goes on the list, a review and removal process and a defined maximum retention period.
    • A retention and deletion schedule for watchlist images and non-matched scan data. There’s no fixed statutory number of days – it depends on your documented policy and the storage-limitation principle under UK GDPR – but near-immediate deletion of non-matches is good practice.
    • Clear, prominent signage at every entry point before the recognition zone, in plain English, explaining what the system does – this is recommended good practice; a data protection adviser should confirm the precise legal wording needed.
    • A subject access and challenge process – a real route to query why someone was flagged, correct an error and be removed from a watchlist wrongly.

This is recommended good practice; a data protection adviser should confirm the precise legal mechanics.

  • Human review of every single match – no automated action on an alert alone. A trained member of staff verifies the match, context and image quality before anyone approaches.
  • Documented staff training covering system operation, the human-review protocol, de-escalation and handling a wrongly-flagged individual with respect.

Notice which item connects most directly back to the Home Bargains case: human review of every match. When that step is genuinely robust – a trained person checking image quality and context every time, with the authority to say “this isn’t a match” – the system catches its own errors before they reach a customer. When it’s a formality, the error reaches the shop floor instead. A qualified installer’s role is largely technical: access restriction, an audit trail on watchlist changes, retention configuration and training material. The governance policy itself – who decides who goes on a watchlist and why – sits with you as the data controller.

One point sits alongside these six safeguards: your contract with the vendor needs data processing terms consistent with Article 28 UK GDPR, because you remain the data controller even when the matching technology and watchlist hosting are supplied by someone else.

Step Seven: Who’s Actually Allowed to Operate It?

This is where a lot of confusion sits. Installing and maintaining a CCTV or facial recognition system is never licensable under the Security Industry Authority (SIA) regime – that applies to individuals monitoring a system and acting on alerts, not to the people who fit it.

SIA licensing currently applies to CCTV monitoring under a contract for services – an outsourced operator – not to your own employees monitoring your own site’s CCTV in-house. The Manchester Arena Inquiry flagged this in-house exemption as a gap. A Home Office and SIA consultation on closing it – Monitored Recommendations 7 and 8 or MR7/MR8 – closed 12 March 2026, with no decision published yet. Treat this as a live regulatory question: anyone telling you in-house monitoring will soon require an SIA licence is getting ahead of the actual position.

Police Powers Are a Different Legal Question From Yours

It’s tempting to assume expanding police use of LFR means the private sector is being waved through on the same basis. It isn’t.

The starting point for this area of law is R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058 – the Court of Appeal ruling that first found police use of live facial recognition unlawful, over an inadequate DPIA and a failure to properly assess the risk of demographic bias in the software. That case illustrates why a DPIA and a documented bias and accuracy check – baseline requirements for any LFR deployment under UK GDPR, private-sector included – matter.

More recently, in April 2026, the High Court dismissed a judicial review brought by two claimants – R (Thompson and Carlo) v Commissioner of Police of the Metropolis [2026] EWHC 915 (Admin) – finding the Metropolitan Police’s LFR policy compatible with Articles 8, 10 and 11 of the European Convention on Human Rights (private life, freedom of expression, freedom of assembly). The claimants have reportedly indicated they intend to appeal, so treat the ruling as significant but not final. Separately, a Home Office consultation on a new statutory framework for police biometrics closed in February 2026 with no government response published yet – so any claim that police LFR now sits on settled statutory footing is premature.

None of that case law changes your position as a retailer. Thompson and Carlo concerns the police’s common-law powers as a public authority, a different regime from the one governing your store. Your exposure runs through UK GDPR and the Data Protection Act 2018, not the Human Rights Act, which binds public bodies rather than private companies – so if the police can lawfully use LFR under their framework, that tells you nothing about whether you can under yours.

Worth noting: the ICO’s 2023 assessment finding Facewatch’s approach compliant is useful evidence that a private operator can satisfy this framework. But the ICO was explicit that this wasn’t a green light for widespread or indiscriminate use – every deployment is assessed on its own facts. The Home Bargains incident, involving the same technology two years later, shows why a 2023 clearance for one deployment doesn’t travel automatically to a different site.

What We’d Recommend Instead – Often

If you’re a frustrated retailer who hasn’t worked through the sequence above yet, you’re exactly who this section is for. We’d rather talk you out of a deployment that won’t stand up – and steer you toward something that solves the underlying problem – than sell you a system that doesn’t. That approach builds more trust than a straight sale ever would.

Depending on what’s driving the request, alternatives usually include: better-specified CCTV with DORI-compliant placement and higher resolution; monitored, detector-activated CCTV for real-time response; remote monitoring with audio challenge; tighter Access Control; and structured incident reporting that builds the evidence base to justify escalating to LFR later. None of these routinely carries the DPIA burden, watchlist governance overhead or reputational exposure of a facial recognition deployment.

Before You Go

Facial recognition is one of the most legally and reputationally demanding tools available to a retailer managing theft or access risk – and the Home Bargains case shows what happens when the safeguards around it aren’t genuinely robust.

Work through that sequence properly and you land in one of two honest places: a defensible position to go ahead, or a clear reason not to – decided before you’ve spent the money, not defended after the fact.

Not sure yet which of those two places you’re in? That’s exactly what we’re here for – get in touch and we’ll help you work out where you stand before you spend anything on cameras or software.

If facial recognition is genuinely on the table for your site, a compliance-led review – the DPIA, the watchlist governance, the human-review process and whether a non-biometric alternative would do the job just as well – is worth doing before a single camera is ordered. As qualified CCTV specialists we can walk you through that technical assessment and fit whatever comes out of it, biometric or not, alongside the data protection and legal advice that decision genuinely needs.

Frequently Asked Questions

What makes live facial recognition legally different from a standard CCTV System?

Live facial recognition extracts a unique biometric template from a face to identify a person, making it special category data under Article 9 of UK GDPR – stricter than ordinary CCTV footage. That triggers a stricter lawful-basis test under Article 6, a mandatory DPIA under Article 35 and a higher bar if something goes wrong. People-counting or heat-mapping technology that doesn’t identify a specific individual falls outside this framework. Confirm exactly what a system technically does before treating it as “just CCTV” – marketing language isn’t a reliable guide.

What legal basis does a retailer need before deploying LFR?

Under Article 6 of UK GDPR, the realistic lawful basis is legitimate interests – crime prevention qualifies, but only after a necessity and balancing test. Because facial recognition is special category data, Article 6 alone isn’t enough: you also need an Article 9/DPA 2018 Schedule 1 condition, typically the unlawful-acts provision, backed by a written Appropriate Policy Document – a job for a data protection specialist, not an installer. The Data (Use and Access) Act 2025’s “recognised legitimate interests” basis simplifies Article 6 only – it doesn’t remove the Article 9 condition or the APD requirement.

What happened in the 2025 Home Bargains case and why does it matter for retailers considering LFR?

In 2025, a shopper was wrongly matched against a retail watchlist by a facial recognition system deployed at Home Bargains and confronted in-store as a suspected shoplifter – a widely reported example of a facial recognition false positive in practice. The core failure was human review: an LFR match is intelligence, not evidence and every credible compliance framework requires a trained staff member to independently check the match, image quality and context before anyone acts on it. Reputational damage happens the moment the wrong person is stopped, not when a regulator later reviews the paperwork.

Does a retailer have to complete a Data Protection Impact Assessment before switching on LFR?

Yes. A DPIA is mandatory under Article 35 of UK GDPR wherever processing is likely to result in high risk and live facial recognition of the public routinely meets that threshold – completed before processing begins, not written up afterwards. It documents the purpose, necessity and proportionality, the risks to individuals and the mitigating measures. Where residual risk stays high even after mitigation, the operator must consult the ICO before going live. A CCTV contractor can supply the technical facts, but shouldn’t present itself as certifying the DPIA unless it has a qualified data protection specialist on staff.

Do staff need an SIA licence to monitor an in-house facial recognition or CCTV System?

Installing and maintaining a CCTV or facial recognition system is never a licensable activity under the Security Industry Authority regime – that applies to individuals monitoring a system and acting on alerts. SIA licensing currently applies to outsourced CCTV monitoring under a contract for services, not to a retailer’s own employees monitoring their own site’s CCTV in-house. The Manchester Arena Inquiry flagged this in-house exemption as a gap. A Home Office and SIA consultation on closing it (Monitored Recommendations 7 and 8) closed on 12 March 2026, with no decision published yet – treat this as a live regulatory question, not a settled requirement.

Does the 2026 High Court ruling on police facial recognition mean retailers are now cleared to use it too?

No – the two sit under entirely different legal frameworks. The starting point for UK facial recognition law is R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058, which first found police LFR unlawful over an inadequate DPIA and an unassessed bias risk. In April 2026, the High Court dismissed a judicial review in R (Thompson and Carlo) v Commissioner of Police of the Metropolis [2026] EWHC 915 (Admin), finding the Met’s policy compatible with the European Convention on Human Rights – though the claimants intend to appeal, so treat it as significant but not final. That’s a public-authority case; a retailer’s exposure runs through UK GDPR, not the Human Rights Act, so it says nothing about whether a retailer can lawfully deploy LFR.

This blog post is provided for general information only. It is not intended to amount to advice on which you should rely. Speak to a professional for specialist advice before taking, or refraining from, any action on the basis of the content on our site.

Although we make reasonable efforts to update the information on our site, we make no representations, warranties or guarantees, whether express or implied, that the content on our site is accurate, complete or up to date.

Property Safety
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.