Skip to main content
Blog·GDPR & Compliance

Five myths about retail facial recognition

Say "facial recognition in a shop" and most people picture a system that scans every face, checks it against some giant database, and decides who to throw out. That version deserves the bad press. It is also not how responsible retail facial recognition works. Here are five myths worth clearing up.

SESam Erpik · Co-founder & CTO4 min read

Facial recognition has an image problem, and a lot of it is earned. Systems that scan the public against opaque databases, or act on a match without a person in the loop, deserve the scrutiny they get. But that is not the only way to build it, and it is not how we build it. Here are five of the most common assumptions about retail facial recognition, and what the responsible version actually does.

Myth

1.It scans everyone and checks them against a national database.

Reality

It compares a detected face only against your own watchlist and your staff whitelist. No public or police database is in the loop. If a face is not on your list, there is no match and nothing to review.

Myth

2.The AI decides who gets stopped or banned.

Reality

It decides nothing. A possible match is flagged 'review required' and sent to a person, who taps Confirm or Not a match. Nothing happens to anyone without a human making that call, and every decision is logged.

Myth

3.It keeps a photo of every customer's face.

Reality

It does not keep a face-print of everyone who walks in. Only the people on your watchlist and whitelist are enrolled, stored as a numeric vector rather than a photo. Retention limits apply, and anyone can be removed on request.

Myth

4.You cannot do facial recognition and stay GDPR-compliant.

Reality

You can, but only if the architecture is right from the start: ICO registration, ISO/IEC 27001, face vectors kept separate from video, a human in every consequential decision, and a DPIA per deployment. Compliance is a design decision, not a policy page.

Myth

5.It needs expensive special cameras.

Reality

It runs on the IP cameras you already have, over RTSP or ONVIF, with detection on a small edge device in the store. No rip-and-replace, and your cameras are not streamed continuously to the cloud.

On your watchlistStaff or trusted-visitor whitelistEveryone else, no match, not enrolled
Facial recognition only compares faces to the lists you built. If someone is not on a list, there is no match and no alert is raised.

Notice the pattern. Every myth assumes the system is doing something to everyone, on its own. The responsible version does the opposite. It only ever matches against the small list you built, it never acts without a person, and it can prove every step afterwards. Narrow, boring and accountable is the whole point.

How a watchlist match actually works
The same flow, step by step, with a 47-second walk-through
Face Recognition on the platform
Watchlist and whitelist, designed to be GDPR-safe, with human review on every match

Frequently asked questions

Does retail facial recognition scan everyone in the store?

No. It compares a detected face only against the retailer's own watchlist and staff whitelist. It does not identify members of the public against a national or third-party database, and if a face is not on your list there is no match and nothing to review.

Does facial recognition decide who gets banned?

No. The system only flags a possible match as 'review required' and sends it to a person, who confirms or dismisses it. Nothing happens to anyone without a human decision, and every decision is written to an audit log.

Does retail facial recognition store everyone's face?

No. Only the people on your watchlist and whitelist are enrolled, and they are stored as a numeric vector rather than a photo. Retention limits apply, and anyone can be removed on request.

Is retail facial recognition GDPR-compliant?

It can be, if the architecture is right. Done responsibly it means ICO registration, ISO/IEC 27001 certification, face vectors kept separate from video, a human in every consequential decision, and a DPIA per deployment.

Do you need special cameras for retail facial recognition?

No. It runs on the IP cameras you already have over RTSP or ONVIF, with detection on a small edge device in the store, so there is no rip-and-replace and cameras are not streamed continuously to the cloud.

Get the monthly brief.

One email a month. The post-of-the-month, the retail-trends summary, and one customer-success snippet. No sales pitches, no event invites. Opt out in one click.