Live Facial Recognition – Crime reduction

INTRODUCTION

This notice explains how we use facial recognition in selected stores to help prevent crime. We only keep your image if you are on a reference list related to prior incidents. All data is processed securely, reviewed by humans, and deleted after 12 months.

Argenbright Security Europe Limited (“ASEL”) is an integrated security solutions provider that supports a number of UK retailers.

ASEL are the Data Controller for all personal data processed in relation to its Live Facial Recognition Service ‘Argus Vizion’.

Argus Vizion is a Live Facial Recognition Solution allowing our customers to upload information (including images) of Subjects of Interest (SOI) into our Live Facial Recognition Software.

The information is stored securely in our database; we call this our reference list. When you enter one of our customers stores our live facial recognition camera and supporting software will scan your face and compare your image to the reference list, if you are identified as a match against that reference list, then the store teams or security officers can take actions to ‘prevent’ crime before it is committed. This protects store colleagues, customers, and the individuals likely to commit crime

If you are not on our reference list, then your image and associated data are deleted within 30 seconds, and your data cannot be recovered. This protects continuity of the customer experience and ensure no further processing can be conducted on data relating to individuals not on the reference list.

Our solution also reduces demand on UK Policing by supporting the ‘prevention of crime’.

You can identify stores using our Argus Vizion Live Facial Recognition solution as ASEL installs clear signage on the front of the store alerting you to its use. Our signage also includes a QR code linking the reader to this privacy notice.

Our signage looks like this and is easily recognisable:

Due to the nature of our processing for crime prevention, data subjects may not always be notified when included in the reference list. ASEL ensures this exemption is applied only when notification would prejudice the purpose of the processing, in accordance with Schedule 2, Part 1(2) of the DPA 2018. Or where the individual meets the criteria of the processing, but we are unable to contact the SOI due to insufficient information being available to us.

 

DEFINITIONS

Controller – Argenbright Security Europe Limited is the organisation which determines the purposes and means of the processing of personal data.

Processor – A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient – A natural or legal person, public authority, agency or other body, to which the personal data is disclosed, whether a third party or not.

Third Party – A natural or legal person, public authority, agency or other body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Personal Data – Any information relating to an identified or identifiable natural person (“Data Subject”) An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Special Category Personal Data – Any information relating to an identified or identifiable natural person (“data Subject”) which falls into one of the following categories. Racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, data concerning a person’s sex life, data concerning a person’s sexual orientation.

Criminal Offence Data – Any information relating to criminal convictions, offences and related security measures. This includes any alleged and / or committed offences.

Data Subject – Any identifiable natural person, who’s personal data is processed by the controller responsible for the processing.

ASEL – Argenbright Security Europe Limited

Customer – ASEL Customer

Partners – Organisations with which we may share your data.

SOI – Subjects of Interest are individuals who are suspected of or have committed crime against our customer or security officers.

HOW TO CONTACT US

If you wish to contact us in relation to this privacy notice or if you wish to exercise any of your rights (described below) then please address your correspondence to.

Argenbright Security Europe Limited

Charles Babbage House, Kingsway Business Park, Rochdale, OL16 4NW

Alternatively, you can email us at dpo@asel.co.uk

We have also appointed a Data Protection Officer (DPO), if you do send correspondence by post, please mark the envelope to the ‘Data Protection Officer’.

OUR DATA PROTECTION OFFICER

The Data protection officer can be contacted by emailing dpo@asel.co.uk.

REASONS FOR PROCESSING YOUR INFORMATION

ASEL deploys its Argus Vizion Live Facial Recognition solution within some of its customers stores to identify SOI who we have good reason to believe are committing or have committed offences against our customer.

Each image added to the software is triaged through the ‘JAPAN’ test. This ensures that we can justify the processing of this image, we are authorised to process the image, processing is proportionate to our purpose, the processing is auditable (ensuring we remain accountable), and the processing of that image is necessary to achieve our purpose.

Our purpose is, ‘the detection and prevention of criminal acts’.

There are two ‘privacy by design’ safeguards in place during the capture of the reference list images.

  1. The reporter must complete the JAPAN test.
  2. ASEL Security Operations Centre trained personnel must check every submission before the image goes live within the reference list.

Following a match in store our software will alert the store colleague or security officer that there is a high likelihood that the image matches the SOI.

Before any action is taken against the SOI, the store colleague or security officer must confirm the image identified matches the SOI. They do this by comparing the image on the reference list with the image captured in store. There is therefore human intervention at every stage of this process. All matches are subject to human review prior to any action being taken. No decisions with legal or similarly significant effects are made solely by automated means.

If the user decides there is a match, they must acknowledge the match electronically before taking any action in store. If the user decides there is not match, then the data is deleted and is irrecoverable. All interactions are logged and auditable.

We consider this process to be less intrusive than store CCTV, store CCTV captures your data and stores it for 30 days, often on internal store hard disks.

WHAT DATA DO WE COLLECT AND PROCESS

To achieve our purpose, we collect the following personal data:

  1. Name
  2. Biometric Data
  3. Images taken from Body Worn Video
  4. Images taken from store CCTV systems

We also process special category data, which is data of a more sensitive nature, the special category data we collect is as follows:

  1. Details of suspected criminal offences
  2. Biometric Data

We do not collect the following data directly, but it can be inferred from other data:

  1. Age
  2. Gender
  3. Racial or ethnic origin

WHO WE SHARE YOUR DATA WITH

We share your personal data with trusted third parties who help us deliver our services. These organisations act as our Data Processors and only process your information on our instructions. They are not allowed to process your data for their own purposes.

Our key processors include:

  • Vix Vizion – who supply the Live Facial Recognition Imagus Software underpinning our Live Facial Recognition Solution.
  • Retail customers using the Argus Vision service for the purpose of preventing a crime following an alert.

RIGHTS OF THE DATA SUBJECT

UK GDPR affords you with a number of rights, your rights are summarised below. ASEL are committed to supporting you with these rights where required and so you may contact our designated Data Protection Officer dpo@asel.co.uk or any employee at any time to exercise these rights.

The right to request access – You have the right to obtain from ASEL free information about your personal data and a copy of the personal data we store (commonly known as a “Subject Access Request”), furthermore you have the right to obtain information as to whether your personal data is transferred to any third countries or international organisations. Where this is the case, you have the right to be informed about any safeguards relating to this transfer.

Right to rectification – You have the right to obtain from ASEL without undue delay the rectification of inaccurate personal data concerning you. Basically, if we hold incorrect data about you, you have the right to have that data corrected.

Right to erasure (right to be forgotten) – UK GDPR grants you the right to have your data deleted when there is no good reason for us to continue to process it. ASEL have an obligation to erase your data without undue delay where one of the statutory grounds applies, as long as the processing is not necessary. ASEL relies on Legitimate Interests as its lawful basis and therefore the processing of your data is necessary to achieve our purpose. For this reason, the right to erasure does not apply in every instance.

Right of Restriction of Processing

You have the right to obtain from ASEL a restriction of processing where a statutory reason applies. This enables you to ask us to suspend processing your data, for example if you want us to establish its accuracy or the reason for processing it.

Right to data portability

You have the right to receive personal data we process concerning you in a structured, commonly used, and machine-readable format. You have the right to request the transfer of your data to another party.

Right to Object

You have the right to object to us processing your personal data, on grounds relating to your situation at any time. This does not mean that we will stop processing your data, but we will review your objection in each case.

Automated individual decision-making, including profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling.

Right to withdraw consent

ASEL does not use consent as the legal basis for processing, we use legitimate interests for this purpose, therefore you do not have the right to withdraw consent.

Right to complain to the supervisory authority

The contact details for the ICO are contained in this privacy notice.

HOW TO EXERCISE YOUR RIGHTS

You will not usually pay a fee to access your personal data or to exercise any of your other rights. We may charge a reasonable fee if your request for access is unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances. If you wish to exercise your rights, then please contact us at dpo@asel.co.uk.

WHAT IS OUR LEGAL BASIS?

ASEL uses the lawful basis “legitimate interests” for processing your data as the processing is necessary to protect the business interests of our customers and there is no less intrusive method to achieve those business interests with the same level of impact. Our legitimate Interest is not outweighed by the rights and freedoms of the affected data subjects as our processing is in the substantial public interest and for the benefit of ASEL, its customers, customer consumers, and subjects of interest.

ASEL has conducted a Legitimate Interests Assessment which is available on request.

Where we process Special Category Data, such as biometric data for the purpose of live facial recognition, we do so on the basis that it is necessary for the substantial public interest, in accordance with Article 9 (2) (g) of the UK GDPR. We have assessed this interest against the appropriate provisions within the Data Protection Act 2018 (DPA 2018) and considered that our processing is necessary for the provision of detecting an unlawful act, in accordance with paragraph 10, schedule 1 of Part 2 of the DPA 2018.

We also recognise that we process criminal offence data, as referred to in Article 10 of the UK GDPR and as further described within the ICO guidance. Our Live Facial Recognition Software relies on a reference list; this reference lists constitute criminal offence data. The condition we rely upon for the processing of this data under the Data Protection Act 2018 is the same as for Special Category Data, i.e. preventing or detecting unlawful acts, as set out within paragraph 10 of Schedule 1 Part 2 of the DPA 2018.

ASEL has conducted a Data Protection Impact Assessment (DPIA) for Argus Vizion, which is reviewed annually and upon significant changes to our processing activities.

PERSONAL DATA AND RETENTION PERIODS

All personal data is held in UK based secure servers. Data processed within our Live Facial Recognition Solution will be held for 12 months before it is permanently and securely disposed of. The secure disposal of your data is an automatic process removing the risk of human error.

Your biometric data used for live facial recognition will be disposed of after 12 months unless you are not on the reference list where by your data will be deleted within 30 seconds.

SECURITY OF PROCESSING

As the Data Controller ASEL have implemented appropriate technical and organisational measures to ensure your Personal Data always remains secure.

HOW TO CONTACT THE ICO

You have the right to lodge a complaint with the supervisory authority if you believe we are infringing UK data protection laws or you are concerned about the way in which we are handling your personal data, in the case of the UK this is the ICO.

You can contact the ICO by following this link https://ico.org.uk/global/contact-us/ or by telephone on 03031231113.

CHANGES TO THIS NOTICE

This notice was last updated on 13/07/2026. We may change this notice by updating this page to reflect changes in the law or our privacy practices at any time.

SIGN UP TO OUR NEWSLETTER

Sign up to our newsletter to receive the latest news, insights, and updates from Argenbright Security Europe Ltd.

From innovative technology and safety initiatives to partnerships and success stories, we’ll keep you in the loop. We promise to keep your data safe and not share it with others. You can opt-out of receiving updates at any time.