Self-Checkout Loss Prevention Without Surveillance: How Scandit Protects Privacy

Published

Categories Retail

In short:

  • Scandit’s Self-Checkout Loss Prevention flags missed items, items left in baskets, barcode switches and walkaways by watching the transaction, not the shopper: no facial recognition or biometric templates.
  • Built on Scandit's ISO 27001:2022-certified security program, with architecture designed to support retailers' GDPR obligations and to avoid, by design, the practices the EU AI Act prohibits — including biometric categorization.
  • Self-checkout loss now makes up 28.5% of all retail loss, up from under 10% in 2018 (ECR Loss 2026).

Scandit's Self-Checkout Loss Prevention can detect loss without identifying anyone or needing to capture any biometric data. This matters more than it used to, particularly with increasing restrictions and privacy issues around facial recognition technology garnering mainstream attention.

Retailers evaluating any camera-based system at self-checkout are now doing so under GDPR's strict rules on biometric data. Selecting the wrong technology is a substantial compliance risk, but it can also significantly impact brand trust, built over years, in a single news cycle.

Why does self-checkout camera technology raise privacy concerns right now?

Self-checkout is an increasingly popular choice among shoppers, with 44% of US grocery customers saying they prefer it to a staffed lane, ahead of traditional checkout (39%) and a fully cashierless just walk out experience (10%). Speed is the fundamental factor: 77% of shoppers who prefer self-checkout cite faster service as the reason, a preference that holds across generations, from 63% of Gen Z shoppers to 45% of Millennials (NCR Voyix, 2025).

However, loss prevention trials using facial recognition at major grocers are now newsworthy, and no retailer wants its loss prevention vendor to be the reason it's in the next one. In August 2026, Coles and Woolworths confirmed they had tested facial recognition in their Australian stores to deter crime.

Privacy advocates like Dr. Jason Pallant, a marketing expert at RMIT University, described the trade-off retailers now face as "a security versus privacy dilemma." In the UK, a large grocer recently suspended live facial recognition after the technology incorrectly flagged an innocent shopper as a suspected offender due to human error. The loss prevention industry's own research doesn't shy away from these concerns. The ECR Retail Loss 2026 study names biometrics, customer data protection, and return on investment as the central open questions facing AI-based self-checkout technology.

It’s not just about detecting loss, but whether the technology can do so responsibly.

The most prominent privacy regulations were built around this type of risk. GDPR classifies biometric identifiers as special-category data subject to its strictest safeguards, and the EU AI Act treats systems that identify or categorize people through biometrics as high-risk, triggering obligations like human oversight and documented conformity assessments.

On the whole, these concerns and regulations aren’t a reason to rule out cameras at self-checkout. Nonetheless, it’s important to be precise about what the camera is actually focusing on. Scandit's Self-Checkout Loss Prevention Solution is built around exactly this distinction – it uses no facial recognition and no biometric identification of any kind.

Scandit's Self-Checkout Loss Prevention Solution

Self-Checkout Loss Prevention is a real-time vision AI solution. It detects loss patterns including missed scans, intentionally skipped items, and abandoned transactions as they happen, giving shoppers the chance to self-correct before an associate ever needs to step in.

Flag what shoppers miss. Recover the revenue. Keep the lane moving.

Scandit’s system runs on a flexible camera hardware setup. There's no need for dedicated AI cameras as it works seamlessly with off-the-shelf cameras, self-checkout built-in cameras, or standard security cameras mounted over the checkout station.

Here's the process:

  1. Monitor the session. A kiosk camera, powered by vision AI, watches the scan session and correlates what it sees with the live scanner and POS (Point of Sale) data stream.
  2. Identify the mismatch. If an item leaves the scan zone, bagging area, or basket without a valid scan, there’s an instant system notification.
  3. Nudge the shopper. An on-screen prompt asks the shopper to scan the flagged item. The shopper re-scans and continues the session without interruption or associates involved in the large majority of cases.
  4. Escalate only if needed. If the shopper doesn't respond, it’s a walkaway where the shopper leaves mid-transaction, an alert with the relevant clip goes to a supervisor. There’s always a human making the decision.
Isometric illustration of a woman at a self-checkout kiosk monitored by a security camera showing an alert warning on screen.

Self-Checkout Loss Prevention

Retail loss prevention technology that recovers or deters more than 75% of self-checkout losses.

How privacy is built into Self-Checkout Loss Prevention by design

Processing runs locally at the lane: Detection happens on a lightweight per-station compute unit, or a local in-store server. There’s no facial or biometric identifier, so there's no biometric data to transmit to the cloud or store centrally.

Multi-Tenant Architecture: The system is designed to separate customer data and strictly limit access so customers can't access each other’s data. Role based access further refines who has access to which data.

Data is minimized by design: Detection is item-based. The system was built to answer "did this item get scanned” and was never designed to collect the kind of data that would need additional identity safeguards.

Most cases never reach a person: Soft-nudge self-correction resolves 80–97% of flagged cases with zero associate involvement (ECR Loss 2026). Escalation is typically the exception.

Access is controlled and accountable: Access is controlled and accountable. Where escalation footage is reviewed, access is role-based and audit-logged, and use is purpose-limited to loss prevention. The EU AI Act expects this level of governance from AI systems, and is what’s required to hold an ISO 27001:2022 certification.

Self-Checkout Loss Prevention: Data Security

For a retailer's compliance team, the details behind a certification matter. ISO 27001:2022, GDPR, and the EU AI Act each set a different bar. Here's what Self-Checkout Loss Prevention's architecture is built around for each:

ISO 27001:2022: This certification is issued after independent, recurring audits of how the company's information security management system controls access, logging, and data protection.

GDPR: The solution is designed to support retailers in meeting their GDPR obligations, using item-level detection instead of biometric identifiers, which are treated as special-category data requiring the strictest safeguards.

EU AI Act: Since February 2025, the Act has prohibited practices including workplace emotion recognition and biometric categorization, and Self-Checkout Loss Prevention doesn't perform either by design. Scandit is building the platform to align with the Act's requirements as they phase in, and supports retailers with the documentation they need for their own transparency obligations.

Read more about how Scandit approaches security by design and Scandit's ISO 27001:2022 certification.

Does Self-Checkout Loss Prevention use facial recognition or biometric data?

Scandit’s Self-Checkout Loss Prevention Solution analyzes the transaction, not the person.

The system reads item movement , more specifically the path an object takes through the scan zone and bagging area, recognizing products. This correlated against the scanner and POS (Point of Sale) data stream.

Scandit does not use facial recognition and the system does not generate or store biometric templates. Moreover, it does not re-identify a shopper across visits or attempt to infer intent. The system is only focused on whether an item's expected path matches its actual one without processing the shopper’s identity.

This distinction is clear in the loss patterns the system is designed to detect include typical patterns:

  • Missed items/left in basket: An item is left in the basket or trolley, or bypasses the scan zone into the bag, without ever being scanned.
  • Barcode switches: A different or cheaper barcode is presented for the item actually being taken, which is common with produce PLU (Price Look Up) codes.
  • Walkaways: A shopper scans some items but leaves with a fuller basket than was paid for.

In every case, our loss prevention technology flags a discrepancy between what a camera or POS expects against what the scanner recognises at the lane. It never needs to know, or store, the identity of the shopper.

How does retail loss prevention technology work?

Scandit’s Self-Checkout Loss Prevention system detects an observable event meaning a human always makes the decision on intent based on the data presented.

This is because self-checkout systems and retail loss prevention technology can't distinguish a shopper who genuinely forgot to scan an item. The ECR Retail Loss 2026 study found that items like oranges, water, and paper towels were among the most commonly missed items because their barcodes are awkward to find or scan. This intent is obviously much different from someone who had no intention of paying.

The system only knows that a mismatch occurred. What happens next, whether it’s a quiet on-screen nudge, an associate notification, or a video-backed review, is a policy decision configured by the retailer.

Think of it less like an accusation and more like a VAR (Video Assistant Referee) review in football: an on-field incident is highlighted, and the referee reviews the evidence and makes the call. Scandit’s system works in the same way; it flags a moment that’s worth a second look, and a retail associate makes the final decision. The human always makes the final call, and in the vast majority of cases the shopper simply finishes the scan and carries on.

Does Self-Checkout Loss Prevention monitor store associates?

This is a common query from works councils and employee representatives across Europe, where camera systems on the shop floor routinely trigger co-determination reviews.

The short answer is no. The system is access-controlled and focused on loss prevention. It is not an associate-performance tool.

Self-Checkout Loss Prevention watches the transaction at the customer-facing scan zone. It does not track associate movement, productivity, or behavior, and access to any footage it generates is scoped to loss prevention roles, not people managers.

Protecting privacy and catching self-checkout loss

Having privacy and accuracy in your self-checkout fleet shouldn’t be a binary choice. Scandit’s Self-Checkout Loss Prevention allows retailers to run accurate self-checkouts with confidence whilst ensuring the privacy of their customers and associates.

Catching a scan mismatch doesn't require knowing who's standing in the lane. It's also the approach the evidence favors: in the ECR Retail Loss 2026 study, technology-based non-scan detection was the best-evidenced intervention category tested, with retailers reporting outcomes including a 9% loss reduction at one chain and $136 million in savings across 2,000 stores at another in a single year.

Additionally, other countermeasures carry their own trade-offs to consider.

Exit gates

Exit gates can reduce walkaways (one retailer reported a 28% drop), but they require significant upfront investment and can increase the risk of abuse and violence toward associates.

Weight scales

Weight scales do catch loss, turning them off increased self-checkout loss by as much as 20% in one case, but they add friction to every transaction which is what self-checkout is meant to remove, including frequently requiring associate intervention to resolve.

Item limits and adhoc audits

Item limits and manual audits can either cap convenience or catch only a small sample of shoppers. Researchers note customers often simply don't follow item-limit rules.

A system that never has to identify anyone and doesn't carry biometric-governance exposure to manage at every store is a more scalable version of loss prevention.

The Bottom Line

Self-checkout loss prevention doesn't require a trade-off between stopping loss and protecting privacy. Scandit's Self-Checkout Loss Prevention Solution detects the mismatch, analyzes item movement and correlates the information with scanner and POS data. No facial recognition, no biometric templates, and no re-identification of shoppers across visits.

Our privacy-first design doesn't come at the cost of simplicity: flexible compute that scales from a single lane to a full fleet, and hardware-agnostic detection that works with any camera.

See how Self-Checkout Loss Prevention works

Do you have a specific compliance question, or want to see how it could help in your own self-checkout lanes? Talk to an expert today.

Frequently Asked Questions

Loading search...

Please wait a moment