Privacy notice for a gym or fitness business
A privacy notice for a gym, fitness studio or sports facility, drafted for the business with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.
Privacy notice for a gym or fitness business
Buy now, £595A gym holds membership and payment data for the subscription it runs on, health questionnaires and injury records that are special category data, access control records that may be biometric, CCTV footage of the floor, the data its app and its members' wearables generate, and the data that passes between it and the freelance trainers who work there. The privacy notice has to deal with each, state the right basis for the health data, address biometrics and CCTV, and say who controls the data a personal trainer collects. Drafting for the business, I deliver the privacy notice, the cookie notice and guidance on consent in five working days for a fixed £595.
Who this is for
Gyms, boutique studios, yoga and pilates studios, climbing walls, boxing clubs, leisure centres and other fitness businesses in England and Wales with members, bookings and a website or app.
What matters in a gym or fitness privacy notice
Membership data and the subscription the business runs on
Article 13 of the UK GDPR requires the business, as controller, to tell members what it collects (contact and identity details, membership type, payment details handled by the direct debit or card processor, attendance records, bookings, communications) and the lawful basis for each: the membership contract under Article 6(1)(b) for the service, legal obligation for tax records, legitimate interests under Article 6(1)(f) for security, attendance analysis and the business's own improvement; the notice should describe the membership management platform and the payment processor as processors or controllers as the case may be, and should address the subscription's cancellation and the data the business keeps after membership ends.
Health questionnaires, injuries and the data that is special category
A pre-exercise questionnaire, a disclosed medical condition, an injury record, a pregnancy disclosure and a disability adjustment are all health data under Article 9 of the UK GDPR, and the notice should state the condition the business relies on for each: explicit consent for the questionnaire where the member chooses what to disclose, or the business's legal obligation and legitimate interests in the member's safety with the substantial public interest condition where the facts support it, with the appropriate policy document the Data Protection Act 2018 requires; the notice should also limit who sees health data (the trainer working with the member, the first aider in an emergency) and how long it is kept, because a health questionnaire stored for years on a shared drive is the breach that follows.
Access control, biometrics and CCTV
Access by fingerprint, face or other biometric means uses special category data under Article 9 of the UK GDPR requiring explicit consent with a non-biometric alternative offered, a data protection impact assessment under Article 35, and the Information Commissioner's biometric guidance followed; CCTV on the gym floor, at entrances and (never) in changing rooms is processed under legitimate interests with signage, a stated retention period, access limited to named staff, a process for police requests and for members' access requests to footage, and a data protection impact assessment where the monitoring is systematic; the notice should describe each system, its purpose and its retention, and the business should be able to show the assessments behind it.
Apps, wearables and the data members generate
Where the business provides an app or integrates with members' wearables and fitness platforms, the notice should describe the data the app collects (bookings, attendance, workouts, body measurements, photographs the member uploads), the data received from wearables with the member's connection, the analytics and tracking in the app (which need consent under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 as similar technologies), the sharing with the app provider and the platforms, and the member's control over what is collected; workout and body data is health data where it reveals health, and the notice should treat it as such.
Marketing, class bookings and the messages members receive
Booking confirmations, class cancellations and membership notices are service messages, but offers, referrals and newsletters are marketing, and regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 allows electronic marketing to individuals only with consent or under the soft opt-in (which it can for members who were offered the chance to refuse at sign-up), with an unsubscribe in every message; the notice should say which the business relies on, should describe the booking platform and the messaging tools, and the website's cookies and the booking widget's tracking need the consent mechanism the pack provides guidance on.
Freelance instructors, personal trainers and who controls what
Self-employed trainers and instructors who work in the gym collect data about the members they train (programmes, progress, health information) and the notice should say who the controller is for it: the gym, where the trainer works under its direction and systems, or the trainer, where they run their own client relationship, with the licence or contract between them setting the position and each having a notice; the notice should also cover how an individual exercises the rights of access, correction, erasure, restriction, portability and objection, the one-month limit on the response, and the right to go to the Information Commissioner's Office, and registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018 is required where the fee applies, and the notice can state it.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our members fill in a health questionnaire. What basis do we use?
Explicit consent where the member chooses what to disclose, or the business's legal obligation and legitimate interests in safety with the substantial public interest condition and the policy document the Act requires. The notice states the condition and limits who sees the data and for how long.
Can we use fingerprint entry?
With explicit consent, a non-biometric alternative, a data protection impact assessment and the regulator's biometric guidance followed. The notice describes the system; the assessment is the business's.
Who owns the data our freelance trainers collect about members?
What the licence between the gym and the trainer says, which the notice reflects: the gym where the trainer works under its systems, the trainer where they run their own client relationship. Each then needs a notice for what they control.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Shareholders agreement for a gym or fitness studio
- Privacy notice for a business using CCTV
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.