Certix

GDPR in gyms and sports centres: minimum documentation and member access control

Certix
Certix®
· 2 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

A gym, sports centre, CrossFit box, pilates studio or personal training room is a controller of personal data from the first registered member. Identification data, contact details, financial data (SEPA direct debit or card), data on the use of the centre (access records, class bookings), in many cases health data provided in the initial questionnaire and, where there is an app or website, also digital behaviour data. The GDPR applies to all of this, regardless of the size of the centre.

This guide explains the proportional minimum documentation any sports centre should have available from day one, and the member access control options compatible with the regulations, in accordance with the GDPR (Regulation (EU) 2016/679), the LOPDGDD (Spain's Organic Law 3/2018) and the LSSICE (Spanish Information Society Services Act, Law 34/2002) where the centre has a digital presence.

Typical processing operations of a gym

Most sports centres can be summarised in five or six processing operations:

Processing Typical data Legal basis
Member sign-up and management Name, ID, contact, date of birth, contract, membership type. Performance of contract (6(1)(b))
Access control Member identifier (RFID, PIN, QR, app), date and time of entry. Performance of contract (6(1)(b))
Billing and collection Data for invoice issuance, IBAN, card, SEPA receipts. Legal obligation (6(1)(c)) + contract (6(1)(b))
Class bookings and appointments Bookings, attendance, waiting lists, personal training. Performance of contract (6(1)(b))
Marketing and communications Newsletter, promotions, website leads, former members. Consent or legitimate interest (6(1)(a)/6(1)(f)) + art. 21 LSSICE
Technical staff and instructors Employment data, payroll, qualifications (sports degrees, federations). Employment contract + legal obligation (6(1)(b) + 6(1)(c))

Where the centre collects health data from the member at sign-up (medical questionnaire, previous injuries, contraindications for certain exercises), an additional processing operation is triggered under art. 9 GDPR, addressed in a specific guide.

Proportional minimum documentation

A small or medium-sized gym reasonably complies with these documentary blocks, without over-engineering:

  • Records of Processing Activities: one page, five or six entries, with the information required by art. 30(1) GDPR.
  • Privacy notices: one for adult member sign-up, another for minor member sign-up (delivered to parents or guardians), one for candidate technical staff and the website privacy policy.
  • Differentiated consent sheet at sign-up for optional processing: member's image on the centre's social media and website, future commercial communications, transfer to related companies (best avoided; if it exists, document it clearly), use of the optional mobile app.
  • Art. 28 GDPR contracts with relevant technology providers: member management software, access control system, payment gateway, booking platform and mobile app, email marketing tool, external accountant.
  • Operational security policy: one or two pages with real measures (individual passwords for staff, two-factor authentication, encrypted backup, control of additions and removals of staff with system access, automatic locking of reception terminals).
  • Breach protocol: two paragraphs on who assesses, in which cases notification to AEPD must be made within 72 hours, and how.
  • Cookie policy on the centre's website, if there is an online presence.
  • CCTV signage at access points where cameras exist (covered in a specific guide).
  • Secure custody of medical questionnaires signed by members, with access restricted to staff with direct duties.

Member access control: options compatible with the GDPR

The access control system is one of the points of greatest technical sensitivity in the gym. The key is to choose options that identify the member without resorting to processing that the regulations severely restrict. The reasonable solutions are:

  • RFID proximity card: card the member carries and presents at the entrance reader or turnstile. The reader identifies the member number, validates whether the fee is up to date and records the access. It is the classic option, robust and well understood by members.
  • Proximity keyring: same technology as the card, in a more compact format. Usually offered as a complement or substitute for the card.
  • Personal PIN code: the member enters a numeric PIN on a keypad at the entrance. Compatible where the centre seeks to minimise physical items to carry.
  • QR code generated by the gym's mobile app: the member opens the app, displays the temporary QR code and the reader validates it. Especially useful for multi-site centres or members who prefer not to carry a physical card.
  • Mobile app with member identifier: the app itself validates entry through an internal identifier or token, without the need for a card or visible QR.

These options process only ordinary identifying data (member number, date and time of access, and in some cases the device model from which the app was accessed) under the legal basis of art. 6(1)(b) GDPR (performance of the member contract). They do not require reinforced legal bases or additional impact assessments beyond reasonable security measures over the system and the record.

Privacy notice at sign-up: what it must contain

The art. 13 GDPR notice is delivered at the time of sign-up, ideally integrated into the contractual document or as a signed annex, and must contain:

  • Identity of the controller (the gym, with tax ID and address) and contact details of the Data Protection Officer if appointed.
  • Specific purposes: member management, access control, bookings, billing, administrative service communications and, where applicable, physical condition assessment at sign-up.
  • Legal bases: performance of the member contract for management, legal obligation for billing, explicit consent for marketing and image.
  • Habitual recipients: external accountant, management platform, payment gateway, tax authorities where applicable.
  • International transfers where tools used operate outside the EEA (typically yes when US solutions such as Stripe, Google Workspace, Mailchimp or some sports CRMs are used). Verify adherence to the Data Privacy Framework.
  • Retention periods by block (contractual, tax, civil).
  • Member's rights and how to exercise them.
  • Mention of the right to lodge a complaint with AEPD.

Contracts with technology providers: the usual weak point

The modern gym typically depends on several SaaS providers: member management software (Trainingym, Provis, Resasports, Mindbody, Glofox and similar), integrated access control system (turnstile, RFID reader, app), payment gateway, email marketing platform and, increasingly, the centre's own mobile app. Each of them is a processor (art. 28 GDPR) and requires a signed contract.

Critical points when contracting:

  • DPA (Data Processing Agreement) signed and filed.
  • Verification of international transfers (Data Privacy Framework for US providers).
  • Procedure for return or export of the member's data to the centre upon termination of the provider's service, so the centre can fulfil its own legal retention periods; destruction by the provider only proceeds after return.
  • Sub-processor clauses (which additional companies access the data through the provider's chain).
  • Reasonable technical and organisational measures: encryption at rest and in transit, access logs, backup.

"In a gym, GDPR done well translates into a clear sign-up, a delivered and signed privacy notice, an access system proportionate to the service and signed contracts with four or five technology providers. You don't need a hundred-page manual: you need a system that is respected every day and a provider who knows the sector."

Mario P. Talamillo · Managing Partner, Certix®

Member's image and the centre's social media

Publishing images of members on the gym's social media (Instagram, TikTok, website, internal posters) requires specific attention:

  • The regime of the right to one's own image (Spanish Organic Law 1/1982) applies in addition to the GDPR.
  • Written, specific, revocable consent, separate from the general sign-up document.
  • Distinguish types of use: institutional image of the centre, challenges and one-off events, testimonials, content in group classes.
  • For minors: mandatory parental consent.
  • Maintain a list of excluded members (revocations, express objections) and an operational procedure for the social media manager to consult before publishing.

Minimum gym checklist

  • Records of processing activities with the actual processing operations (sign-up, access control, billing, bookings, marketing, staff).
  • Privacy notices for adult member, minor member (to parents) and technical staff.
  • Differentiated consent sheet at sign-up.
  • Art. 28 GDPR contracts with management software, access control system, payment gateway, app or booking platform, email marketing and external accountant.
  • Compatible access control system (RFID card, keyring, PIN, app QR code or mobile app) described in the records.
  • Operational security policy adapted to size.
  • Breach protocol and AEPD notification template.
  • Privacy and cookie policy on the website, with correct LSSICE banner.
  • Member image management protocol with exclusion list and revocation procedure.
  • Retention policy by block and secure blocking and destruction procedure.
  • Restricted custody of members' medical questionnaires.

Frequently asked questions

What minimum data protection documentation does a gym need from the first member?

Records of processing activities with identified operations, art. 13 GDPR privacy notice at sign-up, art. 28 GDPR contracts with technology providers (member management, access control, payment gateway, app), basic security policy, breach protocol, cookie policy and CCTV signage where cameras exist.

What member access control system is compatible with the GDPR in a gym?

Compatible systems identify the member through something they carry or know: RFID card, proximity keyring, personal PIN code, QR code generated by the gym's app or mobile app with internal identifier. They process ordinary identifying data under the basis of art. 6(1)(b) GDPR (performance of contract).

Does a small gym with few members need to comply with the GDPR the same way as a large chain?

Yes, with proportional documentary scope. The GDPR applies regardless of size; what varies is the extent. Principles (lawfulness, transparency, minimisation, retention) are the same. AEPD has sanctioned small centres for lack of sign-up information or absence of contracts with technology providers.

Can the gym retain the member's data after they leave?

Yes, for justified periods: billing (Spanish Commercial Code 6 years, General Tax Law 4 years), contractual and civil (5 years art. 1964 Spanish Civil Code). Marketing only while consent lasts. A differentiated policy by block and blocking of data after relationship closure is the clean way to manage it.

This content is merely informative and educational; it does not constitute specialised legal advice in any case. The application of the regulation to each specific case requires individualised analysis. Spanish regional sector regulations may extend or modify periods and requirements.

Want to organise the GDPR compliance of your gym without over-engineering it?

At Certix we assign you an expert in sports sector compliance. No commercial intermediaries, no generic templates.

Talk to an expert

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →