Certix

Sport & wellness

Data protection for
gyms and sports centres

Video surveillance, health questionnaires and the management of images on social media generate significant obligations that should be understood and properly managed.

Art. 9

GDPR — health questionnaires

30 days

maximum video surveillance retention

72 h

to notify a data breach

24 h

personalised proposal

Regulatory context

General obligations for gyms and sports centres

Gyms manage both standard member and employee data and special category data: health questionnaires and data relating to minors. Each type of data has its own rules.

Video surveillance in facilities

Installing cameras requires a prior proportionality assessment, a clearly visible information sign and a maximum retention period of 30 days. It is prohibited in changing rooms, showers and toilets. Each area and purpose must be assessed separately.

Health questionnaires (art. 9 GDPR)

Questions about illnesses, injuries or physical limitations collect special category health data. Their processing requires a specific legal basis, restricted access, and must be limited to the absolute minimum necessary.

Minor members

Minor members require special attention. The usual basis is the contract with their parents or legal representatives. For additional processing — such as images on social media — each situation requires individual analysis.

Training and tracking apps

Applications for tracking activity, training plans or health metrics linked to the member may act as data processors. The legal relationship depends on each provider and must be analysed on a case-by-case basis.

Employee and instructor management

Payroll, occupational health data, scheduling and the hiring of instructors generate employee data with their own obligations. Instructors' access to member data must also be documented.

Legal obligation

Is a Data Protection Officer (DPO) mandatory for a gym?

As a general rule, gyms and sports centres are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. For most centres, a DPO is not required by law automatically. This information is for guidance only; whether the obligation applies depends on the specific circumstances and each case must be analysed individually.

However, gyms that process health data on a large scale and systematically must rigorously assess whether the circumstances triggering the obligation are present. The size, member volume and exact nature of the processing activities are the determining factors.

As a general rule, the final requirement will depend on the scale, volume and exact nature of each centre's processing activities. Each case requires individual analysis. Where analysis recommends the designation, Certix's external DPO assumes this function under a contract separate from the standard consultancy service.

When to assess the designation of a DPO

Gym chains with a large number of members

The volume and scale of processing are relevant factors to consider when assessing designation.

Health programmes with detailed medical data

If clinical data are collected systematically, large-scale processing of special categories may require a DPO.

Continuous activity tracking with wearables

Systematic large-scale processing of health data requires a rigorous assessment of the obligation to designate a DPO.

Centres with medical or physiotherapy services

If the gym integrates healthcare services, assessing the DPO obligation is a priority.

The service

What the data protection service for your gym includes

The standard Certix contract, adapted to the specific circumstances of a gym or sports centre.

RoPA and technical-organisational structure

Tailored Record of Processing Activities: members, employees, video surveillance, health questionnaires and external processors.

Adapted information clauses

First and second-layer texts for the member enrolment form, web forms, video surveillance cameras and training apps.

Adapted web documentation

Documentation adapted for the gym website: contact form, class bookings and online shop where applicable.

Data Processing Agreements (DPA)

DPA templates for management software, training apps, booking platforms and other providers with access to member data.

Data breach protocol

Procedure to detect, classify and notify incidents to the AEPD within the 72-hour period required by the GDPR.

Data subject rights management

Documented procedure for handling requests from members and employees: access, rectification, erasure and objection.

Document management platform

Access to a private platform with all documents, templates and electronic signature, updated in real time.

Ongoing support

Ongoing support in response to regulatory changes, new AEPD guidance or changes in the centre's activity.

External DPO (if applicable)

Separate contract, quoted individually, if the activity analysis recommends the designation of a Data Protection Officer (DPO).

Do you need a proposal for your gym?

Tell us about your activity and the size of the centre. Personalised proposal in under 24 hours.

Request a proposal

Critical aspects

What matters most to know before implementing any system

There are decisions in the management of a gym that have severe regulatory implications and that should be analysed before implementation:

  • Video surveillance in sensitive areas. Cameras in changing rooms, showers or toilets are strictly prohibited: these are areas where users have a reasonable expectation of privacy. In the rest of the premises, their installation requires a prior proportionality assessment, a clearly visible information sign, restricted access to recordings, and deletion within a maximum period of 30 days.
  • Health questionnaires and PAR-Q. Questions about illnesses or physical limitations generate health data. Their collection must be justified, limited to the minimum necessary, and access restricted to staff with functions directly related to the provision of the service.
  • Minors. Minor members require special attention. The usual basis for the service is the contract with the parents or legal representatives. For additional processing — particularly the use of images on social media or promotional materials — each situation must be analysed individually.

Most common legal bases in gyms

Art. 6.1.b GDPR

Performance of the membership contract and subscription management — the main basis for processing standard data.

Art. 9.2.a GDPR

Explicit consent — one of the possible bases for processing special category data.

Art. 9.2.h GDPR

Preventive medicine purposes — may apply to certain health questionnaires linked to sporting activity.

Art. 6.1.f GDPR

Legitimate interest — video surveillance in non-private areas, following a proportionality assessment and with an information sign.

Art. 6.1.a GDPR

Consent — for commercial communications, newsletters and marketing.

FAQ

Frequently asked questions about data protection in gyms

Does a member's health questionnaire contain special category data?

Yes. Any question relating to illnesses, injuries, physical limitations or medical treatments collects health data (art. 9 GDPR). These data require a specific legal basis and may not be accessed by staff without a direct relationship to the service being provided. If the gym has no healthcare staff, it must minimise the collection of health data to the absolute minimum necessary.

Can a gym install video surveillance cameras?

Video surveillance in certain areas may be justified, but requires a prior proportionality assessment, a clearly visible information sign, and compliance with the maximum retention period of 30 days. It is prohibited in areas where people have a reasonable expectation of privacy: changing rooms, showers and toilets. Each installation must be assessed individually.

Is a Data Protection Officer (DPO) mandatory for a gym?

For most gyms and sports centres, the designation of a DPO is not required by law unless the circumstances set out in art. 34 LOPDGDD or art. 37 GDPR are met. However, gyms that process health data on a large scale and systematically (medical monitoring programmes, detailed clinical questionnaires, wearables), or those belonging to large chains, must individually assess their obligation. Each case requires individual analysis.

Can data of minor members of the gym be processed without their consent?

Yes, though under specific conditions. As a general rule, the gym's contractual relationship with a minor member is established through the contract signed by their parents or legal representatives. Consent becomes particularly relevant for processing activities that are not strictly contractual, such as publishing images of the minor on social media or in the centre's promotional materials. Each situation requires individual analysis.

Is the gym's training app a data processor?

It depends on the app's model and its contractual terms. If the gym provides or recommends an app that accesses member data and processes it exclusively on the gym's instructions, it may act as a data processor. Some apps operate under their own terms and may be independent controllers. The exact legal relationship with each provider should be reviewed and formalised using the appropriate instruments.

Can a member who cancels their membership demand the deletion of their data?

Yes, but with qualifications. The right to erasure is not absolute: the gym may retain the data necessary to fulfil legal obligations (fiscal, contractual) for the legally required periods. Once those periods have elapsed, data must be deleted or blocked. The gym must have a documented procedure to handle these requests within one month.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Sport & wellness

GDPR compliance
for your gym.

A data protection expert analyses your activity and proposes the most appropriate solution. No intermediaries, no bureaucracy.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.