Sport & wellness
Data protection for
gyms and sports centres
Video surveillance, health questionnaires and the management of images on social media generate significant obligations that should be understood and properly managed.
Art. 9
GDPR — health questionnaires
30 days
maximum video surveillance retention
72 h
to notify a data breach
24 h
personalised proposal
Regulatory context
General obligations for gyms and sports centres
Gyms manage both standard member and employee data and special category data: health questionnaires and data relating to minors. Each type of data has its own rules.
Video surveillance in facilities
Installing cameras requires a prior proportionality assessment, a clearly visible information sign and a maximum retention period of 30 days. It is prohibited in changing rooms, showers and toilets. Each area and purpose must be assessed separately.
Health questionnaires (art. 9 GDPR)
Questions about illnesses, injuries or physical limitations collect special category health data. Their processing requires a specific legal basis, restricted access, and must be limited to the absolute minimum necessary.
Minor members
Minor members require special attention. The usual basis is the contract with their parents or legal representatives. For additional processing — such as images on social media — each situation requires individual analysis.
Training and tracking apps
Applications for tracking activity, training plans or health metrics linked to the member may act as data processors. The legal relationship depends on each provider and must be analysed on a case-by-case basis.
Employee and instructor management
Payroll, occupational health data, scheduling and the hiring of instructors generate employee data with their own obligations. Instructors' access to member data must also be documented.
Legal obligation
Is a Data Protection Officer (DPO) mandatory for a gym?
As a general rule, gyms and sports centres are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. For most centres, a DPO is not required by law automatically. This information is for guidance only; whether the obligation applies depends on the specific circumstances and each case must be analysed individually.
However, gyms that process health data on a large scale and systematically must rigorously assess whether the circumstances triggering the obligation are present. The size, member volume and exact nature of the processing activities are the determining factors.
As a general rule, the final requirement will depend on the scale, volume and exact nature of each centre's processing activities. Each case requires individual analysis. Where analysis recommends the designation, Certix's external DPO assumes this function under a contract separate from the standard consultancy service.
When to assess the designation of a DPO
Gym chains with a large number of members
The volume and scale of processing are relevant factors to consider when assessing designation.
Health programmes with detailed medical data
If clinical data are collected systematically, large-scale processing of special categories may require a DPO.
Continuous activity tracking with wearables
Systematic large-scale processing of health data requires a rigorous assessment of the obligation to designate a DPO.
Centres with medical or physiotherapy services
If the gym integrates healthcare services, assessing the DPO obligation is a priority.
The service
What the data protection service for your gym includes
The standard Certix contract, adapted to the specific circumstances of a gym or sports centre.
RoPA and technical-organisational structure
Tailored Record of Processing Activities: members, employees, video surveillance, health questionnaires and external processors.
Adapted information clauses
First and second-layer texts for the member enrolment form, web forms, video surveillance cameras and training apps.
Adapted web documentation
Documentation adapted for the gym website: contact form, class bookings and online shop where applicable.
Data Processing Agreements (DPA)
DPA templates for management software, training apps, booking platforms and other providers with access to member data.
Data breach protocol
Procedure to detect, classify and notify incidents to the AEPD within the 72-hour period required by the GDPR.
Data subject rights management
Documented procedure for handling requests from members and employees: access, rectification, erasure and objection.
Document management platform
Access to a private platform with all documents, templates and electronic signature, updated in real time.
Ongoing support
Ongoing support in response to regulatory changes, new AEPD guidance or changes in the centre's activity.
External DPO (if applicable)
Separate contract, quoted individually, if the activity analysis recommends the designation of a Data Protection Officer (DPO).
Do you need a proposal for your gym?
Tell us about your activity and the size of the centre. Personalised proposal in under 24 hours.
Critical aspects
What matters most to know before implementing any system
There are decisions in the management of a gym that have severe regulatory implications and that should be analysed before implementation:
- Video surveillance in sensitive areas. Cameras in changing rooms, showers or toilets are strictly prohibited: these are areas where users have a reasonable expectation of privacy. In the rest of the premises, their installation requires a prior proportionality assessment, a clearly visible information sign, restricted access to recordings, and deletion within a maximum period of 30 days.
- Health questionnaires and PAR-Q. Questions about illnesses or physical limitations generate health data. Their collection must be justified, limited to the minimum necessary, and access restricted to staff with functions directly related to the provision of the service.
- Minors. Minor members require special attention. The usual basis for the service is the contract with the parents or legal representatives. For additional processing — particularly the use of images on social media or promotional materials — each situation must be analysed individually.
Most common legal bases in gyms
Art. 6.1.b GDPR
Performance of the membership contract and subscription management — the main basis for processing standard data.
Art. 9.2.a GDPR
Explicit consent — one of the possible bases for processing special category data.
Art. 9.2.h GDPR
Preventive medicine purposes — may apply to certain health questionnaires linked to sporting activity.
Art. 6.1.f GDPR
Legitimate interest — video surveillance in non-private areas, following a proportionality assessment and with an information sign.
Art. 6.1.a GDPR
Consent — for commercial communications, newsletters and marketing.
FAQ
Frequently asked questions about data protection in gyms
Does a member's health questionnaire contain special category data?
Yes. Any question relating to illnesses, injuries, physical limitations or medical treatments collects health data (art. 9 GDPR). These data require a specific legal basis and may not be accessed by staff without a direct relationship to the service being provided. If the gym has no healthcare staff, it must minimise the collection of health data to the absolute minimum necessary.
Can a gym install video surveillance cameras?
Video surveillance in certain areas may be justified, but requires a prior proportionality assessment, a clearly visible information sign, and compliance with the maximum retention period of 30 days. It is prohibited in areas where people have a reasonable expectation of privacy: changing rooms, showers and toilets. Each installation must be assessed individually.
Is a Data Protection Officer (DPO) mandatory for a gym?
For most gyms and sports centres, the designation of a DPO is not required by law unless the circumstances set out in art. 34 LOPDGDD or art. 37 GDPR are met. However, gyms that process health data on a large scale and systematically (medical monitoring programmes, detailed clinical questionnaires, wearables), or those belonging to large chains, must individually assess their obligation. Each case requires individual analysis.
Can data of minor members of the gym be processed without their consent?
Yes, though under specific conditions. As a general rule, the gym's contractual relationship with a minor member is established through the contract signed by their parents or legal representatives. Consent becomes particularly relevant for processing activities that are not strictly contractual, such as publishing images of the minor on social media or in the centre's promotional materials. Each situation requires individual analysis.
Is the gym's training app a data processor?
It depends on the app's model and its contractual terms. If the gym provides or recommends an app that accesses member data and processes it exclusively on the gym's instructions, it may act as a data processor. Some apps operate under their own terms and may be independent controllers. The exact legal relationship with each provider should be reviewed and formalised using the appropriate instruments.
Can a member who cancels their membership demand the deletion of their data?
Yes, but with qualifications. The right to erasure is not absolute: the gym may retain the data necessary to fulfil legal obligations (fiscal, contractual) for the legally required periods. Once those periods have elapsed, data must be deleted or blocked. The gym must have a documented procedure to handle these requests within one month.
Sector resources
Learn more
Gyms
GDPR in gyms and sports centres: minimum documentation and member access control
GDPR compliance adapted to a gym: proportional records of processing activities, sign-up privacy notice, contracts with technology providers, compatible access control system (RFID, PIN, app, QR) and operational security policy.
8 min·Read article
Gyms
Medical questionnaires in gyms: member health data and GDPR
How to legally handle the member’s medical questionnaire in a gym: dual legal basis (art. 6 and art. 9 GDPR), explicit consent, vital interests, secure custody, restricted access and retention periods.
7 min·Read article
Gyms
CCTV in gyms: permitted areas, prohibited areas and GDPR
Where a gym can and cannot install cameras: permitted areas (entrance, reception), prohibited areas (changing rooms, showers, massage rooms), signage under art. 22 LOPDGDD and retention periods.
7 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Sport & wellness
GDPR compliance
for your gym.
A data protection expert analyses your activity and proposes the most appropriate solution. No intermediaries, no bureaucracy.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.