A gym collects far more personal data than its operator usually realises, and the most common non-compliance sits in biometric access control. Names, addresses, bank details, health declarations, access badge logs, CCTV images and performance data from connected machines all fall under the General Data Protection Regulation (EU) 2016/679. Penalties reach 4% of annual worldwide turnover or 20 million euros, whichever is higher. This guide covers the practical duties for a club operator, with particular attention to the traps in biometrics and connected equipment. It is written for the French regime supervised by the CNIL, and the same regulation applies across Belgium, Luxembourg with their own supervisory authorities, and in Switzerland under the revised federal data protection act.
The core obligations
Two texts apply together in France: the GDPR itself, directly applicable since 25 May 2018, and the amended French data protection act of 6 January 1978, which sets national arrangements. For a gym the major duties are a record of processing activities under article 30, an identified legal basis for each processing operation (contract, consent, legitimate interest or legal obligation), clear information at the point of collection, respect for member rights of access, rectification, erasure, portability, objection and restriction, security measures proportionate to the risk, breach notification to the supervisory authority within 72 hours, and written contracts with every processor.
The five data categories a gym handles
| Category | Concrete examples | Sensitivity |
|---|---|---|
| Identification | Name, address, email, telephone, date of birth | Standard |
| Payment | Bank details, direct debit mandate reference, payment history | Standard, with reinforced security under payment services rules |
| Health | Medical certificate or self-assessment questionnaire, declared conditions, restrictions, heart rate from connected machines | Special category under article 9 |
| Biometric | Fingerprint, facial recognition, palm print used for access control | Special category under article 9, with a specific regime |
| Attendance and performance | Access badges, entry and exit times, connected equipment data (watts, heart rate, time, repetitions) | Standard to sensitive depending on purpose |
Special category data requires either explicit consent or one of the narrow conditions in article 9(2), plus the strongest available security measures.
Biometric access control: where most clubs are non-compliant
Many clubs use fingerprint, facial or palm recognition for member access, marketed on convenience: no badge to lose. In the great majority of cases this practice does not comply.
The reasoning is proportionality under article 5. Biometrics are not justified for simple access control to a gym, because a badge, a membership card or a username and password perform the same function without processing biometric data. Consent alone does not rescue it if biometrics are the only access method offered: a non-biometric alternative must always be available on request, at no extra cost and with no reduction in service. Where biometrics are genuinely justified, storage should be local on a token held by the member rather than centralised on a server, since a central template database multiplies the damage of a breach. A data protection impact assessment under article 35 is mandatory before any systematic biometric processing.
In practice: a club using fingerprints as the sole access method, with no alternative, no documented impact assessment and no formalised explicit consent, is non-compliant. Sanctions observed in the private sector range from formal notice, which can be made public, to administrative fines. Moving to an RFID badge or a login resolves the issue outright.
Membership management software and processor contracts
Most clubs run a membership platform for bookings, billing and access. These suppliers are processors under article 28, and the operator remains the controller. A missing or incomplete processor contract is one of the most frequently recorded failings in inspections of the sports sector.
The contract must be written and must set the duration, the purpose, the security measures and the fate of the data at the end of the contract. Check where the servers sit: if data leaves the European Economic Area, additional safeguards are required, typically standard contractual clauses. Keep an access register listing which of the processor’s staff can reach the data, limited to what is strictly necessary. Finally, the contract must oblige the processor to notify you of any breach fast enough for you to meet your own 72 hour deadline.
CCTV in a gym
Video surveillance sits under a double framework: the GDPR for the personal data filmed, and the French internal security code for video protection of spaces open to the public. Prior prefectoral authorisation is required where cameras cover areas open to the public, such as a reception area accessible without membership.
The other rules are strict and easy to breach. Signage at the entrance must state that surveillance exists, its purpose, the retention period, the controller and how to exercise rights. Retention is capped at 30 days unless a specific incident justifies keeping footage for an ongoing procedure. Changing rooms, toilets and showers must never be filmed, without exception. Permanent filming of staff workstations, including reception and instructor positions, is prohibited under employment law as well as data protection law. Keep a viewing log recording who watched what, when and why.
Health data and connected equipment
Health data is special category data whether it comes from a medical certificate, a self-assessment questionnaire or a heart rate belt. The legal basis must be a strong one, access restricted to authorised staff through a separate area of the software, retention proportionate (typically membership duration plus the statutory contract retention period), and the database encrypted at rest and in transit.
Connected equipment is the newer frontier. Treadmills, bikes and strength machines with touchscreens and smart resistance now collect volumes of individual performance data. Before signing for a connected fleet, three questions decide your exposure.
| Question to the supplier | Why it matters |
|---|---|
| Who is the controller for the data collected on the machine? | If the manufacturer’s cloud platform decides purposes, it is a joint controller, not your processor, and the paperwork differs. |
| Where are the servers, and under which transfer mechanism? | Transfers outside the EEA need documented safeguards. This is a contractual point, not a technical detail. |
| Can the fleet run without individual accounts? | Non-connected machines process no personal data at all, which removes the question. It is a legitimate specification choice. |
The simplest compliance decision is often a specification decision. A robust mechanical fleet with local consoles collects nothing, and for many clubs the connected features are used by a small minority of members. Our guide to commercial cardio equipment specifications sets out where connectivity earns its place.
Frequently asked questions
Do we need a data protection officer?
A single club rarely meets the mandatory appointment criteria, which turn on large-scale monitoring or large-scale processing of special category data. A multi-site chain running biometrics, health questionnaires and connected performance tracking may well cross that line. Appointing one voluntarily is permitted and is often the cheapest way to keep the record of processing current.
How long can we keep a former member’s file?
For the membership duration plus the statutory retention period applying to contracts and accounting records, commonly five years in France. Beyond that, delete or move to secure archive with restricted access. Keeping a full active file indefinitely for marketing purposes is not defensible.
Can we publish member photographs on social media?
Only with specific, informed and freely given consent for that purpose, obtained separately from the membership contract, and withdrawable. A clause buried in the terms and conditions is not valid consent. Keep the consent records: they are what you will be asked for.
Does replacing biometrics with badges solve everything?
It removes the hardest problem. Badge logs are still personal data and still need a legal basis, an information notice, a retention period and access restrictions, but they are ordinary data, not special category data, and they do not require a prior impact assessment for simple access control.
Specify a fleet that fits your compliance position
Light In Fitness has been a manufacturer and B2B distributor of professional fitness equipment since 2013, from Tours in France, with more than 500 facilities equipped. We can specify connected or non-connected fleets according to the data position you want to hold, and supply the technical documentation your record of processing needs. Delivery covers France, Belgium, Switzerland and Luxembourg, with export priced per project, and stock items ship in 5 to 10 working days. Browse the cardio equipment and strength training machines ranges, or request a quote. We reply within 24 working hours.



