Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
SECTOR 25 JUN 2026 · 3 MIN

Gyms, memberships and the health questionnaire nobody deletes

A gym holds two things worth protecting: a card that gets billed every month, and a health form that counts as sensitive data. They are usually stored together and kept for years.

RHODRI EMRYS · ASSURANCE
SHARE LinkedIn X Email
SECTOR cover image

A gym or leisure business sits on an unusual combination. There is the recurring payment - a card or direct debit that gets charged every month without anyone re-entering it - and there is the pre-exercise health questionnaire, which asks about heart conditions, injuries, medication and pregnancy. That second one is special category data under UK law, the kind that needs more care, and it is almost always filled in on paper or a basic form and then never looked at again.

The retention habit is the weak point. Members join, they lapse, they rejoin, and their forms accumulate. Five years on you are holding the medical details and billing information of hundreds of people, most of whom left long ago, in whatever system you happened to use at the time. Nobody decided to keep it. Nobody decided to delete it either, and that is precisely the problem.

The recurring payment side deserves its own thought. Stored card details or mandate information are exactly what a fraudster wants, and a gym's booking system is rarely the most hardened piece of software in the world. If it is breached, the harm is not just a mailing list going astray - it is billing details and health information about your members, and that is a report to the ICO and a very uncomfortable set of phone calls.

The practical answer is ordinary. Do not store card numbers yourself - let a proper payment provider hold them. Keep health questionnaires only as long as the member is active, plus a sensible window, then delete them on a schedule. And make sure the people with access to that system is a short, current list, not everyone who has ever worked a shift on reception.

WHAT TO DO
  • ✓Use a payment provider that stores card details for you, rather than keeping card numbers yourself.
  • ✓Set a retention schedule for health questionnaires and delete lapsed members' data.
  • ✓Restrict access to the booking system to current staff who genuinely need it.
  • ✓Treat health forms as special category data: extra care, less sharing, shorter storage.