Gyms, memberships and the health questionnaire nobody deletes
A gym holds two things worth protecting: a card that gets billed every month, and a health form that counts as sensitive data. They are usually stored together and kept for years.
A gym or leisure business sits on an unusual combination. There is the recurring payment - a card or direct debit that gets charged every month without anyone re-entering it - and there is the pre-exercise health questionnaire, which asks about heart conditions, injuries, medication and pregnancy. That second one is special category data under UK law, the kind that needs more care, and it is almost always filled in on paper or a basic form and then never looked at again.
The retention habit is the weak point. Members join, they lapse, they rejoin, and their forms accumulate. Five years on you are holding the medical details and billing information of hundreds of people, most of whom left long ago, in whatever system you happened to use at the time. Nobody decided to keep it. Nobody decided to delete it either, and that is precisely the problem.
The recurring payment side deserves its own thought. Stored card details or mandate information are exactly what a fraudster wants, and a gym's booking system is rarely the most hardened piece of software in the world. If it is breached, the harm is not just a mailing list going astray - it is billing details and health information about your members, and that is a report to the ICO and a very uncomfortable set of phone calls.
The practical answer is ordinary. Do not store card numbers yourself - let a proper payment provider hold them. Keep health questionnaires only as long as the member is active, plus a sensible window, then delete them on a schedule. And make sure the people with access to that system is a short, current list, not everyone who has ever worked a shift on reception.
- ✓Use a payment provider that stores card details for you, rather than keeping card numbers yourself.
- ✓Set a retention schedule for health questionnaires and delete lapsed members' data.
- ✓Restrict access to the booking system to current staff who genuinely need it.
- ✓Treat health forms as special category data: extra care, less sharing, shorter storage.
- Special category data: what it is and how to handle it INFORMATION COMMISSIONER'S OFFICE ↗
- Small Business Guide: protecting customer data NATIONAL CYBER SECURITY CENTRE ↗
- Storing customer payment details safely UK FINANCE ↗
- Data protection: retention and deletion GOV.UK ↗
Links open each publisher’s live coverage of this topic.