Skip to main content

Booking Bible is opening to independent professionals and venue partners — start free

Back to Blog

GDPR Checklist for Yoga and Fitness Studios

A practical controller checklist for lawful use, contracts, access, retention, rights requests, communications, and incidents.

B

The BOOKING BIBLE Team

BOOKING BIBLE

2026-05-11 7 min read
Share

Most venues are controllers for their client and staff data, while a booking provider commonly acts as a processor for defined services. Buying “GDPR-compliant software” does not transfer the venue's responsibilities.

This checklist is operational guidance, not legal advice. Start with the Danish Data Protection Authority's current explanations of the rules and obtain professional advice for your circumstances.

1. Map the data and purpose

List the personal data used for booking, payment, communications, staff administration, access control, and reporting. Record why each category is needed and the lawful basis relied on.

2. Minimize sensitive information

Do not turn free-text notes into an informal health record. If health or accessibility information is genuinely required, define access, retention, and lawful handling separately.

3. Put processor terms in writing

Review the data-processing agreement, instructions, confidentiality, security measures, sub-processors, assistance with rights requests, deletion or return at exit, and audit information.

4. Understand international transfers

Know where each provider and sub-processor processes data and which transfer mechanism applies when data leaves the EEA. “Cloud” is not a location or legal mechanism.

5. Limit access

Give reception, instructors, managers, and finance only the access they need. Remove dormant accounts, require appropriate authentication, and review privileged activity.

6. Set retention rules

Booking history, marketing consent, staff data, access logs, and financial records may need different retention periods. Document the reason for each rule and how deletion is implemented across exports and connected systems.

7. Handle rights requests

Create a procedure to locate, export, correct, restrict, object to, or delete data where applicable. Verify identity and record the response without exposing another person's information.

8. Separate transactional and marketing messages

A booking confirmation is not blanket permission for promotional communication. Preserve consent evidence and make opt-out behavior reliable across connected tools.

9. Prepare for incidents

Staff should know how to report an accidental disclosure, compromised account, or incorrect export. Preserve facts, contain access, assess risk, and follow the applicable notification process.

10. Test the exit

Before signing, ask how to export data and what is deleted when the contract ends. Payment credentials may be governed by a separate processor and may not be portable like ordinary records.

BOOKING BIBLE's current commitments and boundaries are documented on Trust; they should be reviewed alongside your venue's own policies.

B

The BOOKING BIBLE Team

BOOKING BIBLE

Writing about booking operations, product decisions and the work of building Booking Bible.

Related Posts

Next post

How to Compare Mindbody Alternatives in 2026

A neutral evaluation framework for workflows, total cost, payments, migration, client experience, data controls, and contracts.

Useful product and operating notes

Get practical venue guidance and material Booking Bible updates. No noise, and you can unsubscribe at any time.