GDPR Checklist for Yoga and Fitness Studios
A practical controller checklist for lawful use, contracts, access, retention, rights requests, communications, and incidents.
Most venues are controllers for their client and staff data, while a booking provider commonly acts as a processor for defined services. Buying “GDPR-compliant software” does not transfer the venue's responsibilities.
This checklist is operational guidance, not legal advice. Start with the Danish Data Protection Authority's current explanations of the rules and obtain professional advice for your circumstances.
1. Map the data and purpose
List the personal data used for booking, payment, communications, staff administration, access control, and reporting. Record why each category is needed and the lawful basis relied on.
2. Minimize sensitive information
Do not turn free-text notes into an informal health record. If health or accessibility information is genuinely required, define access, retention, and lawful handling separately.
3. Put processor terms in writing
Review the data-processing agreement, instructions, confidentiality, security measures, sub-processors, assistance with rights requests, deletion or return at exit, and audit information.
4. Understand international transfers
Know where each provider and sub-processor processes data and which transfer mechanism applies when data leaves the EEA. “Cloud” is not a location or legal mechanism.
5. Limit access
Give reception, instructors, managers, and finance only the access they need. Remove dormant accounts, require appropriate authentication, and review privileged activity.
6. Set retention rules
Booking history, marketing consent, staff data, access logs, and financial records may need different retention periods. Document the reason for each rule and how deletion is implemented across exports and connected systems.
7. Handle rights requests
Create a procedure to locate, export, correct, restrict, object to, or delete data where applicable. Verify identity and record the response without exposing another person's information.
8. Separate transactional and marketing messages
A booking confirmation is not blanket permission for promotional communication. Preserve consent evidence and make opt-out behavior reliable across connected tools.
9. Prepare for incidents
Staff should know how to report an accidental disclosure, compromised account, or incorrect export. Preserve facts, contain access, assess risk, and follow the applicable notification process.
10. Test the exit
Before signing, ask how to export data and what is deleted when the contract ends. Payment credentials may be governed by a separate processor and may not be portable like ordinary records.
BOOKING BIBLE's current commitments and boundaries are documented on Trust; they should be reviewed alongside your venue's own policies.
The BOOKING BIBLE Team
BOOKING BIBLE
Writing about booking operations, product decisions and the work of building Booking Bible.
Related Posts
How to Compare Mindbody Alternatives in 2026
A neutral evaluation framework for workflows, total cost, payments, migration, client experience, data controls, and contracts.
Useful product and operating notes
Get practical venue guidance and material Booking Bible updates. No noise, and you can unsubscribe at any time.