Data Protection for Gyms in Switzerland (nFADP 2026)

Since 1 September 2023 the revised Swiss data protection law treats health and biometric data as sensitive. What that means for intake forms, check-ins and member data in a gym or PT studio, the articles that matter, and a 10-step checklist.

Trainera Team
October 11, 2026
8 min read
Data Protection for Gyms in Switzerland (nFADP 2026)
gym data protection SwitzerlandnFADPrevDSG fitnesshealth data consentFDPIC breachpersonal trainer privacy

Get your free AI training and nutrition plan in 60 seconds

What does the Swiss data protection law (nFADP) mean for gyms?

Switzerland's revised Federal Act on Data Protection (nFADP, in German revDSG or nDSG) has applied since 1 September 2023, and it treats health data and identifying biometric data as sensitive personal data (FADP, SR 235.1, Art. 5). For a gym or personal trainer that means injury and health questionnaires, body measurements used for health goals and fingerprint or face entry need extra care, and intentional breaches of key duties can lead to fines of up to CHF 250,000 against the responsible individual.

The rest of this post walks through the articles that matter in a fitness business, a checklist you can work through in an afternoon, and what to ask your software provider. Status as of October 2026.

This is general information, not legal advice. For your own setup, check with a data protection lawyer or the Federal Data Protection and Information Commissioner (FDPIC, in German EDÖB).

Which gym data counts as sensitive under the nFADP?

Under Art. 5 lit. c FADP, sensitive personal data includes, among other things, data relating to health and biometric data that uniquely identifies a natural person.

The law does not list fitness examples. In our reading, these are the gym and coaching data most likely to fall into the sensitive category:

Data you collectLikely categoryWhy
Name, email, phone, addressPersonal dataIdentifies the member
Membership type, payments, check-in timesPersonal dataContract and attendance records
Injuries, illnesses, medication in an intake formSensitive (health)Art. 5 lit. c: data relating to health
Weight, body fat, measurements tied to a health goalProbably sensitive (health context)Depends on context and purpose
Pregnancy or rehab notes from a personal trainerSensitive (health)Health information
Fingerprint or face recognition at the doorSensitive (biometric)Biometric data that uniquely identifies a person
Progress photosPersonal data; check contextCan reveal health information

The middle rows are a judgment call. A simple approach is to handle all intake and progress data as if it were sensitive: it costs little and removes the guesswork.

The nFADP rules that matter most for gyms and trainers

Seven provisions cover most of what a fitness business does with member data day to day.

RuleArticleWhat it means in a gym
Explicit consent for sensitive dataArt. 6 para. 6-7 FADPWhere consent is needed, it must be voluntary after proper information, and for sensitive data it must be explicit
Duty to informArt. 19 FADPTell members what you collect and why when you collect it: a privacy notice
No disclosure of sensitive data without justificationArt. 30 para. 2 lit. c FADPPassing health data to third parties is a violation of personality unless justified
Right of accessArt. 25 FADPA member can ask what you hold; the answer is generally due within 30 days
Data security breachesArt. 24 FADPReport breaches likely to result in a high risk to the FDPIC as soon as possible
ProcessorsArt. 9 FADPA software provider may only process data the way you yourself would be allowed to
Disclosure abroadArt. 16 FADPOnly to countries with adequate protection (Federal Council list) or with suitable safeguards

Source: FADP on Fedlex (text as of 1 September 2023).

One difference from the EU GDPR surprises people. The Swiss law does not require a legal basis for every processing activity. Processing that violates someone's personality needs a justification, such as consent, an overriding private or public interest, or the law (Art. 31 FADP). For sensitive health data in a questionnaire, explicit consent is the clean route.

Impact assessment and records of processing

A data protection impact assessment (DPIA) is required when processing is likely to lead to a high risk, in particular with extensive processing of sensitive data (Art. 22 FADP). A small studio with a few dozen intake forms is in a different position from a chain profiling thousands of members' health data, but the question is worth asking once and writing down.

The record of processing activities (Art. 12 FADP) has an exemption: companies with fewer than 250 employees and natural persons do not have to keep one, unless they process sensitive personal data on a large scale or carry out high-risk profiling (Art. 24 of the Data Protection Ordinance, DPO, as of 15 September 2024). Data security breaches must be documented and the documentation kept for at least 2 years from the notification (Art. 15 para. 4 DPO).

Fines: who pays

The nFADP fines target private individuals, as a rule not the company: up to CHF 250,000 for intentional breaches of duties to inform, to provide access and of due diligence, for example disclosing data abroad without the conditions being met or using a processor without the required safeguards (Art. 60-61 FADP). Only if a fine of at most CHF 50,000 is at stake and finding the responsible person would take disproportionate effort can the business be ordered to pay instead (Art. 64 FADP). In a small gym, the responsible person is often the owner.

Sending member data abroad, including the US

Most gym software, email and payment tools store data somewhere, and Art. 16 FADP decides whether that is allowed.

Disclosure abroad is allowed to countries the Federal Council lists as having adequate protection, or with suitable safeguards such as contract clauses. For the US, the Swiss-U.S. Data Privacy Framework has applied since 15 September 2024: data can go to certified US companies without extra safeguards (Federal Council, 14 August 2024). Whether a given provider is certified is something you check per provider, not something you assume.

Your privacy notice should name the countries where member data goes. Check this on your own site: a privacy page copied from a template often says nothing about the email tool in the US or the booking app hosted elsewhere.

Common mistakes in gyms and PT studios

Many of the risks sit in everyday habits rather than in hacking.

  • Paper PAR-Q forms in an open folder at reception, readable by anyone behind the desk.
  • Health notes in a group chat between trainers, about a member's knee or medication, on a personal phone.
  • One shared login for the gym software, so you cannot tell who saw what.
  • Intake forms that ask everything, including diagnoses that have no bearing on the training.
  • Consent hidden in the general terms, which makes it hard to argue the consent for health data was explicit.
  • No plan for an access request, so 30 days pass while someone searches exports and spreadsheets.
  • Former trainers keep access to member profiles after they leave.

nFADP checklist for a Swiss gym or personal trainer

Work through these steps once, then review them each year or when you change software.

  1. Map your data. List what you collect (contact, contract, payments, check-ins, health intake, measurements, photos, biometric entry), where it is stored and who has access.
  2. Cut what you do not need. Ask only the health questions that change how you train someone.
  3. Get explicit consent for health data with a separate, clear statement in the intake form, not a line in your terms.
  4. Publish a privacy notice (Art. 19): who you are, what you collect, why, who receives it and in which countries.
  5. Sign processing terms with every provider that touches member data (software, email, payments) and check where they store data.
  6. Limit access in the team. Personal logins, role-based access where your software allows it, removal on the last working day.
  7. Prepare a breach process: who decides, how you assess the risk, how you notify the FDPIC, where you document it for 2 years.
  8. Prepare an access request answer so you can respond within 30 days.
  9. Check DPIA and records of processing if you handle health data on a large scale or use biometric entry.
  10. Set retention periods for former members' health data, and delete it when the purpose ends.

Steps 3, 4 and 7 are where an hour with a lawyer pays off, because wording matters.

Where Trainera fits

Trainera is the software where much of this data lives, but the gym or trainer stays the controller and decides what is collected.

  • You are the controller. The gym (or the independent trainer) decides what member data is collected and why, and is responsible for the privacy notice, consent and access requests.
  • Questionnaires (intake forms) are included on every trainer plan, including Free. You choose the questions, so you can keep health questions to what you need and add your own consent statement.
  • Check-ins are recorded with their source (QR, manual, turnstile, registration, offline). The member app shows a digital member card with a QR code.
  • Training and nutrition plans, progress and chat sit in one place instead of spread over spreadsheets and personal phones, which makes an access request easier to answer.
  • What we do not claim: this post makes no statement about Trainera's hosting location, certifications or legal compliance. As with any provider, review the terms and privacy information yourself or with your lawyer before you move member data.
Plan (Switzerland)Monthly priceFor
Trainer StarterCHF 19.90Up to 10 clients
Trainer ProCHF 49.90Up to 30 clients
Trainer BusinessCHF 99Up to 75 clients
Gym CoreCHF 129Gym dashboard, packages, QR check-in, 3 trainers included
Gym White Label / StudioCHF 239 / CHF 279Own branded apps; Studio adds Community Plus and Automations

Prices from trainera.fit/pricing for Switzerland, October 2026; yearly billing is 10 times the monthly price. For how check-in data is collected, see gym check-in and access control software and QR check-in. Lead forms carry personal data too: gym lead management covers the pipeline side. For the rest of the Swiss picture, read gym software in Switzerland and Swiss gym membership contract rules.

Your one-page nFADP summary for the team

Print this and pin it where trainers and reception staff see it.

  • Health and biometric data are sensitive: explicit consent, minimal questions, limited access.
  • Members can ask what we hold: answer within 30 days.
  • Breach with likely high risk: tell the owner at once; FDPIC notification as soon as possible; document it and keep the record for 2 years.
  • No member health details in private chats or on personal phones.
  • Data abroad only with adequate protection or safeguards, and named in the privacy notice.

Want member data, intake forms and check-ins in one place instead of folders and chats? See how Trainera works for gyms.

Frequently Asked Questions

Is health data sensitive under the Swiss data protection law?

Yes. Art. 5 lit. c of the revised FADP (in force since 1 September 2023) lists health data and identifying biometric data as sensitive personal data. Where consent is needed for it, the consent must be explicit.

Do gyms need a record of processing activities in Switzerland?

Companies with fewer than 250 employees are exempt, unless they process sensitive personal data on a large scale or carry out high-risk profiling (Art. 24 DPO). A gym handling lots of health data should check this.

How fast must a gym answer a data access request?

Generally within 30 days under Art. 25 FADP. Prepare in advance where member data is stored so you can export it in time.

What are the fines under the nFADP?

Up to CHF 250,000, imposed on the responsible private individual, for intentional breaches of duties to inform, to provide access and of due diligence (Art. 60-61 FADP). Only in exceptional cases, for fines up to CHF 50,000, can the business itself be ordered to pay (Art. 64).

Is fingerprint entry at a gym allowed in Switzerland?

The law does not ban it, but biometric data that uniquely identifies a person is sensitive. Check consent, information, security and whether an impact assessment is needed with a lawyer before you use it.

Put this into practice with Trainera

Get your free AI training and nutrition plan in 60 seconds

1800+ exercises, wearables and progress tracking, free with no card needed. AI food scanning comes with Premium. Train solo or with a certified coach.

Share This Post