Data Protection for Gyms in Switzerland (nFADP 2026)
Since 1 September 2023 the revised Swiss data protection law treats health and biometric data as sensitive. What that means for intake forms, check-ins and member data in a gym or PT studio, the articles that matter, and a 10-step checklist.

Get your free AI training and nutrition plan in 60 seconds
What does the Swiss data protection law (nFADP) mean for gyms?
Switzerland's revised Federal Act on Data Protection (nFADP, in German revDSG or nDSG) has applied since 1 September 2023, and it treats health data and identifying biometric data as sensitive personal data (FADP, SR 235.1, Art. 5). For a gym or personal trainer that means injury and health questionnaires, body measurements used for health goals and fingerprint or face entry need extra care, and intentional breaches of key duties can lead to fines of up to CHF 250,000 against the responsible individual.
The rest of this post walks through the articles that matter in a fitness business, a checklist you can work through in an afternoon, and what to ask your software provider. Status as of October 2026.
This is general information, not legal advice. For your own setup, check with a data protection lawyer or the Federal Data Protection and Information Commissioner (FDPIC, in German EDÖB).
Which gym data counts as sensitive under the nFADP?
Under Art. 5 lit. c FADP, sensitive personal data includes, among other things, data relating to health and biometric data that uniquely identifies a natural person.
The law does not list fitness examples. In our reading, these are the gym and coaching data most likely to fall into the sensitive category:
| Data you collect | Likely category | Why |
|---|---|---|
| Name, email, phone, address | Personal data | Identifies the member |
| Membership type, payments, check-in times | Personal data | Contract and attendance records |
| Injuries, illnesses, medication in an intake form | Sensitive (health) | Art. 5 lit. c: data relating to health |
| Weight, body fat, measurements tied to a health goal | Probably sensitive (health context) | Depends on context and purpose |
| Pregnancy or rehab notes from a personal trainer | Sensitive (health) | Health information |
| Fingerprint or face recognition at the door | Sensitive (biometric) | Biometric data that uniquely identifies a person |
| Progress photos | Personal data; check context | Can reveal health information |
The middle rows are a judgment call. A simple approach is to handle all intake and progress data as if it were sensitive: it costs little and removes the guesswork.
The nFADP rules that matter most for gyms and trainers
Seven provisions cover most of what a fitness business does with member data day to day.
| Rule | Article | What it means in a gym |
|---|---|---|
| Explicit consent for sensitive data | Art. 6 para. 6-7 FADP | Where consent is needed, it must be voluntary after proper information, and for sensitive data it must be explicit |
| Duty to inform | Art. 19 FADP | Tell members what you collect and why when you collect it: a privacy notice |
| No disclosure of sensitive data without justification | Art. 30 para. 2 lit. c FADP | Passing health data to third parties is a violation of personality unless justified |
| Right of access | Art. 25 FADP | A member can ask what you hold; the answer is generally due within 30 days |
| Data security breaches | Art. 24 FADP | Report breaches likely to result in a high risk to the FDPIC as soon as possible |
| Processors | Art. 9 FADP | A software provider may only process data the way you yourself would be allowed to |
| Disclosure abroad | Art. 16 FADP | Only to countries with adequate protection (Federal Council list) or with suitable safeguards |
Source: FADP on Fedlex (text as of 1 September 2023).
One difference from the EU GDPR surprises people. The Swiss law does not require a legal basis for every processing activity. Processing that violates someone's personality needs a justification, such as consent, an overriding private or public interest, or the law (Art. 31 FADP). For sensitive health data in a questionnaire, explicit consent is the clean route.
Impact assessment and records of processing
A data protection impact assessment (DPIA) is required when processing is likely to lead to a high risk, in particular with extensive processing of sensitive data (Art. 22 FADP). A small studio with a few dozen intake forms is in a different position from a chain profiling thousands of members' health data, but the question is worth asking once and writing down.
The record of processing activities (Art. 12 FADP) has an exemption: companies with fewer than 250 employees and natural persons do not have to keep one, unless they process sensitive personal data on a large scale or carry out high-risk profiling (Art. 24 of the Data Protection Ordinance, DPO, as of 15 September 2024). Data security breaches must be documented and the documentation kept for at least 2 years from the notification (Art. 15 para. 4 DPO).
Fines: who pays
The nFADP fines target private individuals, as a rule not the company: up to CHF 250,000 for intentional breaches of duties to inform, to provide access and of due diligence, for example disclosing data abroad without the conditions being met or using a processor without the required safeguards (Art. 60-61 FADP). Only if a fine of at most CHF 50,000 is at stake and finding the responsible person would take disproportionate effort can the business be ordered to pay instead (Art. 64 FADP). In a small gym, the responsible person is often the owner.
Sending member data abroad, including the US
Most gym software, email and payment tools store data somewhere, and Art. 16 FADP decides whether that is allowed.
Disclosure abroad is allowed to countries the Federal Council lists as having adequate protection, or with suitable safeguards such as contract clauses. For the US, the Swiss-U.S. Data Privacy Framework has applied since 15 September 2024: data can go to certified US companies without extra safeguards (Federal Council, 14 August 2024). Whether a given provider is certified is something you check per provider, not something you assume.
Your privacy notice should name the countries where member data goes. Check this on your own site: a privacy page copied from a template often says nothing about the email tool in the US or the booking app hosted elsewhere.
Common mistakes in gyms and PT studios
Many of the risks sit in everyday habits rather than in hacking.
- Paper PAR-Q forms in an open folder at reception, readable by anyone behind the desk.
- Health notes in a group chat between trainers, about a member's knee or medication, on a personal phone.
- One shared login for the gym software, so you cannot tell who saw what.
- Intake forms that ask everything, including diagnoses that have no bearing on the training.
- Consent hidden in the general terms, which makes it hard to argue the consent for health data was explicit.
- No plan for an access request, so 30 days pass while someone searches exports and spreadsheets.
- Former trainers keep access to member profiles after they leave.
nFADP checklist for a Swiss gym or personal trainer
Work through these steps once, then review them each year or when you change software.
- Map your data. List what you collect (contact, contract, payments, check-ins, health intake, measurements, photos, biometric entry), where it is stored and who has access.
- Cut what you do not need. Ask only the health questions that change how you train someone.
- Get explicit consent for health data with a separate, clear statement in the intake form, not a line in your terms.
- Publish a privacy notice (Art. 19): who you are, what you collect, why, who receives it and in which countries.
- Sign processing terms with every provider that touches member data (software, email, payments) and check where they store data.
- Limit access in the team. Personal logins, role-based access where your software allows it, removal on the last working day.
- Prepare a breach process: who decides, how you assess the risk, how you notify the FDPIC, where you document it for 2 years.
- Prepare an access request answer so you can respond within 30 days.
- Check DPIA and records of processing if you handle health data on a large scale or use biometric entry.
- Set retention periods for former members' health data, and delete it when the purpose ends.
Steps 3, 4 and 7 are where an hour with a lawyer pays off, because wording matters.
Where Trainera fits
Trainera is the software where much of this data lives, but the gym or trainer stays the controller and decides what is collected.
- You are the controller. The gym (or the independent trainer) decides what member data is collected and why, and is responsible for the privacy notice, consent and access requests.
- Questionnaires (intake forms) are included on every trainer plan, including Free. You choose the questions, so you can keep health questions to what you need and add your own consent statement.
- Check-ins are recorded with their source (QR, manual, turnstile, registration, offline). The member app shows a digital member card with a QR code.
- Training and nutrition plans, progress and chat sit in one place instead of spread over spreadsheets and personal phones, which makes an access request easier to answer.
- What we do not claim: this post makes no statement about Trainera's hosting location, certifications or legal compliance. As with any provider, review the terms and privacy information yourself or with your lawyer before you move member data.
| Plan (Switzerland) | Monthly price | For |
|---|---|---|
| Trainer Starter | CHF 19.90 | Up to 10 clients |
| Trainer Pro | CHF 49.90 | Up to 30 clients |
| Trainer Business | CHF 99 | Up to 75 clients |
| Gym Core | CHF 129 | Gym dashboard, packages, QR check-in, 3 trainers included |
| Gym White Label / Studio | CHF 239 / CHF 279 | Own branded apps; Studio adds Community Plus and Automations |
Prices from trainera.fit/pricing for Switzerland, October 2026; yearly billing is 10 times the monthly price. For how check-in data is collected, see gym check-in and access control software and QR check-in. Lead forms carry personal data too: gym lead management covers the pipeline side. For the rest of the Swiss picture, read gym software in Switzerland and Swiss gym membership contract rules.
Your one-page nFADP summary for the team
Print this and pin it where trainers and reception staff see it.
- Health and biometric data are sensitive: explicit consent, minimal questions, limited access.
- Members can ask what we hold: answer within 30 days.
- Breach with likely high risk: tell the owner at once; FDPIC notification as soon as possible; document it and keep the record for 2 years.
- No member health details in private chats or on personal phones.
- Data abroad only with adequate protection or safeguards, and named in the privacy notice.
Want member data, intake forms and check-ins in one place instead of folders and chats? See how Trainera works for gyms.
Frequently Asked Questions
Is health data sensitive under the Swiss data protection law?
Do gyms need a record of processing activities in Switzerland?
How fast must a gym answer a data access request?
What are the fines under the nFADP?
Is fingerprint entry at a gym allowed in Switzerland?
Keep Reading
Put this into practice with Trainera
Get your free AI training and nutrition plan in 60 seconds
1800+ exercises, wearables and progress tracking, free with no card needed. AI food scanning comes with Premium. Train solo or with a certified coach.