AI and coaching privacy: what coaches need to arrange now
AI and coaching privacy: what coaches need to arrange now

Conduct a DPIA as soon as AI processes coachees' personal data, limit what you share to the strictly necessary, and review every AI report yourself before it reaches a client. Sign a data processing agreement with every provider and ask where the data is stored. The GDPR and the Dutch Data Protection Authority form the framework here. A workspace such as Exantur helps coaches organise these steps, but responsibility remains with the coach.
In short:
- A DPIA is often required for AI applications that pose a high risk to clients, especially in behavioural and health analysis.
- Process only the necessary data, such as pseudonymised data and anonymised information, to prevent data breaches and confidentiality issues.
- Always ask about EU hosting, sign a data processing agreement, and limit access to data through role assignment and logs.
- Keep coaching notes and personnel files strictly separate and always explicitly inform clients about the use of AI.
- Use AI primarily for summaries and reports, but stay in control yourself, because human judgement remains essential for ethics and trust.
Table of contents
- Checklist: what to check before using AI in your practice
- When is a data protection impact assessment required?
- Which technical measures should you require from your AI provider?
- Coaching data and personnel files: keep them separate
- Bias, hallucinations, and data breaches: the risks of AI models
- Anonymising and pseudonymising coaching data: how do you approach it?
- AI in coaching: what it works for and what it doesn't
- What do legislation and regulators say about AI in coaching?
- What does AI do to confidentiality and ethics in coaching?
- A practical perspective: what works and what doesn't
- How Exantur helps with privacy-conscious AI support
- Key sources for support
- Sources
- Frequently asked questions
Checklist: what to check before using AI in your practice
Before enabling an AI feature, you go through a set of fixed checks. This checklist prevents you from having to explain later why client data ended up somewhere it didn't belong.
Legal basis and purpose limitation. Ask yourself why you are processing this data and whether AI is really necessary for it. Summarising a session report is something different from predicting a client's behaviour. Both require different justification.
Determine whether a DPIA is required. A data protection impact assessment (DPIA) is a risk analysis you carry out in advance when a processing operation is likely to result in a high risk to the people whose data you process. The Dutch Data Protection Authority (AP) indicates that the use of AI often falls under this obligation, particularly when the system supports decisions or analyses behaviour based on personal data. In the DPIA, describe which data you process, why, what risks this poses for the client, and what measures you take to mitigate those risks.
Map out data categories. Session notes quickly contain more than just goals and action points. Health, relationships, religious beliefs, or mental health issues can appear in them. These are special categories of personal data, and they require extra protection under Article 9 of the GDPR. Mark for yourself which notes contain this kind of information before submitting them to an AI feature.
Ask about EU hosting, the data processing agreement, and retention periods. A provider that processes your data is a processor within the meaning of the GDPR. That requires a data processing agreement (also known as a DPA) that specifies what the provider may and may not do with the data. Also ask where the servers are located. Data that stays within the European Union falls under the same privacy legislation as your own practice, which avoids discussions about transfers to countries outside the EU.
Limit what goes to AI. Never send a complete client file to an AI feature if a summary of the session is sufficient. Remove names, dates of birth, and other identifying data where possible before text is processed. This is called data minimisation: using only what is truly necessary for the purpose.
Arrange access, roles, and logs. Not everyone in your organisation needs to be able to access every client file. Assign roles: who may read notes, who may edit them, who may export reports. A log of who did what (audit logging) makes clear afterwards what happened with a file, which is indispensable if a client asks who has viewed their data.
Pro tip: Make a fixed list of what may never appear in an AI prompt: full names, dates of birth, addresses, and medical terms. Print it out and hang it next to your screen. That works better than relying on memory during a busy workday.

When is a data protection impact assessment required?
A DPIA is needed as soon as a processing operation poses a high risk to clients' rights. With AI in coaching, this is the case sooner than many coaches think, especially if the system recognises patterns in behaviour or processes health-related information. The AP clearly states that organisations deploying AI must comply with the GDPR and are in many cases required to carry out such an assessment.
In the DPIA, you describe:
- Which data the AI processes and for what purpose.
- What risks this poses for the client, for example in the event of a data breach or an incorrect conclusion from an AI summary.
- What measures you take to reduce those risks, such as data minimisation or human review in advance.
- Who within your practice is responsible for overseeing the use of AI.
Legal bases and the limitations of consent. Consent seems like the easiest legal basis, but it isn't always. A client who depends on your coaching may not feel free to say no to the use of AI, and that undermines the validity of that consent. Often a contract with the client, or a legitimate interest with a careful assessment, is a firmer foundation. For each processing operation, record which legal basis you use and why.
Transparency towards clients. Explicitly tell clients when AI is used in drawing up session reports or reports. A simple sentence in your intake document is often enough: "For session preparation and summaries, I may use an AI tool. I check every result myself before you receive it." That one sentence prevents a difficult conversation later.
Access and deletion requests. Clients have the right to ask what data you hold about them and to request deletion. Respond to such a request within a month. Make sure you know which systems contain client data, including data processed via an AI feature, otherwise you cannot fully handle such a request.
When in doubt about a high-risk application, it is wise to consult the AP or to engage a data protection officer (DPO), especially at larger coaching organisations with multiple coaches and clients.
Which technical measures should you require from your AI provider?
Privacy by design means that data protection is already built in before you use the tool, not added as a separate afterthought, as explained in this praktyczny przewodnik pilota. Privacy by default means that the most cautious setting is enabled by default, so you don't have to switch anything off yourself to work safely. For coaches, this translates into a few concrete questions to ask every provider.
Data minimisation and pseudonymisation in practice. With pseudonymisation, you replace a name with a code or number, so that an AI model works with "client 104" instead of an actual name. The link between code and name is kept separately, accessible only to you. This does not mean that data becomes unrecognisable, but it significantly reduces the risk in the event of a breach.
AI works best on anonymised or derived data. An AI feature rarely needs to see a client's full name, date of birth, or contact details to create a session summary. The AP advises organisations to first investigate whether a task can be done without personal data, and only then choose an approach with strong safeguards if that isn't possible.
Access management, logging, and incident response. Multi-factor authentication (MFA) means that in addition to a password, you need a second confirmation, for example a code on your phone, to log in. This prevents a stolen password alone from granting access to client files. A log of actions (who logged in when, who viewed which file) makes it possible, in the event of an incident, to quickly see what happened and who to inform.
Research into the PRISM-Coach model shows an approach in which data is split into separate layers: who someone is, what happens operationally, what is being learned, and what is being coached. The AI only gets access to the layers needed for the task, never to the full identity at once, and a human always checks the result before it goes further. For coaches, the core message is simple: the less an AI system sees at once, the smaller the damage in the event of an error or a breach.

Research into this kind of separation model shows that coaching tools work best when personal identity and substantive coaching data are deliberately kept separate, precisely because personalisation and privacy are often at odds: the more a system links data together over time, the more personal the advice, but also the greater the privacy risk.
Coaching data and personnel files: keep them separate
Do you work as a coach within an organisation, for example in career guidance or leadership coaching on behalf of an employer? Then keep coaching notes strictly separate from the personnel file. Coaching data is confidential between coach and coachee. As soon as that information ends up in an HR system, a manager or HR employee can read along, and that undermines the trust that coaching precisely needs.
At the start of an assignment, agree on what the employer will and will not be able to see. Record this agreement in writing in the coaching agreement, so the coachee knows where they stand.
Do you use AI to draw up reports for the client organisation? Make sure the AI feature only has access to the data intended for that report, not to the full session notes. A system that stores coaching data and personnel data in the same environment makes that separation technically harder to maintain than a system that already keeps them separate.
Bias, hallucinations, and data breaches: the risks of AI models
AI models make mistakes in ways that coaches don't always expect. A language model can fabricate facts that sound convincing but aren't true, also known as a hallucination. With a session summary, that could mean the AI mentions an action point that was never discussed, or draws a conclusion the coachee never expressed.
Bias is another risk: an AI model is trained on large amounts of text from the past, and that text often contains prejudices about gender, culture, or age. A scientific analysis of AI coaches points to this risk and argues for deliberate steering and human review to prevent such patterns from unnoticed working their way into coaching advice.
Data breaches are the third risk. Client data that goes to an external AI model leaves your own system. The less data you send along, the smaller the damage if something goes wrong somewhere. Therefore always choose the most restrictive setting and check every AI result yourself before sharing it with a client.
Anonymising and pseudonymising coaching data: how do you approach it?
Anonymising goes further than pseudonymising: with anonymisation, the link to a real person is completely and irreversibly gone. With pseudonymising, that link is kept somewhere, just not visible to the AI feature itself.
For everyday use, pseudonymisation works practically. Replace names in your notes with a client number before submitting text to an AI feature. Remove specific place names, employers, and family members if they are not relevant to the summary. Keep the link between number and name separate, outside the AI system.
For reports at group level, for example a team analysis after multiple coaching processes, full anonymisation is possible. In that case, don't combine characteristics that could still make someone identifiable, such as job title plus department plus gender in a small team. Three individually harmless details can, together, give away one person.
AI in coaching: what it works for and what it doesn't
AI is strong at summarising session notes, recognising recurring themes across multiple sessions, and drafting a first draft for a final report. It saves coaches time on administrative work, time that can then go to the client.
AI is less suited to interpreting emotional nuance, gauging what a client isn't saying, or making decisions about the direction of a process. That requires a coach's empathy, something a language model doesn't have. Therefore use AI as a tool to support documentation, never as a replacement for your own judgement. Meaningful human intervention, that is, a coach who checks every AI result before it reaches the client, remains at the core of responsible use.
What do legislation and regulators say about AI in coaching?
There are still hardly any specific court cases about AI in coaching. The GDPR remains the defining framework, supplemented by the European AI Act for systems designated as high-risk. The AP oversees compliance with the GDPR and published a practical tool for generative AI with which organisations can test in advance whether their use complies with the rules.
That tool emphasises three things that apply directly to coaching: first investigate whether a task can be done without personal data, apply privacy by design and data minimisation where that isn't possible, and ensure meaningful human intervention for every result that affects a client. Coaches who follow these three points are in a stronger position if the AP ever asks for accountability.
Don't wait for case law before taking action. The GDPR has been in force since 2018, and regulators expect organisations to manage AI risks now, not only after a court has issued a ruling.
What does AI do to confidentiality and ethics in coaching?
Confidentiality is the foundation of a coaching relationship. A client shares things with a coach that they tell no one else, precisely because they trust it stays there. As soon as AI enters that process, something fundamental changes: a third party comes into play, even if it isn't a human.
Therefore always explain to clients when and for what you use AI. Some clients don't mind, others explicitly want certain conversations never to be processed by an AI system. Respect that boundary and record which sessions are and are not eligible for AI support.
Ethically, the coach remains ultimately responsible for every piece of advice and every conclusion, even if it was partly reached via AI. An AI summary that introduces a wrong nuance can damage a client's trust in one go. AI literacy, that is, knowing what an AI system can and cannot do well, is therefore just as much part of the coaching profession as conversation skills.
A practical perspective: what works and what doesn't
Coaches who forward AI summaries without checking run into problems faster than they expect. An AI that summarises a session sometimes misses the tone of the conversation, or draws a conclusion that is just off the mark. A client who reads such a report and thinks "this isn't quite right" loses a bit of trust that you, as a coach, only recover with difficulty.
What does work: using AI for a first draft, and always reading through and adjusting that draft yourself before it reaches the client. That takes a few minutes per session, but prevents a client from feeling misunderstood by a machine. The coach remains the final check, not the AI.
Practices that take privacy as a starting point rather than an afterthought notice that the conversation with clients goes more smoothly. A client who hears that data stays within the EU and that every AI report is checked by the coach asks fewer questions and starts with confidence more quickly. That is precisely what a workspace such as Exantur addresses: providing structure and control, so the coach can concentrate on content rather than on technology.
— Martijn
How Exantur helps with privacy-conscious AI support
Exantur is built for coaches who take confidentiality as seriously as their profession itself. Your data is stored on servers within the European Union, in Frankfurt, and each practice works in its own segregated environment, so that data from one coaching practice never gets mixed with that of another. There is a data processing agreement, and you secure access to your account with multi-factor authentication.
Exantur's optional AI assistant drafts session summaries, session preparations, and final reports from your own notes, without client-identifying data going to the underlying model. You remain the one who reviews every report before a client sees it, exactly as the checklist in this article recommends. Session notes, goals, and progress remain clearly linked to the right client, which makes a DPIA and a conversation with a GDPR advisor a good deal easier.
Would you like to see how this works in your own practice? Take a look at Exantur's plans and start the free 14-day trial. After the trial period, the chosen paid plan automatically begins, unless you cancel before the end.
Key sources for support
For those who want to delve deeper into the subject, these are the main references behind this article:
- The AP rules for AI and algorithms provide the basis for DPIA obligations.
- The AP tool for generative AI helps in testing concrete applications.
- The PRISM-Coach research presents a technical model for separated data processing in coaching.
- The ethical analysis of AI coaches discusses bias and responsibility.
- Want to get started right away? Use the GDPR checklist for coaches or take the coaching privacy check.
This article contains general information and does not replace advice from a qualified lawyer. Consult a qualified legal professional about your own situation before acting on the basis of this content.
Sources
- Rules for using AI & algorithms | Dutch Data Protection Authority
- Tool for generative AI and the GDPR | Dutch Data Protection Authority
- Ethical examination of AI coaches: privacy, bias, and responsibility | Frontiers Digital Health
Frequently asked questions
Is AI in coaching permitted under the GDPR?
Yes, provided you have a valid legal basis, inform clients, and conduct a DPIA where necessary. The GDPR does not prohibit AI, but it does set requirements for how you process personal data in the process.
Do I always need to do a DPIA for AI coaching?
Not always, but often. As soon as AI processes personal data with an increased risk, for example in behavioural analysis, the AP advises conducting a DPIA before you start.
What does Exantur cost for a small coaching practice?
Exantur's Mini plan costs €19 per month or €190 per year. The Starter plan starts at €49 per month, and current rates for all plans are listed on Exantur's pricing page.
Can I just send client notes to an AI tool?
No, that could be a GDPR violation if you share more data than necessary. Remove names and identifying details where possible and use only what is strictly needed for the task.
What should a data processing agreement include for AI coaching?
At a minimum, the purpose of the processing, which data is processed, where it is stored, the retention period, and what happens in the event of a data breach. Always request this before choosing an AI provider.
