DPIA for coaches: when do you really need to carry one out?
DPIA for coaches: when do you really need to carry one out?

In most individual coaching practices, a DPIA is not mandatory. As soon as you work with profiling, large-scale processing of health data, or systematic monitoring of clients, that changes: then Article 35 of the GDPR requires a DPIA. The Dutch Data Protection Authority tests this against a fixed list of high-risk processing activities. In doubt? Then a short check is often enough to give you certainty.
In short:
- A DPIA is mandatory for large-scale processing of health data, profiling with legal consequences, or systematic monitoring of clients.
- If you are unsure whether you fall within the mandatory categories, document your reasoning and consult a privacy advisor if necessary.
- A DPIA must consist of at least a description of the data processing, a necessity and proportionality assessment, a risk analysis, and mitigating measures.
- Practice software helps you with the technical and organisational privacy requirements, but does not replace the legal assessment.
- A short trigger check can help you quickly determine whether a full DPIA is needed, saving you time and costs.
Table of contents
- When is a DPIA mandatory under the GDPR and the Dutch Data Protection Authority?
- Does the exemption for healthcare providers also apply to coaches?
- What must a DPIA contain at a minimum?
- How do you carry out a DPIA as a coach in 10 steps?
- Which practical measures lower the risk for coaches?
- Software organises your privacy, but does not replace a legal assessment
- Sources
- Frequently asked questions
When is a DPIA mandatory under the GDPR and the Dutch Data Protection Authority?
Article 35 of the GDPR requires a DPIA as soon as a processing of personal data is likely to result in a high risk to the people whose data you process. You carry out that assessment before you start collecting, not afterwards, as explained in the guidance from Ondernemersplein.
The Dutch Data Protection Authority has made that open standard more concrete with an official list of 17 categories of processing for which a DPIA is always mandatory. That list is not exhaustive: processing activities that are not explicitly on it can also fall under the general rule of Article 35. The European privacy supervisors (EDPB) additionally use nine indicators to assess risk, such as large scale, sensitive data, and combining datasets.
For coaches, these are the situations that most often trigger a DPIA:
- You use profiling or automated scores that have legal consequences for clients, for example in selection for a programme or reimbursement.
- You process health data on a large scale, such as in coaching focused on burnout, mental health, or medical reintegration.
- You link multiple data sources together, for example client files with assessment results and external data.
- You monitor clients systematically, such as continuous tracking of behaviour or location.
Most everyday coaching activities, such as taking notes or tracking progress, fall outside these categories. They belong to normal business operations, as long as you do not deploy new technology or large-scale sensitive data, as the Ondernemersplein guidance shows.
Does the exemption for healthcare providers also apply to coaches?
That exemption is narrow and does not automatically apply to every coach who works with personal or health-related topics, as shown in the explanatory notes to the decree on mandatory DPIA categories.
You do fall under the DPIA obligation as soon as your processing:
- is large-scale, for example because you work with hundreds of clients at once via a system with shared data,
- involves systematic monitoring, such as continuous behavioural registration,
- or deploys profiling with legal consequences, such as automatic referral or exclusion based on a score.
Unsure whether your practice falls under the exemption? Then briefly document why you consider a DPIA unnecessary and keep that reasoning on file. When in doubt, external advice is often cheaper than solving a problem after the fact.
What must a DPIA contain at a minimum?
The Dutch Data Protection Authority requires four fixed components for every DPIA, as stated on the page about the DPIA:
- A systematic description of the processing: which data, from whom, for what purpose, and by what route it reaches you.
- An assessment of necessity and proportionality: do you process only what is needed for the coaching goal, or do you go further than necessary?
- A risk analysis: what risks do clients run, how likely are they, and how severe is the impact?
- Mitigating measures: which technical and organisational steps do you use to lower the risk, and what residual risk remains?
In addition, you document who made the decision, whether a data protection officer (DPO) was involved, and whether prior consultation with the Dutch Data Protection Authority was necessary. A DPO is the internal privacy supervisor within an organisation; as a solo coach you usually do not have one, but you can consult an external advisor. Keep this documentation: in the event of an audit, you must be able to demonstrate that you made the assessment seriously.
How do you carry out a DPIA as a coach in 10 steps?
Guidance from the Dutch central government and privacy specialists usually uses a model of eight to ten steps, as the explanation from Legiscope shows. For a coaching practice, the following order works best.
- Do a trigger check first. Briefly answer: do you work with health data on a large scale, profiling with consequences, or systematic monitoring? Three times “no” means a full DPIA is usually not needed.
- Define the scope. Which coaching activity, which programme, or which client group are you assessing?
- Describe the data flow. Which personal data do you collect, where does it enter, and where do you store it?
- Assess necessity and proportionality. Can you achieve the coaching goal with less or less sensitive data?
- Identify risks. Think of data breaches, misuse of sensitive notes, or unwanted access by third parties.
- Assess and prioritise those risks by likelihood and impact.
- Formulate measures: technical (encryption, access management), organisational (procedures), and behavioural (training).
- Determine the residual risk and decide: start, adjust, or first consult the Dutch Data Protection Authority.
- Document and have it signed off, recording who made the decision and on what basis.
- Plan a review, for example annually or whenever you introduce a new tool.
Does a high residual risk remain after these steps? Then Article 36 of the GDPR requires prior consultation with the Dutch Data Protection Authority. The supervisor responds within eight weeks, with a possible extension of six weeks, as Ondernemersplein reports.
Pro tip: Use the trigger check from step 1 independently of a full DPIA as well. When in doubt about a new tool or a new coaching programme, that check takes you five minutes and often saves you an entire assessment.

Which practical measures lower the risk for coaches?
You do not have to wait for a full DPIA to lower your risk. A few immediate measures often make the difference between a light assessment and an extensive investigation.
- Limit what you collect. Only ask for data you actually need for the coaching process, and do not keep it longer than necessary.
- Work with software hosted in the EU. Data that stays within the EU falls under the same privacy legislation as you, which makes oversight and enforcement easier.
- Sign a data processing agreement with every supplier that processes personal data on your behalf, such as your accounting system or practice software.
- Secure access with multi-factor authentication (MFA). This means that when logging in you need a second confirmation in addition to a password, for example via a code on your phone.
- Separate client identity from sensitive notes where possible, and limit who has access to which file.
These measures significantly lower the risk profile of your processing, as Ondernemersplein and the Dutch DPA emphasise in their guidance on mitigating measures. If you still find yourself doubting whether your processing falls under a mandatory category, for example with large-scale health data or profiling? Then consult a lawyer or privacy advisor before you proceed.
Software organises your privacy, but does not replace a legal assessment
Practice software can handle much of the practical work from this article for you. Think of encrypted storage, separate access to client files, and a ready-made data processing agreement. Some software offers this as part of secure hosting within the EU, strong access security with multi-factor authentication, and standard data processing agreements. This helps organise the foundation of your data protection without you having to figure out the technology yourself.
But a tool alone does not automatically make your practice GDPR-compliant. Do you work with profiling, large-scale health data, or systematic monitoring? Then the legal assessment under Article 35 of the GDPR remains necessary, possibly with the help of an external privacy advisor. Software organises the execution; you remain responsible for the assessment.
Want to quickly check whether your coaching practice comes close to a DPIA obligation? Take a look at the free privacy check for coaches or discover how secure coaching software makes your everyday data management easier. Exantur offers a free trial period with no costs during the trial; for the full approach, see the page about coaching software for the Netherlands.
— Martijn
This article contains general information and does not replace the advice of a qualified lawyer. Consult a qualified legal professional about your own situation before acting on the basis of this content.
Sources
For the legal basis, consult Ondernemersplein for the practical explanation and the official decree with the list of mandatory processing activities for the exact categories. The Dutch Data Protection Authority publishes the official requirements for a DPIA report.
- Carrying out a DPIA (data protection impact assessment)
- Data protection impact assessment (DPIA) | Dutch Data Protection Authority
- Decree on the list of personal data processing activities for which a data protection impact assessment (DPIA) is mandatory
- DPIA step-by-step plan GDPR art. 35: Dutch DPA list of mandatory cases, methodology, prior consultation
Frequently asked questions
When is a DPIA mandatory for coaches?
A DPIA is mandatory as soon as your processing is likely to result in a high privacy risk, such as with profiling that has legal consequences, large-scale health data, or systematic monitoring. The Dutch DPA's list of 17 categories provides concrete examples, but is not exhaustive.
How do I carry out a DPIA as a coach?
You follow a step-by-step plan of defining the scope, describing the data flow, testing necessity, assessing risks, and formulating measures, and finally documenting and reviewing. The ten-step model describes this approach in detail.
How do I complete a DPIA?
A DPIA contains at least a description of the processing, an assessment of necessity and proportionality, a risk analysis, and the mitigating measures you take. The Dutch Data Protection Authority describes these four components as a fixed requirement.
What exactly does DPIA mean?
A DPIA, in Dutch a gegevensbeschermingseffectbeoordeling (data protection impact assessment), is an investigation into the privacy risks of a data processing activity before you begin it. It is not an administrative checklist but a tool to identify and reduce risks to clients in advance.
