Menu
← All articles

Securing client records: practical steps for coaches

Securing client records: practical steps for coaches

Elegant title card with a secured client record

Store and share client records only with unique access, strong authentication and a tool that deliberately limits sharing. That is the essence of securing client records for coaches. The Dutch Data Protection Authority and the EDPB expect you to work in a risk-based way, not perfectly but deliberately. A GDPR-conscious tool like Exantur helps by building sharing restrictions in by default.


In brief:

  • Only with unique access, strong authentication and deliberate sharing settings can you effectively protect client records against unauthorised access.
  • Carrying out a short risk analysis and recording retention periods helps determine the necessary security measures.
  • A clear data processing agreement with your supplier should describe data purposes, retention periods and security measures concretely.
  • In the event of a data breach, you must record the incident quickly, assess the risk and, if necessary, report it to the supervisory authority within 72 hours.
  • Use software like Exantur that already supports these efforts, but remain responsible yourself for documentation, monitoring and compliance with GDPR rules.

Exantur
Secure client data with more structure
Exantur brings client relationships, session notes and shared documents together in a secure workspace with EU hosting and MFA.
Explore Exantur

Table of contents

Checklist for immediate security measures

A few settings make an immediate difference, even without technical knowledge. Start with the basics and build from there.

  • Give every user their own account and remove shared login credentials between coaches or assistants.
  • Set a strong password and enable MFA: an extra check alongside your password, such as a code on your phone.
  • Share documents via a secure portal instead of a public link that anyone can open.
  • Enable automatic screen locking on your laptop and phone, especially if you work on location.
  • Ensure secure back-ups that you test regularly, so a lost device does not mean a lost record.
  • Give coachees their own portal with only their own data, separated from other client records.

The Dutch Data Protection Authority explicitly calls security a matter of tailoring: a solo coach needs different measures than a practice with ten coaches, but the basic principles remain the same.

Pro tip: Check each month who still has access to your records and immediately remove old accounts of interns or former colleagues.

Illustration of monthly access review

Determining a short risk analysis and retention periods

You don't have to write an extensive report to work responsibly. Four short questions per type of data are enough to determine what's needed.

  1. What data exactly do you store: session notes, goals, assignments, contact details?
  2. Why do you store that data and how long do you really need it?
  3. Who has access, and is that access limited to what's necessary?
  4. What happens if this record is lost or ends up in the wrong hands?

The EDPB emphasises that measures should follow from this risk analysis, not from a standard list that is the same everywhere. Classify sensitive notes, such as personal breakthroughs or health information, more strictly than general scheduling data. Document your choices briefly in a text file: that is your evidence of accountability should the Dutch Data Protection Authority ever ask how you work. Schedule a clean-up moment twice a year at which you remove old records you no longer need.

What belongs in a data processing agreement with your supplier

If you use software that processes client data, you are the data controller and the supplier is the processor. That requires a data processing agreement with clear arrangements.

  • Concretely describe the purpose and type of data: session notes, contact details, progress reports.
  • Record retention periods and what happens to data upon cancellation.
  • Ask about the supplier's security measures and whether sub-processors are engaged.
  • Put the notification timeframe and minimum content of an incident report in writing.
  • Review the agreement annually and add technical appendices when something changes.

The Dutch Data Protection Authority recommends making agreements concrete rather than copying generic legal language. Our GDPR checklist for coaches goes through these points step by step.

What to do in the event of a data breach in your practice

A data breach is broader than you might think. An email sent to the wrong address, a lost laptop or a public link that was accidentally shared all count.

  1. Recognise the incident: what happened and which records are involved?
  2. Immediately record the time, the nature of the incident and which people may be affected.
  3. Assess the risk: is there a chance of harm to the client involved?
  4. In the case of a high risk, report it as quickly as possible, just as the EDPB advises.
  5. Inform the coachee involved yourself if the risk to that person is significant.
  6. Record the measures taken and evaluate how your process can be improved.

Pro tip: Practise this plan once a year with a fictional scenario, so that you are not searching for your supplier's contact details for the first time during a real incident.

Implementing security in five clear steps

You don't have to do this in a single weekend. A logical order prevents you from forgetting anything.

  1. First do the short risk analysis and write down the conclusions briefly.
  2. Set up unique accounts, MFA and limited sharing in your tools, including in existing software.
  3. Conclude or update your data processing agreement and ask your supplier for a clear incident contact.
  4. Test your back-up: can you really retrieve a record after a loss?
  5. Schedule an annual review and keep a short personal checklist for new clients.

Use our coaching agreement generator as a starting point for arrangements with clients about how you handle their data.

How a coaching-specific platform like Exantur helps

Some of these measures are easier if your software already takes care of them for you. Exantur is built for coaches and keeps this in mind.

  • Coaches and coachees each get their own portal, so data is not accidentally visible to the wrong person.
  • Hosting takes place within the EU, with measures to keep data from different practices separated.
  • MFA is available to further secure accounts.
  • A data processing agreement is available that you can use as a basis for your own arrangements.

More details are on our page about secure coaching software. Important: software like Exantur supports GDPR-conscious working, but does not automatically make your practice fully compliant. You remain responsible for documentation and monitoring of your own processes.

Keep it simple and repeat your checks

Security is not a project you complete once. Start small, with the most important measures, and adjust every six months based on what you encounter in practice. Above all, invest time in clear arrangements with your suppliers: they prevent confusion at precisely the moment you can least afford it.

— Martijn

Try Exantur free for fourteen days

Exantur is built around the coaching process itself, with separate portals for coach and coachee, EU hosting and a data processing agreement as a standard component. This means that many of the measures from this article, such as separated access and limited sharing, are already built in rather than something you have to arrange yourself in separate tools.

A trial period of fourteen days is available. Afterwards, the chosen subscription starts automatically, unless you cancel before the end. View the subscriptions on the pricing page, where Mini, Starter, Growth and Practice each have their own price. Note: even with Exantur, you remain the data controller. Always check the data processing agreement and your own procedures yourself.

Sources

For the legal basis and current guidelines, it is best to go to the source itself.

Frequently asked questions

What exactly does securing a client record mean?

It's about protecting a coachee's session notes, goals, progress and documents against unauthorised access, loss or misuse. You do this with unique accounts, strong authentication and limited sharing options, as described by the EDPB.

As a solo coach, do I need a data processing agreement?

Yes, as soon as you use software that processes client data, you are the data controller and you need a data processing agreement with that supplier. The Dutch Data Protection Authority recommends making it concrete with clear timeframes and contact points.

Within what timeframe must I report a data breach?

In the case of a data breach with a high risk, there is in principle an obligation to report it to the supervisory authority within 72 hours. This is described by the EDPB, which also recommends recording the time, nature and affected records immediately.

Does software like Exantur automatically make my practice GDPR-compliant?

No, software supports GDPR-conscious working but does not automatically make a practice fully compliant. You remain responsible for your own risk analysis, documentation and data processing agreement, even if you use a secure tool.

How long should I keep client records?

There is no fixed universal timeframe: you decide for yourself how long you truly need the data and document that choice. Classify sensitive notes separately and schedule regular clean-up moments to remove data you no longer use.

Recommendations