GDPR checklist for coaches
This free checklist walks a coaching practice through the core GDPR obligations for handling client data: a lawful basis and privacy notice, data minimisation and retention, data-subject rights (access, portability, erasure), processor agreements (DPAs) and sub-processors, security (access control, encryption, EU hosting), breach readiness, and basic records. You mark each item as in place, partly, or not yet, and get a transparent readiness count plus a prioritised action list. It runs in your browser, stores nothing, and is guidance, not legal advice.
0 of 14 Getting started
0% in place - obligations that apply
Guidance, not legal advice. This does not certify GDPR compliance.
Your priority actions
- You can name a lawful basis for processing client data: Decide and note your basis (contract or consent) for coaching records.
- Clients receive a clear privacy notice: Add a short privacy statement to your intake or website.
- You collect only the data you actually need: Trim intake forms to what the coaching genuinely requires.
- You have a defined retention period: Write down how long you keep notes and when you delete them.
- You can give a client a copy of their data on request: Make sure you can export a client record within a month.
- You can delete a client’s data on request: Confirm every tool lets you erase a client’s data, backups included.
- You have a Data Processing Agreement with each tool: Collect a DPA from every processor you use.
- You know your tools’ sub-processors and where data sits: Check each tool’s sub-processor list and hosting region.
Everything is worked out in your browser. Your answers are not sent anywhere or stored.
What this checklist covers
Coaching notes are sensitive personal data, so a coaching practice is a data controller under the GDPR (in the Netherlands, the AVG). This checklist turns the obligations that matter most for a small practice into 14 plain-language items across seven areas: lawful basis and transparency; data minimisation and retention; data-subject rights; processors and agreements; security; breach readiness; and accountability and records.
It is deliberately vendor-neutral: these obligations apply whatever software you use. Mark each item honestly; the result is a count of what is in place, not a certificate.
The GDPR checklist
Each obligation below maps to the GDPR article it rests on, so you can look it up yourself. In the interactive tool above, every item also carries why it matters and a concrete next action.
| Obligation | Area | GDPR basis |
|---|---|---|
| You can name a lawful basis for processing client data | Lawful basis & transparency | GDPR Art. 6 |
| Clients receive a clear privacy notice | Lawful basis & transparency | GDPR Art. 13-14 |
| You collect only the data you actually need | Data minimisation & retention | GDPR Art. 5(1)(c) |
| You have a defined retention period | Data minimisation & retention | GDPR Art. 5(1)(e) |
| You can give a client a copy of their data on request | Data-subject rights | GDPR Art. 15, 20 |
| You can delete a client’s data on request | Data-subject rights | GDPR Art. 17 |
| You have a Data Processing Agreement with each tool | Processors & agreements | GDPR Art. 28 |
| You know your tools’ sub-processors and where data sits | Processors & agreements | GDPR Art. 28, 44 |
| Access is controlled (per-user logins, MFA) | Security | GDPR Art. 32 |
| Client data is encrypted in transit and at rest | Security | GDPR Art. 32 |
| You know where data is hosted and transfers are covered | Security | GDPR Art. 44-46 |
| You have a simple data-breach plan | Breach readiness | GDPR Art. 33-34 |
| You keep a basic record of processing activities | Accountability & records | GDPR Art. 30 |
| Where you rely on consent, you can show it was given | Accountability & records | GDPR Art. 7 |
How to read your result
The readiness figure is a simple, transparent count: the number of items you marked "in place" divided by the number that apply to you (items you mark "not applicable" are excluded). There is no weighting and no hidden score. Bands are only labels for that fraction: getting started (under 34%), partly there (34-66%), mostly in place (67-89%), and solid (90%+).
The prioritised action list is just your "not yet" items first, then your "partly" items, in checklist order. Treat it as a to-do list for tightening your own practice, not a compliance verdict.
Where Exantur can help
Several items are easier inside one coaching workspace built for the EU. Exantur is EU-hosted, enforces access at the database layer with row-level security, requires MFA for admins, encrypts data in transit and at rest, supports client data export and deletion, offers a Data Processing Agreement, and runs EU sub-processors under Standard Contractual Clauses. That covers the hosting, security, DPA and data-subject-rights items directly.
This is secondary to the checklist itself. Obligations like your lawful basis, privacy notice, retention period and record of processing are yours to define regardless of tooling, and you should keep any specialist tool that serves a genuine need.
Limitations
This is guidance, not legal advice, and it does not certify that your practice is GDPR-compliant. It is a practical prompt built from the obligations most relevant to a small coaching practice, not an exhaustive legal audit. It contains no benchmarks, no "percentage of coaches" figures, and no assessment of your specific situation.
For a definitive view, read the primary sources below or consult a qualified professional. Requirements can also vary by country and by the kind of data you handle.
Frequently asked questions
- Is my data sent anywhere?
- No. The checklist runs entirely in your browser. Your answers are not sent to a server or stored, and no account is required.
- Does a full checklist mean I am GDPR-compliant?
- No. This is guidance, not legal advice, and it does not certify compliance. It is a practical prompt covering the obligations most relevant to a small coaching practice.
- Is this GDPR or the Dutch AVG?
- The same regulation. AVG (Algemene verordening gegevensbescherming) is the Dutch name for the GDPR. The article references are identical.
- Do I really need a DPA with every tool?
- For any tool that processes client personal data on your behalf, yes, Article 28 requires a data processing agreement. Tools that never see client data do not.
- What is the 72-hour rule?
- A serious personal-data breach generally must be reported to the supervisory authority within 72 hours of becoming aware of it (Article 33). A short breach plan makes that manageable.
Related
Sources
Coaching software built for the EU
See how Exantur covers EU hosting, security, a DPA and data-subject rights.
