Guide
PDPA for gyms and fitness studios in Singapore: a practical guide
Updated 2026-10-07 ยท This guide is general information, not legal advice. Check the PDPC website for the latest guidelines.
In short: a Singapore gym must get members' consent before collecting their personal data, use it only for the purposes it told them about, keep it secure, let members access and correct it, delete it when it's no longer needed, and appoint a Data Protection Officer. It should not collect full NRIC numbers for ordinary memberships, and it needs clear consent before sending marketing messages.
What member data does a gym collect?
More than most owners realise: names, mobile numbers, emails, dates of birth, emergency contacts, health declarations (PAR-Q forms), body measurements, photos for check-in, payment details, attendance logs and CCTV footage. Health data and photos deserve extra care because a leak can cause real harm.
The PDPA obligations, applied to a gym
| Obligation | What it means at the front desk |
|---|---|
| Consent | Members agree to data collection at sign-up, and you keep a record of when and what they agreed to. |
| Purpose limitation | Data collected to run the membership is not reused for unrelated purposes without fresh consent. |
| Notification | Your sign-up form explains why you collect each piece of data. |
| Access and correction | Members can ask what data you hold about them and have it corrected. |
| Accuracy | Contact and health details are kept up to date. |
| Protection | Data is secured: no shared logins, no member lists in personal WhatsApp chats, no paper forms on the counter. |
| Retention limitation | Data from former members is deleted or anonymised once you no longer need it for business or legal purposes. |
| Transfer limitation | If your software stores data overseas, the vendor protects it to a standard comparable to the PDPA. |
| Data breach notification | Notifiable breaches are reported to the PDPC within three calendar days of assessment. |
| Accountability | You appoint a Data Protection Officer and have written data protection policies. |
NRIC numbers: stop collecting them
Since 1 September 2019, PDPC guidance says organisations should generally not collect, use or disclose full NRIC numbers or keep copies of NRIC cards. The exceptions are when the law requires it, or when it's necessary to verify identity to a high degree of fidelity. A gym membership rarely meets that bar. Use a mobile number, email or system-generated member ID instead, and if you collected NRIC numbers in the past, review whether you still need them.
Marketing messages and the DNC Registry
Promotions by SMS, WhatsApp or phone call to Singapore numbers fall under the PDPA's Do Not Call provisions. The simplest approach is to ask for marketing consent at sign-up with a separate checkbox, never pre-ticked, and to keep a timestamped record of it. Members must be able to withdraw that consent easily.
CCTV and check-in photos
Put up clear signs where CCTV is in use, limit who can view the footage, and delete recordings on a fixed schedule. If your check-in uses member photos, store them in your gym software rather than on a front-desk phone.
How gym management software helps
Good software makes most of these obligations the default instead of a manual process. Gymsoftware:
- records timestamped consent at sign-up, with marketing consent kept separate;
- never asks for a full NRIC number;
- gives each staff member a personal login with role-based access and an activity log;
- lets you export or delete a member's data on request;
- stores PAR-Q forms and waivers on the member profile instead of on paper;
- encrypts data in transit and at rest.
See all PDPA features or read how to choose gym management software in Singapore.