Guide

PDPA for gyms and fitness studios in Singapore: a practical guide

Updated 2026-10-07 ยท This guide is general information, not legal advice. Check the PDPC website for the latest guidelines.

In short: a Singapore gym must get members' consent before collecting their personal data, use it only for the purposes it told them about, keep it secure, let members access and correct it, delete it when it's no longer needed, and appoint a Data Protection Officer. It should not collect full NRIC numbers for ordinary memberships, and it needs clear consent before sending marketing messages.

What member data does a gym collect?

More than most owners realise: names, mobile numbers, emails, dates of birth, emergency contacts, health declarations (PAR-Q forms), body measurements, photos for check-in, payment details, attendance logs and CCTV footage. Health data and photos deserve extra care because a leak can cause real harm.

The PDPA obligations, applied to a gym

ObligationWhat it means at the front desk
ConsentMembers agree to data collection at sign-up, and you keep a record of when and what they agreed to.
Purpose limitationData collected to run the membership is not reused for unrelated purposes without fresh consent.
NotificationYour sign-up form explains why you collect each piece of data.
Access and correctionMembers can ask what data you hold about them and have it corrected.
AccuracyContact and health details are kept up to date.
ProtectionData is secured: no shared logins, no member lists in personal WhatsApp chats, no paper forms on the counter.
Retention limitationData from former members is deleted or anonymised once you no longer need it for business or legal purposes.
Transfer limitationIf your software stores data overseas, the vendor protects it to a standard comparable to the PDPA.
Data breach notificationNotifiable breaches are reported to the PDPC within three calendar days of assessment.
AccountabilityYou appoint a Data Protection Officer and have written data protection policies.

NRIC numbers: stop collecting them

Since 1 September 2019, PDPC guidance says organisations should generally not collect, use or disclose full NRIC numbers or keep copies of NRIC cards. The exceptions are when the law requires it, or when it's necessary to verify identity to a high degree of fidelity. A gym membership rarely meets that bar. Use a mobile number, email or system-generated member ID instead, and if you collected NRIC numbers in the past, review whether you still need them.

Marketing messages and the DNC Registry

Promotions by SMS, WhatsApp or phone call to Singapore numbers fall under the PDPA's Do Not Call provisions. The simplest approach is to ask for marketing consent at sign-up with a separate checkbox, never pre-ticked, and to keep a timestamped record of it. Members must be able to withdraw that consent easily.

CCTV and check-in photos

Put up clear signs where CCTV is in use, limit who can view the footage, and delete recordings on a fixed schedule. If your check-in uses member photos, store them in your gym software rather than on a front-desk phone.

How gym management software helps

Good software makes most of these obligations the default instead of a manual process. Gymsoftware:

  • records timestamped consent at sign-up, with marketing consent kept separate;
  • never asks for a full NRIC number;
  • gives each staff member a personal login with role-based access and an activity log;
  • lets you export or delete a member's data on request;
  • stores PAR-Q forms and waivers on the member profile instead of on paper;
  • encrypts data in transit and at rest.

See all PDPA features or read how to choose gym management software in Singapore.

Frequently asked questions

Can a gym in Singapore ask for my NRIC number?

Generally no. Under the PDPC's advisory guidelines on NRIC numbers, which took effect on 1 September 2019, organisations should not collect full NRIC numbers or copies of the NRIC unless the law requires it or it is necessary to establish a person's identity to a high degree of fidelity. For most gym memberships, a mobile number, email or member ID is enough.

Do gyms need a Data Protection Officer?

Yes. Every organisation covered by the PDPA, including small gyms and studios, must designate at least one person as its Data Protection Officer and make that person's business contact details available to the public.

Can a gym send promotional SMS or WhatsApp messages to members?

Only with care. Marketing messages to Singapore telephone numbers are covered by the Do Not Call provisions of the PDPA. Get clear, separate consent for marketing at sign-up and keep a record of it; otherwise check the DNC Registry before sending marketing messages to a number.

What happens if a gym has a data breach?

If a breach is likely to cause significant harm to members or involves 500 or more people, the gym must notify the PDPC within three calendar days of assessing that it is notifiable, and notify affected members if significant harm is likely. Financial penalties can reach S$1 million, or 10% of annual Singapore turnover for organisations with turnover above S$10 million.

See it running with your own gym's data

Book a 30-minute walkthrough. We'll import a sample of your members, set up PayNow billing and show you the reports you'd see on Monday morning.

No credit card. We reply within one Singapore business day.