Exantur
Menu

GDPR checklist for coaches

This free checklist walks a coaching practice through the core GDPR obligations for handling client data: a lawful basis and privacy notice, data minimisation and retention, data-subject rights (access, portability, erasure), processor agreements (DPAs) and sub-processors, security (access control, encryption, EU hosting), breach readiness, and basic records. You mark each item as in place, partly, or not yet, and get a transparent readiness count plus a prioritised action list. It runs in your browser, stores nothing, and is guidance, not legal advice.

Your readiness0/14

0 of 14 Getting started

0% in place - obligations that apply

Guidance, not legal advice. This does not certify GDPR compliance.

Lawful basis & transparency
  • You can name a lawful basis for processing client data
  • Clients receive a clear privacy notice
Data minimisation & retention
  • You collect only the data you actually need
  • You have a defined retention period
Data-subject rights
  • You can give a client a copy of their data on request
  • You can delete a client’s data on request
Processors & agreements
  • You have a Data Processing Agreement with each tool
  • You know your tools’ sub-processors and where data sits
Security
  • Access is controlled (per-user logins, MFA)
  • Client data is encrypted in transit and at rest
  • You know where data is hosted and transfers are covered
Breach readiness
  • You have a simple data-breach plan
Accountability & records
  • You keep a basic record of processing activities
  • Where you rely on consent, you can show it was given

Your priority actions

  1. You can name a lawful basis for processing client data: Decide and note your basis (contract or consent) for coaching records.
  2. Clients receive a clear privacy notice: Add a short privacy statement to your intake or website.
  3. You collect only the data you actually need: Trim intake forms to what the coaching genuinely requires.
  4. You have a defined retention period: Write down how long you keep notes and when you delete them.
  5. You can give a client a copy of their data on request: Make sure you can export a client record within a month.
  6. You can delete a client’s data on request: Confirm every tool lets you erase a client’s data, backups included.
  7. You have a Data Processing Agreement with each tool: Collect a DPA from every processor you use.
  8. You know your tools’ sub-processors and where data sits: Check each tool’s sub-processor list and hosting region.

Everything is worked out in your browser. Your answers are not sent anywhere or stored.

What this checklist covers

Coaching notes are sensitive personal data, so a coaching practice is a data controller under the GDPR (in the Netherlands, the AVG). This checklist turns the obligations that matter most for a small practice into 14 plain-language items across seven areas: lawful basis and transparency; data minimisation and retention; data-subject rights; processors and agreements; security; breach readiness; and accountability and records.

It is deliberately vendor-neutral: these obligations apply whatever software you use. Mark each item honestly; the result is a count of what is in place, not a certificate.

The GDPR checklist

Each obligation below maps to the GDPR article it rests on, so you can look it up yourself. In the interactive tool above, every item also carries why it matters and a concrete next action.

ObligationAreaGDPR basis
You can name a lawful basis for processing client dataLawful basis & transparencyGDPR Art. 6
Clients receive a clear privacy noticeLawful basis & transparencyGDPR Art. 13-14
You collect only the data you actually needData minimisation & retentionGDPR Art. 5(1)(c)
You have a defined retention periodData minimisation & retentionGDPR Art. 5(1)(e)
You can give a client a copy of their data on requestData-subject rightsGDPR Art. 15, 20
You can delete a client’s data on requestData-subject rightsGDPR Art. 17
You have a Data Processing Agreement with each toolProcessors & agreementsGDPR Art. 28
You know your tools’ sub-processors and where data sitsProcessors & agreementsGDPR Art. 28, 44
Access is controlled (per-user logins, MFA)SecurityGDPR Art. 32
Client data is encrypted in transit and at restSecurityGDPR Art. 32
You know where data is hosted and transfers are coveredSecurityGDPR Art. 44-46
You have a simple data-breach planBreach readinessGDPR Art. 33-34
You keep a basic record of processing activitiesAccountability & recordsGDPR Art. 30
Where you rely on consent, you can show it was givenAccountability & recordsGDPR Art. 7

How to read your result

The readiness figure is a simple, transparent count: the number of items you marked "in place" divided by the number that apply to you (items you mark "not applicable" are excluded). There is no weighting and no hidden score. Bands are only labels for that fraction: getting started (under 34%), partly there (34-66%), mostly in place (67-89%), and solid (90%+).

The prioritised action list is just your "not yet" items first, then your "partly" items, in checklist order. Treat it as a to-do list for tightening your own practice, not a compliance verdict.

Where Exantur can help

Several items are easier inside one coaching workspace built for the EU. Exantur is EU-hosted, enforces access at the database layer with row-level security, requires MFA for admins, encrypts data in transit and at rest, supports client data export and deletion, offers a Data Processing Agreement, and runs EU sub-processors under Standard Contractual Clauses. That covers the hosting, security, DPA and data-subject-rights items directly.

This is secondary to the checklist itself. Obligations like your lawful basis, privacy notice, retention period and record of processing are yours to define regardless of tooling, and you should keep any specialist tool that serves a genuine need.

Limitations

This is guidance, not legal advice, and it does not certify that your practice is GDPR-compliant. It is a practical prompt built from the obligations most relevant to a small coaching practice, not an exhaustive legal audit. It contains no benchmarks, no "percentage of coaches" figures, and no assessment of your specific situation.

For a definitive view, read the primary sources below or consult a qualified professional. Requirements can also vary by country and by the kind of data you handle.

Frequently asked questions

Is my data sent anywhere?
No. The checklist runs entirely in your browser. Your answers are not sent to a server or stored, and no account is required.
Does a full checklist mean I am GDPR-compliant?
No. This is guidance, not legal advice, and it does not certify compliance. It is a practical prompt covering the obligations most relevant to a small coaching practice.
Is this GDPR or the Dutch AVG?
The same regulation. AVG (Algemene verordening gegevensbescherming) is the Dutch name for the GDPR. The article references are identical.
Do I really need a DPA with every tool?
For any tool that processes client personal data on your behalf, yes, Article 28 requires a data processing agreement. Tools that never see client data do not.
What is the 72-hour rule?
A serious personal-data breach generally must be reported to the supervisory authority within 72 hours of becoming aware of it (Article 33). A short breach plan makes that manageable.

Related

Sources

Coaching software built for the EU

See how Exantur covers EU hosting, security, a DPA and data-subject rights.