Gym, club, swimming pool: your body has become an entry badge

Back to the blog
15 September 202613 min read

Introduction: "Just put your finger here"

Monday, 6:50 p.m. You're signing a twelve-month membership at a neighbourhood gym. The adviser is friendly, the deal is fair, the tour is quick. As you finalise things, he hands you a small black device: "Just put your finger here, it's for access. That way you don't need a badge, and you can't forget it."

Thirty seconds later, your fingerprint — or a mathematical representation of it — lives inside a computer system you know nothing about: where it's hosted, who maintains it, what becomes of it when the chain changes owners, and what happens if someone one day accesses it without authorisation. Unlike a password, a fingerprint can't be changed. You have ten of them, for life.

Two brass padlocks securing a yellow and orange metal door covered in graffiti

Sport and leisure have long remained a blind spot in the privacy conversation. We think about it for banking, for work, for healthcare — rarely for the municipal swimming pool or the climbing club. And yet it's one of the places where we hand over the most: identity, contact details, medical certificate, body measurements, precise attendance times, sometimes our face. This guide sorts out what's legal, what's tolerated, what isn't remotely acceptable — and what you can refuse without giving up on training.


What a club actually knows about you

The inventory, item by item

A sports membership generates several layers of data, which are almost never handled by the same party.

Data collectedBy whomWhat it reveals
Identity, address, bank detailsThe club and its payment providerCreditworthiness, residential stability
Time stamps for entries/exitsAccess control systemDaily rhythm, working hours, absences, holidays
Medical certificate / health questionnaireThe club, sometimes the federationConditions, medical history, pregnancy
Body measurements (weight, body fat)Coach, connected scalesHealth data within the meaning of the GDPR
Performance on connected machinesMachine manufacturer (often foreign)Fitness level, progress, consistency
Profile photo / CCTVThe clubAppearance, attendance, companions
Mobile app dataThird-party publisher, ad networksGeolocation, habits, devices used

The key point is that second line: entry time stamps are probably the most intrusive data on the list, and they're the ones nobody pays attention to. A year of check-ins is a reliable map of your days. Who knows you're systematically away from home between 7:00 and 8:30 p.m.? Your gym, before your family does.

The special case of 24/7 chains

Venues open around the clock, with no staff at night, have a genuine security problem to solve: making sure only members get in. Hence the biometric temptation, or its more discreet cousin: a camera paired with facial recognition at the turnstile. The need is legitimate. The chosen answer isn't always.


Biometrics: what French law actually allows

The principle: a fingerprint is not a badge

The GDPR classifies biometric data used to identify a person as sensitive data (Article 9). Processing it is prohibited in principle, save for an exhaustively listed set of exceptions: explicit consent, substantial public interest, legal obligation, and so on.

The CNIL has a consistent and very clear position on access control: biometrics should only be used where it is necessary and proportionate in the light of a specific risk. Historically, it has accepted them for access to high-risk areas — laboratories, server rooms, storage of hazardous substances — not for opening a turnstile in front of a rack of dumbbells.

The legal test isn't "is it convenient?" but "is there a less intrusive way of achieving the same goal?". A badge, a PIN, a personal card achieve the same goal. The reasoning ends there.

In other words: a gym that requires a fingerprint for entry is on legally shaky ground. And when the system is presented as mandatory, the consent invoked doesn't hold up: the GDPR requires freely given consent, which presupposes being able to refuse without consequences.

What "freely given" consent means in practice

Three cumulative conditions, often forgotten:

  • A genuine alternative must exist (badge, card, PIN) and be offered at no extra cost and with no degraded service.
  • Information must be provided before collection: purpose, retention period, recipients, legal basis.
  • Withdrawal must be as easy as acceptance: you must be able to request deletion of your biometric template at any time and switch back to a badge.

If any one of the three is missing, the processing is unlawful. You can report it to the CNIL through its online complaint form, including as a group if several members are affected.

Facial recognition: even more tightly regulated

The European regulation on artificial intelligence, adopted in 2024 and whose obligations are being phased in, adds a further layer of constraints on biometric identification systems. In private spaces open to the public, using facial recognition purely for the convenience of access remains very hard to justify. If your club has installed it, the first question to ask in writing is: "What is the legal basis, and where is the data protection impact assessment?" That assessment (DPIA) is mandatory for this type of processing. Its absence is in itself a breach.


The medical certificate and the health questionnaire

This area has changed a great deal. Since 2021, for recreational sport, the medical certificate has largely been replaced by a self-assessment questionnaire for adults, and abolished for minors in most cases, except where an answer to the questionnaire is positive or for disciplines with particular constraints (diving, mountaineering, combat sports with knockouts, etc.). The exact arrangements depend on the federation: the ministry responsible for sport and the federations publish the applicable rules.

What to remember on the privacy side:

  • The health questionnaire is meant to stay between you and you. You merely certify that you answered "no" to every question. You don't have to hand the detail of your answers over to the club.
  • A private club has no legitimate reason to keep a copy of your detailed medical history in its commercial management software.
  • If a coach asks you to enter health conditions into an app, ask where that data is hosted. Health data processed on behalf of a professional should in principle sit on HDS-certified hosting in France — a mere coaching app running on an ad-funded server does not qualify.

A person's hand typing on a laptop keyboard displaying data, in blue and purple light


The devices and apps that speak on your behalf

The smartwatch: a permanent logbook

A fitness band or sports watch records far more than kilometres: resting heart rate, heart rate variability, sleep quality, menstrual cycle in some cases, and above all GPS traces that map out your home, your workplace and your habits.

Three settings do most of the work:

  1. Turn off public activity sharing by default. On social fitness platforms, "public" is often the initial setting. "Privacy zones" (hiding a radius around your home) are useful but imperfect: they don't protect you if you always set off from the same point.
  2. Refuse synchronisation with non-essential third-party apps. Every permission granted to a partner service creates a copy of your data beyond your control.
  3. Prefer, where possible, a device that works offline. A simple chest-strap heart rate monitor, paired locally with the gym equipment, gives you the reading without creating a cloud account. For running, a mechanical pedometer with no connectivity remains unbeatable for discretion.

For gym sessions, a paper training log does exactly the same job as a tracking app, with zero transmission. This isn't romantic nostalgia: it's simply the only medium whose server nobody else owns.

Connected machines

Recent treadmills, rowers and bikes often come with a screen and a user account. Logging into your personal profile on a shared machine means: linking your performance to your identity with the manufacturer, and sometimes leaving a session open for the next member. Using the machine in guest mode changes nothing about your workout — it changes everything about the trace you leave.

Lockers and padlocks

A trivial but real detail: many gyms have replaced key lockers with PIN lockers linked to your badge. Every opening is then time-stamped and attached to your account. A classic combination padlock, on a free locker, breaks that link. It seems trifling until the day someone tries to establish who was in the changing room at a given hour.


The commercial side: membership as a data machine

Direct debit, win-back campaigns, resale

The business model of the big chains rests on long commitments and automatic direct debits. That generates a rich customer file, often hosted with a subscription management provider, containing:

  • your bank details and a history of payment incidents;
  • your actual attendance (valuable commercial data: a member who has stopped coming is a win-back target);
  • your interactions with customer service, recorded and sometimes automatically transcribed.

If the chain is bought out — a frequent occurrence in this sector — the customer file is among the assets transferred. Your contractual relationship changes hands, and so does your data.

What you can demand, article by article

Your rightWhat it means in practiceDeadline
Access (GDPR Art. 15)A copy of everything the club holds: check-ins, sales notes, recordings1 month
Rectification (Art. 16)Correcting a date of birth, an outdated address1 month
Erasure (Art. 17)Deletion after the contract ends, apart from accounting obligations1 month
Objection (Art. 21)Stopping marketing outreach and commercial profilingImmediate for marketing
Restriction (Art. 18)Freezing data during a dispute1 month

A written access request, sent to the chain's data protection officer (DPO), is the most effective tool for finding out exactly what is stored. It's free. If there's still silence after a month, the door to a complaint with the CNIL is open.

After cancellation

The classic question: how long does the club keep your data? Retention periods must be proportionate. In practice, marketing data on a former customer may be kept for a limited time (the CNIL commonly applies three years from the last contact for marketing purposes), and accounting records fall under longer legal obligations, but your check-ins, your body measurements and your biometric template have no reason to outlive the contract. Ask for this explicitly in writing, with proof of receipt.


Signing up smart: the five-step method

1. Compartmentalise your contact identity

Nothing obliges you to give the email address you use for your bank. A dedicated leisure address, or a disposable alias, limits cross-referencing between files and makes breaches far less painful. Same logic for the phone: a secondary number, or a service that sends SMS without revealing your number, is more than enough to receive class confirmations.

2. Read the "sharing with our partners" line

It's always there, often as an unticked box — or a pre-ticked one, which is illegal for electronic marketing. Untick it, and keep a photo of the signed contract: that's your evidence if a partner comes calling afterwards.

3. Politely decline biometrics

The phrasing that works, without conflict: "I'd prefer a badge. Can you confirm in writing that a non-biometric alternative is available?" Nine times out of ten, the badge comes out of the drawer. On the tenth, you've learned something about the chain before committing for twelve months.

4. Keep your body separate from your account

Bioimpedance scales are now standard in intake assessments. If you want to track your body composition, doing it at home with a non-connected bioimpedance scale avoids feeding a third party's sales file with health data. The number belongs to you; so does the trend line.

5. Protect the phone itself

The changing room is a risky environment: open bag, phone left out, club wifi open to everyone. Two habits: don't use the venue's wifi for anything beyond ordinary browsing, and shield your screen when checking messages between sets — a smartphone privacy filter makes the screen unreadable from the side, which also pays off on public transport.

A hand typing on a laptop keyboard while holding a green bank card


Amateur clubs and municipal pools

The instinct is to assume the non-profit sector collects less. That's often true in intention, rarely in practice: small organisations use shared licence management software, consumer messaging groups for internal communication, and shared spreadsheets that sometimes contain members' health data.

A few specific points to watch:

  • Membership lists circulated in the clear. A file sent "to everyone" with addresses and phone numbers amounts to a disclosure. Ask for blind copy and for the shared fields to be limited.
  • Competition photos published on social media. Image rights require authorisation, separately for minors, and revocable. An authorisation signed for life, with no limit on medium or duration, is not valid.
  • Access wristbands at municipal pools. Many are simple anonymous tokens, but some local authorities have linked them to a named account for means-tested pricing. A social tariff should not lead to finer tracking than the full price does.

What to take away

Sport is a space of bodily freedom. It has quietly become a space of bodily measurement — and once a measurement is transmitted, it never comes back.

  • A fingerprint imposed to enter a gym is almost always disproportionate: ask for the badge, it's a defensible right.
  • The time stamps of your entries are the most revealing data in your membership, and the least discussed.
  • The health questionnaire belongs to you: you certify, you don't hand it over.
  • A written access request to the DPO costs five minutes and reveals the entire file.
  • Disconnected objects — combination padlocks, paper logs, local sensors — aren't nostalgic: they're the only ones nobody else holds a copy of.

You have the right to sweat without leaving a trace. That doesn't mean giving up the club: just signing up knowing what you're signing.

Sources and resources: CNIL (guidance on biometrics in the workplace and for access control, online complaint form, customer data retention periods); GDPR, Articles 9, 15 to 22 and 35; the French Code du sport and information from the ministry responsible for sport on the medical certificate and health questionnaire; the European regulation on artificial intelligence (2024) on the regulation of biometric identification systems.

#Vie privée#Confidentialité#RGPD#CNIL#Cadre légal#Anonymat

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme