Latest
issue
GET HCM
magazine
Sign up for the FREE digital edition of HCM magazine and also get the HCM ezine and breaking news email alerts.
Not right now, thanksclose this window I've already subscribed!
Elevate
Elevate
Elevate
Follow Health Club Management on Twitter Like Health Club Management on Facebook Join the discussion with Health Club Management on LinkedIn
FITNESS, HEALTH, WELLNESS

features

Sponsored briefing: Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data

Published in Health Club Management 2017 issue 11
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
Leisure and gym operators are custodians of a huge volume of detailed personal information on members, making our industry not only a soft target, but also an attractive one - Paul Simpson

Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations

Paul Simpson
Paul Simpson

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]

Sign up here to get HCM's weekly ezine and every issue of HCM magazine free on digital.
https://www.leisureopportunities.co.uk/images/299762_993010.jpg
Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital for operators to take action on how they store and secure all member data
Paul Simpson, chief operating officer, Legend Club Management Systems,Legend Club Management Systems, Paul Simpson, member data,
HCM magazine
Fitstop is growing well. In 2023 it added 45 locations and launched in New Zealand, Singapore and the US. It has grown sustainably and has great founder-led energy
HCM magazine
Consumers’ growing love of strength training is to be welcomed, as this long-neglected modality has a renaissance, however, it’s vital we continue to make the case for cardio
HCM magazine
When a hefty round of investment coincided with the pandemic, the CEO of Midtown Athletic Clubs feared the company – founded by his grandfather – would go down on his watch. He talks to Kath Hudson about the pressure to keep the business afloat
HCM magazine
What needs to happen to integrate physical activity with healthcare? Leaders in the sector share their thoughts
HCM magazine
We have a fantastic opportunity in front of us to realise our vision of a happier and healthier world
HCM promotional features
Sponsored
Coaching workshops from Keith Smith and Adam Daniel have been designed to empower your team and transform your service
HCM promotional features
Sponsored
The New Keiser M3i Studio Bike brings ride data to life to engage and delight members
HCM promotional features
Sponsored
Francesca Cooper-Boden says health assessment services can boost health club retention
HCM promotional features
Sponsored
Epassi, a provider of workplace wellness benefits, is creating a fitter and more productive workforce, one membership at a time 
HCM promotional features
Sponsored
University of Sheffield Sport has opened the doors of its flagship Goodwin Sports Centre following a major refurbishment
HCM promotional features
Sponsored
Operators, prepare to revolutionise the way members connect with personal trainers in your club, with the ground-breaking Brawn platform.
HCM promotional features
Sponsored
The partnership between PureGym and Belfast-based supplier BLK BOX is transforming the gym floor
HCM promotional features
Sponsored
GymNation is pioneering the future of fitness with software specialist Perfect Gym providing a scalable tech platform to power and sustain its growth
HCM promotional features
Sponsored
Nuffield Health has worked with ServiceSport UK for more than ten years, ensuring the equipment in its clubs is commercially optimised
HCM promotional features
Latest News
Planet Fitness has announced the repurchase of 314,000 shares at a rate of US$20 million. ...
Latest News
Xponential Fitness today indefinitely suspended founder and CEO, Anthony Geisler, saying it had been notified ...
Latest News
Fast Fitness Japan, master franchisee of Anytime Fitness in Japan, has acquired Eighty-8 Health & ...
Latest News
Xplor Technologies has unveiled a financing solution for small businesses, which aims to counter the ...
Latest News
HoloBike, a holographic training bike that simulates trail rides in lifelike 3D, is aiming to ...
Latest News
Peloton Interactive Inc is believed to be working to get its costs under control in ...
Latest News
Equinox, has teamed up with health platform, Function Health, to offer 100 comprehensive laboratory tests, ...
Latest News
Having good levels of cardiorespiratory fitness cuts disease and premature death by 11 to 17 ...
Featured supplier news
Featured supplier news: Phil Heath, 7x Mr Olympia, shares machine-only leg workout routine
Phil Heath, professional athlete, bodybuilder and 7x Mr. Olympia, has fielded a lot of questions about bodybuilding without machines. Should bodybuilders be limited to just free weights? Why?
Featured supplier news
Featured supplier news: Introducing the Schwinn Z Bike: where innovation meets performance
In the dynamic world of indoor cycling, Schwinn has consistently been at the forefront of innovation. Now, we proudly present the Schwinn Z Bike, the culmination of our legacy of excellence.
Company profiles
Company profile: seca Ltd
As the world market leader of medical measuring and weighing we take body composition analysis ...
Company profiles
Company profile: Core Health & Fitness
Core Health & Fitness creates dynamic fitness experiences for the global market with products and ...
Supplier Showcase
Supplier showcase - Jon Williams
Catalogue Gallery
Click on a catalogue to view it online
Featured press releases
ABC Trainerize press release: New ABC Trainerize Webinar: How to earn more with clients and members you already have
ABC Trainerize, a leading software platform for the fitness industry, recently ran a webinar for studio and gym owners on how to increase gym revenue with Gym Launch CEO, Cale Owen.
Featured press releases
Alliance Leisure Services (Design, Build and Fund) press release: £26 Million Investment Paves The Way For Health and Wellbeing Hub At Lincolnshire Sport Complex
South Holland District Council has bolstered its successful £20 million UK Government, Levelling Up Fund bid with a £6 million investment to see the Castle Sports Complex in Spalding transformed into a health and wellbeing hub to drive positive health outcomes for residents across the district.
Directory
Salt therapy products
Himalayan Source: Salt therapy products
Spa software
SpaBooker: Spa software
Lockers
Crown Sports Lockers: Lockers
Snowroom
TechnoAlpin SpA: Snowroom
Flooring
Total Vibration Solutions / TVS Sports Surfaces: Flooring
Cryotherapy
Art of Cryo: Cryotherapy
Property & Tenders
Loughton, IG10
Knight Frank
Property & Tenders
Grantham, Leicestershire
Belvoir Castle
Property & Tenders
Diary dates
10-12 May 2024
China Import & Export Fair Complex, Guangzhou, China
Diary dates
23-24 May 2024
Large Hall of the Chamber of Commerce (Erbprinzenpalais), Wiesbaden, Germany
Diary dates
30 May - 02 Jun 2024
Rimini Exhibition Center, Rimini, Italy
Diary dates
08-08 Jun 2024
Worldwide, Various,
Diary dates
11-13 Jun 2024
Raffles City Convention Centre, Singapore, Singapore
Diary dates
12-13 Jun 2024
ExCeL London, London, United Kingdom
Diary dates
03-05 Sep 2024
IMPACT Exhibition Center, Bangkok, Thailand
Diary dates
19-19 Sep 2024
The Salil Hotel Riverside - Bangkok, Bangkok 10120, Thailand
Diary dates
01-04 Oct 2024
REVĪVŌ Wellness Resort Nusa Dua Bali, Kabupaten Badung, Indonesia
Diary dates
22-25 Oct 2024
Messe Stuttgart, Germany
Diary dates
24-24 Oct 2024
QEII Conference Centre, London, United Kingdom
Diary dates
04-07 Nov 2024
In person, St Andrews, United Kingdom
Diary dates

features

Sponsored briefing: Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data

Published in Health Club Management 2017 issue 11
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
Leisure and gym operators are custodians of a huge volume of detailed personal information on members, making our industry not only a soft target, but also an attractive one - Paul Simpson

Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations

Paul Simpson
Paul Simpson

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]

Sign up here to get HCM's weekly ezine and every issue of HCM magazine free on digital.
https://www.leisureopportunities.co.uk/images/299762_993010.jpg
Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital for operators to take action on how they store and secure all member data
Paul Simpson, chief operating officer, Legend Club Management Systems,Legend Club Management Systems, Paul Simpson, member data,
Latest News
Planet Fitness has announced the repurchase of 314,000 shares at a rate of US$20 million. ...
Latest News
Xponential Fitness today indefinitely suspended founder and CEO, Anthony Geisler, saying it had been notified ...
Latest News
Fast Fitness Japan, master franchisee of Anytime Fitness in Japan, has acquired Eighty-8 Health & ...
Latest News
Xplor Technologies has unveiled a financing solution for small businesses, which aims to counter the ...
Latest News
HoloBike, a holographic training bike that simulates trail rides in lifelike 3D, is aiming to ...
Latest News
Peloton Interactive Inc is believed to be working to get its costs under control in ...
Latest News
Equinox, has teamed up with health platform, Function Health, to offer 100 comprehensive laboratory tests, ...
Latest News
Having good levels of cardiorespiratory fitness cuts disease and premature death by 11 to 17 ...
Latest News
US gym chain, Crunch Fitness, has bolstered its global expansion plans with the appointment of ...
Latest News
Active Oxfordshire has received £1.3 million to tackle inactivity and inequality and launch a new ...
Latest News
Barry’s – known for its HIIT workouts combining treadmills and weights – is thought to ...
Featured supplier news
Featured supplier news: Phil Heath, 7x Mr Olympia, shares machine-only leg workout routine
Phil Heath, professional athlete, bodybuilder and 7x Mr. Olympia, has fielded a lot of questions about bodybuilding without machines. Should bodybuilders be limited to just free weights? Why?
Featured supplier news
Featured supplier news: Introducing the Schwinn Z Bike: where innovation meets performance
In the dynamic world of indoor cycling, Schwinn has consistently been at the forefront of innovation. Now, we proudly present the Schwinn Z Bike, the culmination of our legacy of excellence.
Company profiles
Company profile: seca Ltd
As the world market leader of medical measuring and weighing we take body composition analysis ...
Company profiles
Company profile: Core Health & Fitness
Core Health & Fitness creates dynamic fitness experiences for the global market with products and ...
Supplier Showcase
Supplier showcase - Jon Williams
Catalogue Gallery
Click on a catalogue to view it online
Featured press releases
ABC Trainerize press release: New ABC Trainerize Webinar: How to earn more with clients and members you already have
ABC Trainerize, a leading software platform for the fitness industry, recently ran a webinar for studio and gym owners on how to increase gym revenue with Gym Launch CEO, Cale Owen.
Featured press releases
Alliance Leisure Services (Design, Build and Fund) press release: £26 Million Investment Paves The Way For Health and Wellbeing Hub At Lincolnshire Sport Complex
South Holland District Council has bolstered its successful £20 million UK Government, Levelling Up Fund bid with a £6 million investment to see the Castle Sports Complex in Spalding transformed into a health and wellbeing hub to drive positive health outcomes for residents across the district.
Directory
Salt therapy products
Himalayan Source: Salt therapy products
Spa software
SpaBooker: Spa software
Lockers
Crown Sports Lockers: Lockers
Snowroom
TechnoAlpin SpA: Snowroom
Flooring
Total Vibration Solutions / TVS Sports Surfaces: Flooring
Cryotherapy
Art of Cryo: Cryotherapy
Property & Tenders
Loughton, IG10
Knight Frank
Property & Tenders
Grantham, Leicestershire
Belvoir Castle
Property & Tenders
Diary dates
10-12 May 2024
China Import & Export Fair Complex, Guangzhou, China
Diary dates
23-24 May 2024
Large Hall of the Chamber of Commerce (Erbprinzenpalais), Wiesbaden, Germany
Diary dates
30 May - 02 Jun 2024
Rimini Exhibition Center, Rimini, Italy
Diary dates
08-08 Jun 2024
Worldwide, Various,
Diary dates
11-13 Jun 2024
Raffles City Convention Centre, Singapore, Singapore
Diary dates
12-13 Jun 2024
ExCeL London, London, United Kingdom
Diary dates
03-05 Sep 2024
IMPACT Exhibition Center, Bangkok, Thailand
Diary dates
19-19 Sep 2024
The Salil Hotel Riverside - Bangkok, Bangkok 10120, Thailand
Diary dates
01-04 Oct 2024
REVĪVŌ Wellness Resort Nusa Dua Bali, Kabupaten Badung, Indonesia
Diary dates
22-25 Oct 2024
Messe Stuttgart, Germany
Diary dates
24-24 Oct 2024
QEII Conference Centre, London, United Kingdom
Diary dates
04-07 Nov 2024
In person, St Andrews, United Kingdom
Diary dates
Search news, features & products:
Find a supplier:
Elevate
Elevate
Partner sites