Follow Health Club Management on Twitter Like Health Club Management on Facebook Join the discussion with Health Club Management on LinkedIn
FITNESS, HEALTH, WELLNESS

features

Sponsored briefing: Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data

Published in Health Club Management 2017 issue 11
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
Leisure and gym operators are custodians of a huge volume of detailed personal information on members, making our industry not only a soft target, but also an attractive one - Paul Simpson

Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations

Paul Simpson
Paul Simpson

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]

Sign up here to get HCM's weekly ezine and every issue of HCM magazine free on digital.
https://www.leisureopportunities.co.uk/images/299762_993010.jpg
Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital for operators to take action on how they store and secure all member data
Paul Simpson, chief operating officer, Legend Club Management Systems,Legend Club Management Systems, Paul Simpson, member data,
HCM magazine
As the entrepreneur who started Wexer, Fresh Fitness, Fitness DK and Repeat, as well as being a former elite athlete, Rasmus Ingerslev’s life looked perfect from the outside, but onthe inside it was a different story. He talks to Kath Hudson about healing old wounds
HCM magazine
I experienced a blissful feeling of joy I hadn’t felt since I was a kid
HCM magazine
Small improvements to sleep, diet and physical activity have major benefits for the heart, according to new research from the University of Sydney
HCM magazine
Collaborations with the medical profession and greater aspirations around wellbeing are creating a need for more experts in our sector. It’s time to reboot our thinking around the workforce
HCM magazine
For every member with a tripod and a big following, there are others irritated at the way equipment is being hogged or wary they’ll be in the background on someone’s Insta feed. Do influencers offer valuable, free marketing or are they just a nuisance? Kath Hudson finds out how operators are responding
HCM promotional features
Sponsored
Greg Bradley looks at the shift towards strength training in gyms and advises on how operators can create the ultimate training environment
HCM promotional features
Sponsored
SnowDome Fitness has added 50 per cent more space with cutting-edge Technogym solutions
HCM promotional features
Sponsored
Find out how your gym can tap into the corporate wellness boom
HCM promotional features
Sponsored
David Lloyd is stepping up its commitment to women’s health as it continues to explore what fit-for-purpose looks like for the female population
HCM promotional features
Sponsored
Starpool supports Olympic champion Marcell Jacobs, says Riccardo Turri
HCM promotional features
Sponsored
Third Space partnered with IndigoFitness to deliver a bespoke training space for its new club at The Whiteley
HCM promotional features
Sponsored
EGYM has opened a new HQ in Paternoster Square, London and revealed a range of new launches
HCM promotional features
Promotion
BLK BOX has been reimagining elite performance spaces for more than a decade. Founder and former athlete, Greg Bradley, tells us what it takes
HCM promotional features
Sponsored
The industry is embracing consumer-facing tech. Now it’s time to streamline back-of-house systems with Orbit4, says Daniel Jones
HCM promotional features
Latest News

Samsung has unveiled a suite of AI-powered health features for its Galaxy Watch ...

Latest News
Celebrating its 10th anniversary, Elevate has had its busiest show to date, with almost 200 ...
Latest News
A new report from Your Personal Training (YPT) suggests UK gym operators could be missing ...
Latest News
Eighty-four per cent of consumers now say wellness is a top priority in their lives, ...
Latest News
Elevate Arena is underway at London's Excel and the hot topic of AI was the ...
Latest News
PureGym Group has announced that group chief financial officer, Alex Wood, is taking over the ...
Latest News
Independent operator, Fitness Worx Gyms, is introducing private blood testing as a service to members. ...
Latest News
International industry lobbying associations are calling for physical activity and strength training to be deeply ...
Opinion
promotion
Strength training has moved from the margins to the mainstream.
Opinion: Building smarter strength spaces for today’s operators
Featured supplier news
Featured supplier news: CoverMe extends matching service to personal training, rewriting how members and personal trainers connect
CoverMe, the global leader in fitness workforce management, today launches CoverMe PT, an on-demand personal training platform that connects the right personal trainer to the right client in under 10 seconds.
Featured supplier news
Featured supplier news: Reaching the people most gyms miss: Bedford Gym & Swim Campaign delivers 410 new members
One of the biggest mistakes the fitness industry still makes is advertising almost exclusively to people who already look and live like gym members.
Company profiles
Company profile: Myzone
Myzone is a global pioneer of Motivation Technology (MoTech), redefining fitness by turning behavioural science ...
Company profiles
Company profile: Alliance Leisure
The company’s core business is the provision of facility development and support for local authorities, ...
Supplier Showcases
Supplier Showcase - From nightclub to health club
Supplier Showcases
Supplier Showcase - Future-proofing
Catalogue Gallery
Click on a catalogue to view it online
Featured press releases
Create PT press release: Create sets a new standard with its new personal training diploma
Create's new Personal Training Diploma is built on the depth, real-client practice and coaching judgement that turn a qualification into genuine readiness - taught as one continuous course so that every skill is reinforced and applied, not cleared once and forgotten.
Featured press releases
Leisure Energy press release: Studley Leisure Centre solar panel installation project begins
Stratford-on-Avon District Council is delighted to announce a new solar panel installation project at Studley Leisure Centre, marking an important step towards improving the sustainability of this valued community facility.
Directory
Fitness tracking platform
SpiviTech: Fitness tracking platform
Industrial washing machines
Miele Company Limited: Industrial washing machines
Water experiences and hydrotherapy solutions
Aquaform s.r.l.: Water experiences and hydrotherapy solutions
Lockers
Crown Sports Lockers: Lockers
Spa and beauty equipment
Oakworks Inc: Spa and beauty equipment
Hot tubs
MSpa International Ltd: Hot tubs
Property & Tenders
Stratford, East London.
Lee Valley Regional Park Authority
Property & Tenders
Y Felinheli, LL56 4QN
Newmark
Property & Tenders
Diary dates
22-23 Jun 2026
WX Wakefield , Wakefield, United Kingdom
Diary dates
21-24 Sep 2026
The Langham Huntington Pasadena , Pasadena, United States
Diary dates
06-08 Oct 2026
Messe Stuttgart, Stuttgart, Germany
Diary dates
22-22 Oct 2026
QEII Conference Centre, London,
Diary dates
26-29 Oct 2027
Koelnmesse Exhibition Centre, Cologne, Germany
Diary dates

features

Sponsored briefing: Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data

Published in Health Club Management 2017 issue 11
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
Leisure and gym operators are custodians of a huge volume of detailed personal information on members, making our industry not only a soft target, but also an attractive one - Paul Simpson

Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations

Paul Simpson
Paul Simpson

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]

Sign up here to get HCM's weekly ezine and every issue of HCM magazine free on digital.
https://www.leisureopportunities.co.uk/images/299762_993010.jpg
Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital for operators to take action on how they store and secure all member data
Paul Simpson, chief operating officer, Legend Club Management Systems,Legend Club Management Systems, Paul Simpson, member data,
Latest News

Samsung has unveiled a suite of AI-powered health features for its Galaxy Watch ...

Latest News
Celebrating its 10th anniversary, Elevate has had its busiest show to date, with almost 200 ...
Latest News
A new report from Your Personal Training (YPT) suggests UK gym operators could be missing ...
Latest News
Eighty-four per cent of consumers now say wellness is a top priority in their lives, ...
Latest News
Elevate Arena is underway at London's Excel and the hot topic of AI was the ...
Latest News
PureGym Group has announced that group chief financial officer, Alex Wood, is taking over the ...
Latest News
Independent operator, Fitness Worx Gyms, is introducing private blood testing as a service to members. ...
Latest News
International industry lobbying associations are calling for physical activity and strength training to be deeply ...
Latest News
Global group exercise specialist, Les Mills, is inviting operators to sign up to its Workout ...
Latest News
Global luxury hospitality brand, Six Senses, has partnered with longevity healthcare provider, HUM2N, to launch ...
Latest News
Premium London health club, KX Chelsea, is gearing up to unveil its most significant redevelopment ...
Opinion
promotion
Strength training has moved from the margins to the mainstream.
Opinion: Building smarter strength spaces for today’s operators
Featured supplier news
Featured supplier news: CoverMe extends matching service to personal training, rewriting how members and personal trainers connect
CoverMe, the global leader in fitness workforce management, today launches CoverMe PT, an on-demand personal training platform that connects the right personal trainer to the right client in under 10 seconds.
Featured supplier news
Featured supplier news: Reaching the people most gyms miss: Bedford Gym & Swim Campaign delivers 410 new members
One of the biggest mistakes the fitness industry still makes is advertising almost exclusively to people who already look and live like gym members.
Company profiles
Company profile: Myzone
Myzone is a global pioneer of Motivation Technology (MoTech), redefining fitness by turning behavioural science ...
Company profiles
Company profile: Alliance Leisure
The company’s core business is the provision of facility development and support for local authorities, ...
Supplier Showcases
Supplier Showcase - From nightclub to health club
Supplier Showcases
Supplier Showcase - Future-proofing
Catalogue Gallery
Click on a catalogue to view it online
Featured press releases
Create PT press release: Create sets a new standard with its new personal training diploma
Create's new Personal Training Diploma is built on the depth, real-client practice and coaching judgement that turn a qualification into genuine readiness - taught as one continuous course so that every skill is reinforced and applied, not cleared once and forgotten.
Featured press releases
Leisure Energy press release: Studley Leisure Centre solar panel installation project begins
Stratford-on-Avon District Council is delighted to announce a new solar panel installation project at Studley Leisure Centre, marking an important step towards improving the sustainability of this valued community facility.
Directory
Fitness tracking platform
SpiviTech: Fitness tracking platform
Industrial washing machines
Miele Company Limited: Industrial washing machines
Water experiences and hydrotherapy solutions
Aquaform s.r.l.: Water experiences and hydrotherapy solutions
Lockers
Crown Sports Lockers: Lockers
Spa and beauty equipment
Oakworks Inc: Spa and beauty equipment
Hot tubs
MSpa International Ltd: Hot tubs
Property & Tenders
Stratford, East London.
Lee Valley Regional Park Authority
Property & Tenders
Y Felinheli, LL56 4QN
Newmark
Property & Tenders
Diary dates
22-23 Jun 2026
WX Wakefield , Wakefield, United Kingdom
Diary dates
21-24 Sep 2026
The Langham Huntington Pasadena , Pasadena, United States
Diary dates
06-08 Oct 2026
Messe Stuttgart, Stuttgart, Germany
Diary dates
22-22 Oct 2026
QEII Conference Centre, London,
Diary dates
26-29 Oct 2027
Koelnmesse Exhibition Centre, Cologne, Germany
Diary dates
Search news, features & products:
Find a supplier:
Partner sites