Personal Trainers and Personal Data
If you are a personal trainer in the UK with a website, you are almost certainly processing personal data. The moment a prospective client fills in your contact form, books a consultation, or submits a health questionnaire, personal data processing begins.
For many PTs, this extends to health data — injury history, medical conditions, fitness goals, dietary information. Under UK GDPR, health data is special category data that carries stricter obligations than ordinary personal data. You need explicit consent to process it, a lawful basis for holding it, and appropriate technical measures to protect it.
Most personal trainers focus on their programming, their client results, and their marketing. Website security is rarely on the list. This guide covers what you actually need to know — without the corporate IT department jargon.
What Data Are You Collecting?
Before looking at security, it is worth mapping what you are actually collecting through your website and systems:
**Contact forms** — Name, email address, phone number. Personal data. Requires a privacy notice.
**Health and fitness questionnaires** — Injury history, medical conditions, medications, fitness goals. Special category health data. Requires explicit consent and careful handling.
**Booking and scheduling systems** — If you use an online booking tool (Acuity, Calendly, Mindbody, etc.), you are transferring personal data to a third-party processor. You need a Data Processing Agreement with that provider.
**Payment details** — If you take card payments through your website, you are subject to PCI DSS compliance obligations in addition to GDPR. Using a reputable payment processor like Stripe or PayPal means you are not storing raw card data — the processor handles that — but you must ensure your website does not intercept it.
**Email marketing lists** — If you collect emails for a newsletter or follow-up sequence, you need clear consent and must provide an unsubscribe mechanism.
You are not required to be a data protection expert. You are required to handle this data responsibly, which means having appropriate security measures in place.
The Real Risks for a PT's Website
**Contact form exploitation** — Most personal trainer websites use WordPress or a website builder. Contact forms, booking widgets, and lead capture pages built on outdated plugins or with default configurations are a consistent source of vulnerabilities. SQL injection through a contact form on a six-month-old WordPress site is an extremely common finding.
**Client login portal weaknesses** — If you use a client portal (common in coaching apps and custom website builds), weak authentication — no brute force protection, no multi-factor authentication, weak password requirements — is often the easiest way in. A compromised client portal exposes health questionnaires and personal programme details.
**Outdated WordPress plugins** — The majority of personal trainer websites run on WordPress. WordPress itself is regularly updated and reasonably secure, but the plugin ecosystem is not. An abandoned plugin with a known SQL injection vulnerability sits in thousands of PT websites. Attackers scan for these systematically.
**Hosting account compromise** — If your hosting account (cPanel, Cloudways, WP Engine dashboard) is compromised through a weak password or phishing, an attacker has full control over your website and everything in it.
**Domain spoofing** — Without SPF and DMARC records on your domain, anyone can send emails appearing to come from your address. This enables impersonation — sending fraudulent payment requests to your clients, for example.
UK GDPR Obligations for Personal Trainers
You do not need to register with the ICO as a sole trader if you only process data for core business purposes (managing your clients, keeping accounts). But if you use client data for marketing, you do need to register. ICO registration costs £40–£60 per year.
Regardless of registration, you must:
**Have a privacy notice on your website** — Tell people what data you collect, why you collect it, how long you keep it, and their rights under UK GDPR. The ICO provides a template.
**Get explicit consent for health data** — A health questionnaire must include a specific consent statement for processing health information. Pre-ticked boxes do not count.
**Protect the data you hold** — Appropriate technical measures for a PT website include: HTTPS, a reputable hosting provider, keeping your CMS and plugins updated, not storing client health data in an unencrypted spreadsheet in your email account.
**Report breaches** — If your website is compromised and client data is exposed, you may be required to notify the ICO within 72 hours. If it is high-risk data (health information, financial details), you must also notify the affected clients.
Practical Security Steps for Personal Trainers
These are low-cost, high-impact steps that address the most common vulnerabilities:
**Keep WordPress and all plugins updated** — Enable automatic updates or check monthly. Delete plugins you are not using — they are still exploitable.
**Use a reputable contact form plugin** — Contact Form 7 with the Flamingo add-on, Gravity Forms, or WPForms are maintained, regularly updated, and widely supported. Avoid obscure plugins with few updates.
**Install a free security plugin** — Wordfence Security (free tier) adds brute force protection, file integrity monitoring, and firewall rules to a WordPress site with no technical knowledge required.
**Enable HTTPS** — If your site still serves any pages over HTTP, fix this. Free SSL from Let's Encrypt is available through almost all hosting providers.
**Use strong, unique credentials** — Different passwords for your hosting account, WordPress admin, email, and payment processor. A password manager makes this practical.
**Add SPF and DMARC records** — Prevents domain spoofing. Your domain registrar's DNS settings is where to add these. Ask your hosting provider if you need help.
**Run a security scan** — Yrzo AI runs 44 automated security checks on your website and delivers a plain-English report identifying what needs fixing, in under 20 minutes. Starting at £99, it is designed for small businesses and self-employed professionals who want to know where they stand without commissioning a full penetration test.
Your clients trust you with their health information. Protecting it is part of the service.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →