Home › Blog › GDPR for coaches: what client data you hold and how long to keep it
CoachingAgreements · Published 5 October 2026 · Last reviewed 5 October 2026 · 4 min read

GDPR for coaches: what client data you hold and how long to keep it

List every kind of client information you hold, why you hold it, where it is kept and when you will delete it. The UK GDPR sets no fixed retention period, so you choose one you can justify, and sole traders who use personal information need to pay the ICO data protection fee unless they are exempt.

Do coaches have to follow UK data protection law?

Yes, if you handle information about identifiable people, and every coach does: names, emails, session notes, payment details, goals. The ICO says organisations, including sole traders, that use personal information need to pay a data protection fee, unless they are exempt. Check the ICO's website to see whether you need to pay, because the rules on who is exempt are set out there.

None of this needs a large compliance project. A short written register of what you hold is a sensible first step, and it makes your privacy notice easier to write accurately.

Map what you hold

Go through your practice and list each type of client information. A typical coach holds more than they realise.

Choosing a lawful reason and being honest about it

For each item, note why you hold it. The ICO says the contract lawful basis can apply where you need to process data to deliver a contractual service to someone, but the processing must be more than just useful: it should be a targeted and proportionate step integral to delivering the service. Contact details and invoices are usually easy to justify. Optional extras, such as recordings or testimonials, normally need the client's separate agreement instead. Tell clients what you do in a privacy notice.

How long to keep client information

The ICO says the UK GDPR does not set specific time limits for different types of data. That is up to you, depending on how long you need the data for your purposes. It also says you should document standard retention periods for categories of information, review whether you still need data at the end of the period, and erase or anonymise it unless there is a clear justification to keep it.

Practical points: tax and accounting records may have their own rules, so ask your accountant. Check your insurer's terms for how long they expect records to be kept. Then set one period for each category of information and write it in your register and privacy notice.

Keeping it secure

The ICO says you need appropriate technical and organisational measures to ensure security appropriate to the risk, that you should review the personal data you hold and how you use it, and that data should be accessible only to people you authorise. It recommends encryption for personal data you store or send over the internet. For a solo coach that usually means strong unique passwords, two-step verification, locked devices and not leaving client files in shared folders.

See our guide to confidentiality clauses that build client trust for how to explain this to clients.

What a client data and retention register should capture

A preview of our free Client Data and Retention Register. The complete, print-ready version is sent to you by email.

Client Data and Retention RegisterPreview

Your practice

  • Practice or business name
  • Date register completed or reviewedDate
  • + 2 more in the full form

What you hold

  • Contact details: where are they kept, and for how long?Free text
  • Agreements and invoices: where are they kept, and for how long?Free text
  • + 5 more in the full form

Why you hold it

  • Reason you need each type of information to deliver your coachingFree text
  • Anything you hold only with the client's separate agreement (for example recordings or testimonials)Free text
  • + 1 more in the full form

Security and sharing

  • Devices and accounts that hold client informationFree text
  • Do you use strong, unique passwords and two-step verification?Yes / No
  • + 3 more in the full form

The full form has 19 questions in 4 sections, a signed declaration and space for your business details. Get it free below.

Free template

Get the print-ready Client Data and Retention Register

A one-page register of what client information you hold, where it is kept and when it is deleted. Free, and yours to adapt.

We send one email to confirm your address first. See our privacy policy.

Frequently asked questions

Do I need to pay the ICO data protection fee as a coach?

The ICO says organisations, including sole traders, that use personal information need to pay a fee unless they are exempt. Check the ICO's website for whether you are exempt.

How long should a coach keep client notes?

The UK GDPR sets no fixed period. Choose one you can justify, document it and delete or anonymise the notes when it ends. Check your insurer's expectations and ask your accountant about financial records.

Do I need a privacy notice for coaching clients?

You need to tell clients what you do with their information in a clear, accessible way. A privacy notice is the usual method. Keep it consistent with your register.

Is it safe to keep client notes on my phone or in email?

The ICO says security should be appropriate to the risk. Use device locks, strong passwords and two-step verification, keep as little as you need and think about encryption for sensitive material.

Sources

Every agreement your coaching practice needs

Starter (£29) covers the coaching agreement, cancellation and refund policy, GDPR and confidentiality and online coaching addendum. Pro (£49) adds group, corporate and intake documents. One payment, no auto-renewal.

See the packs, from £29 →

These articles are general guidance for UK coaches, not legal advice. Our documents are editable templates: adapt them to your own practice, your insurer's terms and, where it matters, take advice from a solicitor. Coaching is not therapy or counselling.