Studio Journal
Compliance17 June 20267 min read

POPIA for fitness studios: a plain-English checklist

You hold names, numbers, medical notes and payment records. Here is what POPIA actually asks of a small studio, without the legal jargon.

The Protection of Personal Information Act applies to your studio whether you have twelve members or twelve hundred. The good news is that most of what it asks is what a careful studio would do anyway. This is not legal advice — get that from someone qualified — but it will tell you where to look.

You are the responsible party

In POPIA language, you are the "responsible party" for your members' personal information. Your booking software is an "operator" processing it on your behalf. That means the obligations sit with you, and your job is to make sure the tools you use let you meet them.

What you almost certainly hold

  • Names, email addresses and phone numbers
  • Emergency contact details
  • Medical notes and injury information — this is special personal information and deserves more care
  • Payment and invoice records
  • Attendance history, which reveals where someone was on a given evening

The checklist

Work through these in order. Most studios can do the whole list in an afternoon.

  • Collect only what you use. If you have never once phoned a member's home address, stop asking for it.
  • Say why you are collecting it. A short privacy policy linked from your signup page is enough for most studios.
  • Get consent at signup, not afterwards. Members should accept your terms and privacy policy as part of joining.
  • Keep medical notes restricted to staff who genuinely need them to keep someone safe in class.
  • Be able to export a member's data if they ask. They have a right to it, and "I would have to go through three spreadsheets" is not an answer.
  • Be able to delete a member on request — while keeping the invoices SARS requires you to retain.
  • Know who on your team can see what. Front-desk staff rarely need billing access.
  • Have a plan for a breach. Even a small one: who you tell, and how fast.

The retention tension

A member asks to be deleted, but you are legally required to keep tax records for five years. The workable answer is anonymization rather than deletion — redact the personal details, keep the invoice with an anonymous reference. Your software should do this in one action rather than leaving you to do it by hand.

Waivers are a separate conversation

Your indemnity waiver is a contract about risk. Your privacy consent is about data. Bundling them into one tick box weakens both. Keep the waiver as its own explicit signature, versioned, so you can prove exactly which wording a member agreed to and when. If you later change the wording, ask people to sign again rather than assuming the old signature covers the new text.

Where studios usually slip

Not in the policy document — in the WhatsApp group. Class lists shared in a group chat, medical notes forwarded to a stand-in instructor, a spreadsheet of member phone numbers on a personal laptop. POPIA compliance is mostly about where information ends up, not what your website says. Keeping member data inside a system with proper access control is the single biggest improvement most studios can make.

Pulse Studio does the admin part of this.

Bookings, waitlists, packages and invoicing for South African studios — free to start, pricing on the website, no sales call required.

Ready to see it with your classes in it?

Free plan for small studios. 14-day free trial on every paid plan — no credit card, no sales call.