ArabGym
Compliance

Saudi PDPL Compliance for Gyms: A Practical Checklist

A gym collects more sensitive data than most owners realize: ID photos, a fingerprint, an emergency contact, sometimes body measurements. Saudi PDPL has been actively enforced since September 2024, and it has moved from published guidance to real decisions and fines.

7 min read

Ask a gym owner what the most sensitive data they hold is, and they usually answer “card numbers” — and in doing so they have already answered that they do not store those at all, since payments pass straight through a payment provider. What they rarely mention is what they actually do store: every member’s ID photo, phone number, emergency contact, date of birth, and sometimes a fingerprint if the entrance gate scans one. All of that is personal data under Saudi Arabia’s Personal Data Protection Law (PDPL), and some of it sits in the higher-risk category: sensitive data.

The common mistake is assuming PDPL is a law for banks and hospitals. It applies to any entity that processes the personal data of Saudi residents, regardless of size or sector. The law came into force in September 2023, with a one-year transition period, and became fully enforceable on 14 September 2024. Since then it has stopped being theoretical: the regulator has moved from publishing guidance to actually issuing decisions against organizations found in violation.

What counts as personal data at your front desk

Any information that identifies a member, or can be linked back to one, is personal data — and that is a much wider net than most gym owners picture. A normal front-desk record already contains more than half of the list below, without anyone thinking of it as “data” that needs protecting:

  • Full name, phone number, and email address.
  • The ID or residency photo uploaded at sign-up.
  • The emergency contact — another person’s name and phone number, which is personal data belonging to that person, not only to the member.
  • The attendance log: when the member checked in, how often, and at which branch.
  • Body metrics a coach logs — weight, body-fat percentage, and similar figures.
  • IP address and browsing activity on the member portal, which counts as personal data too.

A legal point that gets missed often: your gym is not the “owner” of this data in the legal sense — it is the Data Controller, the party that decides why the data is collected and how it is used. Any system you run the gym on, ArabGym included, acts as a Data Processor executing instructions on your behalf. That distinction matters because the core legal obligations — getting valid consent, having a lawful basis for processing — sit with you as the controller, not with the software vendor.

The higher-risk category: sensitive data

The law defines “sensitive data” as data revealing racial or ethnic origin, religious, intellectual or political belief, criminal record data, biometric or genetic data used to identify a person, health data, and data indicating that one or both of a person’s parents are unknown. This category carries higher requirements: stronger safeguards, and in some cases an impact assessment before processing.

If your gym uses fingerprint scanning, the practical step is not necessarily abandoning it — it is confirming that whatever stores that data, whether the gate device itself or the connected system, isolates and encrypts it, and that staff access to it is restricted and logged rather than open to any shared front-desk login.

What members are entitled to over their own data

PDPL grants the data subject — your gym’s member — a clear set of rights over their own data. Ignoring them is not only a violation; it is a real source of friction with members who ask simple questions and cannot find anyone able to answer quickly.

Member rights and what they mean on the gym floor
RightWhat it means in practice
AccessA member can request a copy of every piece of data you hold on them — not a summary, the full record.
CorrectionAn outdated phone number or a wrong birth date must be correctable easily, not through a complicated formal request.
DeletionOn cancellation, a member can request deletion of their data once any legally required retention period has passed.
ObjectionA member who does not want marketing messages must be able to stop them without cancelling their whole membership.
Withdrawing consentConsent once given can be withdrawn later, and withdrawing it must be as easy as giving it was.
Member rights and what they mean on the gym floor

If a breach happens: the 72-hour clock

If data leaks — an exposed database, a stolen device holding a member list, even a spreadsheet emailed to the wrong recipient — the law requires notifying the regulator within 72 hours of discovering the breach, with no exception based on the breach’s perceived size or severity. That is stricter than some comparable international frameworks, which allow skipping notification when the data was encrypted or the risk is assessed as low.

The notification itself is not one sentence — it needs a description of what happened and how, the category and approximate number of affected individuals, an assessment of the likely impact, and the steps taken to contain it and prevent a repeat. Having that information ready before any incident occurs, rather than assembling it during the first panicked hours, is what makes the 72-hour deadline realistic to meet.

Registration, and the real cost of getting it wrong

Entities that process sensitive data, transfer data outside the Kingdom, or handle the data of minors or vulnerable groups are required to register as a data controller on SDAIA’s National Data Governance Platform. A gym using fingerprint check-ins, or storing health-adjacent data through body-metric tracking, may fall inside that scope — and that is a question worth putting to your own legal advisor specifically, rather than assuming the answer.

And the fine figures are not symbolic. Substantive violations reach SAR 5 million, doubling to SAR 10 million for repeat violations. Intentional disclosure of sensitive data carries a criminal penalty of up to two years in prison, a fine of up to SAR 3 million, or both at the court’s discretion, doubling on repeat offenses. The regulator can additionally order a full suspension of processing, while the courts — or the committee that reviews violations — can order publication of the judgment at the violator’s own expense and confiscation of any proceeds tied to the violation.

A practical checklist for a gym owner

  1. Collect only what you actually need. A mandatory “nationality” or “email” field with no clear operational purpose is risk without benefit — make it optional or drop it.
  2. Ask your software vendor three specific questions: is data encrypted in transit? Is your gym’s data isolated from other gyms on the same platform? And what is the retention policy after an account is cancelled?
  3. Make marketing messages explicitly opt-in, with a clear opt-out the member can find — not buried three menus deep.
  4. Restrict staff access to member data by actual role, and turn on an audit log that shows who opened which file and when — not one shared front-desk login everyone uses.
  5. Name one responsible person — even if it is you — who receives member access or deletion requests and responds within a reasonable window, not whenever someone remembers to.
  6. Write an actual privacy policy describing your own data practices, not one copied from another business in a completely different sector.

Nothing on this list slows down the gym’s daily operation. Most of it is a one-time setup, and the rest becomes part of the front-desk routine within a week. The real cost is not compliance — it is deferring it until it becomes a forced response after an incident.

Frequently asked questions

Does PDPL apply to a small gym, or only to large companies?
It applies to any entity processing the personal data of Saudi residents, regardless of size. Some additional obligations — like mandatory registration or appointing a data protection officer — hinge on the nature and scale of the processing rather than company size alone, which is why checking your specific situation with a qualified advisor matters more than assuming an exemption just because you run one small gym.
Is a fingerprint used for attendance check-in considered sensitive data?
Yes. A fingerprint used to identify a person is biometric data, one of the categories the law defines as sensitive, and it requires stronger safeguards than data like a name or phone number. That does not rule out using it — it raises the bar for how it must be stored and who can access it.
What happens if member data is breached?
The law requires notifying the regulator within 72 hours of discovering the breach, with no exception based on the incident’s size, and the notification must include a description of what happened, the category and approximate number of affected individuals, an impact assessment, and the steps taken. Having that information ready in advance is what makes the deadline realistic.
Does using software like ArabGym make me automatically PDPL-compliant?
No. The software is a Data Processor operating under specific security controls — such as encryption in transit, per-gym data isolation, and a defined retention policy — but you remain the Data Controller: the one who decides why data is collected, what the lawful basis for processing is, and how member consent is managed. Compliance is a shared responsibility, not a one-party guarantee.
What is the difference between ZATCA e-invoicing and PDPL?
E-invoicing governs how tax invoices are issued and documented, overseen by the Zakat, Tax and Customs Authority. PDPL governs how people’s personal data is collected, protected, and used, overseen by the Saudi Data and AI Authority. Your gym needs to comply with both, and they are entirely independent of each other.

Related ArabGym features

Saudi PDPL Compliance for Gyms: A Practical Checklist | ArabGym