A Coach's Guide to GDPR: What You Actually Need to Worry About
By The Mentric Team
Most coaches know they should care about GDPR. Far fewer know what they actually need to do about it. The regulation is long, the language is dense, and the guidance out there tends to be written for large enterprises, not someone running a coaching practice.
This is not legal advice. But it is practical guidance from people who work with coaches every day and have seen how data protection plays out in real coaching contexts.
You are almost certainly a data controller
If you decide what data to collect from coachees, how to store it, and what to do with it, you are a data controller under GDPR. That applies whether you are an independent coach or part of an organisation.
Being a data controller means you are responsible for how personal data is handled. You cannot outsource that responsibility entirely, even if you use third-party tools to store it.
If you work within an organisation’s coaching programme, the organisation may be the data controller and you may be a data processor acting on their instructions. This distinction matters. If you are unsure, clarify it in your contract before you start the engagement.
What counts as personal data in coaching?
More than you might think. Personal data is any information that can identify a living person, directly or indirectly. In a coaching context, that includes:
- Names, email addresses, phone numbers
- Session notes (yes, even your handwritten ones)
- Assessment results and 360 feedback responses
- Goals and development plans
- Audio or video recordings of sessions
- Any notes that reference a coachee’s health, relationships, or personal circumstances
That last category is worth flagging. Notes about someone’s mental health, stress levels, or personal relationships could qualify as “special category data” under GDPR. This type of data gets extra protection and generally requires explicit consent to process.
Consent is not a magic word
Coaches often assume that getting a signature on a coaching agreement covers GDPR consent. It might. It might not.
For consent to be valid under GDPR, it needs to be freely given, specific, informed, and unambiguous. A blanket clause buried in paragraph twelve of your terms does not meet that standard.
More importantly, consent is not always the right legal basis for processing data. If you are coaching someone as part of their employer’s programme, the legal basis might be “legitimate interests” or “performance of a contract” rather than consent. The right basis depends on the context.
What matters most is that you can explain, clearly and simply, what data you collect, why you collect it, and what you do with it. Write a short privacy notice for your coaching practice. It does not need to be long. One page is fine.
What to do when a coachee asks for their data
Under GDPR, individuals have the right to request a copy of all personal data you hold about them. This is called a Subject Access Request (SAR), and you have one month to respond.
When this happens:
- Confirm the identity of the person making the request
- Gather all personal data you hold about them, across every system and notebook
- Provide it in a commonly used electronic format (PDF or CSV works fine)
- Do it within 30 days
Coachees also have the right to ask you to delete their data (the “right to erasure”). You can refuse if you have a legitimate reason to keep it, such as a legal obligation or an ongoing contractual relationship, but you need to explain why.
This is one area where having your data organised in a single system rather than scattered across notebooks, email threads, and spreadsheets makes a real difference. If someone asks for their data and you have to dig through three years of handwritten notes, you are going to have a bad afternoon.
Data retention: how long is too long?
GDPR does not specify exact retention periods. Instead, it says you should keep personal data only for as long as necessary for the purpose it was collected.
For coaching, a reasonable approach is to keep session notes and records for the duration of the engagement plus a defined period afterwards. Many coaches settle on two to three years post-engagement, which aligns with typical professional indemnity insurance periods.
Whatever you decide, document it. Write down your retention policy, stick to it, and actually delete data when the time comes.
Practical steps you can take this week
You do not need to hire a lawyer to get the basics right. Here is a short list of things you can do immediately:
- Write a privacy notice that explains what data you collect, why, how long you keep it, and who you share it with. Give it to every new coachee.
- Audit your tools. Where does coachee data live right now? Email, Google Drive, a CRM, a coaching platform, paper notebooks? List them all.
- Check your contracts. If you work with organisations, make sure your contract addresses data protection responsibilities. Who is the controller? Who is the processor?
- Set up a retention schedule. Decide how long you keep data after an engagement ends, and put a reminder in your calendar to review and delete.
- Use a platform with built-in data export. When a coachee requests their data, you want to click a button, not spend a day compiling files.
The bigger picture
GDPR is not really about compliance checklists. It is about treating people’s personal information with respect, something coaches should care about anyway. Your coachees trust you with sensitive, personal details about their lives and careers. Handling that data carefully is part of the professional relationship.
Getting the basics right is not hard. It just requires a bit of thought upfront and some discipline in how you manage information. Most coaches who take an afternoon to sort this out find it far less painful than they expected.
And if you are ever truly unsure about something, get proper legal advice. A one-hour consultation with a data protection specialist is worth far more than guessing.
← Back to Resources