Early bird
tickets
available now!
GET HCM
magazine
Sign up for the FREE digital edition of HCM magazine and also get the HCM ezine and breaking news email alerts.
Not right now, thanksclose this window I've already subscribed!
Savills
Savills
Savills
Follow Health Club Management on Twitter Like Health Club Management on Facebook Join the discussion with Health Club Management on LinkedIn
FITNESS, HEALTH, WELLNESS

features

Sponsored briefing: Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data

Published in Health Club Management 2017 issue 11
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
Leisure and gym operators are custodians of a huge volume of detailed personal information on members, making our industry not only a soft target, but also an attractive one - Paul Simpson

Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations

Paul Simpson
Paul Simpson

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]

Sign up here to get HCM's weekly ezine and every issue of HCM magazine free on digital.
https://www.leisureopportunities.co.uk/images/299762_993010.jpg
Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital for operators to take action on how they store and secure all member data
Paul Simpson, chief operating officer, Legend Club Management Systems,Legend Club Management Systems, Paul Simpson, member data,
HCM magazine
As the UK healthcare sector struggles with ever-increasing demand, health club operators are stepping in and offering members welcome medical support. Kath Hudson reports
HCM magazine
Indoor bikes may remain stationary, but the discipline is in constant motion. Innovators tell Steph Eaves how they’re keeping pace with the latest trends
HCM magazine
Dr Tim Anstiss is developing coachbots that are supporting positive behaviour change for operators such as Life Leisure and KA Leisure
HCM magazine
Weight loss drugs are altering consumer behaviour, disrupting sectors from food retailing (smaller portions) to apparel (less fabric needed). We need to move fast to align with this new reality
HCM magazine
Disappointment about being passed over for promotion gave Neil Randall, the resilience he needed to climb the ranks. He talks to Kath Hudson about the challenges he faced early in his career and the skills he learned from them
HCM promotional features
Sponsored
The level of support I get from Xplor Gym is what customer service is all about
HCM promotional features
Sponsored
Adding EGYM’s easy onboarding, personalised workouts and progress-tracking is driving retention and engagement at Vivacity Premier Fitness
HCM promotional features
Sponsored
Life Fitness has reimagined cardio with the launch of its Symbio line which has been designed with advanced biomechanics and offers deep levels of customisation
HCM promotional features
Sponsored
Sustainability in the fitness industry is coming on in leaps and bounds as more operators refurbish their gym equipment to save money and the planet
HCM promotional features
Sponsored
A major refurbishment of Sport Ireland Fitness by Technogym has created a world-class public gym at the home of Irish sport
HCM promotional features
Sponsored
We all know we need to stand more. Now an exciting new partnership between Physical and Teca Fitness expands this thinking into UK gyms and beyond
HCM promotional features
Sponsored
At the heart of the Sydney Swans new headquarters in Australia is an elite player-focused training facility by strength equipment specialist BLK BOX
HCM promotional features
Sponsored
Coaching workshops from Keith Smith and Adam Daniel have been designed to empower your team and transform your service
HCM promotional features
Latest News
Urban Gym Group CEO Neil Randall talks in this month’s HCM about how being passed ...
Latest News
Boxing and strength franchise UBX has taken a step closer to realising its ambitions to ...
Latest News
Fitness International has announced the acquisition of XSport Fitness, adding to its portfolio of brands, ...
Latest News
Community Leisure UK (CLUK) and The Richmond Group of Charities have joined forces to support ...
Latest News
Mental Health Swims has been awarded almost £18,000 of lottery money to extend its mission ...
Latest News
Employee wellness app GoJoe has teamed up with Les Mills for a major new content ...
Latest News
Former footballer, David Beckham, has become a strategic investor in health sciences company, Prenetics, which ...
Latest News
Gymbox has partnered with Haringey Council and not-for-profit organisation, Raza Sana, to give opportunities to ...
Featured supplier news
Featured supplier news: THFI’s new online coaching course partners with FITR: launch your business confidently post-completion
In today's rapidly evolving fitness industry, where many online courses promise secret formulas for entrepreneurial success, the reality is that few provide the necessary knowledge to thrive in this fast-changing profession.
Featured supplier news
Featured supplier news: Altrafit introduces custom functional fitness equipment at Third Space
Altrafit has taken further steps to cement its reputation as a provider of high-quality, affordable functional fitness equipment that is built to last with the development and introduction of a new functional fitness keg for luxury gym operator, Third Space.
Company profiles
Company profile: Orbit4
Orbit4 is a leading FitTech brand that provides gym operators with a comprehensive software solution ...
Company profiles
Company profile: Matrix Fitness
Preferred by some of the world’s finest hotels and resorts, Matrix offers an array of ...
Supplier Showcases
Supplier showcase - Matrix: Futureproofing
Supplier Showcases
Supplier showcase - Safe Space: Delivering the vision
Catalogue Gallery
Click on a catalogue to view it online
Featured press releases
Servicesport UK Limited press release: ServiceSport UK awarded Ministry of Justice contract for gym equipment maintenance in prisons
In a significant milestone, ServiceSport UK proudly announces that we have been awarded the prestigious Ministry of Justice contract for the inspection, service, and maintenance of PE equipment across 106 public prisons in England and Wales.
Featured press releases
Alliance Leisure Services (Design, Build and Fund) press release: Alliance Leisure celebrates official opening of its first Leisure Local Health Hub
This month sees the official opening of a brand new, £9 million Health Hub in Nottinghamshire. Based on Sport England’s Leisure Local model, the new community provision delivers a host of leisure facilities designed to bring new active living opportunities to the whole community.
Directory
Lockers
Crown Sports Lockers: Lockers
Salt therapy products
Himalayan Source: Salt therapy products
Flooring
Total Vibration Solutions / TVS Sports Surfaces: Flooring
Spa software
SpaBooker: Spa software
Snowroom
TechnoAlpin SpA: Snowroom
Cryotherapy
Art of Cryo: Cryotherapy
Property & Tenders
Jersey
Jersey War Tunnels
Property & Tenders
Chiswick, Gillingham, York and Nottingham
Savills
Property & Tenders
Diary dates
03-05 Sep 2024
IMPACT Exhibition Center, Bangkok, Thailand
Diary dates
08-10 Sep 2024
Wyndham® Lake Buena Vista Disney Springs™ Resort, Lake Buena Vista, United States
Diary dates
19-19 Sep 2024
The Salil Hotel Riverside - Bangkok, Bangkok 10120, Thailand
Diary dates
20-22 Sep 2024
Locations worldwide,
Diary dates
01-04 Oct 2024
REVĪVŌ Wellness Resort Nusa Dua Bali, Kabupaten Badung, Indonesia
Diary dates
09-13 Oct 2024
Soneva Fushi, Maldives
Diary dates
10 Oct 2024
QEII Conference Centre, London,
Diary dates
22-25 Oct 2024
Messe Stuttgart, Germany
Diary dates
24-24 Oct 2024
QEII Conference Centre, London, United Kingdom
Diary dates
04-07 Nov 2024
In person, St Andrews, United Kingdom
Diary dates
04-06 Feb 2025
Coventry Building Society Arena, Coventry, United Kingdom
Diary dates
11-13 Feb 2025
Fairmont Riyadh , Saudi Arabia
Diary dates
10-13 Apr 2025
Exhibition Centre , Cologne, Germany
Diary dates
07-07 Jun 2025
Worldwide, Various,
Diary dates
28-31 Oct 2025
Koelnmesse, Cologne, Germany
Diary dates

features

Sponsored briefing: Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data

Published in Health Club Management 2017 issue 11
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
New laws about how you hold your data come into effect in 2018 and demand attention now to avoid regulatory fines / PHOTO: SHUTTERSTOCK.COM
Leisure and gym operators are custodians of a huge volume of detailed personal information on members, making our industry not only a soft target, but also an attractive one - Paul Simpson

Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations

Paul Simpson
Paul Simpson

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]

Sign up here to get HCM's weekly ezine and every issue of HCM magazine free on digital.
https://www.leisureopportunities.co.uk/images/299762_993010.jpg
Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital for operators to take action on how they store and secure all member data
Paul Simpson, chief operating officer, Legend Club Management Systems,Legend Club Management Systems, Paul Simpson, member data,
Latest News
Urban Gym Group CEO Neil Randall talks in this month’s HCM about how being passed ...
Latest News
Boxing and strength franchise UBX has taken a step closer to realising its ambitions to ...
Latest News
Fitness International has announced the acquisition of XSport Fitness, adding to its portfolio of brands, ...
Latest News
Community Leisure UK (CLUK) and The Richmond Group of Charities have joined forces to support ...
Latest News
Mental Health Swims has been awarded almost £18,000 of lottery money to extend its mission ...
Latest News
Employee wellness app GoJoe has teamed up with Les Mills for a major new content ...
Latest News
Former footballer, David Beckham, has become a strategic investor in health sciences company, Prenetics, which ...
Latest News
Gymbox has partnered with Haringey Council and not-for-profit organisation, Raza Sana, to give opportunities to ...
Latest News
In a bid to get girls more active, Nuffield Health has launched a campaign, Move ...
Latest News
Sport for Confidence CIC has received a national award for its pioneering work hardwiring occupational ...
Latest News
Mindbody, has launched a specialist insurance programme for its customers which is being delivered through ...
Featured supplier news
Featured supplier news: THFI’s new online coaching course partners with FITR: launch your business confidently post-completion
In today's rapidly evolving fitness industry, where many online courses promise secret formulas for entrepreneurial success, the reality is that few provide the necessary knowledge to thrive in this fast-changing profession.
Featured supplier news
Featured supplier news: Altrafit introduces custom functional fitness equipment at Third Space
Altrafit has taken further steps to cement its reputation as a provider of high-quality, affordable functional fitness equipment that is built to last with the development and introduction of a new functional fitness keg for luxury gym operator, Third Space.
Company profiles
Company profile: Orbit4
Orbit4 is a leading FitTech brand that provides gym operators with a comprehensive software solution ...
Company profiles
Company profile: Matrix Fitness
Preferred by some of the world’s finest hotels and resorts, Matrix offers an array of ...
Supplier Showcases
Supplier showcase - Matrix: Futureproofing
Supplier Showcases
Supplier showcase - Safe Space: Delivering the vision
Catalogue Gallery
Click on a catalogue to view it online
Featured press releases
Servicesport UK Limited press release: ServiceSport UK awarded Ministry of Justice contract for gym equipment maintenance in prisons
In a significant milestone, ServiceSport UK proudly announces that we have been awarded the prestigious Ministry of Justice contract for the inspection, service, and maintenance of PE equipment across 106 public prisons in England and Wales.
Featured press releases
Alliance Leisure Services (Design, Build and Fund) press release: Alliance Leisure celebrates official opening of its first Leisure Local Health Hub
This month sees the official opening of a brand new, £9 million Health Hub in Nottinghamshire. Based on Sport England’s Leisure Local model, the new community provision delivers a host of leisure facilities designed to bring new active living opportunities to the whole community.
Directory
Lockers
Crown Sports Lockers: Lockers
Salt therapy products
Himalayan Source: Salt therapy products
Flooring
Total Vibration Solutions / TVS Sports Surfaces: Flooring
Spa software
SpaBooker: Spa software
Snowroom
TechnoAlpin SpA: Snowroom
Cryotherapy
Art of Cryo: Cryotherapy
Property & Tenders
Jersey
Jersey War Tunnels
Property & Tenders
Chiswick, Gillingham, York and Nottingham
Savills
Property & Tenders
Diary dates
03-05 Sep 2024
IMPACT Exhibition Center, Bangkok, Thailand
Diary dates
08-10 Sep 2024
Wyndham® Lake Buena Vista Disney Springs™ Resort, Lake Buena Vista, United States
Diary dates
19-19 Sep 2024
The Salil Hotel Riverside - Bangkok, Bangkok 10120, Thailand
Diary dates
20-22 Sep 2024
Locations worldwide,
Diary dates
01-04 Oct 2024
REVĪVŌ Wellness Resort Nusa Dua Bali, Kabupaten Badung, Indonesia
Diary dates
09-13 Oct 2024
Soneva Fushi, Maldives
Diary dates
10 Oct 2024
QEII Conference Centre, London,
Diary dates
22-25 Oct 2024
Messe Stuttgart, Germany
Diary dates
24-24 Oct 2024
QEII Conference Centre, London, United Kingdom
Diary dates
04-07 Nov 2024
In person, St Andrews, United Kingdom
Diary dates
04-06 Feb 2025
Coventry Building Society Arena, Coventry, United Kingdom
Diary dates
11-13 Feb 2025
Fairmont Riyadh , Saudi Arabia
Diary dates
10-13 Apr 2025
Exhibition Centre , Cologne, Germany
Diary dates
07-07 Jun 2025
Worldwide, Various,
Diary dates
28-31 Oct 2025
Koelnmesse, Cologne, Germany
Diary dates
Search news, features & products:
Find a supplier:
Savills
Savills
Partner sites