Get HCM digital magazine and ezines FREE
Sign up here ▸
Jobs   News   Features   Products   Magazine      Advertise  
Sponsored briefing
Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data


Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations




 

Paul Simpson
 

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]


FEATURED SUPPLIERS

Introducing the Schwinn Z Bike: where innovation meets performance
In the dynamic world of indoor cycling, Schwinn has consistently been at the forefront of innovation. Now, we proudly present the Schwinn Z Bike, the culmination of our legacy of excellence. [more...]

Sue Anstiss' Game Changers podcast headed for Elevate 2024
Join us at Elevate from 12-13 June in London for a special one-off live recording of The Game Changers Podcast with Sue Anstiss, CEO of Fearless Women. [more...]
+ More featured suppliers  
COMPANY PROFILES
miha bodytec

Founded in 2007 in Gersthofen, Germany, miha bodytec is the market-leading supplier of Electro Muscl [more...]
Safe Space Lockers

We provide a full turn-key solution for clients from design and consultation, through to bespoke man [more...]
+ More profiles  
CATALOGUE GALLERY
 
+ More catalogues  

DIRECTORY
+ More directory  
DIARY

 

18-22 May 2024

Eco Resort Network

The Ravenala Attitude Hotel, Mauritius
23-24 May 2024

European Health Prevention Day

Large Hall of the Chamber of Commerce (Erbprinzenpalais), Wiesbaden, Germany
+ More diary  
 
ABOUT LEISURE MEDIA
LEISURE MEDIA MAGAZINES
LEISURE MEDIA HANDBOOKS
LEISURE MEDIA WEBSITES
LEISURE MEDIA PRODUCT SEARCH
 
HCM
LEISURE OPPORTUNITIES
HEALTH CLUB HANDBOOK
PRINT SUBSCRIPTIONS
FREE DIGITAL SUBSCRIPTIONS
ADVERTISE . CONTACT US

Leisure Media
Tel: +44 (0)1462 431385

©Cybertrek 2024
Get HCM digital magazine and ezines FREE
Sign up here ▸
Jobs    News   Products   Magazine
Sponsored briefing
Legend - Data Matters

With the new General Data Protection Regulation (GDPR) on the horizon, Paul Simpson, chief operating officer of Legend Club Management Systems, explains why it’s vital operators take action on how they store and secure all member data


Rarely a week goes by without news of a data security breach hitting the headlines, with issues such as the global WannaCry ransomware attack – which crippled parts of the NHS – and our own industry-specific PayAsUGym attack in December 2016 heightening fears for the wider industry.

Unfortunately, this increased awareness isn’t leading to action to improve matters. Furthermore, ignorance about basic data security principles and obligations is placing the industry at significant risk of everything from accidental misadventure to financial fraud, with the repercussions ranging from regulatory fines and brand damage to business failure.

Data vulnerability
Leisure and gym operators are custodians of a huge volume of detailed personal information about members and customers, making our industry not only a soft target, but also an attractive one.
To safeguard valuable information, think about your data assets. What information do you hold on your customers? Where is it stored? Is it up to date? Is it still required? Is it digital, or are paper records still in use? Are your employees accessing information via their own mobile devices?

Data breaches occur in many forms, including password theft, physical attacks and the biggest threat of all – user error.

Common user error breaches include obvious examples, such as incorrect handling of credit card data, and less obvious examples, such as paper-based customer information being stored in unlocked filing cabinets.

Routine tasks undertaken by front of house staff are often conducted without data safeguards in place and in many cases, too little staff training is provided on data security protocols and their importance, leaving operators vulnerable.

This situation is complicated by the nature of the industry. For example, staff turnover makes it challenging to ensure training is given to all staff who are handling customer data. The result is inadequate security, which jeopardises both the customer and the operator.

Better Guidance
In our unregulated industry there has historically been little or no guidance provided to staff regarding the safeguarding of information.

In addition, although existing legislation – such as the Data Protection Act (DPA), and the Payment Card Industry Data Security Standards (PCI DSS) – requires adherence to very specific data security processes and policies, many in the industry would be hard pressed to demonstrate compliance, leaving them in a highly vulnerable position.

The situation will become even more challenging in May 2018, when the EU’s new General Data Protection Regulation (GDPR) comes into effect, bringing with it higher penalties and even more stringent requirements regarding information security, as well as the need to inform any individual affected by a data breach within 72 hours.

In short, GDPR demands the attention of all businesses and operators who hold customer data of any kind.

Business Implications
The UK Payment Card Industry Security Standards Council (PCI SSC) has warned that UK businesses could face up to £122bn in penalties for data breaches when the GDPR comes into effect. It has also stated that fines are likely to be dwarfed by the reputational damage incurred by data breaches.

If customers lose confidence in an establishment’s ability to safeguard personal data, then the online portals and payment processes that have streamlined our businesses so effectively over recent years will be put at risk.

Creating a New Ethos: Confidentiality, Availability & Integrity
So now is the time to take action. Only by considering every piece of information in line with three guiding principles – confidentiality, availability and integrity – can you begin to protect your data.

• Confidentiality
Assurance of data privacy is achieved by ensuring it’s only accessed by authorised individuals and that excellent access controls and good internal processes are in place for the use of paper-based documentation.

• Availability
This demands that data is available whenever it’s needed – a ransomware attack, for example, denies this.

• Integrity
Achieving data integrity is all about ensuring it’s accurate and up to date.

There are two areas of GDPR where focus is needed. One is consent, which imposes robust criteria on you to obtain permission from individuals for the processing of their data. The second is data retention, and the individual’s ‘right to be forgotten’.

These two areas need careful assessment to ensure there’s a clear case for holding data for specific time periods and that consent has been given to do so.

Next steps
The coming of the GDPR is a real opportunity for leisure and health and fitness businesses to embrace the chance to make huge improvements to the way their extremely valuable data is stored and handled.

It's also the time to expand the current view of information beyond that which is held electronically to include all information assets in the business, both digital and paper-based. Finally, it's time to embed best practice into all daily operations. This includes improving physical infrastructure and creating a robust, ethical security culture, that protects customer data, for the long-term.

To learn more about how Legend has helped its customers get ready for the arrival of the fast-approaching GDPR legislation, please visit our website at: www.legendware.co.uk/accreditations




 

Paul Simpson
 

Paul Simpson, Legend’s chief operating officer, is responsible for Legend’s ISO27001 Information Security Management accreditation.

Simpson makes his expertise available to those who have industry GDPR/ information security concerns. He can be contacted at: [email protected]


LATEST NEWS
UK Active and Savanta launch quarterly consumer engagement insight
Improving physical strength and fitness, mental health and confidence are the main reasons for joining a health club, while cost, time and motivation are the main reasons for leaving.
Snap Fitness' holding company – Lift Brands – is up for sale
Speaking to HCM, global CEO of Lift Brands, Ty Menzies, has confirmed that the company –  owner of Snap Fitness and Fitness On Demand – is up for sale.
Planet Fitness increases price of basic membership for first time in over 20 years
Planet Fitness has announced the repurchase of 314,000 shares at a rate of US$20 million. The Class A common stocks were repurchased and retired, using cash.
Xponential dumps Geisler as company faces investigation by US Attorney’s Office
Xponential Fitness today indefinitely suspended founder and CEO, Anthony Geisler, saying it had been notified on 7 May that the company is facing a legal challenge by the United States Attorney’s Office for the Central District of California.
Fast Fitness Japan acquires master franchisee rights to Anytime Fitness Germany
Fast Fitness Japan, master franchisee of Anytime Fitness in Japan, has acquired Eighty-8 Health & Fitness, giving the company master franchisee rights to Anytime Fitness in Germany.
Saga Holographic hits Kickstarter target to roll out holographic indoor bike
HoloBike, a holographic training bike that simulates trail rides in lifelike 3D, is aiming to push indoor cycling technology up a gear.
Peloton considers de-listing to draw a line under pandemic challenges
Peloton Interactive Inc is believed to be working to get its costs under control in a bid to align with the expectations of private equity investors as it considers de-listing.
'Huff and Puff' – Australian research emphasises the importance of keeping up the cardio
Having good levels of cardiorespiratory fitness cuts disease and premature death by 11 to 17 per cent according to new research from the University of South Australia.
Active Oxfordshire secures £1.3 million to tackle shocking levels of inequality
Active Oxfordshire has received £1.3 million to tackle inactivity and inequality and launch a new programme for children.
Barry’s considers next investor move, as North Castle Partners looks to exit
Barry’s – known for its HIIT workouts combining treadmills and weights – is thought to be looking at strategic options, including taking on a new backer.
Bannatyne has bounced back from the pandemic
The Bannatyne Group says it has officially bounced back from the pandemic, with both turnover and profits restored to pre-2020 levels in 2023, according to its year-end results.
Basic-Fit hints Spanish Holmes Place clubs might be sold
There is speculation that Basic Fit will sell the five Spanish Holmes Place clubs it has just acquired from RSG Group in a 47-club deal.
+ More news   
 
FEATURED SUPPLIERS

Introducing the Schwinn Z Bike: where innovation meets performance
In the dynamic world of indoor cycling, Schwinn has consistently been at the forefront of innovation. Now, we proudly present the Schwinn Z Bike, the culmination of our legacy of excellence. [more...]

Sue Anstiss' Game Changers podcast headed for Elevate 2024
Join us at Elevate from 12-13 June in London for a special one-off live recording of The Game Changers Podcast with Sue Anstiss, CEO of Fearless Women. [more...]
+ More featured suppliers  
COMPANY PROFILES
miha bodytec

Founded in 2007 in Gersthofen, Germany, miha bodytec is the market-leading supplier of Electro Muscl [more...]
+ More profiles  
CATALOGUE GALLERY
+ More catalogues  

DIRECTORY
+ More directory  
DIARY

 

18-22 May 2024

Eco Resort Network

The Ravenala Attitude Hotel, Mauritius
23-24 May 2024

European Health Prevention Day

Large Hall of the Chamber of Commerce (Erbprinzenpalais), Wiesbaden, Germany
+ More diary  
 


ADVERTISE . CONTACT US

Leisure Media
Tel: +44 (0)1462 431385

©Cybertrek 2024

ABOUT LEISURE MEDIA
LEISURE MEDIA MAGAZINES
LEISURE MEDIA HANDBOOKS
LEISURE MEDIA WEBSITES
LEISURE MEDIA PRODUCT SEARCH
PRINT SUBSCRIPTIONS
FREE DIGITAL SUBSCRIPTIONS