Your gym's old records could get you in trouble under the new law.

Think about this. A member left your gym two years ago. But their phone number, Aadhaar copy, and trainer notes are still sitting in your file or app. Under India's new data law, this is not allowed. You must delete people's information once they stop using your service. If you don't, your business can face serious trouble. Does this apply to you? Yes — if you run a gym, yoga studio, or wellness centre.
Say a member stopped coming to your gym in 2024. Their phone number, diet plan, and Aadhaar copy are still saved on your computer. That is a problem now. You must delete their information. Same for old booking records on your app. Also, if someone's information ever leaks — say a WhatsApp group message goes wrong — you need one person in your team whose job is to handle it fast. Decide that person today. Write their name down.
List all members who left over one year ago. Delete their files.
Pick one staff member to handle any information leak or complaint.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“An expired membership should not mean endless storage.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.