You record a coaching session. You upload notes. You store session summaries somewhere, maybe in a shared doc, maybe in a platform you signed up for last year. Have you ever checked where that data actually goes? Most coaches have not. And the answer matters more than you think.
The question most coaches skip
When I work with organisations on data governance, the first thing I ask is whether they know where their data live. The most common answer is a pause, followed by something like "the cloud". That is not an answer. That is a marketing term.
The cloud is not a place. It is a data centre. That data centre is in a country. That country has laws. Those laws determine who can reach your clients' most sensitive professional conversations, and under what circumstances.
If you are a European coach working with European clients, this is not an abstract concern. It is the core of your professional responsibility. Where a provider stores personal data in the United States, be aware there is no overarching national privacy law equivalent to the GDPR, and that data may be subject to access by American intelligence services, although under defined conditions. The GDPR provides strict protection and clearly justified access rights.
What happens when session data crosses a border
The GDPR is clear on this point. Personal data can only leave the European Economic Area if the destination country provides an adequate level of protection, or if specific safeguards are in place.
For US based services, the current mechanisms are Standard Contractual Clauses and the EU US Data Privacy Framework. The Framework is functional for now, and it has already faced legal challenges. Privacy advocates argue it does not resolve the underlying conflict between EU privacy rights and US surveillance law.
What does that mean for coaching data? If you use a US based platform to store session recordings, transcripts or notes, your clients' data is subject to US jurisdiction. Even if the platform promises encryption. Even if it says it is GDPR compliant. Compliance is not the same thing as immunity from foreign access requests.
This is not about being alarmist. It is about understanding what you are consenting to when you click agree on a terms of service page.
The tools coaches actually use
Let me walk through the most common setup I see.
Video calls. Most coaches use Zoom, Google Meet or Microsoft Teams. All three are operated by US companies. Zoom processes data through US servers by default, and while EU data routing is available on certain paid plans, most coaches have never configured it. Google Meet and Teams route through global data centres, with limited control over which region handles your particular call.
Session notes. Google Docs, Notion, Evernote. All US based. If you write session notes in any of them, that data sits on US infrastructure and is subject to US law.
AI transcription. Otter.ai, Rev, tools built on Whisper. Increasingly popular for automating session notes, and most process audio through US based servers. Some use the data to train their models unless you opt out. Your client's words become training data for a product they never agreed to contribute to.
CRM and scheduling. HubSpot, Calendly, Acuity. The entire backbone of most coaching practices is US hosted. Client names, email addresses, session histories, billing details, all sitting on American servers.
None of this is illegal. It does create a specific set of risks that most coaches have never thought about, and that most clients have never been told about.
What GDPR compliant actually means
GDPR compliant means more than having a privacy policy in place, and it does not by itself mean data is stored in the EU. Real compliance is structural. It means:
- Data minimisation. Collecting only the data necessary for the stated purpose.
- Purpose limitation. Collecting data only for specific, explicit and legitimate purposes. Not using data collected for coaching for undisclosed purposes such as training AI models, serving ads, or building user profiles.
- Storage limitation. Keeping personal data only as long as it is required for the stated purpose. Deleting it when it is no longer needed, rather than keeping it indefinitely just in case.
- Data subject rights. Giving clients access to their data, the ability to export it, and the ability to request deletion.
- Data processing agreements. Formal contracts with every processor and sub processor that touches the data, specifying exactly what they can and cannot do. Where processing involves partners outside the EU, EEA or UK, approved transfer mechanisms have to be in place.
So when you evaluate a coaching platform, asking whether they are GDPR compliant is only the opening question. Ask where your data is stored. Ask who their sub processors are. Ask what happens to session recordings after transcription. Ask how your data is used.
Why this matters for the coaching relationship
Coaches build their practice on trust. Clients say things in coaching sessions that they would not say to their manager, their partner, or their closest friend. The vulnerability is the point. It is what makes coaching work.
I am not arguing that every coach needs to become a data protection expert. I am arguing that every coach should be able to answer one question. Where does my client data live, and who can reach it?
What good infrastructure looks like
The alternative is not complicated. It requires choosing tools that were built with European data protection as a starting point rather than as an afterthought. Where you have the choice, choose providers that host their infrastructure in the EU or the UK, where robust data protection law applies. The GDPR, and the UK GDPR alongside it, is the world's most comprehensive data protection framework, and it has influenced legislation from California to Japan.
At CoachNova, I advised on exactly this question during the platform's development. The architecture is EU hosted, in Frankfurt, on every account rather than on an upgraded plan. Data is never used for AI model training. Client data is isolated per coach, so no other coach can reach your sessions. Only authorised CoachNova personnel on a need to know basis, such as technical support, can access data, and that access is logged and time limited. Transcripts are held for the life of the engagement, because nothing should disappear from under an active client, and when an engagement closes there is a window to download everything before it is permanently deleted.
That is what GDPR native looks like. Not a checkbox on a compliance page. A set of architectural decisions that protect the coaching relationship at the infrastructure level.
Four things you can do this week
- Audit your tools. List every platform that touches client data: video calls, notes, scheduling, billing, AI tools. For each one, find out where it stores data and whether a data processing agreement is available that says where your data is transferred and how it is used.
- Read the fine print. Especially now, read it to find out whether your data and your client's data is used to train the provider's AI. Providers often set this to opt in by default, and you have to actively opt out if you do not agree.
- Update your client consent forms. If you use tools to record client conversations, whether transcription, session summaries or anything automated, your clients need to know. Informed consent is not optional under the GDPR. It is a legal requirement.
- Ask the questions that cut to the core. The next time a platform tells you it is GDPR compliant, ask where your data is stored, who the sub processors are, what happens to session recordings after transcription, and how your data is used. If they cannot answer clearly, that tells you everything you need to know.
Card at signup, first charge on day 61. Pause or cancel any client at any time.