DxtraBETA
Back to blog
Use CasesUKMicro Business July 2026 6 min read

No website? You're still a data controller — and a spreadsheet plus WhatsApp is where it shows

No website doesn't mean no data-protection duties. If you run your clients on a spreadsheet and WhatsApp, here's what you actually risk — and the one-page privacy notice (shared by QR code) that sorts it.

Daryl ArnoldDaryl Arnold
Two people practicing yoga on mats in a warm, sunlit studio.

I was having coffee with a university friend in Islington, London — a professional musician who teaches yoga in her spare time. She is completely solo — no studio of her own, no website, no "business" in the way most people picture one. Her entire client base lives in a Google Sheet, she books people over WhatsApp one-to-one, and she runs a WhatsApp group for class updates. When I mentioned what I do, she said the thing I hear from nearly every solo teacher, trainer and therapist: "But I don't even have a website — so all that data-protection stuff doesn't really apply to me, does it?"

It does. And not in a scary, paperwork way — in a way that is actually about the people who trust her.

The website was never the point

Here is the uncomfortable bit, said gently: the law never cared about the website. UK data-protection law cares about whether you are a business collecting and using people's personal information. The moment you take money to teach, and you keep a list of who your clients are — their names, their numbers, maybe some notes about their health — you are a data controller. A website is just one place some businesses happen to publish their privacy information. Not having one does not remove the duty; it just means you have nowhere obvious to put it. (More on that, because it is the neat bit.)

Yes, there is a genuine exemption for purely personal or household activity — your family group chat, your own address book. But the moment it is a paid activity, that exemption stops applying. A spreadsheet of paying clients is not a personal address book. It is business records, and it is yours to look after.

The sensitive bit most wellness pros miss

Wellness work has a wrinkle most solo teachers never clock. If you note that a client is pregnant, recovering from a back injury, managing a heart condition, or nursing a dodgy knee — exactly the kind of thing a good teacher writes down to keep people safe — you are holding health data. Under UK GDPR that is "special category" data: the sensitive tier, with stricter rules.

It is not that you should not hold it — often you should, for safety. It is that you need explicit consent to collect it, and you need to look after it more carefully than an ordinary contact list. This is the point where "a bit of admin" quietly becomes "actually protecting your clients."

Where a spreadsheet and WhatsApp start to bite

None of this means your setup is wrong. It means three specific things are worth a look.

1. The WhatsApp group shows everyone's number to everyone. A standard WhatsApp group discloses every member's phone number to every other member. That is a disclosure of personal data — usually without anyone having agreed to it. It is also, in my experience, the single most likely thing to prompt a complaint: someone joins for class times and is unsettled to find a stranger now has their mobile number.

2. The Google Sheet is a single point of failure. Your whole client list — names, numbers, and those health notes — sits in one account. If that account is weakly protected and someone gets into it, that is a personal-data breach, and because it includes health data, a serious one. Keeping it secure is not optional; UK GDPR calls it the "integrity and confidentiality" duty.

3. There is no privacy notice anywhere. Your clients have a right to a short, plain explanation of what you do with their data and how they can ask about it. Right now there is nowhere for them to read that — because the standard advice, "put it in your website footer," assumes a website you do not have.

The honest version of the risk

Before this tips into worry: the realistic outcome for a good-faith solo teacher is not a fine. The regulator's instinct with small operators acting in good faith is "put it right," not punishment. The risk that actually matters is more human and more immediate — a client upset that their number got shared, or their health details sitting unprotected in a file anyone with a link could open. Fix those, and you have protected the people who trust you, and your reputation along with them. That was always the real point; the compliance is just the name for it.

The fixes — and the QR code that ties them together

The good news is that the fixes are small, and one neat move handles the biggest gap.

Give people a real privacy notice — by QR code. This is the part built for someone with no website. Dxtra generates a proper, plain-English privacy notice and a consent form for you, and gives you a QR code (and a short link) that point to them. You put that QR code on your intake form, a card at the studio, a class flyer, or your WhatsApp and Instagram bio. A new client scans it, reads the notice, and ticks consent — including the explicit health-data consent — and you have a record that they did. Think of it as the privacy notice for people who do not have a website.

Swap the group for a broadcast list. If you mostly send one-way updates, a WhatsApp broadcast list does the same job without exposing everyone's number to each other. If you genuinely want a group chat, just ask people to agree to being in a visible-number group first.

Lock the Google account. Turn on two-factor authentication, use a strong password, and change sharing from "anyone with the link" to named people only. Two minutes, and your client list is no longer one leaked link away from a breach.

And yes — register with the ICO. Most businesses handling personal data need to, and it is a small annual fee. Run the ICO's two-minute self-assessment and set it to renew. Quick admin — genuinely not the point of any of this.

That is the whole list. An afternoon, mostly — and much of it is a one-time setup you never think about again.

The fix fits on a QR code

If you take one thing from this: you do not need a website to do right by your clients. You need a privacy notice they can actually read, proper consent for the sensitive stuff, and a bit of care about where their details live.

Get a privacy notice and consent form you can share with a QR code → Dxtra generates both, hands you the QR code and short link, and you put it wherever your clients already are — your intake form, your studio wall, your booking chat. From $10 a month (about £7.40), and you review everything before it goes live.

The yoga teacher did not need a lecture on UK GDPR. She needed to know it was a handful of small jobs, not a wall — and that the fix fit on a QR code.


This article is for general information and is not legal advice. Privacy rules depend on your circumstances — confirm anything that matters with the ICO (ico.org.uk) or a qualified adviser before you rely on it.

Ready to get compliant?

Start your privacy program today — from $10/month.