GDPR for a sports club: which member data do you keep?
Almost every committee thinks the privacy file is about a form that members sign. That is the part that matters least. Where a sports club actually comes unstuck is that nobody can list how many places the member data sits in, who can get at it, and what happens on the evening a volunteer attaches the wrong file to an email.
You don't have one membership list — you have seven
Ask a committee where the member data lives and you get one answer: in the membership system. Then spend an hour walking around the club and you end up with seven or eight places:
- The federation's administration, where the club registers and deregisters members so they are eligible to play.
- Your own membership package: name, address, date of birth, type of membership.
- The bookkeeping, with bank details, direct debits and unpaid subs.
- The team app or coaching tool, with attendance, statistics and notes on each player.
- The group chats: one per team plus the committee ones, all of them full of phone numbers.
- The spreadsheets kept by the technical committee, the tournament committee and the volunteer coordinator.
- The shared drive, where annual accounts, old membership lists and volunteers' background-check certificates are all still sitting.
- The mailing tool, with addresses that haven't belonged to a member for years.
That is why "we deleted the former members" is almost never true: someone pressed one button in the membership package while the same names stayed put in every other system — and it is precisely the bottom four on this list that have no owner. So don't start with a form. Start with this inventory.
The lawful basis: not consent, but the membership agreement
The most common mistake is asking members to sign a consent form for the ordinary membership administration. That isn't just unnecessary, it is the weakest choice available: consent can be withdrawn at any moment. If a member withdraws it while you need their address to run the membership, you are left with nothing.
The GDPR names six lawful bases — the same articles wherever it applies, whatever your country calls the law that implements it. A sports club uses four of them:
- Performance of a contract (article 6(1)(b)): the membership administration itself — name, address, date of birth, contact details, subscription, team allocation, registration with the federation. Anyone who joins enters into an agreement; nothing extra needs signing.
- Legal obligation (6(1)(c)): the financial records.
- Legitimate interests (6(1)(f)): the newsletter to your own members, CCTV in the hall, and the sporting data a coach keeps — attendance, statistics, observations.
- Consent (6(1)(a)): whatever is left. Photos and video, the newsletter to non-members, and anything a member can refuse without anything else changing.
That last one is the test for the borderline cases: can this member say no without consequences for their membership? If not, you have to point to one of the other three bases. If so, then that no has to be easy to give — and you have to be able to see in your systems who has given it. Photos and video are the best-known case where you record consent person by person; how to do that per player is in which player details you need as a coach. For minors a parent signs the agreement; the age at which a child can consent to online services themselves sits somewhere between thirteen and sixteen under the regulation and differs per country.
The record of processing: one line per system, not a report
Article 30 asks for a record of processing activities. Plenty of committees skip it because small organisations supposedly don't need one. That exemption does exist, but it falls away as soon as the processing is regular rather than occasional — and a membership administration is regular by definition. So assume you need it.
It isn't a report but a spreadsheet with one line per system from the inventory above — for most clubs about ten lines — and seven columns. System and owner. Which data, grouped in categories: contact, financial, sporting and health data; that last group falls under a stricter regime (article 9), so record only what you genuinely need in the hall. What you use it for. On which lawful basis. Who can get at it, by role rather than by name. How long you keep it. Who you share it with, and where that data then sits.
That is one evening's work, and it delivers more than the policy document wrapped around it: filling in the columns on access and retention brings the gaps up all by itself. Put the record in the club handbook and update it on the same evening you do the budget.
How long do you keep what after someone resigns?
There is no general retention period for member data, and that is exactly what committees go looking for. The rule is a principle: no longer than you need it for the purpose. So you decide per type of data when the purpose runs out. At a sports club that gives you four piles:
- Membership administration (name, address, date of birth, contact details, federation number): the purpose ends when the membership ends. Allow a short wind-up period for the last subs payment and the deregistration with the federation, then clear it out.
- Financial records (invoices, subscription payments, direct debit details): these you keep longer, because there is a statutory retention duty on them. How long differs per country, so check the period with your own tax authority or accountant and put the number in your record. It applies only to the financial records, not to the rest.
- Sporting data (attendance, statistics, notes, goals): the purpose is coaching, and that ends the moment someone no longer plays in the team. The end of the season after they leave is a defensible moment; longer is only possible if you can explain what for.
- Volunteer and safeguarding data (volunteers' background-check certificates, committee contacts, reports made to a confidential contact person): these belong to a different role than membership, and therefore to their own retention period and their own limited access. Which certificate your federation or government asks for, and what it is called, differs per country.
The club archive may stay, but it is not a licence to keep old member files complete: keep names, teams and results, and strip out addresses, dates of birth and bank details. Then put one clear-out moment in the annual calendar, for instance six weeks after the last match day. Without a fixed date, clearing out never becomes anybody's job and the pile grows every season. What else happens when someone leaves is in a player leaving the team.
The four cases no GDPR template covers
Model documents for clubs are written for an organisation with a membership list and a newsletter. These four situations come up at every sports club and never appear in them:
- Coaching notes on a youth member. Those are personal data, sometimes sensitive personal data. They may exist as long as they serve the coaching, but the club arranges two things: that they are about behaviour and skill rather than character or home life, and that a parent can see them on request. The writing rule that enforces this is in keeping player notes: write nothing down you wouldn't let the player read.
- The attendance history of somebody who stopped last year. Ask out loud what you are still keeping it for. For the former member there is no purpose left; for the club there is, but that is about totals — how many players per team, how turnout developed over the seasons. So keep the team total and throw away the rows with names on them.
- Can the new coach see their predecessor's notes? For players still in the team: yes, because the purpose — coaching this team — hasn't changed, and the data belongs to the club rather than to the departing coach. For players who have left: no, they belong in the clear-out. Make that an explicit moment during a coaching handover.
- Who sees the phone numbers of youth members? This is the gap committees miss most often. The moment there is one group chat per team, every member — plus every parent, stand-in or former player who was added and never removed — has the number of every child in that team. Nobody decided that and nobody clears it up. So agree who administers a group chat and that departing members are removed within a week. Why the group chat structurally falls short here is in why the team group chat grinds to a halt.
Who inside the club may see which data?
The GDPR doesn't ask for a lock on the door, but it does ask that access matches the role. This is where clubs come apart: nearly every club has a shared folder that too many people can open, and nobody remembers why the last person was added. A workable split:
- Membership administration: name, address, date of birth, federation number, membership status. No notes, no statistics.
- Treasurer: name, bank details, payment status. No health questions, no sporting data.
- Coach: their own team only — contact details, emergency number, whatever is needed in the hall, and their own notes. No bank details and no payment arrears: a coach knowing who hasn't paid yet is a classic leak.
- Technical committee: name, age, position, team allocation and the recommendation a coach writes — not the full archive of notes. How that committee organises its decision moments is in the technical leadership and the four moments in the club year.
- Confidential contact person and committee: if your club has that role — whether it exists and what it is called differs per country and per federation — then that person keeps a separate file; the committee has no automatic right to see it. Being accountable as a board is not the same thing as having access to every field.
The quickest test of whether this holds up: who could, tonight, without asking anyone, download the full membership list with dates of birth and phone numbers? If you can't name those people off the top of your head, your access isn't sorted, however well the policy document is written.
Software with real roles does most of the work here: in Koach a coach only sees the teams they are linked to, while club management sits at club level. The principle is separate from the package — any system without roles is a system where everybody sees everything.
Data processing agreements: with your software, and the federation separately
As soon as an outside party processes member data on your instructions, that calls for a data processing agreement (article 28). For a club that quickly means eight or so parties: the membership package, the bookkeeping, the team app, the mailing tool, the forms tool, the cloud drive, the web hosting and sometimes a video service. Virtually every serious supplier has one ready to go; look it up and accept it, no negotiation needed.
With the federation it works differently. Many federations determine the purpose of their own membership administration and are then not your processor but a controller in their own right — that differs per country and per federation, so ask how yours has set it out.
Meanwhile the gap sits with the tools nobody ever declared: the treasurer's personal drive, the tournament committee's free forms tool, the printing account used for membership cards. Ask every committee one question: which tools do you use that have names or numbers in them? That almost always turns up a system or two that wasn't in the record.
A member who asks for their data, or asks you to erase it
Members have rights the club has to be able to act on: access (article 15), rectification (16), erasure (17), objection (21) and portability (20). In practice that comes down to three arrangements. One address on the website, for instance privacy@yourclub, that lands with two committee members — requests that end up with a random coach disappear. One month to respond, extendable to a maximum of three months for a complex request, provided you tell them about the extension within that first month; so always acknowledge receipt straight away. And one pass through every system: an erasure request carried out only in the membership package has not been carried out.
Two situations chafe. An erasure request runs into the tax retention duty: then you erase everything except the financial data you are legally required to keep, and you explain that in two sentences — doing it half-way and silently always earns you a second, angrier message. And a request about a minor goes through the parent, but if it concerns notes about the child themselves, discuss those with child and parent together. The coaching side of the same questions is in privacy and data for coaches.
Data breach: the 72 hours start with the volunteer
A data breach sounds like a hack, but at a sports club it is almost always something everyday: the membership list attached to an email to the wrong group, a laptop taken from a car, a former committee member who can still get into the cloud drive, or a shared password that has been doing the rounds for four years.
Article 33 asks you to notify the supervisory authority without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to the people involved; where the risk is high you inform those people yourself (article 34). The sting is in when the clock starts: those 72 hours begin the moment the organisation becomes aware — so when the volunteer notices, not when the committee discusses it a fortnight later. Which authority is yours differs per country: that is your national data protection authority, and its name and reporting page belong in the handbook before you need them.
So arrange three things, and no more than three:
- One reporting address and one decision-maker, with a deputy. Everybody — coach, team manager, bar volunteer — knows they report there within 24 hours, including when they aren't sure and including when it was their own mistake.
- An internal log of every breach, including the ones you don't report. That is mandatory (article 33(5)) and it is the only document that later shows you weighed it up rather than doing nothing.
- An attitude that makes reporting safe. Anyone who fears trouble doesn't report, and then after three days it is too late regardless. Say in as many words that reporting never leads to blame.
Key point: a club isn't in order because there is a privacy statement on the website, but because three questions have an answer. Where does our member data sit, who can get at it in which role, and who calls whom within 24 hours if something leaks? Those three on a single page are the bulk of the GDPR.
Frequently asked questions
Do members have to give consent for the membership administration?
No. The ordinary membership administration runs on performance of the membership agreement (article 6(1)(b)), not on consent. Keep consent for things a member could also refuse without consequences, such as photos and video. The test: can the member say no without anything changing about their membership?
How long may a sports club keep member data after someone resigns?
The rule is: no longer than you need it for the purpose, so it differs per type of data. Contact details go shortly after the membership is wound up, sporting data at the end of the season after someone leaves, and the financial records you keep longer because there is a statutory retention duty on them. That tax period differs per country — check it with your own tax authority.
Does a small club really need a record of processing activities?
In practice, yes. The exemption for organisations with fewer than 250 employees falls away as soon as the processing is regular, and a membership administration is regular by definition. It doesn't have to be a report: one line per system in a spreadsheet, with the lawful basis, the access and the retention period next to it.
May a coach see the data of players in other teams?
Not without a reason. Access belongs to the role: a coach needs their own team, emergency numbers included, and nothing beyond that. If anyone with a login can download the whole membership list, that is a set-up problem — fix it with roles in your system, not with an agreement.
What counts as a data breach at a sports club?
Any situation where personal data reaches someone who shouldn't have it, or where you have lost it. A membership list emailed to the wrong group, a stolen laptop, a former committee member who still has access to the drive. Notification to your national data protection authority happens where feasible within 72 hours of the club becoming aware, unless a risk to the people involved is unlikely.
Who inside the club is responsible for the GDPR?
The committee, even when the work is done by the membership secretary or a sub-committee. Appoint one committee member as the point of contact, with a deputy, put that address on the website and update the record every year on the same evening as the budget. A data protection officer is usually not mandatory for an ordinary sports club.


