It is imperative that every club understands the principles of Data Protection and how the upcoming changes in legislation will affect them. The following are key steps clubs should take:
As a Data Controller, each athletic club, county or provincial board will be accountable for how it collects, uses and stores information about its members. Every member should be aware of the changes that GDPR will bring and how that impacts them, either as a volunteer working on behalf of the club or as an individual club Member. Clubs should ensure that information relating to GDPR is made available to committee members, club Members, coaches, volunteers or anyone who involved with the Club.
Athletic Clubs should understand exactly what personal information it holds (and is responsible for). To ensure this is clear, it is important that every club makes an inventory of the personal data that it holds and examines it under the following headings:
Consideration must be given to paper membership forms and how these are managed once they have been completed and received by the club. It is permissible to collect information on paper forms, and to retain them in hard copy after they have been completed, as long as the member is made aware of this at the time they are completing the form. Tick boxes (or similar) should be used to obtain the person’s explicit consent to process their information. It is vitally important that any completed forms are stored securely in a specified location.
The same logic should be applied to any other system or database used to assist a club when managing its membership. It is permissible to use technology in this way but careful attention must be paid to how and where data is stored (it must be secure and should be encrypted) and individuals must be informed if a third party is being used to provide a system for this purpose. Most of the third party providers of these kinds of systems (online registration, text messaging, fundraising) will be well aware of GDPR and will be able to advise on how they are ensuring compliance. If your club is using a third party system you should contact them to verify that they are in compliance with GDPR and request their Privacy Policy.
Other likely categories of Personal Information help by athletic clubs will include:
As noted above, it is required that individuals are made aware of certain information such as why their data is being collected and who will have access to it, before their data is obtained. Under existing Data Protection law, it has always been a requirement to provide some of this information to individuals. GDPR builds on this requirement and expands the information that must be given to Individuals in advance of collecting and using their data.
Existing membership forms, and other forms used to collect data must be updated to specifically tell individuals the following:
GDPR enshrines certain rights for individuals that must be supported by every organisation.