Guidance for clubs on GDPR compliance by May 25th 2018
It is imperative that every club understands the principles of Data Protection and how the upcoming changes in legislation will affect them. The following are key steps clubs should take:
As a Data Controller, each athletic club, county or provincial board will be accountable for how it collects, uses and stores information about its members. Every member should be aware of the changes that GDPR will bring and how that impacts them, either as a volunteer working on behalf of the club or as an individual club Member. Clubs should ensure that information relating to GDPR is made available to committee members, club Members, coaches, volunteers or anyone who involved with the Club.
Athletic Clubs should understand exactly what personal information it holds (and is responsible for). To ensure this is clear, it is important that every club makes an inventory of the personal data that it holds and examines it under the following headings:
1. Why is it being held?
2. How was it obtained?
3. Why was it originally gathered?
4. How long is it being retained for?
5. How secure is it?
6. Is it shared with any third parties?
Consideration must be given to paper membership forms and how these are managed once they have been completed and received by the club. It is permissible to collect information on paper forms, and to retain them in hard copy after they have been completed, as long as the member is made aware of this at the time they are completing the form. Tick boxes (or similar) should be used to obtain the person’s explicit consent to process their information. It is vitally important that any completed forms are stored securely in a specified location.
Other likely categories of Personal Information held by athletic clubs will include:
• Information required for Garda Vetting
• Text or messaging systems
• Email lists or distribution groups
• Attendance lists
• Information captured on club social media and websites
There may also be others, depending on individual clubs, and it is important that each club has a record of all of the Personal Data that it ‘controls’.
As noted above, it is required that individuals are made aware of certain information such as why their data is being collected and who will have access to it, before their data is obtained. Under existing Data Protection law, it has always been a requirement to provide some of this information to individuals. GDPR builds on this requirement and expands the information that must be given to Individuals in advance of collecting and using their data.
Existing membership forms, and other forms used to collect data must be updated to specifically tell individuals the following:
• The Clubs identity
• The reasons for collecting the information
• The uses it will be put to
• Who it will be shared with
• If it’s going to be transferred outside the EU
• The legal basis for processing the information
• How long it will be retained for
• The right of members to complain if they are unhappy with the club’s implementation of GDPR
• Other specific personal privacy rights relevant under GDPR (as outlined in Personal Privacy Rights section)
Ensure Personal Privacy Rights
GDPR enshrines certain rights for individuals that must be supported by every organisation.
• Access to all information held about an individual (Subject Access Request) – This allows for any member to request a copy of all information held about them. This must be provided within 30 days.
• To have inaccuracies corrected
• To have information erased (right to be forgotten)
• To object to direct marketing
• Data portability - ability to receive all of their information in a standard format to move to another provider (more relevant for switching banks or utility providers than athletic clubs.
Obtain and Manage Consent
GDPR is very clear that an individual must be informed of what their personal information is going to be used for, who will have access to it, where it will be stored and how long it will be held for. They must give their consent for their data to be used. Consent must be ‘freely given, specific, informed and unambiguous’. Members cannot be forced into consent or unaware that they are giving consent. Obtaining consent requires a positive indication of agreement – it cannot be inferred through silence (not objecting), pre-ticked boxes or inactivity. Explicit consent must be obtained by the member clearly indicating and recording their consent.
Consent must also be verifiable – Data Controllers must be able to demonstrate that consent was given and an audit trail should be maintained. Note: Where paper forms are used to collect personal information (e.g. Membership applications), the retention period (how long its kept for) for the form, or relevant portion of the form, should align with the need to demonstrate consent. Clubs must have a valid reason to capture data in the first instance and must be able to defend whatever policy is stated for the management of that data.
Report Data Breaches
If unauthorised access to personal data occurs or personal data is lost or stolen, this must be notified to the Data Protection Commissioner within 72 Hours of being identified. This is a requirement for all paper information and all electronic information (unless the data is encrypted or anonymised). If the breach is likely to cause harm to the individual (Identity Theft or breach of confidentiality) then the individual must also be informed. A procedure to detect, report and investigate data breaches should be in place.
It is imperative that Data Breaches or possible Data Breaches are not ignored in the hope that no one will notice, they must be investigated and reported if appropriate to do so. Advice on data protection queries can be obtained by emailing firstname.lastname@example.org
Identify Data Protection Officers
Every club should identify someone to coordinate their approach to meeting their data protection obligations. This will include identifying and recording the specific locations where data is held in each club, ensuring that consent is obtained in the appropriate manner and maintained accordingly. Athletics Ireland has a Data Protection Officer who will provide expertise and guidance for any Data Protection queries that require additional / legal advice. Queries of this nature can be submitted to email@example.com
Click HERE to download your club GDPR Privacy Statement
Click HERE to download 7 steps to compliance for sports clubs
Data Protection Commissioner, (2018), Sports club 7's do's.
Data Protection Commissioner, (2017), GDPR and You.
England Athletics, (2018) GDPR and data protection advice.
GAA, (2017), Ensuring GDPR compliance.