Skip to content

GDPR & data protection

Empty football stadium with rows of seats in evening light

Data protection lawyer for sport

Personal data in sport, kept under legal control

A club keeps medical files on its players. A federation manages a membership database with fitness certificates. An organiser films the stadium and sells named tickets. The GDPR treats health data and biometric data as a special category: the starting point is a prohibition, with a short list of exceptions. Choose the wrong legal basis and you have little to say once an athlete or a supporter files a complaint.

Data protection in sport is not a routine exercise. Federation rules, the player contract, anti-doping legislation and the Belgian football act all apply at the same time. We combine GDPR practice with sports law and stay with your file from the first review up to the Litigation Chamber of the Belgian Data Protection Authority. We also handle international matters: transfers outside the EEA, the rules of FIFA, UEFA, UCI and WADA, and proceedings before the CAS in Lausanne.

Discuss your file

What a data protection lawyer for sport does for you

From a first review of your processing to the defence of your file before the regulator.

GDPR audit and record

We map which data you process, on which legal basis and for how long you keep it. You receive a record of processing activities, a privacy notice that matches actual practice, and a list of the points that need correction first.

Athletes’ medical data

Fitness examinations, injury files, rehabilitation and insurance claims. We set out who may consult which data, what the club doctor may share with the coaching staff, and how to organise the athlete’s consent so that it still holds up.

Wearables and performance data

GPS vests, heart rate monitors and tracking software produce a continuous profile of every player. We settle in the contract who owns that data, what the supplier may do with it, and what happens to the profile when the player transfers.

Scouting of minors

Youth scouting runs on databases full of children’s data. We check parental consent, the retention period for scouting records, the use of footage from youth matches, and the arrangements with agents and external scouting platforms.

Stadium cameras and ticketing

Stadium cameras fall under the Belgian camera act and the football act, each with its own rules on notification, retention and access to images. We also advise on facial recognition, named ticketing, stadium bans and the transfer of supporter data to the police.

Processor agreements and breaches

Every supplier of ticketing, video analysis or membership software needs a processor agreement. We negotiate those contracts, check transfers outside the EEA, and guide you through a data breach: the investigation, the notification and the message to the people concerned.

How a case runs

Who decides

A complaint reaches the Data Protection Authority in Brussels. The Front Line Service filters it, the Inspection Service investigates, and the Litigation Chamber decides and may impose a fine. That decision can be appealed to the Market Court, a chamber of the Brussels Court of Appeal.

Deadlines

You report a personal data breach within seventy-two hours of becoming aware of it. You answer a request from a data subject within one month, extendable by two months for a complex file. An appeal against the Litigation Chamber runs within thirty days.

What to do first

Preserve the logs and delete nothing. Appoint one contact person and keep the rest of the organisation off the subject. Gather your record of processing, your processor agreements and the contracts involved. Call us before you answer the regulator or the complainant.

Frequently asked questions

Within what period must we report a data breach?

Within seventy-two hours of becoming aware of it, unless the risk to the people concerned is negligible. Keep an internal record of every incident, even where you do not report, because that record is your proof that you weighed it up. Preserve the logs in the meantime and delete nothing.

May our club keep medical records on players?

Only under stricter conditions than ordinary data. The GDPR treats health data as a special category: the starting point is a prohibition, with a short list of exceptions. Limit access to those who genuinely need the data, record the retention period in writing, and do not pass it on to a next club as a matter of course.

May we publish photographs of youth matches?

A photograph or a clip of a match is processing of personal data, and where a minor is recognisable the threshold is higher. Ask the parents for consent, keep it to one clear purpose and one clear channel, and provide a simple way to withdraw it.

Who handles a complaint about our processing?

The Data Protection Authority in Brussels. The Front Line Service filters it, the Inspection Service investigates, and the Litigation Chamber decides and may impose a fine. That decision can be appealed to the Market Court, a chamber of the Brussels Court of Appeal, within thirty days.

A player asks for access to his data. How long do we have?

One month, extendable by two months for a complex file. Reply within that period, even where you contest the request. Keep your register of processing activities up to date, because without it every request takes longer than it needs to.

Get in touch

Has the Data Protection Authority contacted you?

Call +32 (0)9 334 94 70 or write to sport@everest-law.be. We review your file and tell you what needs to happen.

or call +32 (0)9 334 94 70

Everest Sports Law