GDPR for sports clubs and sports federations
All articles

GDPR for sports clubs and sports federations

The General Data Protection Regulation (the “AGV”, also known by its English abbreviation “GDPR”) will enter into force throughout the European Union on May 25, 2018.

The GDPR has a number of consequences for every organization that processes personal data. The concepts of “personal data” and “processing” are very broadly defined, so that in fact almost every entity will sooner or later be confronted with these new rules.

Sports clubs, sports federations and even competition organizers also fall within the scope of the GDPR. Since sports clubs and sports federations process personal data in many ways, such as membership or participant lists, or via databases for subscriptions and ticket sales, special attention is required. This attention is all the more justified now that sports clubs and sports federations often work with -13 year olds, which entails additional obligations.

The GDPR builds on existing privacy legislation, but also changes it substantially. A selection of the most important obligations under the GDPR:

  • Any sports club or federation that has personal data processed by other companies (for example certain IT services, personnel administration, certain subcontractors) is obliged to conclude a written agreement (a so-called processing agreement) that complies with the GDPR and which specifies the obligations of this service provider or subcontractor with regard to data protection.
  • The requirements for valid consent from an individual to process their personal data are becoming stricter;
  • Any sports club or federation that processes personal data must maintain an internal register of its processing activities, have an appropriate privacy policy and implement measures that comply with the principles of data protection by design (privacy by design) and data protection by default settings (privacy by default).
  • Certain sports clubs or federations may need to submit a ‘Data Protection Impact Assessment‘ to execute (Data Protection Impact Assessment – PIA);
  • Certain organizations may also require one data protection officer (Data Protection Officer) have to appoint;
  • In certain circumstances, leaks of personal data must be reported to the competent authority (in Belgium the Data Protection Authority) within 72 hours.
  • Infringements can be punished with fines (up to 20 million euros or 4% of global turnover);

As mentioned, the GDPR comes into effect May 25, 2018. Until then, organizations have time to comply with the GDPR.

However, the implementation of all these obligations requires the necessary time and adjustments within the sports club, sports federation or competition organization.

We therefore recommend all sports clubs, federations and organizers to tackle this issue as quickly as possible. A first step is to analyze which personal data is processed within your club, federation or organization and what obligations this will entail for your club or federation under the new legislation.

Everest Sport can guide your company in drawing up an initial analysis and further implementation of the obligations.

For more information and advice about the GDPR, do not hesitate to contact us via our  contact form, by email (sport@everest-law.be) or by telephone (09/334.94.70).