Data protection for clubs: sample template and checklist for your data security
For many organisations, the privacy policy initially seems daunting. The GDPR (General Data Protection Regulation) seems to be too complex and confusing, which explains the fear of contact, especially in voluntary areas. The aim of data protection is to inform members of the association about how their personal data is handled. Article 13 of the GDPR stipulates the obligation to create a privacy policy - even for sports clubs, regardless of their size. In this context, there are always terms that we would like to explain in the following paragraph:
- Personal Data: These are all pieces of information that can be attributed to an identified or identifiable person. This means that such data can lead to conclusions about the individual. This includes name, address, date of birth, email address, occupation, or phone number. Ultimately, almost any information about a person is considered personal data and is therefore relevant to data protection within the organization.
- Data Processing: This refers to the handling of personal data. It begins with the collection of data and ends with its deletion. In between, this includes writing, organizing, storing, modifying, or transmitting data. A privacy policy must be made available accordingly.
- Controller: Controllers are always individuals who decide on the purposes and means of processing personal data. In associations, these are often board members.
- Consent: As soon as the data subject gives their consent, it is considered an agreement to the specific data processing. The person must have been informed beforehand and must have actively agreed. For example, checking a box counts as active consent.
The collection of data in clubs begins with the registration of new members.
Names, addresses, dates of birth, and bank account details are collected from each member for administrative purposes. The GDPR ensures that all data is processed responsibly, fostering transparency and trust between members and the club. Email addresses used for communication or photos taken during training sessions or competitions also count as personal data, requiring compliance with the GDPR.
In addition, sports clubs usually participate in competitions or league operations. In such cases, the relevant sports associations also require member data to ensure the proper organization of matches and events.
GDPR: What Clubs Must Pay Special Attention To
Dies DSGVO sieht für alle Vereine eine verpflichtende Erstellung der Datenschutzerklärung vor. Das heißt: Sobald personenbezogene Daten erhoben werden, muss der Verein der betroffenen Person eine Datenschutzerklärung vorzeigen. Und weil das Erheben personenbezogener Daten im Vereinsalltag unausweichlich ist, ist die DSGVO auch in Sportorganisationen von Relevanz. Die DSGVO regelt außerdem, welche Informationen den Personen zur Verfügung gestellt werden müssen. In diesem Zusammenhang sind zwei Faktoren entscheidend:
- Rechtsgrundlage: Die Rechtsgrundlage ist im Zuge der Datenverarbeitung stets zu benennen. Hier kann beispielsweise Paragraf 6 der DSGVO als rechtlicher Hinweis ausformuliert werden. Die Rechtsgrundlage weist darauf hin, in welchen Fällen personenbezogene Daten vom Verein erhoben und verarbeitet werden dürfen.
- Mitgliederrechte: Hierzu zählen das Recht auf Auskunft über die gespeicherten Daten zur Person, das Recht auf Berichtigung oder Löschung der Daten und das Recht auf Datenübertragung. Darüber hinaus gibt es ein Widerspruchsrecht, welches im Text besonders hervorgehoben werden muss.
Darüber hinaus sind folgende Informationen wichtig:
- Kontaktdaten des Datenschutzbeauftragten, falls vorhanden.
- Sofern die Datenübermittlung an Server im Nicht-EU-Ausland vonstattengeht, ist ein entsprechender Hinweis zu vermerken.
- Erläuterungen zur Datenspeicherung. Grundsätzlich gilt: Sobald die Daten nicht mehr benötigt werden, erfolgt die Löschung.
Hinweis: Generell ist immer die Einwilligung der Mitglieder einzuholen. Das gilt besonders für das Veröffentlichen von Fotos auf der Webseite oder auf Social-Media-Kanälen.
How long is data storage permitted?
Data storage is permitted as long as the data is necessary for the purposes for which it was collected.
This provides some flexibility when it comes to deleting data after a member leaves the club. In general, members can withdraw their consent at any time, which means the club should have an efficient process in place to respond accordingly. As previously mentioned, it is recommended that personal data be deleted immediately once a member leaves the organization.
Tip: Make sure that access to complete member data is limited to a small group of people within the club. Not every coach or board member needs access to all personal data. Restricting access reduces the risk of errors and protects the data from misuse.