Skip to main content

BetaFormSide is free while we are in beta.

What that includes
FormSide

GDPR for sports clubs: what you must do with families' data

A working guide to UK GDPR for clubs and camp organisers: what counts as personal data, why children's health notes are special, how long to keep things, and how to answer a parent who asks what you hold.

FORMSIDE TEAM9 MIN READ

Yes, it applies to you

If you take bookings for a camp, you hold personal data: names, email addresses, phone numbers, dates of birth, emergency contacts, and very often health information about children. UK GDPR and the Data Protection Act 2018 apply to small clubs and sole traders as much as to large companies; there is no 'too small to count'. The Information Commissioner's Office (ICO) is the regulator, and its website is the place to check anything in this guide that has changed.

The good news is that for a camp organiser the obligations are mostly common sense written down: collect only what you need, tell people what you do with it, keep it safe, do not keep it forever, and be able to show it to someone who asks.

Know what you hold and why

Start with a list. For each thing you collect on the booking form, write down why you need it and what you do with it. If you cannot finish the sentence, stop collecting it. A booking form typically needs: who is coming, who is booking, how to reach them, who to call in an emergency, and what a coach must know to keep the child safe.

Each of those has a lawful basis. Most camp data is processed because it is necessary to perform the contract (the booking) or because you have a legitimate interest in running the camp safely. Health information is different: it is special-category data, and for a camp the usual route is the family's explicit consent given on the form, alongside your duty of care. Marketing emails are different again and need separate, opt-in consent.

  • Contract: names, contact details, booking and payment records.
  • Explicit consent and duty of care: medical notes, allergies, medication.
  • Separate opt-in consent: marketing emails, photography.
  • Legal obligation: the financial record you must keep for accounts and tax.

Tell people, in a privacy notice they can read

Families have a right to know what you do with their data, and the way you meet that is a privacy notice linked from the booking form. It does not need to be long. Say who you are, what you collect, why, who you share it with (your booking system, your payment provider, your coaches), how long you keep it, and how to contact you about it. Write it in the same plain English you would use at the desk.

Keep it safe, and keep it narrow

Security for a small club is mostly about access. A shared spreadsheet that every coach can open contains every child's medical note and every parent's phone number, and nobody needs all of that. The principle is least privilege: the person at the desk sees the register; the coach sees the safety notes for their group; the treasurer sees the money; nobody sees bank details they do not need.

  • Use a system with per-person logins and roles rather than a shared password.
  • Do not email spreadsheets of children's data. If you must share a list, share access, not a copy.
  • Printed registers are personal data too: closed folder at the desk, shredder afterwards.
  • Know what you would do if a laptop were lost or an email went to the wrong person. Some breaches must be reported to the ICO within 72 hours; check the current guidance on when.

Do not keep it forever

Storage limitation is the rule organisers most often break, not through malice but because nobody ever deletes anything. Decide a retention period, write it in your privacy notice, and apply it. A reasonable pattern is to keep booking and payment records for as long as your accountant or HMRC requires, and to delete or anonymise the personal details — especially medical notes — much sooner, once the camp is over and any reasonable complaint or insurance window has passed.

Anonymisation is your friend here. You can keep the fact that a place was sold for £X on a date with reference Y for your accounts, while removing the name, the contact details and the health note. Your books still balance; the child's data is gone.

When a parent asks what you hold

Anyone can ask you for a copy of the personal data you hold about them or their child. This is a subject access request, it can be made informally (an email saying 'what do you have on us?' counts), and you generally have one month to respond. Families can also ask you to correct data, to delete it where you no longer need it, and to stop marketing to them.

Plan for this before it happens. You should be able to find everything held against a family's email address in minutes, not days, export it in a readable form, and — when the request is for erasure — remove the person while keeping the financial record you are obliged to retain. Keep a log of each request and what you did, because the second question an auditor asks is 'how do you know?'.

Processors, and who is responsible

When you use a booking system, an email service or a payment provider, you are the controller — you decide what is collected and why — and they are processors acting on your instructions. You need a written agreement with each processor covering what they do with the data, and you should know who their sub-processors are. Any decent provider publishes these; if one does not, ask why.

A short checklist

If you do these seven things you are most of the way there.

  • A list of what you collect and why, reviewed each season.
  • A privacy notice linked from the booking form.
  • Separate, opt-in tick boxes for marketing and photography.
  • Role-based access instead of a shared spreadsheet.
  • A retention period you actually apply.
  • A way to export and erase a family's data on request, and a log of doing so.
  • Written agreements with your booking, email and payment providers.

Doing it without a compliance department

FormSide was built by people who have read the ICO guidance so that organisers do not have to do this from scratch: the consent boxes, the role-scoped access, the export and erasure tools, the retention job and the privacy log are all part of the product. Our own data-processing terms and sub-processor list are published in the policy centre. It is free while in beta, and a good first step is simply to see what a well-behaved booking form asks for.

FAQ

Questions organisers ask

Do I need to register with the ICO?

Most organisations that process personal data must pay a data-protection fee to the ICO, with some exemptions. The ICO website has a short self-assessment; run it rather than assuming either way.

Can a child make a subject access request?

Children have the same rights as adults, and older children may exercise them themselves; for younger children a parent usually acts on their behalf. The ICO publishes guidance on how to judge this.

Is a WhatsApp group for parents a data protection issue?

It can be. Adding parents' numbers to a group shares them with every other member, so ask first and offer an alternative. Never put children's medical or personal details in a group message.

KEEP READING

Further reading

FREE WHILE IN BETA

See it on a real camp page.

Set up takes about twenty minutes. No card, no contract, no commission on what you take.