The club is responsible, not its tool

That is the starting point, and it often surprises: the association is the controller. It decides which data it collects and why. The software it uses is only a processor: it handles that data on the association's behalf, following its instructions.

The relationship is put in writing. A processing agreement states what the provider may do with the data, where it is hosted, and what becomes of it when the club leaves. A supplier who cannot show you one should worry you: the liability, after all, stays with you.

On what basis are you collecting?

Every piece of data collected needs a reason, and the reason is chosen use by use, not once for the whole file. In a club, three keep coming back.

What membership requires. Name, address, date of birth, contact details: without them you cannot register the person, insure them or bill them. You do not need permission for what membership genuinely requires. Some of it the law imposes on you outright: the register of members, the accounting records.

What serves the club without surprising anyone. Writing to your own members about club life, knowing who has access to the file: that is legitimate interest. It is weighed — your reason against what the person could reasonably expect — and it can be contested: the right to object exists.

What nobody is obliged to accept. Photos on the club's page, passing contact details to a sponsor: that takes consent — freely given, separate, and refusable with no consequence for joining.

So the question for each field is: what is it for, and what entitles me to use it? A field you have no answer for is a field you do not ask for.

Only collect what you use

The principle is called minimisation, and it is the easiest to apply: data you do nothing with is data not to ask for.

The classic example in a sports club is the national register number. Health-fund forms ask for it, so clubs collect it “just in case”. They do nothing with it: it belongs on the half the member fills in personally, and it never passes through the club. Worse, using it is subject to a ministerial authorisation a club must hold. See the health-fund sports form.

The same reasoning covers occupation, health, household composition. A field that serves nothing does not make a database better: it only adds risk.

The record of processing activities

The GDPR requires a record of processing activities: which data, for what, passed to whom, kept how long.

An exemption exists for organisations under 250 people — but it falls away as soon as the processing is not occasional. Running a member file all year is precisely the opposite of occasional. In practice, then, a club keeps that record.

The good news: for a club it fits on two pages. The member file, the accounts, the mailings, possibly the photos. It is not a document to have drafted; it is a list to write once and reread when something changes.

How long to keep

“Forever” is not a retention period. Each category of data has its own, and it follows from what the data is for.

Accounting records are kept for a long time because the law requires it — subscriptions collected are among them. The contact details of a member who has left, on the other hand, have no reason to be kept indefinitely: after a reasonable period they are deleted.

One distinction that matters: deleting a member must never delete their paid subscription. The two have different retention periods because they serve different purposes.

What a member can ask for

  • To see what the club holds about them
  • To have corrected what is wrong
  • To have erased what no longer has a reason to be kept
  • To object to a use that was not necessary, such as the newsletter

The right to erasure is not absolute. A member cannot make a collected subscription disappear: it belongs to the accounts, which the association must keep. A club is entitled to explain that.

The mistake of the “To” field

It is the most common data breach in club life, and it hangs on one form field.

Sending a message to forty members with everyone in the “To” field hands each person's address to all the others. Nobody consented to that. If the message is a payment reminder, it also reveals who has not paid.

That can amount to a data breach to be reported to the Data Protection Authority within 72 hours. The remedy is trivial: blind copy, or a tool that produces one message per person.

Read this as orientation
This page is not legal advice.

It describes what comes up in a club of thirty to a hundred and fifty members, so you know what to check. A club that films its matches, publishes photos of minors or handles health data has further questions that deserve real counsel.

What the tool guarantees you

Three things that fall to the processor, and that a club should not have to police.

01
Your data stays yours Hosted in Belgium, backed up every day, fully exportable at any time. If you leave, you leave with the file.
02
The fields are yours too You decide which are required and which are optional. The national register number is not offered at all: using it is subject to a ministerial authorisation.
03
No club ever sees another Several clubs share the instance, never their files. There is no shared record between two clubs: the same person is two independent members.

Frequently asked questions

Do we need a data protection officer?
A club of a few dozen members is not required to appoint one: it is not a public authority, and it carries out neither monitoring of people nor processing of sensitive data on a large scale. Naming a point of contact on the committee stays useful, so a member's request does not get lost.
Can we publish photos from a tournament?
A group shot at a public event and a photo where someone is recognisable and singled out are not the same thing. For the second, ask; for a minor, ask the parents. And plan how you take a photo down when someone asks.
Our list lives in a shared spreadsheet — is that a problem?
The format is not the issue, access is. A spreadsheet shared by link is open to whoever holds the link, including former committee members. The question to ask is: who has access today, and who should?
What do we do after a leak?
Write down what happened, which data and how many people are affected. If there is a risk to those people, notification to the Data Protection Authority is due within 72 hours. A misaddressed bulk email counts: it is the most common case.