Data protection in esports clubs
A club run by volunteers is a controller too. The obligations apply regardless of size, and they fall on the board.
Clubs work with the same data as companies, only with fewer resources. That does not change the obligations, but it does change the route to meeting them. That route has to be lean, documented, and built so that a change on the board does not carry it away.
Where we start
- Records of processing activities, kept to the essentials
- Legal bases for membership administration, fees and communication
- Assessing and securing the use of Discord, messengers and cloud services
- Information duties towards members and those with parental responsibility
- Handling of streams, photographs and recordings at tournaments
- A deletion concept for former members
- Responsibilities on the board recorded so that they survive a handover
Member data outwards and inwards
Two questions come up in every club, and neither has much to do with technology.
Outwards it is about publishing names, results and photographs. For the ongoing competition the legitimate interest of the club comes into consideration, for advertising and sponsor presentation rather not. The scope stays limited, an objection under Art. 21 GDPR has to be respected, and old lists belong offline after a while.
Inwards it is about the list of members. Under narrow conditions a member may request the names and addresses of the other members, for instance in order to prepare a general meeting. A blanket request does not carry that, but neither does a blanket refusal citing data protection. What has to be examined is the purpose, and the scope follows from it.
How we support you
We build a solution with you that matches the size of the club and draft the documents so that they can be carried on without specialist knowledge. Where ongoing support is wanted, our sister company takes it on.
Club being restructured?
We bring data protection to a level that matches your size.
Get in touchFrequently asked questions
Does our club need a data protection officer?
That depends on the number of people constantly engaged in automated processing and on the nature of the processing. Many small clubs fall below the threshold. The remaining obligations do not fall away with it: records, information duties and data subject rights apply regardless.
May we use Discord or WhatsApp for club communication?
Using them is not prohibited but calls for the same assessment as any other service: legal basis, processing agreement, handling of third-country transfers and an alternative for anyone who does not want to use the service. With underage members, the age threshold of the platform has to be observed.
May we publish result lists with names?
For the ongoing competition the legitimate interest of the club comes into consideration, because a league does not work without results. The scope nonetheless stays limited: name and result suffice, address and date of birth do not belong there. For members who are minors the balancing is stricter, and an objection under Art. 21 GDPR has to be respected. Leaving old lists online indefinitely can hardly be justified by the competition.
Is the board personally liable?
The controller is the club, and a fine is directed against it. Internally, however, where board work is unpaid or only marginally remunerated, the club may take recourse under section 31a of the German Civil Code only in cases of intent or gross negligence. That relief does not remove the task itself: a board that arranges nothing and documents nothing is moving towards gross negligence.
What applies to streaming club tournaments?
Alongside the data protection basis, image rights have to be observed, and for minors the agreement of those with parental responsibility is added. A notice at the entrance does not cover everything. Anyone being recorded should know in advance and be able to object.