Skip to content
GlossaryLegal

GDPR

EU Regulation 2016/679 governing personal data processing across the European Union. Applies to every sports club handling member, player or family data.

Definition

GDPR (General Data Protection Regulation, EU Regulation 2016/679) has regulated personal data processing across the EU since 2018. It replaces former national laws and is complemented in Spain by LOPDGDD (Organic Law 3/2018).

For a sports club its impact is high: you handle sensitive data (minors, health data, image, financial), and you are the data controller. Core obligations: valid legal bases for each processing activity (consent, contract, legal obligation, legitimate interest), clear information to data subjects (privacy policy), record of processing activities (RAT), guarantee data subject rights (access, rectification, erasure, restriction, portability, objection), notify security breaches and, when applicable, appoint a Data Protection Officer (DPO).

When does it apply?

Applies from the very first personal data point you process: a registration sheet with member name and email already falls under GDPR. No minimum size threshold. Obligations scale with volume and sensitivity, but the principles (lawfulness, fairness, transparency, minimisation, accuracy, storage limitation, integrity, accountability) always apply.

Practical example

C.D. Voleibol Costa drafts its privacy policy stating it collects name, date of birth, ID, address, email and phone of members and one parent for minors; that data is used for club management, billing and communications; that the legal basis is the membership contract (contractual basis) and, for social media images, the explicit consent of parents. It maintains a spreadsheet RAT with five processing activities: member management, billing, communication, image, federation. Designates the secretary as internal controller and hires an external GDPR advisor for €150/year.

Common mistakes

  • Posting photos of minors on social media without signed explicit consent: very common and serious breach.
  • Not keeping a RAT: Spain's AEPD requires it even from small entities; absence is sanctionable.
  • Confusing consent with contractual basis: consent must be revocable; contractual basis is not.
  • Forgetting data processors: club software, accountant, email provider are processors and need data-processing agreements.

Related terms

Go deeper

Long-form guides and product pages where we cover this topic in depth:

This is not specific legal or tax advice

Information as of May 2026. Regulation evolves and every club has its own casuistry (region, federation, size, activities). For your specific case talk to a lawyer or tax advisor specialised in Spanish sports law.

Move from Excel to software built for sports clubs

SEPA + card payments with Stripe, member portal, player onboarding, ticketing. Free up to 50 members, no card required.