For many clubs, GDPR can feel like a complicated piece of legislation designed for large organisations rather than volunteer-run sports clubs.
The reality is much simpler.
GDPR is about looking after people's information, only collecting what you need, keeping it secure, and deleting it when you no longer need it. Whether you're running a local paddlesport club with 20 members or a large organisation with hundreds of participants, the same principles apply.
Recent changes to UK data protection law, combined with increasing expectations from the Information Commissioner's Office (ICO), mean now is a good time for clubs to review how they handle personal information.
What has changed?
The biggest development is the Data (Use and Access) Act 2025 (DUAA), which became law on 19 June 2025. It does not replace UK GDPR, but it does update and amend parts of the existing data protection framework. The ICO has now published guidance explaining how organisations should prepare for these changes.
Some of the changes include:
- New requirements around handling data protection complaints.
- Updates to subject access request processes.
- Greater emphasis on protecting children's data.
- Updated provisions around automated decision-making and AI tools.
Most clubs will not need to make major operational changes overnight, but the direction of travel is clear: organisations are expected to be able to demonstrate good governance, good record keeping and sensible data management practices.
The Challenges Clubs Face
1. Holding information for too long
One of the most common GDPR issues is retaining personal information indefinitely simply because "we might need it one day".
Old membership spreadsheets, historic event entries, former volunteers' details, expired consent forms and outdated medical information can often remain stored years after they are needed.
The ICO is clear that personal information should not be kept longer than necessary and organisations should have a documented retention schedule.
Simple solution
Set regular dates throughout the year to review and delete information that is no longer required.
Ask yourself:
"If this person asked us today why we're still holding this information, could we justify it?"
If the answer is no, it is probably time to delete it.
2. Youth and safeguarding data
Sports clubs often hold information about children and young people, making this one of the highest-risk areas of data protection.
This may include:
- Medical forms
- Emergency contacts
- Photography consent
- Participant records
- Safeguarding information
Children's information requires additional protection, and the ICO has signalled an increasing focus on children's data rights and safeguarding considerations.
Simple solution
Store youth information only in approved systems.
Avoid:
- Personal laptops
- Personal email accounts
- WhatsApp groups
- Unmanaged spreadsheets
Ensure only those who genuinely need access can view the information.
3. WhatsApp and informal messaging
Most clubs use WhatsApp because it is convenient. The challenge comes when groups start containing membership information, medical details, safeguarding discussions or documents that should be held elsewhere.
Once data enters multiple chat groups, it becomes much harder to manage, secure and delete appropriately.
Simple solution
Use WhatsApp for communication and coordination, not long-term record keeping.
Messages such as:
✅ "The session starts at 6pm" are generally low risk.
Messages containing:
❌ Medical information
❌ Safeguarding concerns
❌ Membership records
❌ Full contact lists should be kept in secure club systems instead.
4. Knowing where information is stored
Many clubs have information spread across:
- Email inboxes
- Club laptops
- Google Drive
- OneDrive
- Spond
- Personal devices
This makes it difficult to respond to subject access requests or delete information when required.
Simple solution
Create a simple data map.
List:
- What information you hold
- Where it is stored
- Who can access it
- How long it is kept
You don't need expensive software. A simple spreadsheet is often enough.
Why Retention Matters
Retention is likely to be one of the biggest areas of focus for clubs over the coming years. The ICO recommends organisations have a documented retention schedule setting out:
- What information is held
- How long it is kept
- Why it is retained
- What happens at the end of the retention period. Whether that means deletion, anonymisation or archiving.
At Paddle Cymru, we are currently working alongside Paddle UK, Paddle Northern Ireland and Paddle Scotland to develop a new aligned retention framework and policy approach. The aim is to provide greater consistency across the paddlesport sector while ensuring all national governing bodies remain aligned with current UK legislation and ICO guidance.
Further information and guidance will be shared once this work is finalised.
Free GDPR Health Checks for Clubs
The good news is that you do not need to guess whether your club is compliant.
The ICO provides several free resources that can help organisations assess their current position:
ICO Data Protection Self-Assessment
A free online tool that helps organisations review their compliance and identify areas for improvement. [ico.org.uk], [uploads.te...blecdn.com] ICO Self-Assessment Toolkit
ICO Records Management Checklist
Useful for clubs looking to improve how they manage and retain information. [cy.ico.org.uk], [cy.ico.org.uk] ICO Records Management Checklist
Don't Use Your Email Inbox as a Filing Cabinet
One of the most overlooked GDPR risks in sports clubs is email.
Many volunteers keep years of membership forms, incident reports, medical information and safeguarding correspondence sitting in their inboxes long after it is needed. A cluttered inbox doesn't just make information harder to find, it also increases the amount of personal data being held unnecessarily.
The ICO is clear that organisations should have retention periods for personal information and should not keep data "just in case". Retention schedules should cover emails as well as documents and databases.
Good practice
✅ Save important records to the club's approved storage location
✅ Delete emails once information has been stored appropriately
✅ Regularly review old folders and archives
✅ Ensure shared club mailboxes are managed consistently
Avoid
❌ Keeping membership applications indefinitely
❌ Retaining old medical forms in email folders
❌ Using personal email accounts for club business
❌ Forwarding sensitive information between personal and club accounts
Remember: if information exists in both a secure club system and an email inbox, you may be holding duplicate personal data unnecessarily.
Children's Data Requires Extra Protection
Not all personal data carries the same level of risk.
For most clubs, the highest-risk information they hold relates to children and young people.
Children are considered more vulnerable under data protection legislation, which means organisations are expected to take additional care when collecting, storing and sharing their information. Recent guidance and legislative changes continue to place greater emphasis on children's privacy and data protection rights.
Examples of children's data
- Medical information
- Emergency contacts
- Consent forms
- Attendance records
- Photographs and video consent
- Safeguarding reports
- Behavioural or welfare concerns
Best practice
✅ Restrict access to those who genuinely need it
✅ Store information in approved systems
✅ Review information regularly
✅ Delete operational records when no longer needed
✅ Follow safeguarding retention requirements where applicable
Avoid
❌ Storing children's data on personal devices
❌ Sharing information via WhatsApp groups
❌ Leaving former junior member records in club databases indefinitely
❌ Keeping documents "just in case"
Subject Access Requests (SARs): Don't Panic
A Subject Access Request, often known as a SAR, is when an individual asks to see the personal information an organisation holds about them.
This could be:
- A club member
- A volunteer
- A parent
- A coach
- A former member
Most SARs are straightforward, but they can become challenging if information is spread across personal email accounts, old spreadsheets, WhatsApp groups and various online platforms.
If your club receives a SAR:
- Record the request.
- Do not delete anything.
- Identify where information may be held.
- Gather relevant records.
- Seek advice if you're unsure.
Having good record keeping and a clear retention schedule makes responding to SARs significantly easier.
One of the best ways to prepare for a SAR is actually to reduce the amount of unnecessary information you hold in the first place.
Where to Get Help
Data protection can feel overwhelming, particularly for volunteer-led clubs, but you don't have to tackle it alone. The ICO provides a wide range of free resources, including self-assessment tools, records management checklists and retention guidance designed to help organisations improve their data protection practices.
If your club is unsure about any aspect of GDPR, data retention, Subject Access Requests, safeguarding data or data security, support is available.
Paddle Cymru clubs can contact Bonnie Ireland, Marketing, Communications and Data Protection Lead, for advice and guidance on data protection matters Bonnie.Ireland@paddlecymru.org.uk
Whether you're reviewing your club's processes, responding to a query from a member, or simply want reassurance that you're heading in the right direction, we're here to help.
Final Thoughts
GDPR is not about preventing clubs from operating. It's about making sure information is handled responsibly.
For most clubs, compliance comes down to a few simple questions:
- Do we really need this information?
- Is it stored securely?
- Does the right person have access?
- Do we know when it should be deleted?
If you can answer those questions confidently, you're already well on the way to good data protection practice.
As legislation and guidance continue to evolve, Paddle Cymru will continue supporting clubs with practical advice, templates and sector-wide guidance to help make compliance as straightforward as possible.
Useful Resources for Clubs
Information Commissioner's Office (ICO)
The ICO is the UK's independent regulator for data protection and should be your first port of call for official guidance.
Getting Started with Data Protection
Data Protection Self-Assessment Toolkit
- Assess your club's GDPR compliance and identify areas for improvement.
- ICO Self-Assessment Toolkit [ico.org.uk], [uploads.te...blecdn.com]
Records Management Checklist
- Useful for reviewing how your club stores and manages information.
- Records Management Checklist [cy.ico.org.uk]
Subject Access Request Guidance
- Advice on how to respond when someone asks for a copy of their personal information.
- ICO Subject Access Request Guidance [ico.org.uk], [ico.org.uk]
UK Data Protection Updates
Data (Use and Access) Act 2025 (DUAA)
- Details of the latest changes to UK data protection legislation.
- ICO Data (Use and Access) Act Hub [ico.org.uk]
Government Summary of Changes
- Plain-English overview of the key changes introduced by the Act.
- Government DUAA Guidance [gov.uk]
CONTACT THE MEDIA TEAM
If you have a story that would be of interest to the Paddle Cymru team please get in touch using the online contact form linked below or get in contact using one of our social feeds.
SIGN UP TO CEUFAD MAGAZINE
Ceufad is our quarterly magazine, covering everything that's important in Welsh paddlesport.
Share Post








