Lobby — home

GDPR for sports club member data: the practical version

A club holds names, emails, phone numbers, booking history, and sometimes health notes for hundreds of people. GDPR asks the club to know why it holds each one and what happens to it. This is the working checklist, not legal advice.

Lobby · Published 14 August 2026

01

Write down what you hold and why

Start with a list. For each type of data, note where it is stored, who can see it, and what it is used for. Most clubs end up with 5 or 6 rows: contact details for bookings, payment records held by the card provider, booking history, membership status, waiver or health notes for classes, and marketing consent.

The list is the document that answers most questions later. When a member asks what the club holds, or a vendor asks what to include in a contract, the list is the answer.

  • Contact details: name, email, phone
  • Booking and attendance history
  • Membership plan and payment status
  • Health or waiver notes for classes and lessons
  • Marketing preferences and the date consent was given
  • Skill ratings and match results, if the club runs leagues

02

Pick a lawful basis for each use

Every use of personal data needs a reason the law recognises. For bookings and payments, the basis is usually the contract with the member: the club cannot deliver a booked court without knowing who booked it. For marketing emails, the basis is usually consent, which must be given and recorded, and easy to withdraw. For keeping records after a member leaves, it is often a legal obligation, for example accounting rules on invoices.

Write the basis next to each row on the list. Where the answer is consent, check that the booking flow actually asks and records it, rather than assuming it.

03

Get a DPA from every vendor that touches the data

A data processing agreement, or DPA, is the contract between the club and any vendor that stores or processes member data on the club’s behalf: the booking software, the email provider, the payment provider. It sets out what the vendor may do with the data, how it protects it, who its sub-processors are, and what happens when the contract ends.

Ask each vendor for one. A vendor that cannot provide a DPA is a vendor to reconsider. Read the section on data return and deletion at termination most carefully, because that is the clause you will rely on if you ever switch.

  • Subject matter and duration of the processing
  • The types of data and the categories of people it concerns
  • The vendor’s security measures, at least in outline
  • A list of sub-processors and how the club is told about changes
  • Return or deletion of data when the contract ends
  • Help with member requests, such as access or erasure

04

Be able to export and delete on request

A member can ask for a copy of their data and can ask for it to be deleted. The club needs a way to do both without a support ticket to the vendor. In practice that means the booking software can export one member’s record as a file and can delete or anonymise it, keeping only what the club is legally required to retain, such as invoice records.

Test both paths once with a staff account before a real request arrives. The first request should not be the first time anyone tries the button.

05

Set a retention rule and apply it

Decide how long the club keeps each type of data after a member’s last activity, and write the period next to each row. Booking history might be kept for a set number of years for accounting. Marketing consent should lapse if the person has not engaged for a period. Health notes should go as soon as they are no longer needed for the class.

Then apply it. A rule that is written down but never run is not a rule. A yearly review where staff delete or anonymise records past their period is enough for most clubs.

06

Know where the data lives

Where the data is stored matters under GDPR. EU hosting keeps the data inside the same legal framework and removes a set of questions about international transfers. Ask each vendor where the data lives and where its backups live, and note the answer on the list. Lobby hosts club data in the EU, in Frankfurt, and provides a DPA on request.

Takeaways

If you read one thing

  1. 01

    Keep one list of what data the club holds, where, why, and for how long.

  2. 02

    Match each use to a lawful basis: contract for bookings, consent for marketing.

  3. 03

    Get a DPA from every vendor and read the termination clause first.

  4. 04

    Test export and deletion before a real request arrives.

  5. 05

    Ask where data and backups are hosted. EU hosting simplifies the answer.

Questions

The short version

Does a small club really need a DPA?

Yes, whenever a vendor processes member data on the club’s behalf. Size does not change the requirement, and most vendors have a standard one ready.

Can we keep booking history after a member leaves?

Usually, for a defined period and a defined reason such as accounting. Write the period down and delete or anonymise after it.

How does Lobby handle this?

Lobby hosts data in the EU, provides a DPA on request, lets the club export its member list at any time, and keeps card data with Stripe so the club and Lobby never see it.

Ready when you are

Try it on your own schedule.

A free preview workspace with your courts, prices, and rules. No card, nothing published until you say so.

Book a demo