01
Write down what you hold and why
Start with a list. For each type of data, note where it is stored, who can see it, and what it is used for. Most clubs end up with 5 or 6 rows: contact details for bookings, payment records held by the card provider, booking history, membership status, waiver or health notes for classes, and marketing consent.
The list is the document that answers most questions later. When a member asks what the club holds, or a vendor asks what to include in a contract, the list is the answer.
- Contact details: name, email, phone
- Booking and attendance history
- Membership plan and payment status
- Health or waiver notes for classes and lessons
- Marketing preferences and the date consent was given
- Skill ratings and match results, if the club runs leagues
02
Pick a lawful basis for each use
Every use of personal data needs a reason the law recognises. For bookings and payments, the basis is usually the contract with the member: the club cannot deliver a booked court without knowing who booked it. For marketing emails, the basis is usually consent, which must be given and recorded, and easy to withdraw. For keeping records after a member leaves, it is often a legal obligation, for example accounting rules on invoices.
Write the basis next to each row on the list. Where the answer is consent, check that the booking flow actually asks and records it, rather than assuming it.
03
Get a DPA from every vendor that touches the data
A data processing agreement, or DPA, is the contract between the club and any vendor that stores or processes member data on the club’s behalf: the booking software, the email provider, the payment provider. It sets out what the vendor may do with the data, how it protects it, who its sub-processors are, and what happens when the contract ends.
Ask each vendor for one. A vendor that cannot provide a DPA is a vendor to reconsider. Read the section on data return and deletion at termination most carefully, because that is the clause you will rely on if you ever switch.
- Subject matter and duration of the processing
- The types of data and the categories of people it concerns
- The vendor’s security measures, at least in outline
- A list of sub-processors and how the club is told about changes
- Return or deletion of data when the contract ends
- Help with member requests, such as access or erasure
04
Be able to export and delete on request
A member can ask for a copy of their data and can ask for it to be deleted. The club needs a way to do both without a support ticket to the vendor. In practice that means the booking software can export one member’s record as a file and can delete or anonymise it, keeping only what the club is legally required to retain, such as invoice records.
Test both paths once with a staff account before a real request arrives. The first request should not be the first time anyone tries the button.
05
Set a retention rule and apply it
Decide how long the club keeps each type of data after a member’s last activity, and write the period next to each row. Booking history might be kept for a set number of years for accounting. Marketing consent should lapse if the person has not engaged for a period. Health notes should go as soon as they are no longer needed for the class.
Then apply it. A rule that is written down but never run is not a rule. A yearly review where staff delete or anonymise records past their period is enough for most clubs.
06
Know where the data lives
Where the data is stored matters under GDPR. EU hosting keeps the data inside the same legal framework and removes a set of questions about international transfers. Ask each vendor where the data lives and where its backups live, and note the answer on the list. Lobby hosts club data in the EU, in Frankfurt, and provides a DPA on request.