Data Privacy & Compliance Guide — GoClubPro
Training Module 33 | Privacy Act, GDPR, and Member Data Responsibilities
What This Guide Covers
GoClubPro stores personal data about your members. As a Club Admin, you have responsibilities under Australian privacy law (and GDPR if your club has members in the EU). This guide explains what data is stored, what rights members have, and what you need to do to stay compliant.
Primary audience: Club Admins, Treasurers Also relevant to: All members (their rights section)
Disclaimer: This guide explains how GoClubPro handles data. It is not legal advice. If your club has specific compliance requirements, consult a legal professional.
WHAT DATA DOES GOCLUBPRO STORE?
Per Member
| Data Type | Where stored | Who can see it |
|---|---|---|
| Full name | Profile | Admin, Coach (within club), member |
| Email address | Profile | Admin only (not visible to other members) |
| Phone number | Profile (optional) | Admin only |
| Date of birth | Profile (optional) | Admin only |
| Emergency contact | Profile | Admin, Coach (during fixture) |
| Profile photo | Profile | All club members |
| Payment history | Payments ledger | Admin, Treasurer, member |
| RSVP history | Schedule | Coach, Admin, member |
| Attendance records | Schedule | Coach, Admin, member |
| Injury flags | Profile | Coach, Admin, member |
| Blockout dates | Profile | Coach, Admin, member |
| Match statistics | Profile | All club members (if made public) |
| IP address / login logs | Security → Sessions | Member (their own), Platform Admin |
| your league platform ID | Profile (optional) | Admin |
MEMBER RIGHTS UNDER PRIVACY LAW
Right to Access (Australian Privacy Act / GDPR Art. 15)
Members can request a copy of all personal data held about them.
How to fulfill in GoClubPro:
- Direct the member to: Profile → Download My Data
- The download includes all personal data, payment history, RSVP history, and attendance records in a standard format
- Alternatively, an Admin can export the member's data from Admin Panel → Members → select member → Export
Response time: Under Australian Privacy Act, respond within 30 days. Under GDPR, within 30 days.
Right to Correction
Members can request correction of inaccurate personal data.
How to fulfill:
- Members can update most fields themselves in Profile
- For fields they can't change (e.g., registered email), Admin Panel → Members → edit member details
- Always confirm the correction with the member via email
Right to Deletion ("Right to Be Forgotten" — GDPR Art. 17)
Members in the EU (and under some state laws in Australia) can request deletion of their personal data.
How to fulfill:
- Profile → Account Management → Delete Account (member self-service — irreversible)
- For admin-initiated deletion: Admin Panel → Members → find member → Remove from Club (this removes club access but retains anonymised financial records for accounting integrity)
- For complete data deletion: contact GoClubPro platform support — they can perform a full data purge
Important exception: Financial records (payment history, ledger entries) may need to be retained for 5–7 years for tax/legal purposes even after deletion. The platform anonymises these records (name replaced with "Deleted Member") rather than removing them entirely.
Right to Data Portability (GDPR Art. 20)
Members can request their data in a machine-readable format.
How to fulfill:
- Profile → Download My Data exports as CSV/JSON — this satisfies portability requirements
- The export includes all data in a standard format
YOUR OBLIGATIONS AS CLUB ADMIN
1. Only Collect What You Need
GoClubPro has optional fields (phone, DOB, etc.). Only collect these if you genuinely need them.
Recommendation: Brief your committee on which fields are required for your club's purposes. Don't collect DOB unless required (e.g., for age-group verification in junior cricket).
2. Keep Data Secure
- Do not export member lists and share them via email or WhatsApp
- Do not share admin credentials with non-admins
- Enable MFA on all admin accounts (Profile → Security → Enable MFA)
- Remove former committee members' admin access promptly when they leave a role
In GoClubPro: Admin Panel → Members & Roles → change a former admin's role back to Player when they step down.
3. Limit Data Access
Members should only see data they need. GoClubPro's role system handles most of this:
| Role | Can see |
|---|---|
| Player | Their own data, public profile info of teammates, fixtures, standings |
| Coach | Player availability, RSVP status, injury flags, attendance — for their team |
| Treasurer | Payment data for all members |
| Admin | All member data within the club |
| Platform Admin | All data across all clubs (access is audit-logged) |
You cannot grant more granular access than these roles. If a volunteer needs limited access (e.g., schedule management only), the nearest role is Co-Admin — be aware this grants broader access.
4. Respond to Member Requests Promptly
If a member requests their data, correction, or deletion:
- Log the request (date, type, member name) — keep records
- Respond within 30 days (Australian Privacy Act requirement)
- For deletion requests, confirm completion in writing
5. Data Breach Notification
If you suspect a data breach (e.g., admin credentials were compromised, data was exported and shared without authorisation):
Immediate steps:
- Change the compromised admin account's password immediately
- Revoke all active sessions: Profile → Security → Sign Out All Other Sessions
- Contact GoClubPro platform support immediately — they can audit access logs
- Under Australian law (Notifiable Data Breaches scheme): if the breach is likely to cause serious harm, notify OAIC (Office of the Australian Information Commissioner) within 30 days
- Notify affected members if their data was exposed
CHILDREN'S DATA (PARTICULARLY IMPORTANT)
Junior sports clubs handle children's data. Additional obligations apply:
Collecting Children's Data
- Children under 13 (AU) / under 16 (GDPR) should not create their own accounts without parental consent
- Recommended approach: Parent creates an account; children are added via Family Hub (Module 14)
- If an older junior (14–17) has their own account, a parent/guardian's email should still be on file
What Data to Collect for Juniors
Minimum needed:
- Child's name
- Date of birth (required for age-group eligibility verification)
- Parent/guardian contact details (emergency contact on child's profile)
Avoid collecting:
- Medical details beyond injury flags
- School information
- Photos used for anything other than in-app identification
Photo Policy
Profile photos of minors are visible to all club members. Your club should have a child-safe photography policy that covers:
- Written consent from parents before uploading photos of minors to club systems
- GoClubPro profile photos are visible only to club members (not public internet)
VISUAL: Data Flow Summary
Member signs up
│
▼
Personal data stored in GoClubPro database (encrypted at rest)
│
├──▶ Visible to: Member themselves (full)
├──▶ Visible to: Coaches (availability, RSVP, injury)
├──▶ Visible to: Treasurers (payment data)
├──▶ Visible to: Admins (all club data)
└──▶ NOT visible to: Other members (email, phone, DOB)
Payment data
│
└──▶ GoClubPro ledger (payment history, amounts)
league platform data (if connected)
│
└──▶ Fixture data only — no personal league platform data imported to GoClubPro
TOOLTIPS & HINTS
- "Download My Data" is self-service — point members here first; it's faster than an admin export
- Deletion is irreversible — if a member asks to be deleted, confirm twice; the action cannot be undone
- MFA on all admin accounts — the most impactful single security action you can take as an admin
- Former admins — change their role as soon as they leave the committee; don't wait for the next committee meeting
FAQ
Q: Do we need a Privacy Policy for our club? A: If your club has an ABN and handles personal information, yes — Australian Privacy Act likely applies. A simple one-page document covering what you collect, why, and how members can access it is sufficient for most amateur sports clubs.
Q: Can we share our member list with sponsors? A: No — not without explicit consent from each member. Member data collected for club purposes cannot be used for third-party marketing.
Q: A member wants us to delete them but they still owe match fees. What do we do? A: You can retain their payment records (anonymised) for accounting purposes. Their personal profile can be deleted. This is standard practice under both Australian Privacy Act and GDPR.
Q: Do we need to register with OAIC? A: Small sports clubs (under $3M turnover) are generally exempt from Australian Privacy Act registration requirements, but the Notifiable Data Breaches scheme still applies. Check oaic.gov.au for current thresholds.
Q: Is GoClubPro GDPR compliant? A: Contact GoClubPro platform support for the current Data Processing Agreement (DPA). For EU member clubs, you'll need a DPA in place.
COMMON MISTAKES
| Mistake | Risk | Prevention |
|---|---|---|
| Sharing member export via WhatsApp/email | Data breach — personal data outside secure system | Never export and share; use in-app communication tools |
| Not removing former admin access | Former admin retains full data access | Same-day role change when admin steps down |
| Collecting DOB for all members "just in case" | Data minimisation violation | Only collect what your club genuinely needs |
| Ignoring deletion requests | Privacy Act breach | Treat deletion requests as time-sensitive; log and respond within 30 days |
| Using same admin login for multiple people | No audit trail; breach liability is murky | Each admin has their own login; use MFA |
SHORT ONBOARDING SCRIPT
"As Club Admin, you're the data controller for your members' personal information. Three rules: collect only what you need, secure it (MFA on your account today), and respond to member data requests within 30 days. If a member wants their data downloaded, point them to Profile → Download My Data. If they want deletion, contact platform support. If an admin leaves, change their role immediately. That covers 95% of your privacy obligations."
MICRO-TRAINING QUICK TIPS
- MFA on all admin accounts — do this today
- Former admin stepping down? Change their role today, not next month
- Member wants their data? → Profile → Download My Data
- Member wants deletion? → Platform support for full purge
- Never share member lists via WhatsApp/email
- Children's data: prefer Family Hub (parent account) over child accounts under 13
TROUBLESHOOTING
| Symptom | Check | Action |
|---|---|---|
| Member says their data is wrong | Profile fields | Admin → edit member → correct the data; confirm in writing |
| Suspected breach: admin credentials shared | Active sessions | Change password → revoke all sessions → contact platform support |
| Member requests deletion but has unpaid fees | Platform support | Anonymise personal data; retain financial records |
| Can't find member's data for access request | Admin Panel → Members → Export | Export member data; provide to member within 30 days |
Training Module 33 | See also: 15 Security Settings · 08 Player Profile · 17 Central Command