33Club Admins, Treasurers

Data Privacy & Compliance Guide — GoClubPro

Training Module 33 | Privacy Act, GDPR, and Member Data Responsibilities


What This Guide Covers

GoClubPro stores personal data about your members. As a Club Admin, you have responsibilities under Australian privacy law (and GDPR if your club has members in the EU). This guide explains what data is stored, what rights members have, and what you need to do to stay compliant.

Primary audience: Club Admins, Treasurers Also relevant to: All members (their rights section)

Disclaimer: This guide explains how GoClubPro handles data. It is not legal advice. If your club has specific compliance requirements, consult a legal professional.


WHAT DATA DOES GOCLUBPRO STORE?

Per Member

Data TypeWhere storedWho can see it
Full nameProfileAdmin, Coach (within club), member
Email addressProfileAdmin only (not visible to other members)
Phone numberProfile (optional)Admin only
Date of birthProfile (optional)Admin only
Emergency contactProfileAdmin, Coach (during fixture)
Profile photoProfileAll club members
Payment historyPayments ledgerAdmin, Treasurer, member
RSVP historyScheduleCoach, Admin, member
Attendance recordsScheduleCoach, Admin, member
Injury flagsProfileCoach, Admin, member
Blockout datesProfileCoach, Admin, member
Match statisticsProfileAll club members (if made public)
IP address / login logsSecurity → SessionsMember (their own), Platform Admin
your league platform IDProfile (optional)Admin

MEMBER RIGHTS UNDER PRIVACY LAW

Right to Access (Australian Privacy Act / GDPR Art. 15)

Members can request a copy of all personal data held about them.

How to fulfill in GoClubPro:

  • Direct the member to: Profile → Download My Data
  • The download includes all personal data, payment history, RSVP history, and attendance records in a standard format
  • Alternatively, an Admin can export the member's data from Admin Panel → Members → select member → Export

Response time: Under Australian Privacy Act, respond within 30 days. Under GDPR, within 30 days.


Right to Correction

Members can request correction of inaccurate personal data.

How to fulfill:

  • Members can update most fields themselves in Profile
  • For fields they can't change (e.g., registered email), Admin Panel → Members → edit member details
  • Always confirm the correction with the member via email

Right to Deletion ("Right to Be Forgotten" — GDPR Art. 17)

Members in the EU (and under some state laws in Australia) can request deletion of their personal data.

How to fulfill:

  • Profile → Account Management → Delete Account (member self-service — irreversible)
  • For admin-initiated deletion: Admin Panel → Members → find member → Remove from Club (this removes club access but retains anonymised financial records for accounting integrity)
  • For complete data deletion: contact GoClubPro platform support — they can perform a full data purge

Important exception: Financial records (payment history, ledger entries) may need to be retained for 5–7 years for tax/legal purposes even after deletion. The platform anonymises these records (name replaced with "Deleted Member") rather than removing them entirely.


Right to Data Portability (GDPR Art. 20)

Members can request their data in a machine-readable format.

How to fulfill:

  • Profile → Download My Data exports as CSV/JSON — this satisfies portability requirements
  • The export includes all data in a standard format

YOUR OBLIGATIONS AS CLUB ADMIN

1. Only Collect What You Need

GoClubPro has optional fields (phone, DOB, etc.). Only collect these if you genuinely need them.

Recommendation: Brief your committee on which fields are required for your club's purposes. Don't collect DOB unless required (e.g., for age-group verification in junior cricket).


2. Keep Data Secure

  • Do not export member lists and share them via email or WhatsApp
  • Do not share admin credentials with non-admins
  • Enable MFA on all admin accounts (Profile → Security → Enable MFA)
  • Remove former committee members' admin access promptly when they leave a role

In GoClubPro: Admin Panel → Members & Roles → change a former admin's role back to Player when they step down.


3. Limit Data Access

Members should only see data they need. GoClubPro's role system handles most of this:

RoleCan see
PlayerTheir own data, public profile info of teammates, fixtures, standings
CoachPlayer availability, RSVP status, injury flags, attendance — for their team
TreasurerPayment data for all members
AdminAll member data within the club
Platform AdminAll data across all clubs (access is audit-logged)

You cannot grant more granular access than these roles. If a volunteer needs limited access (e.g., schedule management only), the nearest role is Co-Admin — be aware this grants broader access.


4. Respond to Member Requests Promptly

If a member requests their data, correction, or deletion:

  • Log the request (date, type, member name) — keep records
  • Respond within 30 days (Australian Privacy Act requirement)
  • For deletion requests, confirm completion in writing

5. Data Breach Notification

If you suspect a data breach (e.g., admin credentials were compromised, data was exported and shared without authorisation):

Immediate steps:

  1. Change the compromised admin account's password immediately
  2. Revoke all active sessions: Profile → Security → Sign Out All Other Sessions
  3. Contact GoClubPro platform support immediately — they can audit access logs
  4. Under Australian law (Notifiable Data Breaches scheme): if the breach is likely to cause serious harm, notify OAIC (Office of the Australian Information Commissioner) within 30 days
  5. Notify affected members if their data was exposed

CHILDREN'S DATA (PARTICULARLY IMPORTANT)

Junior sports clubs handle children's data. Additional obligations apply:

Collecting Children's Data

  • Children under 13 (AU) / under 16 (GDPR) should not create their own accounts without parental consent
  • Recommended approach: Parent creates an account; children are added via Family Hub (Module 14)
  • If an older junior (14–17) has their own account, a parent/guardian's email should still be on file

What Data to Collect for Juniors

Minimum needed:

  • Child's name
  • Date of birth (required for age-group eligibility verification)
  • Parent/guardian contact details (emergency contact on child's profile)

Avoid collecting:

  • Medical details beyond injury flags
  • School information
  • Photos used for anything other than in-app identification

Photo Policy

Profile photos of minors are visible to all club members. Your club should have a child-safe photography policy that covers:

  • Written consent from parents before uploading photos of minors to club systems
  • GoClubPro profile photos are visible only to club members (not public internet)

VISUAL: Data Flow Summary

Member signs up
 │
 ▼
Personal data stored in GoClubPro database (encrypted at rest)
 │
 ├──▶ Visible to: Member themselves (full)
 ├──▶ Visible to: Coaches (availability, RSVP, injury)
 ├──▶ Visible to: Treasurers (payment data)
 ├──▶ Visible to: Admins (all club data)
 └──▶ NOT visible to: Other members (email, phone, DOB)

Payment data
 │
 └──▶ GoClubPro ledger (payment history, amounts)

league platform data (if connected)
 │
 └──▶ Fixture data only — no personal league platform data imported to GoClubPro

TOOLTIPS & HINTS

  • "Download My Data" is self-service — point members here first; it's faster than an admin export
  • Deletion is irreversible — if a member asks to be deleted, confirm twice; the action cannot be undone
  • MFA on all admin accounts — the most impactful single security action you can take as an admin
  • Former admins — change their role as soon as they leave the committee; don't wait for the next committee meeting

FAQ

Q: Do we need a Privacy Policy for our club? A: If your club has an ABN and handles personal information, yes — Australian Privacy Act likely applies. A simple one-page document covering what you collect, why, and how members can access it is sufficient for most amateur sports clubs.

Q: Can we share our member list with sponsors? A: No — not without explicit consent from each member. Member data collected for club purposes cannot be used for third-party marketing.

Q: A member wants us to delete them but they still owe match fees. What do we do? A: You can retain their payment records (anonymised) for accounting purposes. Their personal profile can be deleted. This is standard practice under both Australian Privacy Act and GDPR.

Q: Do we need to register with OAIC? A: Small sports clubs (under $3M turnover) are generally exempt from Australian Privacy Act registration requirements, but the Notifiable Data Breaches scheme still applies. Check oaic.gov.au for current thresholds.

Q: Is GoClubPro GDPR compliant? A: Contact GoClubPro platform support for the current Data Processing Agreement (DPA). For EU member clubs, you'll need a DPA in place.


COMMON MISTAKES

MistakeRiskPrevention
Sharing member export via WhatsApp/emailData breach — personal data outside secure systemNever export and share; use in-app communication tools
Not removing former admin accessFormer admin retains full data accessSame-day role change when admin steps down
Collecting DOB for all members "just in case"Data minimisation violationOnly collect what your club genuinely needs
Ignoring deletion requestsPrivacy Act breachTreat deletion requests as time-sensitive; log and respond within 30 days
Using same admin login for multiple peopleNo audit trail; breach liability is murkyEach admin has their own login; use MFA

SHORT ONBOARDING SCRIPT

"As Club Admin, you're the data controller for your members' personal information. Three rules: collect only what you need, secure it (MFA on your account today), and respond to member data requests within 30 days. If a member wants their data downloaded, point them to Profile → Download My Data. If they want deletion, contact platform support. If an admin leaves, change their role immediately. That covers 95% of your privacy obligations."


MICRO-TRAINING QUICK TIPS

  • MFA on all admin accounts — do this today
  • Former admin stepping down? Change their role today, not next month
  • Member wants their data? → Profile → Download My Data
  • Member wants deletion? → Platform support for full purge
  • Never share member lists via WhatsApp/email
  • Children's data: prefer Family Hub (parent account) over child accounts under 13

TROUBLESHOOTING

SymptomCheckAction
Member says their data is wrongProfile fieldsAdmin → edit member → correct the data; confirm in writing
Suspected breach: admin credentials sharedActive sessionsChange password → revoke all sessions → contact platform support
Member requests deletion but has unpaid feesPlatform supportAnonymise personal data; retain financial records
Can't find member's data for access requestAdmin Panel → Members → ExportExport member data; provide to member within 30 days

Training Module 33 | See also: 15 Security Settings · 08 Player Profile · 17 Central Command