Gomersal & Cleckheaton Football Club (“the Club”, “we”, “our”, “us”) is committed to protecting personal data and processing it responsibly, transparently, and in compliance with the UK General Data Protection Regulation (UK GDPR).
This policy applies to all members, officers, committee members, volunteers, contractors, coaches, managers, and anyone else acting on behalf of the Club who may have access to or process personal data in any capacity.
Purpose
This policy explains how the Club manages personal data lawfully and fairly, and the responsibilities of those handling it on behalf of the Club. It supports our aims to:
Defintions
Personal Data: Any information that can identify an individual (e.g. name, contact details)
Processing: Anything done with personal data (collecting, storing, sharing, deleting, etc.)
Data Subject: The person whose data is being processed
Data Controller: The Club (who decides how and why personal data is processed)
Data Processor: Anyone acting on behalf of the Club (e.g. volunteers or coaches)
(See the ICO glossary for more detail: ICO – Key Definitions)
What Data We Handle
We process personal data relating to:
Data is collected via registration forms, communication, event attendance, or third-party systems (e.g. Whole Game System).
Legal Basis
Our legal bases for processing data include:
If you do not provide the required personal data, you may be unable to fulfil your role or participate in Club activities.
Responsibilities
The Club Management Committee is responsible for overseeing compliance. Questions or concerns should be directed to the Club Secretary
Data Retention & Security
Breach or Concern
Any potential data breach must be reported to the Club Secretary immediately. The Club will follow appropriate procedures to investigate, report, and manage the situation.
This policy will be reviewed annually or sooner if required by legislation or Club operations. Last reviewed: April 2025