Member Records for Clubs: Storing Contact, Medical and Consent Details
Information about a member's health is special category data under Article 9 of the UK GDPR, which means a junior football club holding one child's asthma plan is under the same obligation as a hospital holding the same fact. Most clubs meet that obligation with a ring binder in the office and a spreadsheet somebody shared by link in 2023, and the problem is rarely the law. It is that the coach standing on the touchline at 10:15 on a Sunday cannot get to the information they need.
TL;DR
Collect four things and stop: who the member is, two emergency contacts, the health facts that change what a coach does in the room, and dated permissions for photography, travel and first aid. Health information is special category data under the UK GDPR, so it needs an Article 9 condition and a real access boundary, which a link-shared spreadsheet does not give you. Put the record where the member or parent updates their own line, where the coach on duty can read it from a phone in ten seconds, and where the club can see at a glance who has not filled it in. Then give it a deletion date, because the record you no longer need is the one most likely to leak. Bitir holds this as a per-member profile with role-limited access, collects permissions as deadline polls, and shows the coach who is still missing.
What does a club actually need to hold about a member?
Less than most clubs collect, and more reliably.
Start from the question a coach asks in an emergency. Who do I ring, and what do I need to know before the ambulance arrives? Everything that does not answer one of those two questions is optional, and optional data is a liability rather than an asset.
That gives four categories. Identity and group, so you know which squad the member trains with and who their coach is. Two emergency contacts with the relationship stated, because "Mum" on its own is useless when the member is 34 and lives alone. The health facts that change a session: asthma, anaphylaxis, epilepsy, diabetes, a current injury, medication kept on site. And a dated permission record covering photography, away travel, and consent to administer first aid.
Notice what is missing. There is no full medical history, no GP address, no free-text box asking parents to describe their child's needs in their own words. Some clubs collect all three out of a general sense that more is safer. The opposite is true: a record that contains a paragraph of narrative about a child's mental health is a record that now needs stricter handling, and no coach will read it at the moment it matters.
The Information Commissioner's Office puts data minimisation near the front of its guidance for small organisations for exactly this reason. Collect what you will use. Justify anything else or drop it.
Why is a shared spreadsheet the wrong place for medical details?
Three reasons, and none of them are theoretical.
The first is access. A spreadsheet shared by link is readable by anyone who has ever been sent that link, including the assistant coach who left last spring and the parent who was helping with the tour in 2024. There is no role boundary, no expiry, and no log of who opened it. Access control that depends on people not forwarding a URL is not access control.
The second is that copies multiply. Somebody downloads the sheet before an away fixture so it works without signal. That copy now lives on a personal laptop, outside anything the club can see or delete, and it is the version that gets emailed to the next volunteer.
The third is staleness, which is the one that actually hurts people. Nobody opens a club spreadsheet to correct their own mobile number. Emergency contacts drift out of date at a rate clubs consistently underestimate, and the moment you find out is the moment you are ringing a disconnected number from a treatment room. A record that members update themselves stays current for the same reason: it is their number, and they are the only person who knows it changed.
Under the UK GDPR, health information sits in the Article 9 category, and Schedule 1 of the Data Protection Act 2018 sets out the conditions that let an organisation hold it. This does not mean a club needs a compliance officer. It means the club should be able to say, in one sentence, why it holds health data and who can see it, and a spreadsheet shared by link makes the second half of that sentence impossible to say truthfully.
How do you collect all this without chasing 140 families?
Cranleigh Otters Swim School in Guildford is a useful worked example: 140 swimmers across 11 squads, nine coaches, run by a head coach called Hannah Bickerstaff who works two evenings and Saturday mornings. Her old system was a paper form at joining, a folder in the office, and a WhatsApp message every September asking parents to let her know if anything had changed. Roughly a dozen replied.
What she does now takes eleven fields and one evening a year to run.
- The form is part of joining, not a separate task. A new swimmer's account is not active until the eleven fields are complete. Nobody is chased, because nobody starts without it.
- Members and parents own their own line. Changed your number, moved house, new inhaler? The family edits it. Hannah is not a data entry clerk.
- Health facts are structured, not narrative. Condition, what a coach should do, medication kept on site, and where it is. Four short answers beat a paragraph nobody reads at speed.
- Permissions are annual deadline polls. Every September, photography, away travel and first aid consent go out as three questions with a cut-off date. The screen shows who has not answered, so the reminder goes to eleven families rather than 140.
- The squad coach sees their own squad. The under-11 coach reads the under-11 details on a phone, poolside. The committee member who runs the raffle sees nothing.
- Everything carries a date. A consent given in September 2024 and never renewed shows as expired rather than quietly counting as a yes.
The first September took Hannah about two hours, most of it deciding what not to ask for. The second September took twenty minutes.
In Bitir the same shape is a per-member profile with role-limited visibility, a set of polls with deadlines for the annual permissions, and a view of who is still missing. The mechanics are ordinary. What changes is that the missing eleven are visible in the first week of the season rather than discovered at a gala in March.
How long should a club keep member records?
Give every category a deletion date and write it in the privacy notice. UK law sets no fixed retention periods, which clubs often read as permission to keep everything forever. It is the opposite: the storage limitation principle means you have to decide, and be able to explain the decision.
A defensible default for a junior club looks like this. Contact and health details go within a season of the member leaving, because they have no purpose after that. Attendance, grading and award records stay as long as the governing body needs them, which for most sports is a fixed number of years. Anything connected to a safeguarding concern comes out of the ordinary rule entirely and follows the retention period set by the designated safeguarding lead, in line with the club's safeguarding communication policy.
We would go further than most club handbooks and argue for deleting former members' health data at the end of the season rather than keeping it "in case they come back". A returning swimmer takes ninety seconds to re-enter an inhaler. A three-year-old asthma record that nobody has checked is worse than no record, because a coach will trust it.
Who should be able to see what?
Access follows the role, not the length of service. That principle is the whole of it, and it is the one clubs find socially awkward, because the long-standing committee member who has done the fixtures since 2011 is precisely the person who expects to see everything.
- Coach on duty: full health and emergency contact details for the members they are responsible for that day. Reachable from a phone, not a cupboard.
- Head coach or welfare officer: the whole club, plus the permission status view.
- Assistant and volunteer helpers: attendance and session logistics. No contact details, no health data.
- Committee and administrators: membership status and fees. Not medical information, which has nothing to do with the job.
- Parents: their own child's record, including the ability to correct it, which is also how the club satisfies a rectification request without any process at all.
The same logic applies to adult groups, where clubs are often laxer because the members are grown-ups. A running club that publishes a member list with mobile numbers to everyone in the club has made the same mistake with a friendlier face. Our guide to member privacy in group programmes covers the adult version of this in more detail, and the joining agreement is where the club tells people what it holds before it holds it.
Questions club administrators ask
What member information should a club actually collect?
Four things, and not much else. Who the member is and which group they train with. Two emergency contacts with a stated relationship. The health information that changes what a coach does in the room, such as asthma, allergies, epilepsy, diabetes or a current injury, plus any medication kept on site. And a dated record of the permissions the club relies on, typically photography, away travel and first aid. A full medical history is not required to run a session and it makes the record harder to hold safely.
Is medical information about a club member special category data?
Yes. Under the UK GDPR, information about someone's health is special category data under Article 9, which means the club needs a lawful basis and a separate Article 9 condition to hold it. Schedule 1 of the Data Protection Act 2018 sets out those conditions, and the Information Commissioner's Office expects small organisations to record which one they are relying on. In practice a short line in the club's privacy notice covers it, but the point is that health data cannot sit in the same casual place as a fixture list.
Can a club keep emergency contacts in a shared spreadsheet?
It can, and this is where most clubs come unstuck. A spreadsheet shared by link has no access control worth the name, no record of who opened it, and no way to stop a copy being downloaded to a personal laptop. It also goes stale, because nobody edits a spreadsheet to correct their own phone number. Hold the record where the member or parent can update their own line, where access follows the role, and where the club can see what is missing.
How long should a club keep member records after someone leaves?
Long enough for the reason you collected it, and no longer. UK data protection law sets no fixed period, so the club decides and writes it down. A workable default for a junior club is to delete contact and health details within a season of the member leaving, keep attendance and award records for as long as the governing body requires, and treat anything connected to a safeguarding matter under a separate retention rule set by the designated safeguarding lead.
Who at a club should be able to see a member's medical details?
Whoever is responsible for that member on the day, and nobody else by default. The coach taking the squad needs to know that a swimmer carries an inhaler. The volunteer who runs the raffle does not need the member list at all. Give access by role rather than by seniority, and make sure the person on the poolside or the touchline can reach the information from a phone in the time it takes to walk to the office, because a folder in a locked cupboard is not a safety measure.
Hold your member records where the coach on duty can reach them
A per-member profile with role-limited access, emergency contacts and health facts the family keeps current, annual permissions collected as deadline polls, and one screen showing who is still missing.
Set Up Your Club