Player Data Rights Under UK GDPR: A Guide for Sports Clubs
Written by Oluwagbenga Onojobi
Who controls the performance and health data collected from professional athletes? Gbenga’s article explains the rights players have and the responsibilities clubs, analytics providers and wearable companies must meet.
Player Data Rights Under UK GDPR: A Guide for Sports Clubs
Pre-season is underway. Across football, rugby and other contact sports, clubs are strapping GPS vests and bicep-worn heart rate monitors onto players again.
As a result, an old question returns: who does player performance data belong to? The club? The analytics company? The wearable manufacturer? The betting firm that profits from it? Or the player it’s actually about?
The honest answer is nobody.
UK law does not treat personal data as property. UK GDPR does not give anyone ownership of personal data. Instead, it defines personal data as information that “relates to” an identified individual, not information that belongs to one. That distinction is deliberate.
However, players do have rights. They can ask how organisations use their data, access it, correct it, object to its use and, in some circumstances, have it deleted.
Meanwhile, the organisations handling that information act as controllers or processors. They have legal obligations, not property rights. That is exactly where the tension sits.
This responsibility does not sit with clubs alone. A club acts as a controller for the data it collects. However, analytics companies and wearable providers may also act as controllers if they use the data for their own purposes, such as refining products or benchmarking across clients.
Where a club and provider process the same data for a shared purpose, they become joint controllers under Article 26. They must agree who is responsible for each obligation and explain this clearly to players.
Therefore, clubs cannot simply assume that a provider is “processing on our behalf.” They need to check.
Why This Keeps Coming Up
Project Red Card has brought this issue into sharp focus.
Hundreds of current and former professional footballers have challenged gaming, betting and data companies over the unconsented use of their personal data.
Media coverage has reported potential exposure running into the hundreds of millions of pounds. Players are seeking to recover lost income going back six years, which is the statutory limit for such claims in the UK.
At the same time, players and their unions are making the same argument. PFA England chief executive has said players need to be “at the heart of these decisions around data use both on and off the pitch.”
FIFPRO’s own survey found that most professional footballers want access to their performance data to help them improve. However, they are also concerned about how organisations collect and use it. Many feel they do not have clear information about their rights.
Put simply, players are not against data collection. They want a say in it.
The Rights in Practice
Under UK GDPR, players have the right to know how organisations use their data. They can also make a subject access request to any organisation processing their information, not just their club.
In addition, they can ask an organisation to correct inaccurate data. They can object to processing under Article 21 and, in certain circumstances, request the deletion of their information.
FIFPRO developed its Charter of Player Data Rights with FIFA. The Charter sets out a near-identical list of rights.
Therefore, this is not just DPP’s position. It is the standard the game’s own governing bodies are pushing towards.
Where Clubs Get Exposed
Clubs usually have a lawful basis for collecting player data. However, the risk often appears further downstream.
Once a club licenses data to Football DataCo, shares it with an analytics provider or passes it to a commercial partner, each transfer needs its own lawful basis.
For example, a third-party provider may continue using player data after a contract ends. It may use the information for “product improvement” or include it in an aggregated dataset because nobody checked the exit terms.
As a result, the club may be unable to explain who holds the data or what they use it for. A player or union is entitled to challenge exactly this kind of gap.
Health data raises the stakes further. Heart rate, injury risk and recovery data are special category data under Article 9. This means organisations must meet a higher legal standard and will usually need a DPIA.
Euro 2024 showed how easily this can go wrong. A wearable manufacturer publicly posted one player’s heart rate and another player’s sleep data on social media. This attracted scrutiny over how far a provider’s control over player data should extend.
Finally, many technology providers operate outside the UK. Consequently, clubs may need restricted transfer mechanisms. This could include an International Data Transfer Agreement supported by a genuine Transfer Risk Assessment, not a box-ticking exercise.
This is live, active work across the sector right now.
How Data Protection People Can Help
At Data Protection People, we work on these issues now.
We review and negotiate data processing agreements with analytics providers, wearable manufacturers and commercial partners. Crucially, we cover what happens when the relationship ends, including the retention, deletion and return of data.
We also put International Data Transfer Agreements and Transfer Risk Assessments in place when data moves outside the UK.
In addition, we carry out DPIAs before organisations introduce new tracking technology, not after they have already rolled it out to the training ground.
Where a club is unsure whether a provider acts as a processor, an independent controller or a joint controller, we help establish the correct relationship. This is often one of the first things worth checking because it changes the contractual requirements and determines who is accountable if something goes wrong.
We currently advise football clubs on exactly this kind of work. With the new season starting and clubs signing fresh wearable and analytics contracts across the division, now is the point in the calendar when getting it right matters most.
Otherwise, the paperwork may remain buried until the next renewal comes around.
Nobody owns personal data. However, every player has rights over theirs. Clubs, providers and betting companies must be able to show that they respect those rights.
Sources
- ICO: Controllers, joint controllers and processors
- Computer Weekly: Footballers to take legal action over use of performance and tracking data
- FIFPRO: Charter of Player Data Rights launched for professional footballers
- FIFPRO: Maheta Molango, “Players need to be at the heart of decisions around their data”
- nss sports: What is the Whoop wristband and why do football players use it?