This article covers the three things you need to set up in ClubRight to support your club's GDPR compliance: your Terms and Conditions, your Privacy Policy, and your member consent options. It also covers how ClubRight helps you handle ongoing data requests from members.
What is GDPR?
The General Data Protection Regulation (GDPR) is the law that governs how organisations collect, store, and use personal data. If your club holds member information, GDPR applies to you. The core requirements are simple to state: collect only the data you need, be transparent about how you use it, get clear consent for marketing, and give members access to or deletion of their data when they ask.
How ClubRight supports your GDPR compliance
ClubRight cannot guarantee GDPR compliance on its own, no software platform can, but it gives you the tools to make compliance practical:
A secure central database for all member personal data, accessible only to approved staff
Granular consent options that you define, captured at sign-up and editable by members at any time
A self-service member area where members can view their data, update incorrect information, and change their marketing preferences
Data export and deletion tools in each member's profile, for handling subject access and erasure requests
An audit trail of staff access to member records
Terms and Privacy Policy pages presented to members at sign-up, requiring acceptance before they can continue
Setting up your club for GDPR
There are three things to set up in ClubRight to support your GDPR obligations.
Your Terms and Conditions and Privacy Policy
Members must read and accept your Terms and Conditions and your Privacy Policy when they sign up. Both pages are edited the same way. See Setting up your Terms, Privacy Policy, and other member area pages for the steps.
Your consent options
Consent options are the tick-box options shown to members during registration, covering marketing consent, club rules, photography permissions, and similar. They control which members you can send marketing communications to. For the setup steps, see Consent Options.
Important: GDPR requires consent to be granular. Each distinct purpose needs its own option. Email marketing, SMS marketing, and photography consent should each be separate tick-boxes, not bundled together. Only ask for consent for activities you actually do: if you don't send newsletters, you don't need a newsletter consent option.
Handling member data requests
Under GDPR, members can ask for a copy of the personal data you hold on them, or for it to be deleted. Both actions can be carried out from a member's profile in ClubRight. For the steps, see Customer data deletion requests (GDPR).
Members can also manage their own marketing preferences at any time through the member area, which is the simplest and most up-to-date way for them to opt in or out.
A note on legal advice
ClubRight is not a legal advisor. The information in this article is intended to help you set up your account in a way that supports GDPR compliance. Your Privacy Policy, your Terms and Conditions, and your wider data handling practices should be reviewed with a qualified legal professional. ClubRight Limited accepts no responsibility for the accuracy of legal interpretation in your specific circumstances.
Useful external resources
