How the club handles personal data internally under UK GDPR: principles, lawful bases, retention, security and photography consent. Adopted May 2026.
South London Topcats – Brixton Topcats Basketball Club is committed to protecting the personal data of all its members, volunteers, coaches, and contacts. This policy sets out how the Club collects, uses, stores, and protects personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Following the UK's departure from the European Union, the EU GDPR was retained and adapted into UK law as the UK GDPR, which came into effect on 1 January 2021. The Data Protection Act 2018 supplements the UK GDPR. This policy reflects these current legislative requirements.
The Club acts as a Data Controller in respect of personal data it holds. The Club is not required to register with the Information Commissioner's Office (ICO) unless it processes data in ways that trigger a registration requirement. The Club will keep this under review.
The Club must ensure that all personal data is:
The Club will identify and document a lawful basis for each type of personal data processing. The lawful bases the Club may rely on include:
Some personal data requires extra protection. "Special category" data includes information about health, disability, ethnicity, religion, or sexual orientation. The Club will only process special category data where strictly necessary (e.g., medical information for junior safeguarding purposes) and with a clear lawful basis and additional safeguard.
The Club may collect and process the following categories of personal data:
The Club will not retain personal data for longer than necessary. General retention guidelines are:
Under UK GDPR, individuals have the following rights in respect of their personal data:
Requests should be submitted in writing to the Club Chair or Secretary and will be responded to within one calendar month.
The Club will implement appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, or disclosure. This includes:
The Club may share personal data with third parties only where necessary and lawful, including:
The Club will not sell or share personal data for commercial marketing purposes.
The Club will obtain separate written consent before photographing or filming junior members. Adult members should also be informed of any photography taking place at Club events. Consent may be withdrawn at any time. Photographs or videos of children will not be shared on social media without specific parental consent.
The Club CEO/Chair has overall responsibility for data protection compliance. All Club volunteers and committee members who handle personal data must comply with this policy. Breaches will be taken seriously and may result in disciplinary action.
If you have a concern about how the Club is handling your personal data, please contact the Club CEO or Chair in the first instance. You also have the right to make a complaint to the Information Commissioner's Office (ICO) at www.ico.org.uk or call 0303 123 1113.
This policy will be reviewed annually, or earlier where required by changes in legislation or Club practice.
See also the club's Privacy Policy, which explains how personal data is handled for members and website visitors.