Privacy and GDPR
Can you record audio at children's training? GDPR for clubs
· 4 min read
The question comes up the moment a club considers using audio, video or AI tools in the youth section: are we even allowed to?
The short answer: yes, but not casually, and not without having made some decisions.
What follows is a practical walkthrough, not legal advice. If you are rolling this out across a whole youth section, have a lawyer look at your specific setup. It costs less than doing it twice.
What makes it sensitive
Three things at once:
- It is personal data. A recording concerning a named player is personal data, even if the only voice on it is the coach's.
- It involves children. Children have heightened protection under data protection rules.
- It contains assessments. An assessment of a child's performance is a different thing from a team sheet.
The combination means you cannot get away with "it is only our own notes".
The five things a club has to decide
1. The lawful basis
You need a lawful basis to process the data. For a coach's own observations, legitimate interests can be defensible. For anything tied to a named minor and shared with others, consent is the safe choice.
Consent has to be informed, documented, and possible to withdraw. A tick box at registration that nobody remembers is not consent.
2. Parental consent
Who can consent, and at what age, varies by country — under the GDPR the age for information-society services sits somewhere between thirteen and sixteen depending on the member state, and the UK has its own equivalent. Check the rule where your club actually is.
In practice most clubs sidestep the question by taking parental consent for the whole youth section regardless of age. That is the conservative choice, and it is rarely the wrong one.
3. People other than the players
A phone recording on a touchline also records parents, opponents, referees and other people's children.
You cannot avoid that entirely. You can limit the damage: be clear about the purpose, keep the audio for a short time, and never pass raw recordings on to anyone.
4. How long you keep it
This is the single decision that reduces risk the most.
Raw audio rarely needs to exist once it has been processed. A short retention period — days, not months — means a breach hits something that no longer exists. Text and summaries can live longer, because they contain less.
5. Where the data sits
Know which suppliers process the data and where, and have a data processing agreement with each of them. That includes the sub-processors: speech recognition, the AI model, email, hosting.
Ask specifically. "Our data is in the EU" is a claim about storage that often does not cover the third parties doing the processing, and it is worth pinning down which is which.
What gets overlooked most often
The right of access and erasure. Sooner or later a parent will ring and ask for everything you hold on their child — or ask for it to be deleted. If that requires somebody to dig through a database by hand, it will not be done properly. Build the capability in from the start.
The human in the middle. This is as much safeguarding as data protection. Coaches say things in the heat of a match they would never write to a child. No automation should send anything to a player without an adult having read it first. We have written more about that side of it in feedback culture in youth sport.
A reasonable minimum setup
- Consent per player, obtained from the parent, withdrawable
- Raw audio deleted automatically after a short period
- Known processors, with data processing agreements in place
- No automatic sending to players — the coach reads it first
- Export and deletion per player, as an ordinary feature
Get that in place and you are further ahead than most clubs already sharing photographs of children in closed Facebook groups without having thought about it at all.