A Practical GDPR Data Audit Checklist for Running Clubs

Written by Gavin Pedley

Founder of Running Club Check-In and committee member of Carn Runners. Drawing on real-world experience managing a UK running club and developing software used by running club committees, Gavin shares practical advice to help clubs grow, engage members and reduce committee workload.

Create your free club site
Running club committee volunteers completing a GDPR data audit checklist on a laptop

Running clubs collect personal information in more places than committees often realise. Membership forms, attendance registers, guest-runner details, emergency contacts, incident reports, welfare notes, payment records and volunteer email accounts can all contain member data.

A practical data audit brings those records into view. It helps the committee identify what the club holds, why it is needed, who can access it and what should be updated, restricted, anonymised or deleted.

This does not need to become an expensive compliance exercise. For most volunteer-run clubs, the best starting point is a focused annual review, repeated when committee roles change or the club replaces an important system.

1. Give the audit a clear owner and scope

Choose one committee member to coordinate the audit, but do not expect them to know where everything is stored. The membership secretary, treasurer, welfare officer, run coordinators and communications volunteers may each hold different records.

Set a manageable scope before starting. A useful first audit should answer five questions:

  • What personal data does the club hold?
  • Where is it stored?
  • Why does the club still need it?
  • Who can see or change it?
  • When will it be reviewed or removed?

Record the answers in one simple audit document. A spreadsheet is sufficient if access is appropriately controlled and the document does not reproduce all the personal information being audited.

2. Find every place where club data is kept

Begin with the club’s main membership system, then look beyond it. Personal data often becomes scattered because volunteers create working copies to solve an immediate problem.

Check the following locations:

  • membership databases and renewal spreadsheets;
  • paper membership and guest forms;
  • attendance registers and session reports;
  • shared drives and online forms;
  • club and personal email accounts;
  • committee members’ phones, laptops and downloads folders;
  • messaging groups used for club administration;
  • payment and subscription records;
  • emergency contact lists;
  • incident, accident and welfare records; and
  • website, mailing-list and photography records.

The purpose is not to copy everything into another spreadsheet. Note the type of record, its location, its owner and whether another version exists. That will reveal duplicates and unofficial copies without creating an additional data risk.

3. Ask why each type of information is needed

The Information Commissioner’s Office explains that the data minimisation principle requires personal information to be adequate, relevant and limited to what is necessary for its purpose.

For every field or document, ask: “What do we use this for?” A clear answer might be checking runners into a session, administering membership, contacting somebody after an incident or managing an unresolved welfare concern.

“It might be useful one day” is not a strong purpose. If nobody can explain why the club collects a date of birth, medical history, workplace, second telephone number or free-text note, reconsider whether it should be requested or retained.

This review is especially useful when online forms have grown over several years. Remove questions that no longer support a genuine club process rather than continuing to collect information by habit.

4. Check accuracy and remove competing copies

Old information can be as problematic as missing information. During the audit, look for former addresses, outdated membership statuses and obsolete emergency contacts.

Our guide to keeping running club emergency contact details up to date provides a fuller review process for these particularly important records.

Where several versions of a list exist, decide which one is authoritative. Update the main record and safely dispose of unnecessary working copies. A central system will not improve data management if volunteers continue consulting old spreadsheets saved to personal devices.

5. Review access by role, not convenience

Not every committee member needs access to every record. A run-night coordinator may need attendance and emergency information without requiring access to private welfare notes. A communications volunteer may need an email distribution function but not the full membership database.

List who currently has access to each system or folder, including:

  • committee members;
  • run leaders and coaches;
  • temporary volunteers;
  • former officers whose accounts remain active; and
  • external providers or advisers.

Remove access that is no longer required and document who can authorise future changes. Include this check within every running club committee handover so permissions do not remain active after somebody leaves a role.

Running Club Check-In’s GDPR and data protection features are designed to help committees move away from scattered forms and records while keeping important club information organised.

6. Create a retention schedule the club can actually follow

The UK GDPR does not give one fixed retention period for every type of club record. The ICO’s storage limitation guidance says organisations must decide and justify how long data is needed for its stated purpose.

A short retention schedule is more useful than a detailed policy nobody reviews. Start with the following framework:

Record Review trigger Question to answer
Current member details Renewal or resignation Which details are still needed after membership ends?
Emergency contacts Renewal, reported change or departure Is the information current and still required for participation?
Guest and trial-runner records End of the trial or joining process Does the club still have a defined reason to identify this person?
Attendance history At the agreed retention review Are identifiable records still needed, or would anonymous totals meet the reporting purpose?
Incident records After follow-up and at scheduled intervals Do insurer, governing-body, legal or operational requirements justify continued retention?
Welfare records When the concern closes and at scheduled intervals What information remains necessary, and who still needs access?
Volunteer permissions Immediately after a role change Should the account be removed, restricted or transferred?

For financial, incident or other records that may be subject to specific requirements, check the club’s obligations with its governing body, insurer, accountant or an appropriate adviser. Do not select a period simply because another club uses it.

7. Give sensitive records a closer review

Information that reveals somebody’s physical or mental health can be special category data. This may include parts of an incident report, welfare record or membership note, even if the club does not consider itself to be keeping formal medical records.

The ICO’s special category data guidance explains that organisations need both a lawful basis and an additional condition for processing this information.

During the audit, check whether sensitive details are:

  • necessary for a clearly stated purpose;
  • stored in the correct record rather than a general notes field;
  • visible only to authorised people;
  • written factually and without irrelevant opinion;
  • covered by the club’s privacy information; and
  • subject to a documented review or follow-up date.

Our guides to recording accidents and incidents and handling a running club welfare concern explain how to keep these processes focused and proportionate.

8. Make sure the privacy notice matches reality

A privacy notice copied from an old template may not describe the club’s current practices. Compare it with the audit findings.

It should accurately explain the types of data collected, the purposes and lawful bases, who receives the information and how long it is kept. ICO guidance says that where a fixed retention period is not available, organisations should explain the criteria used to decide it.

Update the notice if the club has introduced online guest registration, welfare records, a new mailing system or another significant process that is not currently described.

9. Agree how the club will handle deletion requests

Members can ask for personal information to be erased verbally or in writing. The right to erasure is not absolute, so a request does not always mean deleting every record immediately. The club may still have a justified or legally necessary reason to retain particular information.

Nominate somebody to receive requests, record the date, identify the relevant systems and coordinate the response. Current ICO guidance says organisations generally have one month to respond, making it important that ordinary volunteers recognise a request and pass it to the right person promptly.

10. Finish with assigned actions

An audit is only useful if the findings lead to changes. Finish the meeting with a short action list covering:

  • records to correct;
  • duplicate files to remove;
  • permissions to withdraw;
  • retention decisions requiring advice;
  • privacy information to update;
  • systems or forms to simplify;
  • a named owner for each action; and
  • the date of the next review.

Store the completed audit with the club’s committee records, but avoid including unnecessary copies of the personal information itself.

A quick annual data-audit checklist

  • We know which systems, forms and devices contain club data.
  • Every type of information has a defined purpose.
  • Unnecessary form fields and free-text notes have been removed.
  • Member and emergency details have an accuracy-check process.
  • Old spreadsheets, downloads and paper lists have been reviewed.
  • Former volunteers no longer have access.
  • Incident and welfare records receive a separate sensitive-data review.
  • Our retention schedule covers members, guests, attendance and sensitive records.
  • Our privacy notice reflects what the club actually does.
  • Volunteers know where to pass access, correction or deletion requests.
  • Every audit action has an owner and deadline.

Bring scattered club records into one place

Running Club Check-In helps UK running clubs organise membership, attendance, guest, emergency contact, welfare and incident records in one connected platform. This can make access reviews, committee handovers and routine data checks more manageable than relying on separate paper forms and volunteer spreadsheets.

Create a free club site to explore the system without providing payment details, or review the complete Running Club Check-In feature list.

Want to run your club with less admin?

Running Club Check-In helps clubs manage attendance, members, guests, welfare, incidents and reports in one simple platform.

More running club resources