CompteamDocumentationData protection guide for GDPR

GDPR data protection

Data protection guide for GDPR

This guide explains the operating model for European branches using Compteam. It is product guidance, not legal advice; your branch remains responsible for its own privacy notice, lawful bases, retention periods, and local legal review.

Map the roles first

Your branch normally acts as the controller for athlete, guardian, attendance, membership, billing, and communication data because you decide why that data is collected and how it is used. Compteam acts as a processor for the platform services it provides under the Data Processing Agreement.

How Compteam supports this

Compteam makes the controller/processor split explicit through the DPA, branch-scoped administration, audit trails, and product flows that process athlete data on your branch instructions rather than for unrelated purposes.

  • Keep your branch legal name and contact details current.
  • Accept and keep the DPA with your vendor records.
  • Use the platform only for branch operations and documented purposes.

Use a clear privacy notice

Before athletes or guardians register, explain what personal data you collect, why you need it, the lawful basis, who receives it, how long it is kept, and how people can exercise their GDPR rights.

How Compteam supports this

Compteam gives you the operational map behind that notice: registration, plans, attendance, billing, payments, guardian consent, public booking, CRM follow-up, and AI-assisted workflows are separated enough that you can describe them clearly.

  • Mention membership administration, attendance, billing, payments, communication, competitions, and guardian consent where relevant.
  • Keep local retention rules for accounting and club records separate from marketing retention.
  • Review the notice when you add a new workflow or provider.

Keep evidence in the system

Compteam keeps operational records that help answer GDPR questions: registration acceptance, consent records, guardian approvals, invoices, payment references, exports, erasure actions, and audit trails.

How Compteam supports this

Compteam records who accepted terms, which guardian approved a child, which invoices and payment references exist, and which admin actions changed sensitive records, so you can evidence decisions without building a separate compliance log.

  • Avoid storing sensitive health notes in free-text fields unless you have a separate lawful basis and explicit process.
  • Use role-based access instead of shared admin accounts.
  • Document unusual manual exports outside the platform.

Handle member rights consistently

Members can ask for access, correction, export, restriction, objection, and erasure. The branch is responsible for the decision, while Compteam provides tools and processor assistance for common requests.

How Compteam supports this

Compteam supports profile edits, admin-side data export, consent-history review, and guarded erasure flows that preserve records you may still need for invoices, accounting, disputes, or legal retention.

  • Verify the requester before exporting or erasing data.
  • Do not erase invoice or accounting records before retention duties allow it.
  • Record what you did and when, especially for refused or partially fulfilled requests.

Control transfers and processors

Review the DPA and listed subprocessors for hosting, payments, email, and AI-assisted workflows. Where data leaves the EU/EEA, make sure the transfer mechanism and safeguards are documented.

How Compteam supports this

Compteam centralises key subprocessors in the DPA, keeps payment-provider configuration explicit, avoids forcing Stripe for SEPA-native branches, and separates optional integrations so you can decide which external systems your branch connects.

  • Use Stripe or SEPA according to your branch setup and local payment needs.
  • Limit exports to staff with a real operational need.
  • Review integrations before connecting external CRM or communication tools.

Prepare for security incidents

If a breach affects personal data, GDPR timelines can be short. Keep owner contact details current, restrict admin access, and know how to gather the facts needed for a supervisory-authority or member notice.

How Compteam supports this

Compteam reduces incident risk with branch-scoped access, role controls, encrypted sensitive fields where applicable, hosted backups, and support escalation paths that help identify affected records if something suspicious happens.

  • Remove staff access when roles change.
  • Use strong account security for admins.
  • Escalate suspicious access, unintended exports, or payment-data exposure immediately.

Official GDPR references