The data left behind: players’ performance data and the rights to access and portability on transfer
A midfielder completes a transfer from one European top-flight club to another. Their medical records travel with them, their agent negotiates image rights, and their social media following is already public. But the most detailed record of their professional life may not move at all: thousands of hours of data generated by their own body during years of training and matches (including heart rate curves, GPS distances, sprint speeds, sleep and recovery metrics) stay behind, locked inside the selling club’s wearables platform and the servers of its technology vendor. This data can have significant practical value for our player: longitudinal workload and heart-rate records can help the new club calibrate training from day-one; historical injury data can help inform preventive programs; and a verified multi-season performance profile can strengthen a player's hand in contract negotiations.
Under the European Union’s (EU) General Data Protection Regulation[1] (GDPR), our player holds a legal right to access and/or take a meaningful part of that data with them, and a club that ignores the obligation faces real compliance exposure. Yet in the author’s experience, portability and access requests remain virtually unheard of in the European transfer market. Players rarely know the rights exist, and contracts are generally silent on how access and transfer mechanics work, despite the ballooning scale of data being captured.
This article examines the issues around football players accessing and transferring their training and other performance data when transferring clubs (although it is also applicable to other sports). It focuses on rights under the GDPR, which applies directly to all clubs and data vendors established within the EU (and can also reach non-EU controllers that monitor the behavior of individuals within the EU[2]). UK-based players and clubs should note that the UK GDPR[3] largely mirrors the EU GDPR, and so the rights examined below are also relevant (see Article 20[4]). However, such rights are not universal: Brazil’s LGPD offers a broadly analogous right,[5] but many jurisdictions, including most US states, do not.
Article Overview
- Performance data is personal data, and often special category data (health data)
- The right to take your data with you
- What a player can take with them - and what they cannot
- Contracts and federation rules have not caught up
- Who answers the request: club (data controller) or vendor (data processor)?
- Why this is becoming a genuine legal battleground
- What clubs, players and agents should be doing now
- Conclusion: a right that exists but is not yet widely used
To continue reading or watching login or register here
Already a member? Sign in
Get access to all of the expert analysis and commentary at LawInSport including articles, webinars, conference videos and podcast transcripts. Find out more here.
- Tags: Commercial | Contract | Data | Data Protection | EU | European Union | Football | GDPR | IP | UK GDPR | United Kingdom (UK)
Written by
Giulio Novellini
Giulio is a Partner at Portolano Cavallo and specializes in Privacy, Cyber Security and Data Protection, Internet and Ecommerce and new technologies (Artificial Intelligence, Blockchain and Smart Contracts). Throughout his professional career, Giulio has assisted national and international companies with litigation and compliance issues related to Personal Data Protection.He has acquired particular experience in advising clients in matters concerning websites, apps, online compliance relating to the use of cookies, the processing of data for marketing, Ecommerce, the foreign use of personal data and violations of personal data. Giulio supports clients by providing legal advice, privacy-by-design and privacy-by-default, evaluation of impact on privacy and audits. He also deals with the application of new technologies in Life Sciences-Healthcare, Fintech and Insurtech as well as their respective consequences on the processing of personal data.
