Governance & Legal Centre

Data Protection Impact Assessment (Public Summary)

Last Reviewed: 7 July 2026Version: 1.04 min read

Document Information

Document
Data Protection Impact Assessment (Public Summary)
Document ID
CLB-DPIA-001
Category
Governance
Version
1.0
Status
Approved
Effective Date
7 July 2026
Last Reviewed
7 July 2026
Next Review
7 July 2027
Review Cycle
Annual
Owner
Cluboom

Cluboom holds information about children, their families and the volunteers who run their clubs. Before and during the build of the platform, we assessed what that means in practice: what is collected, who can see it, what could go wrong and what is in place to stop it. This page is a public summary of that assessment. It deliberately describes measures at a high level and does not publish confidential security detail, internal procedures or internal risk ratings.

1. Purpose of this assessment

A Data Protection Impact Assessment (DPIA) is a structured way of identifying, assessing and minimising the privacy risks created by a processing activity. Cluboom has undertaken a DPIA because the platform handles information about children and, in some cases, health-related information such as injury and recovery records.

The assessment looks at what personal information the platform processes, why that processing is necessary, whether it is proportionate to the aim, and what could reasonably go wrong for the people whose information it is. Where a risk was identified, the assessment records what has been done to reduce it.

This document is a public summary of that work, published so that clubs, parents and members can understand how privacy has been considered. It is not legal advice, and it does not replace the assessment a club may need to carry out for its own activities.

2. Scope of the assessment

The assessment covers the processing of personal information relating to everyone who comes into contact with Cluboom:

  • Club administrators — the people responsible for setting up and running a club on the platform.
  • Team administrators — those managing a specific team, its squad and its fixtures.
  • Coaches — head coaches, assistant coaches and coaching staff working with a team.
  • Parents and guardians — those responding on behalf of a child and receiving club communications.
  • Players — including children, who access a limited player view of their own information.
  • Volunteers and support staff — those helping a club in other roles.
  • Website visitors — people browsing the public Cluboom site without an account.

It covers the Cluboom application, the public website and the supporting services used to operate them.

3. Processing activities assessed

The following activities were assessed. In each case the assessment asked what information is needed, who can see it and how long it is kept:

  • Account management — creating, inviting, verifying and removing accounts and player profiles.
  • Team management — squads, roles, positions and the structure of a club.
  • Attendance — recording who attended training and matches.
  • Availability — collecting and displaying responses for upcoming sessions and fixtures.
  • Fixtures — scheduling, venues, opposition and matchday information.
  • Match statistics — appearances, minutes and other performance records a club chooses to keep.
  • Training records — session plans, participation and coaching notes.
  • Fitness testing — optional physical benchmarking, where a club chooses to use it.
  • Notifications — email and push messages relating to club activity.
  • User support — handling questions and issues raised with the Cluboom support team.
  • Subscription management — billing and account status for paying clubs.

4. Privacy by design

Rather than treating privacy as something added at the end, Cluboom has been built around a set of principles that shape how features are designed:

  • Data minimisation — only the information a club genuinely needs to run a team is requested, and optional information stays optional.
  • Role-based permissions — what a person can see and do is determined by their role within a specific club and team.
  • Secure authentication — separate sign-in routes for adults and for players on shared family devices, with limits on repeated failed attempts.
  • Encryption — information is protected in transit and at rest by the platform’s hosting and database infrastructure.
  • Audit logging — significant actions are recorded so that unusual activity can be investigated.
  • Least privilege — accounts and internal services are granted the narrowest access that still allows them to function.
  • Annual governance review — this assessment and the wider governance suite are reviewed at least once a year.

5. Risks considered and mitigations

The table below sets out the main privacy risks identified during the assessment and the measures in place to reduce each of them. Mitigations are described at a high level; confidential implementation detail is not published.

  • Privacy risk

    Unauthorised access to club information

    Mitigation

    Every account is tied to a defined role, and each role only sees the information it needs to do its job. Parents see their own children, coaches see their own teams, and club-level information is restricted to club administrators. Access rules are enforced by the platform itself rather than by the interface alone.

  • Privacy risk

    Collecting more information than is needed

    Mitigation

    Cluboom asks for the minimum information required to run a team — squad details, availability, attendance and the records a club chooses to keep. Optional fields stay optional, and features that would require additional personal information are only added where there is a clear grassroots need.

  • Privacy risk

    Inaccurate or out-of-date personal information

    Mitigation

    Parents and members can review and correct their own details, and club and team administrators can amend records they are responsible for. Correction requests can also be made directly to Cluboom under the Data Subject Rights Policy.

  • Privacy risk

    Children's privacy

    Mitigation

    Player records are created and managed by adults within the club, parental consent sits with the club, and player access is deliberately limited. Contact details for children are not exposed to other members, and the platform avoids open, unmoderated communication between adults and children.

  • Privacy risk

    Keeping information for longer than necessary

    Mitigation

    Defined retention periods apply to each category of club information, with deletion and export routes when a club leaves the platform. Retention is set out publicly in the Data Retention Policy.

  • Privacy risk

    Account compromise on shared or family devices

    Mitigation

    Player access uses a short PIN tied to a specific device rather than an email inbox, sign-in attempts are rate limited, and staff accounts use standard authenticated sign-in. Access can be revoked by the club at any time.

  • Privacy risk

    Third-party processing

    Mitigation

    Only a small number of vetted providers are used, each under written data-processing terms, and each is listed publicly in the Subprocessor Register. New providers are assessed before they are introduced.

  • Privacy risk

    Security incidents

    Mitigation

    Cluboom maintains a defined breach response procedure covering identification, containment, assessment, notification, recovery and review, together with logging that supports investigation of unusual activity.

6. Assessment outcome

The overall assessment concludes that, with the implemented technical, organisational and governance measures, the remaining privacy risks are considered proportionate and manageable for the intended purposes of the platform.

No platform can claim to carry zero risk, and Cluboom does not make that claim. What the assessment records is that the identified risks have been understood, that measures are in place to reduce them, and that the residual risk is acceptable in the context of helping grassroots clubs run their teams.

Clubs remain the controller of their own members’ information. The decisions a club makes — who it gives administrator access to, what optional records it keeps and how it communicates with families — materially affect the real-world risk, and are outside Cluboom’s control.

7. Ongoing review

Privacy risks are reviewed:

  • following significant platform changes, such as a new feature that introduces a new category of personal information;
  • following changes to UK data protection legislation or regulatory guidance;
  • following any major security incident or personal data breach; and
  • during scheduled governance reviews, which take place at least annually.

Where a review changes the conclusions of this assessment, this public summary is updated and the version and review dates in the document information above are revised.

9. Feedback

Questions regarding this assessment, or feedback on how Cluboom handles privacy risk, should be directed to support@cluboom.co.uk.

If you believe your information has been handled incorrectly, you can also raise the matter with your club, or with the Information Commissioner’s Office.

Cluboom maintains a single governance register. Every document in the register is published and publicly available. Browse the full library in the Governance Centre.

Questions about this document? Contact us at support@cluboom.co.uk.

Cluboom is a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079), 24 Brynaeron, Dunvant, Swansea, United Kingdom, SA2 7UX.

  • Built in the UK
  • Designed with privacy in mind
  • Secure cloud infrastructure
  • Designed for grassroots sport