GDPR & DPA 2018

    GDPR-NATIVE FOR IRISH CLUBS

    ClubRovia is built around the General Data Protection Regulation (EU 2016/679) and the Irish Data Protection Act 2018. Data residency in the EU, granular consent, one-click Subject Access Requests and Row-Level Security at the database — engineered for volunteer committees, not enterprise IT teams.

    Illustration of the Clubrovia platform on a laptopPlatform illustration

    What 'GDPR-native' actually means

    EU Data Residency

    All member data is stored in the European Union. No cross-Atlantic transfers, no Privacy Shield grey areas.

    Row-Level Security

    Each club's data is isolated at the database row level. Even an internal query can't reach across club boundaries.

    One-Click SARs

    Respond to a Subject Access Request in minutes. Generates a complete, structured PDF of every record on the member.

    Granular Consent

    Separate, versioned consent for medical info, photography, marketing and third-party sharing. Withdrawable any time.

    Right to Erasure

    Hard-delete member records on request, with cryptographic confirmation. Financial records are anonymised where retention is legally required.

    Sub-processor Register

    Public, versioned list of every sub-processor (Stripe, hosting, email). DPAs available on request.

    Your committee's GDPR checklist — pre-built

    • Privacy notice templates for members & parents
    • Lawful basis recorded per data field
    • Data Processing Agreement (DPA) ready to sign
    • Sub-processor register with versioning
    • Breach notification workflow (72-hour rule)
    • Retention schedule per data category
    • DSAR portal for members
    • Auditable consent history per member

    Frequently Asked

    Is ClubRovia a data controller or processor?▾

    ClubRovia is a data processor. Your club is the data controller and remains responsible for your members' data — ClubRovia provides the tools to do that properly.

    Where is our data stored?▾

    All personal data is stored on EU infrastructure with encryption at rest and in transit. No data is transferred outside the European Economic Area.

    How do we respond to a Subject Access Request?▾

    From the member's record, click "Generate SAR". The system produces a structured PDF of every piece of personal data we hold on that member, ready to send within the statutory 30-day window.

    What about children's data?▾

    Children's data is gated through the multi-guardian consent model. Communication to minors is automatically shadowed to the Designated Liaison Person — see our Safeguarding page.

    Can we get a Data Processing Agreement?▾

    Yes. A standard DPA is available on request and is signed automatically when you upgrade to White Label.

    Ready to run your club the right way?

    No setup fees. No monthly fees. Service fees apply when payments are collected.