Skip to main content Skip to site footer

EFL Privacy Notice

The EFL is committed to protecting the privacy and security of your personal data. ‘Personal data’ is essentially information from which an individual person can be identified.

This privacy notice (“Notice”) describes how we collect and use personal information about you in a range of circumstances. You should read this Notice together with any other privacy information which may be provided on the specific occasions when personal data about you is collected by the EFL. This Notice supplements any other notices and is not intended to override them.

The Notice is set out in sections so you can click through to the specific areas you want to know.  The detail is in each section, along with a quick read summary where relevant:

In brief… the EFL is the organiser of various football competitions in the United Kingdom, and has 72 member clubs. For further details about the EFL and its group companies, click here.  Details of our Data Protection Officer can be found below.

 

The EFL organises and administers the Sky Bet EFL, Carabao Cup and Checkatrade Trophy along with certain other competitions and events from time to time. Click here for company information about the EFL and other companies in the EFL group. References to “we”, “us” and “our” in this Notice are all references to the EFL.

Where personal data is collected for the purposes set out in this Notice, the EFL will usually be a ‘data controller’ under data protection law applicable in the EU (“Data Protection Law”). That means we decide the purposes and manner in which your data is used – as set out in this Notice. Sometimes however, we may only be using your personal information as directed by other organisations in which case that organisation will tell you why and how your data is used.

Contact details for the EFL’s Data Protection Officer can be found in the “Who can you contact for further details?” section below.

 

In brief… personal data collected by the EFL group where another specific privacy notice applies. For example (a) the EFL Website Privacy Policy  applies to personal data collected through the EFL official website (b) our Candidate Privacy Policy applies if you are applying for work with us and (c) our Regulated Persons Privacy Policy applies if you are a player or regulated person under the EFL Rules and Regulations, and we are processing your personal data as part of our regulatory function.

 

This Notice does not apply where another privacy notice or policy of ours applies to your specific circumstances. This may include, for example, in the circumstances set out in this section.

Online

This Notice does NOT apply in relation to any data collected through the EFL official website or associated EFL platforms, in which case the EFL Website Privacy Policy will apply.

Job Applicants & Staff

This Notice does NOT apply where you are applying for work with us, in which case the Candidate Privacy Notice will apply. A separate Staff Privacy Notice will apply, if you are successful.

Players & Regulated Persons

This Notice does NOT apply where we process your personal data as part of our regulatory function if you are a football player, player family member, agent, manager, trialist, coach, scout, or member of staff for one of the seventy two member Clubs of the EFL. Where we are processing your personal data as part of our regulatory function the EFL Regulated Persons Privacy Policy will apply.

In brief…information which identifies you, contact information, financial or transactional information, data which builds a profile about you, and/or information about your communications with us. We use safeguards for any collection of children’s data.

We may collect, use, store and transfer different kinds of personal data about you. For the purpose of this Notice we have grouped these together as follows:

  • Identity Data such as your name(s), title, date of birth, gender, username, ID number or other similar identifier, your employer or education provider, supporter or similar Club number, job or role title, photographs and imagery (including CCTV if you visit our premises) and marital status (where relevant).
  • Contact Data such as your personal and/or work address(es), billing address (where different), email address(es), preferred language, telephone numbers and any of the above for any parent, guardian, helper or other persons connected to you where applicable.
  • Financial Data such as your bank account, PayPal account and/or card and other payment details.
  • Transaction Data such as details about payments to and from you and other details of products, services, competitions, event attendance and other opportunities you have purchased from or accessed or acquired through us (if any).
  • Profile Datasuch as (where relevant) your personal and/or corporate interests, qualifications, training or occupational experience, associated social media accounts, supported team and/or Club, any username and password we may allocate you for use of our facilities, preferences, feedback and/or survey responses you provide. 
  • Communications Dataincludes information you provide when communicating or meeting with us, history of your attendance and/or communication with us, and your preferences in receiving marketing or other communications from us and our affiliated third parties.
  • Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be generated from your personal data but does not directly reveal your identity. However, if we combine or connect Aggregated Data with your personal data so that it can directly identify you, we treat the combined data as personal data which will be used in accordance with this Notice.

Special Categories of Personal Data includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. We generally limit our collection of this information – see below for further information.

If you fail to provide personal data

Receipt of services, products, opportunities or fulfilment of other obligations we may owe to you might require you to provide specific types of information. Where you fail to provide that information, we may not be able to enter or perform the relevant contract or specific obligation we have, or allow you to engage in the opportunity.

Children’s Data

We understand that children and young people, including those under 13 years of age (“minors”), may interact with us. Minors may need their parent or guardian’s permission to use or access certain facilities, opportunities or receive certain information from us. Minors may also be asked to confirm they have that permission, and we reserve the right to verify parental or guardian consent, where required.

We try not to make a minor's participation in activities with us contingent on the minor disclosing any more personal information than is reasonably necessary in order to do so. We do not actively market to minors or use (or pass to any third party) personal information on persons known to be minors for any commercial purposes, without proper consent.

 

Other age restrictions may apply to certain products, services or opportunities we make available from time to time. 

In brief… through direct interactions with you or your organisation, shared platforms and databases, others in the football industry, and relevant third parties and publicly available sources. Some data passes through our contractors systems before coming to us.

We use different methods to collect data about you, including through:

  • Direct interactions. we may collect data when interacting with you or your organisation directly. For example, when you or your organisation correspond with us or fill in forms for sending to us.
  • Shared technologies or platforms. Sometimes your data may be contained in private shared platforms we are entitled to access. For example, those associated with football clubs may have their details uploaded to the Club Portal System (CPS), and members of the press or photographer details may be contained in shared industry databases for accreditation purposes.
  • Football Clubs, Authorities & Organisations.  Other organisations in the football industry (including clubs, leagues, governing bodies, membership and collective interest bodies, equality, inclusion and not-for profit sporting organisations), may provide us with your details as part of ensuring proper governance and administration of the game. For example, our member Clubs may provide us with details of certain individuals relating to participation or attendance at EFL events, and personnel in the football industry may find their details are shared with us due to the nature of their role.
  • Third parties or publicly available sources. We may receive personal data about you from various third parties as set out below:
    • Our sponsors and other commercial partners, including where required to administer prizes through promotions they run in the course of their partnership with us;
    • Our suppliers and service providers, including providers of technical, payment, delivery and fulfilment services;
    • Social media platforms and websites which are publicly available or through which you may interact with us;
    • Data brokers or aggregators such as those used for any credit reference or similar pre-service vetting facility (if any);
    • Corporate and other official databases, such as electoral roles and company registries; and
    • Other information from lawfully availably sources where relevant to our bringing, defending or assisting in legal action (such as the police, regulators, investigators or other public interest organisations).  

We may also supplement the information collected with other information that we obtain from our dealings with you or which we receive from other organisations such as our group companies.

In brief… To deliver or receive services, products or opportunities to or from you or your organisation; run our events and competitions; take or make payments; make relevant publications or announcements; manage and improve our operations; communicate with you; protect and enforce our legal rights or those of others; marketing (only where you have agreed for electronic direct marketing); administer, analyse and improve our operations. We process special categories of data only where the law allows.

Several legal grounds apply to our use of your data, depending on which of the above purposes we use it for. These may include where: we need to perform any contract with you; we need to comply with legal requirements; you consent; or where necessary for our legitimate interests, but balanced against your rights.

 

We use information about you for the following purposes:

  • Services, Products & Opportunities - to allow you to apply for and receive products, services and other opportunities (such as tickets to EFL competition finals) and fulfil any of our obligations for delivery of those. Likewise for receipt by us of any products, services or opportunities from you or your organisation. Processing your data for this purpose will usually be necessary (i) to perform any contract with you for the relevant service (ii) to comply with legal obligations where applicable or (ii) for our and/or our clubs’ legitimate interests in receiving deliverables pursuant to any commercial relationship with you or your organisation.

 

  • Events & Competitions – in connection with your accreditation or attendance at and/or fulfilment of obligations relating to relevant events we organise and other competitions we may administer from time to time. This may include fans, corporate attendees and/or those requiring accreditations such as members of the press and/or photographers. This will usually be necessary (i) to perform any contract with you for your attendance or participation (ii) to comply with legal obligations where applicable or (ii) for our and/or our clubs’ legitimate interests in ensuring proper and effective governance, regulation and administration of our events and competitions.

 

  • Payments and Finance- to collect payments from you for any paid for products or services, opportunities and attendance at events, and/or administer any payments which may become due to you or your organisation.  This will usually be necessary (i) to perform any contract with you for the paid for service or (ii) to comply with legal obligations where applicable or (iii) for our legitimate interests in recovering debts due to us.

 

  • Publications and Announcements– to include you in relevant publications or announcements. For example, relevant staff of EFL member clubs will have their work contact details included in the annual EFL handbook. Fans may also be included in publications such as to promote you as a winner of promotions or surveys we or our commercial partners run, or in relation to crowd photographs from our events. The processing of your personal data here will usually be on the basis you have given permission or where necessary for our legitimate interests in properly administering, developing and raising awareness of our services, events, competitions and operations, managing the relationship between you or your organisation and us or our affiliates, and making any lawful press releases or announcements.

 

  • Manage and Improve- to manage and improve our operations, including notifying you of applicable changes where required. This will usually be necessary (i) to perform any contract with you (ii) to comply with legal obligations where applicable or (iii) for our legitimate interests in managing our relationship with you or your organisation, improving our operations, and/or record keeping.

 

  • Communications & Engagement- to communicate with you where necessary, including dealing with queries, complaints, meetings and other correspondence other than for marketing purposes (for which, see below). This will usually be necessary (i) to perform any contract with you for applicable products or services (ii) to comply with legal obligations where applicable or (iii) for our legitimate interests in managing our relationship with you or your organisation, improving our operations, and/or record keeping.

 

  • Administration, Protection & Security- to administer and protect our businesses and rights, and those of other associated third parties (including those of our member clubs, partners and other stakeholders (whether organisations or individuals)). This may include routine tasks such as data analysis (for example, checking event attendees against any banning list or order databases), system maintenance and support as well as more formal matters such as bringing, defending or assisting in legal action where necessary.  

 

We take our obligations to safeguard vulnerable people seriously, including youth players and other children. We do this by collecting/accessing and analysing records of incidents and allegations of abuse, exploitation or inappropriate conduct, and preventative measures by reference to the law and our rules and regulations. We may collect and process personal data (including from public sources) without your knowledge where this is required and/ or permitted by law.

 

We also operate CCTV at our office premises for security purposes (see below).

 

Processing for these purposes will usually be necessary (i) for our legitimate interests in running our business and systems in a secure manner, protecting rights and property (including intellectual property), and preventing or tackling illegal activity or (ii) to comply with a legal obligation.

 

  • Marketing & Associated Profiling- to alert you to information about events, opportunities, surveys, competitions, offers, products, services and other exciting updates relating to us, our group, clubs and/or commercial partners.

 

We only do this through email, sms, automated phone calls or online direct messaging (such as using any direct private message facility i.e. social media messaging) where you have agreed, so this is on the basis of your consent. You can change your mind or adjust your preferences any time afterwards either in your personal profile page (also known as a ‘preference centre’) which is accessible from all of our emails, or emailing us at [email protected]. We will also stop sending these in direct response to any other express communication from you asking to do so.

 

We may use tools to measure the effectiveness of our communications, including whether you open, delete, or access links contained in the communications, and the browser, app or general device type used.

 

  • Research, Analysis & Personalisation- to carry out market research so that we can improve our operations, events and products, services and opportunities we offer, and in some circumstances personalise communications or facilities made available. Your feedback is valued and helps for inform the regulatory and commercial strategy, marketing activity and initiatives across the EFL group. This will usually be necessary for our legitimate interests to study how stakeholders engage with us, to develop our operations, grow our business and to inform our strategies.

We may also process your personal data for other reasons, in compliance with the above rules, where this is required or permitted by law. Where we reasonably consider that we need to process your personal data for another reason that is compatible with the original purpose set out in this Notice we will do so. If that is ever the case and you wish to get an explanation as to how processing for any new purpose is compatible with the original purpose, please contact us.

If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so. In some circumstances, this may require your consent.

In the occasional circumstances where we require special categories of personal data or that relating to criminal convictions, this will only be in accordance with Data Protection Law and therefore usually if:

  • It is necessary for us to carry out our legal obligations.
  • It is needed in the public interest.  For example, where it is necessary for the purposes of measures designed to protect the integrity of a sport or a sporting event, and/or prevention of unlawful acts.
  • We have your explicit written consent.
  • You have already made the information public.
  • It is needed for administration of justice or in relation to legal claims.
  • It is needed to protect your interests (or someone else’s interests) and you are not capable of giving your consent.

We may also collect special categories of personal data to be held in an anonymised form detached from your other data so does not reveal your identity. For example, if we carry our equal opportunities or similar inclusion based surveys from time to time.

In relation to any CCTV at our premises, visitors are made aware of this by appropriate signage. Cameras are located in communal areas only where necessary for the above security purposes and not in any area which would have a disproportionate intrusion on your privacy. Footage is subject to restricted access and personnel controls, stored on our secure systems and deleted at regular intervals in accordance with standard industry practice.

In brief… usually in the European Economic Area (EEA) or US but always in a manner that ensures proper security.  We will only keep the minimum amount of information for as long as we need it for the purpose(s) in this Notice.

 

Location

We are committed to protecting the security of your personal data, which we generally hold in secure data centres in the European Economic Area (EEA) or process through US based organisations.

In relation to personal data sent to the US, we usually check whether the Privacy Shield applies – that ensures a similar level of protection to personal data shared within the EEA. See https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/eu-us-privacy-shield_en, for further details.

Some organisations to which we may disclose your personal information may be situated outside of the EEA. Whenever we transfer your personal data out of the EEA, we take reasonable steps to ensure that your information is still properly protected. This may include safeguards such as checking the relevant countries have been deemed to provide an adequate level of protection for personal data by the European Commission, or using contractual provisions to ensure your information is properly protected (certain contracts are approved by the European Commission).

Duration

We will keep the personal data you have provided only for as long as we reasonably require to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means. This is in addition to any applicable legal requirements. Details of specific retention periods for different aspects of your personal data are available on request by contacting us at [email protected].

For legal reasons we may have to keep basic information about our customers and suppliers (including Contact, Identity, Financial and Transaction Data) for up to seven years after they cease being customers – this is particularly for any relationship subject to payments or contract (if any).

We may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

Security

We have put in place appropriate operational, technical and security measures to reduce the risk of your personal data from being accidentally lost, used or accessed in an unauthorised way. This includes use of encryption where relevant in our and our third party service providers systems. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

If we have given you a password to access certain facilities we make available, you must keep the password safe and make sure you use secure devices, apparatus and software.

In brief… other companies in the EFL group;  new owners of our business; selected contractors who help us fulfil our operations (including logistics, communications and event services; payment processing, hosting and other technical providers); affiliates in the football industry; commercial partners and sponsors of the EFL; legal bodies and vetting or compliance database operators.

 

We may disclose your information to third parties as follows:

  • to other companies within our corporate group, including any of our affiliated community trusts and charitable schemes;

 

  • to third parties to whom we may choose to merge with, sell or transfer all or parts of our business or our assets (or businesses we may acquire). New owners  of our business may use your personal data in the same way as set out in this Notice;

 

  • to service providers who carry out data processing activities on our behalf. For example, event management services (including host venues), communication, meeting and mailing services, shared platform operators, payment processing, IT infrastructure, software and hosting service providers, along with other relevant partners used to help us operate our business or fulfil obligations to you, your organisation and other third parties.

 

We do not allow our third-party service providers to use your personal data for their own purposes unless they have legal grounds to do so;

 

  • to commercial partners or sponsors. For example, if required for prize or opportunity fulfilment in relation to promotions you engage with (but only for direct electronic marketing purposes where you have agreed to this). Click for details about the current EFL commercial partners and sponsors;

 

  • other organisations in the football industry where required for completion of the purposes set out in this Notice, such as other football leagues, clubs, governing bodies, member and collective interest bodies, equality, inclusion and not-for profit sporting organisations. For example club staff details may be shared with other clubs where necessary as part of your role, or details of fans who win or purchase tickets to a match or event may need to be shared with the stadium, venue host or participating clubs, for ticket delivery and/or health and safety or other lawful reasons;

 

  • to professional advisers including lawyers, bankers, auditors and insurers where required for those parties to provide services to us;

 

  • to law enforcement agencies, Courts or other dispute resolution forum, or other legal or regulatory authorities if we are under a duty to disclose or share your personal data to comply with any legal obligation, or are enforcing or protecting our rights, or lawfully co-operating in the protection of third party rights; and/or

 

  • to any credit reference or similar pre-service or communication vetting agency (if any) for the purposes of fraud protection, credit risk reduction in relation to paid for services you request from us or compliance with requirements of law.

 

We may have to share your personal data with the parties above for the purposes set out in this Notice. In some circumstances, there may be other lawful reasons for the third party to use your data in accordance with any privacy notice they make available to you.

We may also provide Aggregated Data to third parties. Certain details such as your name, organisation or image may be made available in relevant publications or announcements we lawfully make.

In brief… Access or object to use of your data; have your data corrected, erased, transferred or used only in a restricted way; complain to us or the Information Commissioner; withdraw consent to use of your data. Some rights are only available in limited circumstances.

 

Under the Data Protection Laws you may have the following rights in relation to your personal data in certain circumstances:

  • Request Access: (also known as a "data subject access request"). You can receive a copy of the personal data we hold about you.
  • Request Correction: You can have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of new data you provide.
  • Request Deletion: You can ask us to delete or remove personal data where: there is no good reason for us continuing to process it; you have successfully exercised your right to object to processing (below); or where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
  • Object to Processing of your personal data: this applies where: we are relying on a legitimate interest or those of a third party (see the “What do we use your information for?” section above) and you feel our processing on this ground impacts your fundamental rights; or where we are processing your personal data for direct marketing purposes.
  • Request Restriction of Processing: you can ask us to suspend processing of your personal data where: you want us to establish the data's accuracy; our use of the data is unlawful but you do not want us to erase it; where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request Transfer: you can ask us to provide to you, or a third party of your choice, your personal data in a machine-readable format. This right only applies to automated information which: you initially provided consent for us to use your data (see the “What do we use your information for?” section above); or we used the information to perform a contract with you (see the “What do we use your information for?” section above).
  • Right to withdraw consent;. This only applies where we are relying on consent to process your personal data (see the “What do we use your information for?” section above). If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

All requests set out in this section or other queries relating to this Notice should be addressed to the EFL, see the “Who can you contact for further details?” section below for contact details. Please note we may not always be able to comply with your request due to our legitimate interests or other legal reasons. If applicable, these will be notified to you in response to a relevant request.

You will not usually have to pay a fee to exercise any of the above rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive (or we may refuse to comply with your request in these circumstances).

For security reasons, we may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). We may also ask you for further information in relation to your request.

If you have any concerns about how we use your data you also have the right to raise this with the Information Commissioner’s Office at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF (https://ico.org.uk). However we will always try to help with any concerns so ask that you contact us in the first instance.


 

In brief… Yes we like to ensure you are up to date about our use of your personal data. If we update this Notice we will notify you, unless the changes are minor.

 

We may need to update this Notice, and minor changes will be posted on this page so you should check back from time to time. Significant changes will be notified to you.

This Notice was last updated on 11 May 2018. 

Data Protection Officer, EFL, EFL House, 10-12 West Cliff, Preston, Lancashire PR1 8HU or [email protected] Please include your name, address, and/or email address when you contact us.