Skip to main content

Club privacy policy template — plus a photo consent form that actually works

A plain-English privacy policy outline for community clubs, a field-by-field photo and video consent form template, what the Privacy Act does and doesn't require of small clubs, and the everyday data habits that matter more than the documents.

By The ClubHelix team · Published 27 June 2026 · 8 min read

Your club holds more personal information than most small businesses: names, addresses and birthdates for every member, medical conditions disclosed at registration, emergency contacts, payment records, photos of children, and sometimes sensitive matters raised in complaints or incident reports. Members hand all of this over on trust — and one mishandled spreadsheet or one photo published against a parent's wishes burns that trust in an afternoon.

A privacy policy is how a club makes its promises about that information explicit, and a photo consent process is the piece members care about most viscerally. This guide gives you a policy outline you can adapt, a consent form template field by field, and — because documents alone protect nothing — the handful of data-handling habits that do the real work.

General information only. This guide is general information for community clubs, not legal or financial advice. Requirements differ by state and change over time — always confirm with the official sources linked below.

What the law actually requires of a small club

The starting point is the Office of the Australian Information Commissioner (OAIC), the national privacy regulator. The Privacy Act 1988 and its Australian Privacy Principles (APPs) apply to organisations with annual turnover over $3 million — which exempts many small clubs — but the exemption is narrower than committees assume: the OAIC's small business guidance explains the carve-outs, including that organisations providing health services and handling health information are covered regardless of turnover. A club collecting medical information at registration should read that carefully. Health information is classed as sensitive information and gets the strictest treatment — see the OAIC's health information pages.

Three more reasons the "we're too small for the Privacy Act" shrug is the wrong posture. Your national sporting body's policies almost certainly bind affiliated clubs to privacy standards contractually, whatever the Act says. State laws add layers, particularly around health records and surveillance. And most practically: members expect it. The APPs are simply a good description of what reasonable data handling looks like — collect only what you need, say why, keep it secure, let people see and correct it, don't repurpose it. Run your club to that standard and the legal question mostly takes care of itself.

Club privacy policy: the outline

Keep it to two pages, in plain English, published on your club website. Section by section:

SectionWhat it says
Who we areClub name, incorporation details, and the role to contact about privacy (secretary or privacy officer — a role, not a person's name)
What we collectMember details (name, DOB, contacts), emergency contacts, medical information relevant to safe participation, payment records, photos/videos at club activities, website/analytics basics
Why we collect itRunning memberships and teams, safety and emergency response, competitions and results, club communications, legal and insurance obligations
How we collect itRegistration forms, event entries, incident reports, direct correspondence — and a commitment to collect only what's needed
How we store and protect itClub systems with role-based access, not personal spreadsheets; who can see what; how long we keep it
Who we share it withYour association or league (results, registrations), insurers when claims arise, government agencies where required — and a plain statement that the club never sells member data
Photos and videosCross-reference to the consent process below; how consent choices are respected in practice
Your rightsHow members can see the information held about them, correct it, and complain — first to the club, then to the OAIC
ChangesHow the policy is updated and where the current version lives

Adopt it at committee, minute the adoption, link it from your registration form ("by registering you acknowledge our privacy policy"), and review it annually alongside your risk register.

Photos are where privacy gets personal. Parents have real and varied reasons for keeping children's images offline — family safety situations among them — so consent must be genuinely optional, granular, and operationally respected. A tick-box nobody looks at again is worse than no consent at all, because it creates a false promise.

Collect consent at registration, per person, per season. The template:

FieldOptionsNotes
Member nameTextOne form per member — never "all my children" blanket forms
Consenting personText + relationshipThe member themselves if an adult; parent/guardian for under-18s
Photos in club online channelsYes / NoWebsite, social media, newsletters — your widest audience, so its own line
Photos in internal/team channelsYes / NoTeam chats and member-only pages; many decline public but allow internal
Photos in print and club displaysYes / NoPrograms, clubroom walls, local press releases
Name published with imageYes / NoEven a "yes to photos" family may want no names attached; never publish a junior's full name with their image as a default
Media/broadcast consentYes / NoLocal paper at finals, streamed matches — separate because the club can't recall it once given
Signature and dateSignatureDigital acknowledgement at registration is fine and easier to store

And the operational rules that make the form mean something: keep a current no-consent list available to whoever posts on club channels (a name list, not the reasons — reasons are nobody's business); brief your team photographers and social media volunteers each season; check group shots against the list before posting; and take an image down promptly, without argument, when asked. Consent can be withdrawn at any time — say so on the form.

A club photographer shooting from the sideline at sunset

Collect it once, store it properly

The biggest privacy upgrade most clubs can make has nothing to do with documents: it's getting member data out of email threads and personal spreadsheets and into one access-controlled system. When registration, consent, medical notes and emergency contacts are collected through structured registration and consent forms and stored against the member record, the club gets what paper never delivers: the consent answer is findable when someone's about to post a photo, medical details are visible to the team manager who needs them and nobody else, and when a family updates a phone number it updates everywhere.

Building registration and consent forms in ClubHelix

ClubHelix applies role-based access across all of it — committee roles see what their job requires, coaches see their team's essentials, and sensitive records like incident reports stay locked to named officers. Member data lives in one place with per-tenant isolation and forced row-level security; the platform's security page covers the engineering underneath. The habits that complete the picture cost nothing: no member lists in personal inboxes or USB sticks, no full-membership exports "just in case", access reviewed at every AGM when roles change, and old data actually deleted when your retention period ends.

When something goes wrong

Data incidents happen to small organisations too — a stolen laptop with a member export, an email to the wrong list, a website misconfiguration. Have a two-line plan before you need it: contain it (revoke access, recall what can be recalled), then assess honestly who's affected and how badly. The Notifiable Data Breaches scheme requires covered organisations to notify the OAIC and affected individuals of eligible breaches — the OAIC's data breach pages explain the scheme and, whatever your club's coverage status, its guidance is the sensible playbook: be prompt, be straight with affected members, and fix the cause. A club that fronts up to a mistake keeps more trust than one that hopes nobody notices.

Frequently asked questions

Does the Privacy Act apply to our small sports club?

Maybe — the small business exemption (annual turnover under $3 million) covers many clubs, but there are important carve-outs, including for organisations that provide health services and hold health information, and clubs collecting medical details at registration should read the OAIC's guidance on where the line falls. Your sport's affiliation requirements may also bind you to privacy standards regardless. The practical answer: run the club to APP standards anyway — it's what members expect and it's not onerous.

Get consent at registration for all club photography, with the granular options in the template above, and honour it operationally — especially for juniors. Crowd and incidental shots at public events sit in greyer territory legally, but the club standard should be simple: know your no-consent list, check identifiable shots against it before publishing, and remove images promptly on request. Never publish a junior's full name alongside their photo as a matter of course.

How long should a club keep member data?

Only as long as there's a genuine purpose: current member records for the membership plus your association's requirements, financial records typically seven years, and incident/injury records much longer because claims can surface years later (and minors can claim after turning 18). What shouldn't persist is everything else — old exports, superseded spreadsheets, ex-members' medical details. An annual clean-out, minuted at committee, is a fine tradition.

Who at the club should be able to see medical information?

Only the people who need it to keep the member safe: typically the relevant team's coach or manager (allergies, conditions that matter at training, emergency contacts) and the first aid officer — not the whole committee, and never the general membership. This "need to know" test is the heart of good club privacy practice, and it's why medical details belong in a system with role-based access rather than a spreadsheet where seeing one member's asthma plan means being able to read everyone's. Decide the access rules once, write them into your privacy policy, and review who actually holds access at every AGM when roles change hands.

Can we share our member list with sponsors?

Not without explicit, opt-in consent collected for that specific purpose — repurposing member data for third-party marketing is exactly what privacy principles prohibit and exactly what erodes member trust fastest. If sponsors want reach, offer club-controlled channels instead: sponsored posts in the club newsletter, logos on the website, a sponsor page. The list itself is never the product.


Collect consent once, respect it everywhere. ClubHelix's forms capture registration, medical and photo-consent answers straight into access-controlled member records — read about the security underneath or see pricing.