Legal Framework of Athlete Data
1. Introduction
In the modern world of sports, technology has become an integral part of performance measurement. Millions of data points are collected through smartwatches, heart rate monitors, GPS trackers, and wearable sensors.
This data reflects not only training performance but also health, biometric profiles, and psychological state .
However, this situation the Turkish Personal Data Protection Law (KVKK) and the GDPR .
2. Legal Nature of Athlete Data
According to Article 6 of the Turkish Personal Data Protection Law (KVKK), health data and biometric information "special categories of personal data .
Information such as a football player's heart rate, running speed, oxygen level, or injury history is both personal and health data.
As stated in the Supreme Court's 12th Criminal Chamber's decision numbered 2021/4312 E., 2021/7196 K .:
"Linking personal data to physical performance metrics makes it possible to directly identify an individual."
Therefore, explicit consent , security measures , and data minimization principles are of great importance for processing this type of data
3. Data Controller: Clubs or Federations?
According to Article 3 of the KVKK (Turkish the "data controller"is the person who determines the purposes and means of processing the data.
In this context:
-
Sports clubs are data controllers when they collect training and performance data.
-
The Turkish Football Federation (TFF) or other federations are considered joint data controllers if they process data for licensing and health checks
The decision of the Personal Data Protection Board dated 31.03.2022 also clarifies this situation:
“Performance data collected by sports federations may be processed based on explicit consent and in accordance with the terms and conditions of sharing with the relevant club.”
4. Explicit Consent and Processing Conditions
In accordance with Articles 5/2 and 6/2 of the Personal Data Protection Law (KVKK), for the processing of athlete data:
-
Explicit consent must be obtained
-
Data should only be processed for specific, explicit, and legitimate purposes
-
Excessive information should not be collected.
Example Application:
A club could collect GPS and heart rate data from its players for performance evaluation. However, it could not use this data advertising campaigns or sponsorship analysis .
5. Wearable Technologies and Legal Risks
Wearable devices (e.g., Polar, Garmin, Catapult) transmit real-time data.
This data is stored in club infrastructure or cloud systems.
The risks here are:
-
Cloud providers being based abroad (e.g., AWS, Google Cloud) → prohibition on transferring data abroad (KVKK Article 9)
-
Risk of cyberattacks and data breaches
-
Athlete loses control over data
Personal Data Protection Law Decision – June 10, 2021:
"Explicit consent must be obtained and technical security measures demonstrated for data transfer to foreign cloud systems."
6. Data Security Obligations
Clubs' obligations according to Article 12 of the KVKK (Turkish Personal Data Protection Law):
-
Only allow authorized personnel to access the data
-
Hosting servers on secure systems,
-
Implementing anonymization and encryption,
-
data processing activities the Data Controllers Registry (VERBIS) system.
Otherwise, administrative fines of up to 1 million TL and imprisonment under Article 136 of the Turkish Penal Code may be imposed.
7. Data Analytics and Consent-Based Processing Model
Today, clubs use analytical algorithms to process athlete data and predict injury risks, fitness declines, or performance improvements.
In this case, data analyticsshould be conducted within the framework of "consent-based processing."
This approach is also supported in CAS decisions.
CAS 2018/A/5799 – Player v. Club:
"The club's use of player data for advertising or marketing purposes other than performance analytics is a breach of contract."
8. Athlete Rights and Application Procedures
Athletes have the following rights in accordance with Article 11 of the Personal Data Protection Law:
-
To find out if your data is being processed,
-
Requesting correction of incorrect or incomplete data,
-
Requesting deletion or anonymization,
-
File a complaint with the Board.
Procedure: If a football player discovers that their club is sharing wearable device data with third parties, they can first contact the club and then file a complaint with the Personal Data Protection Board (KVKK )
9. International Framework: GDPR and WADA
Article 9 of the GDPR in the EU strictly regulates the processing of health data. WADA (World Anti-Doping Agency), on the other hand, applies the International Standard for Protection of Privacy and Personal Information (ISPPPI) standards when processing athlete data within the scope of doping control .
In this context, clubs in Turkey must comply with both the Turkish Personal Data Protection Law (KVKK) and the WADA-FIFA data policies
10. Conclusion and Evaluation
Wearable technology, performance analytics, and data science are shaping the future of sport.
However, this development should not come at the expense of athletes' right to privacy and data security .
Clubs should only specific and measured data when gathering training information, obtain explicit consent, and clearly restrict the sharing of data with third parties.
Otherwise, both GDPR penalties and reputational damage will be inevitable.