This article was published in LawInSport on September 11, 2026.
Summary
Football clubs collect vast amounts of biometric performance data on players (heart rate, GPS, sprint speed, sleep and recovery metrics), yet when a player transfers, this valuable dataset typically stays with the selling club rather than moving with them. Performance data qualifies as personal data under the GDPR, and often as special category health data under Article 9, which complicates portability: clubs usually process it on employment-law or occupational-medicine grounds, not on consent or contract, the two lawful bases that trigger Article 20 portability. However, the position is nuanced, since many clubs incorporate wearable monitoring as a contractual obligation in the playing contract, which would engage in Article 20; clubs should therefore audit their actual lawful basis.
Where portability applies, players can obtain “observed” raw data (heart-rate readings, GPS outputs), but not derived data such as proprietary injury-prediction models or performance scores, which embed confidential methodology. Article 15 access rights are broader, apply regardless of lawful basis, and reach derived data too; in Italy, the Garante and the Corte di Cassazione have grounded the employee’s right of access also in the duties of good faith under the Civil Code (Articles 1175 and 1375). CJEU case law (SCHUFA, Dun & Bradstreet Austria) reinforces a right to meaningful explanation of algorithmic logic affecting players.
Playing contracts, transfer agreements and federation rules remain silent on data portability. Vendor agreements often fail to specify whether the wearable provider is a processor or an independent controller; where the provider independently determines further purposes for the data, it risks being classified as a joint controller with direct obligations to the player. The article notes that Article 20 UK GDPR remains unchanged, though the Data (Use and Access) Act 2025 has modified the automated decision-making regime. Initiatives like Project Red Card and FIFPRO’s Charter of Player Data Rights signal growing industry attention, though the former has not progressed to litigation.
The article recommends building practical infrastructure now: contractual portability clauses, defined data formats and export deadlines, and clarity on vendor responsibilities, treating data access as a standard due diligence item alongside medical records and image rights. The practical stakes should not be overstated, but the compliance risk is real: the value of performance data lies less in standalone commercial worth and more in its role as an input to better-informed decisions.
Want to know more about players’ rights over their performance data?
👉 Read the full article here.