Poker Tournament Management App
Run Poker Tournaments Like a Pro!
From First Hand to Final Table
Seat draws, table balancing, the clock, payouts and league standings: Shuffle Up and Deal! runs the whole night from your iPhone or iPad.
Player Data Privacy for Organisers: FIFPRO Model & Shuffle Up
Player data privacy covers everything from match stats to biometric health readings, and the rules get stricter the closer the data gets to someone’s body. Biometric and health-derived inferences typically need explicit consent or another strong legal basis under regimes such as the GDPR, and organisations handling that data must build in risk-based safeguards from day one.
TL;DR:
- Most biometric and health-derived player data requires explicit consent and strong safeguards due to its high legal sensitivity under GDPR and recent case law.
- Combining multiple data points, even if collected for non-medical purposes, can reveal health information that falls under strict GDPR protections.
- Consent must be freely given, purpose-specific, informed, and revocable without penalty, with straightforward mechanisms for players to manage their data.
- Data minimization, pseudonymisation, encryption, role-based access, and DPIAs are essential to mitigate re-identification, breach, and misuse risks.
- Industry efforts are shifting toward player-controlled data platforms that allow ownership, transparency, and revenue sharing, though regulatory and practical challenges remain.
Table of Contents
- What counts as player data: categories and examples
- The legal baseline: GDPR, special categories and recent case law
- Consent, legitimate interest and what organisations can (and cannot) do
- Risks and technical safeguards: from telemetry inference to breach impact
- Practical checklist for players and for organisations
- Industry responses and platforms that centre player control
- How tournament management software can support player privacy
- Treat data like you’d treat a hand you’re not ready to show
- Sources
- FAQ
What counts as player data: categories and examples
Not all player data carries the same weight. Event data (scores, match results, league standings) sits at one end of the spectrum. Tracking data, biometric readings and health-derived inferences sit at the other, carrying far greater legal sensitivity.
In professional sport, this plays out through specific tools and feeds:
- GPS vests and optical tracking systems that log speed, distance and positioning.
- Heart rate monitors and wearables that feed into electronic medical records.
- Performance metrics that, combined over time, can reveal fatigue patterns or injury risk.
- Account data such as logins, payment details and contact information.
The tricky part is inference. A single sprint speed reading tells you very little. A season’s worth of sprint data, cross-referenced with recovery times, can reveal something close to a medical profile, even though nobody explicitly collected health information.
The legal baseline: GDPR, special categories and recent case law
The GDPR splits personal data into two tiers. Ordinary personal data needs a lawful basis under Article 6. Special category data, including biometric and health data, needs a stronger basis under Article 9, usually explicit consent.
Collated data can become health data even when nobody intended it to. Recent reasoning from the Court of Justice of the European Union indicates that data capable of revealing health status through collation or deduction can fall within Article 9’s definition of data concerning health. This matters for sport specifically: performance telemetry that looks harmless on its own can meet that threshold once it is combined with other data points.
This is the direction regulators are heading more broadly. The AI Act adds further constraints on automated profiling and biometric identification, which affects how analytics systems can be used in recruitment or contract decisions. For anyone running player data programmes, the safe assumption is that granular telemetry sits closer to “special category” than most organisers would like to admit.

Consent, legitimate interest and what organisations can (and cannot) do
Organisations often reach for “legitimate interest” as a catch-all justification. For sensitive player data, that rarely holds up. Legitimate interest requires a necessity test and a balancing exercise against the player’s rights, and commercial exploitation of biometric or health-derived data tends to fail that test outright.
Valid consent needs to meet four criteria:
- Freely given, with no pressure tied to selection, pay or playing time.
- Specific to the exact purpose, not a blanket agreement covering future unknown uses.
- Informed, meaning players understand what is collected and why.
- Revocable at any point, without penalty.
Operationally, this means separating consent options by purpose (medical monitoring versus commercial analytics versus broadcast use), making withdrawal as easy as giving consent in the first place, and keeping clear records of what was agreed and when.
Pro Tip: Give players a single dashboard where they can see, and revoke, every consent they’ve granted, rather than burying withdrawal options in separate forms.
Risks and technical safeguards: from telemetry inference to breach impact
The harms here are not abstract. Re-identification from “anonymised” datasets, profiling errors that affect contract decisions, and opaque algorithms that quietly shape a player’s career are all live risks. Malicious reuse, where data meant for performance analysis ends up sold to betting firms or data brokers, has already triggered legal action in the form of Project Red Card, where players pursued claims over alleged unauthorised exploitation of their personal data.
Technical and organisational safeguards reduce this risk, though none of them work in isolation:
- Data minimisation: collect only what the stated purpose requires.
- Pseudonymisation and encryption, both at rest and in transit.
- Role-based access controls so medical staff see different data than marketing teams.
- Data protection impact assessments (DPIAs) before any new biometric or telemetry system goes live.
| Safeguard | What it addresses |
|---|---|
| Data minimisation | Reduces the volume of sensitive data exposed in a breach |
| Pseudonymisation | Limits direct identification, though not re-identification risk |
| Encryption | Protects data in transit and storage from interception |
| Role-based access | Restricts who can view medical versus public-facing data |
| DPIA | Flags high-risk processing before it starts |
FIA guidance makes a sharp point worth repeating here: pseudonymisation alone is often insufficient if someone can re-identify a person by collating other datasets. That is precisely why role-based access and strict retention rules matter as much as the encryption itself.
Practical checklist for players and for organisations
Players have more leverage here than most realise. You can:
- Request a copy of all personal data an organisation holds about you.
- Withdraw consent for any specific use, at any time, without needing to justify it.
- Ask for your data to be used only in anonymised or aggregated form where that option exists.
- Exercise portability rights to move your data to another provider or platform.
A simple template covers most requests: “Please provide all personal data you hold about me, including the categories of data, the purposes of processing and any third parties it has been shared with.”
Organisations, meanwhile, should publish plain-language privacy notices, offer genuine consent management (not a single accept-all button), build export and portability tools into their systems, and set retention schedules that delete data once its purpose has lapsed.
Pro Tip: Before signing with any data vendor, ask them directly how long they retain raw telemetry and whether they can produce an audit trail showing who accessed a specific player’s record and when.
Industry responses and platforms that centre player control
The clearest sign of where this is heading came in February 2025, when FIFPRO partnered with Sports Data Labs to build a consent-based, player-controlled platform. The idea is straightforward even if the engineering behind it isn’t:
- Players store and control their own career data in a portable repository.
- A centralised clearinghouse manages third-party requests, so players set the terms rather than discovering after the fact that their data has been sold on.
- Players can participate in revenue share when they choose to let their data be used commercially.
This model still has limits. It depends on transparent terms, approved third parties, and regulatory frameworks that vary by jurisdiction, so it is a direction rather than a finished solution. But it reframes player data as something players own and licence, not something clubs or federations simply hold.
How tournament management software can support player privacy
The same principles apply well below elite level. A well-built app can give organisers auditable player profiles and merge-without-loss functionality that keeps records accurate without duplicating sensitive history. Fine-grained access, where medical or financial details stay separate from the public tournament display, turns privacy-by-design from a policy document into something organisers actually use at the table, as explained in practical advice on chess online etiquette.

Treat data like you’d treat a hand you’re not ready to show
I’ve spent years watching tournament directors wrestle with spreadsheets, paper sign-up sheets and half-updated apps, and the pattern is always the same: the data piles up long before anyone thinks about who should see it. Publish a plain privacy notice, give players an export option, and run a DPIA before you plug in any biometric wearable. Do it now, not after someone asks why their data turned up somewhere it shouldn’t have.
- Jason
Sources
- FIFPRO - Policy position: player data
- FIFPRO - FIFPRO partners with Sports Data Labs
- Court of Justice of the European Union - Case C‑620/24 (Lindenapotheke-related materials)
- FIA - Guidelines for the collection and usage of biometric data in motorsport
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
FAQ
What is considered player data under GDPR?
Player data includes event data like scores, tracking data such as GPS or optical feeds, biometric and health-derived data, and account information. Biometric and health-related categories receive stronger protection under GDPR Article 9, which demands a higher legal basis than ordinary data.
Can performance telemetry count as health data?
Yes, when it can be collated or deduced to reveal health status, even if it was not collected for medical purposes. Recent CJEU reasoning supports this broader interpretation, so organisations should treat granular telemetry cautiously.
What rights do players have over their own data?
Players can request access to their data, withdraw consent for specific uses, and exercise portability rights to move their data elsewhere. Initiatives like the FIFPRO and Sports Data Labs platform are built specifically to give players more control over how their career data gets used and monetised.
Does Shuffle Up and Deal! store sensitive player health data?
Shuffle Up and Deal! is built for tournament management such as registration, table balancing, blind levels and statistics, not for storing medical or biometric records. Organisers using it for player registration and profiles can review plan options, including the Tournament Director plan at £13.99 per month, to find the features that suit their event.
How can smaller tournament organisers protect player data without a legal team?
Start with data minimisation: collect only what the tournament genuinely needs, such as names and contact details for registration. Clear, simple privacy notices and easy consent withdrawal cover most of the legal groundwork that smaller organisers need, as outlined in guidance on player registration essentials.

