LGPD in Sports Schools: Minors’ Data Protection Guide
The Brazilian General Data Protection Law (LGPD — Law 13,709/2018) is in full effect and applies to every organization that processes personal data — including sports schools, academies, and training clubs. If your school collects names, IDs, birth dates, addresses, photos, or any other data from children and adolescents, you need to be compliant.
And make no mistake: the risk is real. The National Data Protection Authority (ANPD) can impose fines of up to R$ 50 million per violation, in addition to administrative sanctions including suspension of data processing activities.
In this guide, you will find everything you need to know about LGPD in the context of sports schools: legal bases, parental consent, processing principles, storage limitations, and a practical compliance checklist.
Why Sports Schools Are on the LGPD Radar
Sports schools are environments of high volume and high sensitivity data:
- Basic personal data: name, ID number, address, phone, email
- Health data: medical certificates, exams, cardiological reports, physical fitness assessments
- Minors’ data: LGPD dedicates special attention to children and adolescents (Art. 14)
- Biometric data: photos, training videos, attendance records via facial or fingerprint recognition
- Location data: geolocated athlete check-in
- Financial data: tuition billing information, parents’ banking details
What Art. 14 of LGPD Says
Article 14 establishes that processing children’s and adolescents’ data must be carried out in their best interest and with specific and highlighted consent from at least one parent or legal guardian. This means:
- Consent must be an affirmative clear act — it cannot be presumed or inferred
- The data subject (or guardian) must be informed in a simple and accessible way about what data is collected, for what purpose, and for how long
- Data cannot be used for purposes different from those informed in the consent
Legal Bases for Data Processing in Sports Schools
LGPD provides 10 legal bases for data processing (Art. 7). For sports schools, the most relevant are:
| Legal Basis | Application |
|---|---|
| Consent (Art. 7, I) | Photos and videos for publicity, marketing, social media |
| Contract execution (Art. 7, V) | Registration data for enrollment, tuition billing |
| Legal obligation (Art. 7, II) | Invoice issuance, declaration for public agencies |
| Legitimate interest (Art. 7, IX) | Attendance records, internal sports performance evaluation |
| Protection of life (Art. 7, VII) | Health data in emergency situations during training |
Sensitive Data (Art. 11)
Health data (certificates, exams, medical reports) are classified as sensitive data and require additional protection. Consent for their processing must be:
- Specific: the form must describe exactly which health data will be collected
- Highlighted: visually separated from the rest of the enrollment form
- Clear purpose: “to verify physical fitness for practicing [sport]“
Consent in Practice: How to Draft It
The parental consent form is the most important document in your compliance program. Here is what it needs to contain:
Consent form structure
-
School identification: tax ID, address, legal representative, Data Protection Officer (DPO) contact
-
Minor’s identification: full name, date of birth, sport practiced
-
Data processing purposes (each must be accepted or rejected separately):
- Processing of registration data for enrollment and sports-academic management purposes
- Collection of health data for physical fitness assessment
- Photographic and audiovisual recording for internal use (technical evaluation)
- Photographic and audiovisual recording for social media and website publication
- Sharing with sports federations and confederations for competition registration purposes
- Sending communications, notices, and news via email, SMS, or WhatsApp
-
Storage period: how long data will be kept after the student leaves
-
Data subject rights: list of rights provided by LGPD (access, correction, deletion, portability, etc.) with instructions on how to exercise them
-
Legal guardian’s signature: with date and, preferably, electronic signature with IP and timestamp record
Example of accessible language
Instead of:
“The personal data collected will be processed in accordance with Law 13,709/2018, observing the principles of purpose, adequacy, and necessity…”
Prefer:
“We will store your child’s name, ID, and address for enrollment and class organization. Medical exams are archived so we know they can train safely. None of this will be shared with anyone outside the school, except when we register the athlete for competitions.”
Processing Principles You Must Follow
LGPD establishes 10 principles (Art. 6). For sports schools, the most impactful are:
Purpose
Data can only be collected for specific and informed purposes. You cannot ask for an ID “for registration” and then use that same ID to send sports product advertising without specific authorization.
Adequacy
Processing must be compatible with the informed purpose. If you collected health data to certify physical fitness, you cannot use it to profile performance without new consent.
Necessity
Collect only the strictly necessary data for the purpose. For school registration, you need name, date of birth, and parental contact — but probably not the voter ID number or grandparents’ professions.
Transparency
Data subjects (parents and students) have the right to know exactly what data you hold, where it is stored, and with whom it has been shared. Respond to access requests within 15 days (Art. 19, §3).
Security
Adopt technical and administrative measures to protect data against unauthorized access. This includes:
- Strong passwords and two-factor authentication for systems
- Data encryption at rest
- Role-based access control (secretary accesses registration data; fitness coach accesses health data; marketing does NOT access health data)
- Regular and secure backups
Storage and Disposal Limitations
How long to store?
- Registration data: for the duration of the relationship + 5 years (for legal defense, per Civil Code)
- Health data: for the duration of the relationship + Consumer Protection Code period (5 years)
- Attendance and performance data: for the duration of the relationship; afterwards, they can be anonymized for statistical purposes
- Publicity photos and videos: only while consent is in effect
Secure disposal
At the end of the storage period, data must be securely eliminated:
- Logical deletion of records from the system
- Physical document disposal (shredding)
- Deletion from backups containing the eliminated data
Parents’ and Athletes’ Rights (Art. 18)
Parents or guardians (and athletes themselves, when over 18) have the following rights:
- Confirmation of processing existence: know if the school holds the minor’s data
- Data access: receive a complete copy of stored data
- Correction: request correction of incomplete or outdated data
- Deletion: request data deletion, except when there is a legal obligation to retain it
- Portability: request data transfer to another school
- Consent revocation: at any time, cancel previously granted authorizations
- Information on sharing: know with whom data has been shared
Your school needs a service channel for these requests — which can be a DPO email or a form on the website.
Compliance Checklist for Sports Schools
Use this checklist to assess and fix your school’s situation:
LGPD Checklist for Sports Schools
- Appointed a Data Protection Officer (DPO), even informally, and published the contact
- Mapped all personal data the school collects (registration, health, photos, financial)
- Prepared a parental consent form with specific and highlighted purposes
- Each processing purpose can be accepted or rejected separately (granular consent)
- Consent forms are stored with evidence of date, time, and IP
- Implemented access control: each employee only accesses data necessary for their role
- Systems used (management software, CRM) have encryption and documented security policies
- Have a documented procedure to handle access, correction, and deletion requests
- Supplier contracts (software, accounting, marketing) include data protection clauses
- Conducted basic LGPD training with school staff
- Defined retention periods for each data category and secure disposal procedures
- Have a data breach incident response plan
- Publicity photos and videos have specific and separate authorization
Consequences of Non-Compliance
LGPD sanctions (Art. 52) include:
- Warning with a deadline for correction
- Fine of up to 2% of revenue, capped at R$ 50 million
- Publication of the violation (severe reputational damage for the school)
- Blocking or deletion of personal data subject to the violation
- Partial or total suspension of the database
For small schools, the fine may be applied on revenue, but even smaller penalty amounts can be devastating for the business.
Protect your students’ data and keep your school LGPD compliant. Torneyo offers sports school management with built-in data protection: digital consents, role-based access control, data encryption, and audit trail — everything so you can focus on what matters: developing athletes.