Skip to content
Constaia

Health data in sports registrations: GDPR Article 9

What the GDPR says about medical certificates in race sign-ups, the Spanish DPA fine over COVID certificates, and what organisers should really ask for.

By Constaia team6 min read

Also in: Español

Many sports registrations ask for a medical certificate: for an ultra, for a federation licence, for a summer camp. That piece of paper is health data, and the GDPR treats it as a special category with stricter rules than a name or an email address.

This article summarises what the regulation says, what we can learn from a real fine imposed on a Spanish sports federation, and what an organiser can and should not ask for. It is written for clubs, federations and registration platforms, with a Spanish case study but EU-wide rules.

Not legal advice

This is a general overview. Every case depends on your rules, national law and your activity. Check with your data protection officer or a lawyer.

Why a medical certificate is special category data

Article 4(15) of the GDPR defines data concerning health as personal data about a person's physical or mental health that reveal information about their health status. A certificate saying "fit for sport" falls within that definition, even without a diagnosis.

Article 9(1) prohibits processing health data. The prohibition only lifts if one of the exceptions in Article 9(2) applies. You also need a legal basis under Article 6. That is two cumulative requirements, not one.

The Article 9(2) exceptions people usually rely on

Not all of them fit sport. These are the ones that come up in practice:

ExceptionIn shortComment
9(2)(a)Explicit consent of the data subjectThe most common. Must be freely given, specific and informed, and can be withdrawn.
9(2)(c)Vital interests, where the person cannot consentMeant for emergencies, not ordinary registrations.
9(2)(g)Substantial public interest, on the basis of lawMember State law must provide for it.
9(2)(h)Preventive or occupational medicine, healthcareMember State or EU law must provide for it.
9(2)(i)Public interest in public healthMember State or EU law must provide for it.

National law matters here. In Spain, Article 9(2) of the LOPDGDD (the Spanish data protection act) requires processing based on points (g), (h) and (i) of GDPR Article 9(2) to be covered by a rule with the rank of law. A federation's rulebook or an internal protocol is not enough on its own. Other Member States have their own rules, so check yours.

On consent there is a debate worth knowing about: if handing in the certificate is a condition for racing, is consent really free? GDPR Article 7(4) asks you to consider whether a service is made conditional on consent that is not necessary for it. If your race rules require the certificate for athlete safety, document why it is necessary and collect the minimum.

The AEPD case: COVID certificates in handball

Decision PS-00263-2022 by the AEPD, the Spanish data protection authority, shows what can go wrong. The facts, according to the decision itself:

  • In the 2021-22 season, the Royal Spanish Handball Federation required athletes and other participants to provide a COVID-19 vaccination certificate or a negative antigen test in order to compete.
  • The documents were uploaded to a digital platform. The platform provider had signed a processor agreement under GDPR Article 28.
  • The federation relied on Articles 9(2)(c) and 9(2)(i), and later also 9(2)(g).

The AEPD concluded that:

  • 9(2)(c) did not apply: the requirement was imposed on every athlete, and it was not a case of someone unable to consent.
  • 9(2)(g), (h) and (i) required a rule with the rank of law enabling that processing in sports competitions, and there was none.

The outcome: a €20,000 fine for infringing Article 9 and €7,000 for Article 13 (information to data subjects). The AEPD found no infringement of Article 6(1). The decision dates from July 2023 (Iberley).

Three practical lessons:

  1. A processor agreement does not fix a missing legal basis. The Article 28 contract was in place and there was still a fine.
  2. Justify your Article 9(2) exception up front, not in your reply to the regulator.
  3. Transparency counts too: part of the fine was for Article 13.

Data minimisation and storage limitation

Two principles in GDPR Article 5 shape what to do with a medical certificate:

  • Data minimisation (Art. 5(1)(c)): adequate, relevant and limited to what is necessary. To decide whether someone can race you need to know whether they are fit, the date and who signed.
  • Storage limitation (Art. 5(1)(e)): do not keep data longer than necessary. If the certificate is only needed for one race, there is no reason to keep it for years.

A reasonable policy based on those principles:

  • Keep the result (fit yes/no, issue date, doctor registration number, holder name), not the file.
  • Do not extract or keep diagnoses, detailed restrictions, medication or test results.
  • Set a deletion date (for example, after the race and the appeals period) and enforce it automatically.
  • Limit who can see the document while it exists.

Controller and processor: who is who

  • Controller: whoever decides why and how the data is processed. Usually the race organiser, the club or the federation.
  • Processor (Art. 28): whoever processes data on the controller's behalf. A registration platform, or a document validation API.

Article 28 requires a contract or data processing agreement (DPA) setting out, among other things, that the processor acts only on the controller's documented instructions, the security measures, the use of sub-processors and what happens to the data when the service ends.

What an organiser can and should not ask for

Reasonable, if your rules justify it:

  • A certificate of fitness for sport, issued by a registered doctor, with a date.
  • The official template of the race or federation, if there is one.
  • A check that the holder is the registered participant.

Avoid:

  • Full medical reports, lab results or test outcomes when you only need to know whether someone is fit.
  • Keeping the PDF "just in case" with no deletion date.
  • Emailing certificates around the organising team.
  • Collecting health data without clearly explaining the purpose, legal basis and retention period (Art. 13).

Where Constaia fits

Constaia acts as a processor for whoever integrates it. It is designed so that minimisation is the easy path:

  • Processing in the EU: servers at Hetzner, Mistral OCR and models on AWS Bedrock eu-central-1.
  • storage: "none" by default: the file is deleted as soon as the analysis finishes.
  • keep_results: false: extracted fields are not stored either, only what is needed for billing.
  • extract with your own JSON Schema: ask only for the fields you need, nothing else.

If you use storage: "persistent", the file is kept until you delete it through the API: that is an option, not the default.

An example that extracts only fitness, date, doctor number and holder:

curl https://api.constaia.com/v1/analyze \
  -H "Authorization: Bearer $CONSTAIA_API_KEY" \
  -F file=@medical_certificate.pdf \
  -F 'options={
    "expect": "medical_certificate_sport",
    "extract": {
      "type": "object",
      "properties": {
        "patient_name": { "type": "string" },
        "issue_date": { "type": "string", "format": "date" },
        "doctor_license_number": { "type": "string" },
        "fit_for_sport": { "type": "boolean" }
      },
      "required": ["issue_date", "fit_for_sport"]
    },
    "checks": { "max_age_days": 365, "holder": { "full_name": "Lucía Fernández Ruiz" } },
    "storage": "none",
    "keep_results": false,
    "language": "en"
  }'

Constaia does not choose your legal basis or retention period for you: that is the organiser's responsibility. What it does is make sure you don't have to receive or keep more than you need. More in storage and privacy, checks and the /v1/analyze reference.

Checklist

  • I know which Article 9(2) exception I rely on, and it is documented.
  • My privacy notice explains purpose, legal basis, retention and recipients.
  • I only ask for the minimum: fit, date, doctor number, holder.
  • I don't keep the file or, if I do, it has a deletion date.
  • I have an Article 28 agreement with every provider that touches the certificates.

To see how it works with your own documents, create a free account. Test keys don't use credits and the free plan includes 250 credits a month.

Sources

  1. 01Regulation (EU) 2016/679 (GDPR), official text on EUR-Lex
  2. 02Spanish Organic Law 3/2018 (LOPDGDD), BOE
  3. 03AEPD — Sanctioning decision PS-00263-2022 (EXP202103924)
  4. 04Iberley — AEPD decision PS-00263-2022