Summary
The Arsenal Football Club Limited (‘Arsenal’, ‘we’, ‘us’) is the controller and responsible for protecting your personal data and handling it responsibly.
This policy covers the personal data that Arsenal processes whenever you interact with us, including when you engage with us online (such as on social media or by using our websites and apps), when you attend events at Emirates Stadium, and when you correspond with us (such as by email or over the phone). It also covers personal data that we may receive from third parties.
The sections below explain in more detail:
- the types of personal data we collect from you
- the types of personal data we receive from third parties
- why we process your personal data
- who we share your personal data with
- personal data transfers outside of the UK
- how long we retain your personal data
- your rights to withdraw your consent and to object (including to direct marketing)
- your other personal data rights
- how to contact us and exercise your rights
If you would like to know how we collect information about your use of our websites, apps and social media sites, you can read our Cookies Policy here.
Whilst interacting with us, you may decide to follow links to websites which are operated by third parties who control the collection and use of your personal data. In these situations, Arsenal does not control how your personal data is processed and therefore you should read the privacy policy and cookie policy (as applicable) located on such third-party websites.
Personal data Arsenal collects from you
We collect personal data from your interactions with us, such as when you engage with us online (such as on social media or by using our websites and apps), attend an event at Emirates Stadium, or when you email or phone us.
The personal data we collect from you includes:
- the name and contact details that you provide when you register as a member with us
- your purchase, payment and address details
- your marketing preferences, including any consents you have given us
- your browser or device information
- information about your use of our websites and apps
- information about your engagement on social media, including on accounts belonging to Arsenal, our staff and our players
- your communications with us
- information about your attendance at Arsenal events, such as matches, concerts and conferences held at Emirates Stadium. Photos and video footage of you may be taken at these events
- information you provide us to comply with our site entry procedures
- information you provide as part of a job application process with the Club, including your employment history
- if you are a Member of My Arsenal Rewards: (i) information about your qualifying purchases and activities, so that we can award you with Rewards Points; and (ii) information about your redemption of Rewards Points on Rewards
- information you provide us as part of a survey
Personal data Arsenal receives from third parties
Sometimes we receive personal data from third parties, in particular:
- our commercial partners provide us with your name and contact details if you’ve asked to receive information from Arsenal. Click here to see a list of our current partners
- ticketing providers and overseas ticketing agents let us know if you’ve purchased tickets to an event at Emirates Stadium
- access control providers let us know if your tickets have been used at Emirates Stadium
- online personalisation providers tell us how you engage with our websites and apps
- data specialists provide us with insights about our supporters, based on their own aggregated data sets
- if you register for Digital Membership using your social media account, the social media platform provides us with information that you have consented to share with us
- government and law enforcement authorities provide us with personal identification and background information when they are involved in official inquiries
- finance providers may inform us about a credit arrangement you have with them for Arsenal season tickets
- agencies who partner with Arsenal in the Community may share information with us about participants that we refer to them
- other football clubs and football authorities (such as the Premier League, The Football Association or The Union of European Football Associations (‘UEFA’)) may provide us with personal data to, amongst other things: (i) assist in preventing violent and antisocial behaviour at matches, (ii) enforce sanctions under the Premier League’s Commitment Regarding Abusive and Discriminatory Conduct, (iii) combat ticket touting, and/or (iv) support with handling fan inquiries
- if you are a My Arsenal Rewards Member, Rewards Affiliates and/or Fortress (GB) Limited may share information about you with us so that we can administer your Membership
Why Arsenal processes your personal data
This section explains the reasons why we process your personal data and our legal bases for doing so.
Consent
If you’ve opted-in to receive information and offers relating to the Club and our commercial partners (for example by ticking a box on one of our websites or apps), then we’ll provide this information to you by email, text, or phone. Click here for a list of our current partners.
We also rely on your consent to process information about your use of our websites, apps and social media sites, so that we can improve your browsing experience and deliver online advertising that is relevant to you (for more information, click here to see our Cookies Policy).
“And occasionally we may rely on your consent to process racial or ethnic origin, health, sexual orientation or other sensitive information..
Wherever we rely on your consent to process personal data, you have a right to withdraw that consent. Click here for information on how to exercise your rights.
Legitimate interests
We process your personal data when necessary to pursue our legitimate interests in the following:
- tailoring our websites and communications for you. We collect information about your engagement with us online (such as pages that you have visited on our websites or apps) and combine that with aggregated insights we have about our supporter base, to build a fuller understanding of your individual preferences
- monitoring, improving and protecting our products, content and services
- monitoring and enforcing compliance with our ticketing terms and conditions and ground regulations
- preventing abusive, discriminatory or otherwise inappropriate or offensive behaviour, whether in person or online, that is directed towards any football club (including their players or other members of staff), match official or any other individual attending or involved in a football match
- administering any Membership you have with us
- checking the credit or debit card details you provide (to process your payments and prevent fraudulent transactions)
- sending you some types of direct marketing, including by email and post
- responding to your comments or complaints
- undertaking, or inviting you to take part in, market research or surveys
- querying whether you have had an issue completing an online form
- preventing, investigating and/or reporting fraud, terrorism, misrepresentation, security incidents or crime
- to protect the health and safety and security of our spectators, staff and other visitors to our sites; to enforce our terms and conditions and ground regulations; and to help detect and prevent unlawful activity using, for example, incident reports and CCTV footage
- managing legal claims, compliance, regulatory and investigative matters
- processing job applications received through www.careers.arsenal.com
- administering programmes run by us or our partner agencies that you have chosen to participate in
You have a right to object to any processing that we undertake for our legitimate interests. Click here for information on how to exercise your rights.
Contract
We process your personal data when necessary for contractual reasons, such as to administer your account registration and competition entries and to provide products and services that you have requested.
Legal obligation
We are legally required to process your personal data in cases where we need to:
- obtain parental consent to provide online services directly to children
- respond to certain requests by government or law enforcement authorities
- comply with local Council safety requirements to collect CCTV footage of particular areas around Emirates Stadium
Sensitive data
In limited circumstances, we may need to process your sensitive personal data, such as race or ethnicity data, health data, biometric data, or data about criminal offences. This will only ever be where we meet a lawful condition for such processing, such as where we have your consent, where the data has been made public by the data subject, or where processing is necessary for: the prevention or detection or unlawful acts, the substantial public interest, or legal claims.
Who Arsenal shares personal data with
We may share your personal data with the following recipients:
- Arsenal Broadband Limited, a company within the Arsenal Holdings Plc Group, for the purpose of administering our websites and apps
- commercial partners, so they can advise us how best to communicate with you on their behalf. We do not give your data to partners for them to communicate with you directly. Click here to see a list of our current partners
- Facebook, so that we can display relevant advertising to you on their platform (your data is converted into a unique ID before it is shared with Facebook)
- third party suppliers involved in: data insights; website hosting; online personalisation; advertising; tracking online abuse; systems maintenance; ticketing; database management; identity checking; payment processing; delivery logistics; facilities management; and credit and debt management
- organisations undertaking official data scout spotting activities within Emirates Stadium
- public authorities or law enforcement officials, to assist with their official requests and comply with our legal obligations.
- recruitment and vetting agents, to assist with our recruitment processes
- other football clubs and football authorities (such as the Premier League, The Football Association, or UEFA), where this is necessary to, amongst other things: (i) ensure the safety and security of supporters, (ii) assist in preventing violent or antisocial behaviour at matches, (iii) enforce sanctions under the Premier League’s Commitment Regarding Abusive and Discriminatory Conduct, (iv) combat ticket touting, (v) support with handling supporter inquiries, or (vi) if we think it’s appropriate to inform them of incidents at Emirates Stadium involving supporters
- if you are a My Arsenal Rewards Member, we may share information about you with Rewards Affiliates and/or Fortress (GB) Limited in order to administer your Membership
- our advisers, any prospective purchaser’s advisers, and any new owners of the business (in the event our business is sold or integrated with another business)
- agencies who partner with Arsenal in the Community (if you have been referred to those agencies through us)
Personal data transfers outside of the UK
Where your personal data is transferred to a country outside of the UK, and that country is not subject to a UK Adequacy Regulation, we will ensure your data is protected by appropriate safeguards (for example, approved standard contractual clauses or a supplier’s Binding Corporate Rules). A copy of the relevant safeguard can be provided for your review on request – click here to see how to contact us.
How long Arsenal retains personal data
We retain personal data about your membership for as long as your account remains active, and for a limited period of time afterwards (in case you decide to reactivate your membership or have queries about it).
We retain personal data relating to your purchases for several years from the date of the relevant transaction. This is to understand your purchasing preferences and to meet our legal and contractual obligations. If your purchase has enduring relevance (such as a Celebration Corner plaque) then we’ll keep relevant information for as long as we remain responsible to you for that purchase.
Where you have asked us not to send you direct marketing, we keep a record of that fact to ensure we respect your request in future.
We keep a record of call centre recordings for 27 months and CCTV security footage for 30 days, unless we need to hold this data for longer to resolve an issue or to meet a legal requirement.
We also retain information with the potential to give rise to legal disputes for 7 years.
Your rights to withdraw consent and to object (including to direct marketing)
Wherever we rely on your consent to process personal data, you always have a right to withdraw that consent. Click here to see the situations where we rely on your consent.
You also have the right to object to any use of your personal data for direct marketing purposes, as well as to processing that we undertake based on our legitimate interests Click here to see the situations where we process data for our legitimate interests.
Click here for information on how to exercise your rights.
Your other personal data rights
In addition to your rights to withdraw your consent and to object, you have the right to ask us:
- for access to information about your personal data or for a copy of your personal data
- to correct or delete your personal data
- to restrict (i.e. stop any active) processing of your personal data
- to provide you with certain personal data in a structured, machine readable format and to transmit that data to another organisation
These rights may not always apply, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law to keep or have a compelling legitimate interest in keeping. If this is the case then we’ll let you know when we respond to your request.
Click here for information on how to exercise your rights.
How to contact us and exercise your rights
The easiest way to stop receiving information from us is by opting out of communications through your online preference centre (this is linked to in our communications with you and is accessible at times via your account settings). You can also correct your registration details through your online account.
We will do our best to assist with any queries you have about your personal data within 30 days of receipt. You can contact our Data Protection Officer at any time using the contact details below. When you do so, please provide your full name, your preferred contact information, and a summary of your query.
dpo@arsenal.co.uk |
Data Protection Officer Arsenal Football Club |
To comply with the General Data Protection Regulation (2016/679) we have also appointed a European representative. If you wish to contact them, their details are as follows:
Bird & Bird GDPR Representative Services SRL
Avenue Louise 235
1050 Bruxelles
Belgium
EUrepresentative.ArsenalFC@twobirds.com
If you have unresolved concerns, you also have the right to complain to an EU data protection authority where you live, work or where you believe a breach may have occurred. This is likely to be the Information Commissioner’s Office in the UK (www.ico.org.uk).
Last updated 05 March 2024
We suggest that you check back here for updates, as we will update this policy from time to time.
Copyright 2024 The Arsenal Football Club Limited. Permission to use quotations from this article is granted subject to appropriate credit being given to www.arsenal.com as the source.