Skip to content
Tietosuoja haltuun harrastustoiminnassa -hankkeen logo, jossa on tietosuojalainsäädäntöön ja lapsiin liittyvä kirjainlyhenne GDPR4CHLDRN. Tietosuoja haltuun harrastustoiminnassa -hankkeen logo, jossa on tietosuojalainsäädäntöön ja lapsiin liittyvä kirjainlyhenne GDPR4CHLDRN.
Search
  • English
    • Suomi
    • Svenska
    • English
  • Front page
  • Guiding materials
    • Board of the association
    • Coaches and instructors
    • Parents
    • Children and young people
  • Material bank
    • Term bank
    • Quizzes
    • Downloadable materials
    • Data protection icons 
    • Articles
  • Information on the site
  • English
    • Suomi
    • Svenska
    • English
  • Front page
  • Guiding materials
    • Board of the association
    • Coaches and instructors
    • Parents
    • Children and young people
  • Material bank
    • Term bank
    • Quizzes
    • Downloadable materials
    • Data protection icons 
    • Articles
  • Information on the site
Search
  1. Front page
  2. Board of the association
  3. What should you take into account when processing health data in hobby activities?
Skip to page content

Board of the association

  • Starting page
  • Why is the protection of personal data important?
    • 1. Privacy is a fundamental right
    • 2. Sensitive personal data requires particularly careful protection
    • 3. Personal identity codes may only be processed if necessary
  • What roles are involved in processing?
    • 1. The controller is responsible for the processing of personal data
    • 2. A processor acts on behalf of the controller
  • What principles must be observed in the processing of personal data?
    • 1. Take data protection into account from the start and in all circumstances
    • 2. Processing requires a basis
      • 2.1 Legal bases for processing personal data
      • 2.2 Consent requires an indication of the participant's wishes
      • 2.3 Consent from minors
    • 3. Only use personal data for the planned purposes
    • 4. Inform data subjects transparently of the processing of personal data
    • 5. Only process necessary personal data
    • 6. Only process accurate personal data and rectify inaccurate data
    • 7. Ensure the security of processing
    • 8. Define storage periods for personal data and erase unnecessary data
      • 8.1. Storage period
      • 8.2. Storage location
      • 8.3 Erasure 
    • 9. Demonstrate compliance with data protection legislation
  • What obligations does a hobby organiser have in the processing of personal data?
    • 1. Fulfil the participants' data protection rights
    • 2. Describe the hobby organiser's processing of personal data with a record of processing activities
    • 3. Agree on processing
    • 4. Assess the risks and impact of processing
    • 5. Report personal data breaches
    • 6. Only transfer personal data out of the EU if the conditions are met
    • 7. Give people involved in the hobby instructions and training in data protection
    • 8. Manage the life cycle of personal data from planning to collection, storage and erasure
  • What should you take into account when publishing photos and videos?
  • What should you take into account when processing health data in hobby activities?
  • What should you take into account when disclosing personal data in hobby activities? 
  • Annex 1: Consent form - template
  • Annex 2: Comics to inform about data protection

What should you take into account when processing health data in hobby activities?

The icon features a rectangle depicting information. There is an eye crossed over with a line on the bottom right corner of the rectangle. The icon is surrounded by a light green frame. The icon can be used to indicate the processing of special categories of personal data or instructions for such processing.



Information on a child’s allergies, illnesses or medication is often essential for guaranteeing the child’s health and safety in hobbies and leisure activities.

Health data is a special category of personal data, the processing of which is generally prohibited. The processing of health information can be permitted, for example based on the data subject’s consent. If health data is collected based on the consent of the child or their representative, they must only be requested to provide health data necessary for the child’s health and safety.

Data may not be collected just in case or for possible future needs. For example, it is not permitted to collect data on food allergies if there is no appropriate basis and need for it at the time. The hobby organiser must be able to demonstrate that the child or their representative has given their explicit consent for processing the child’s health data.

Jump to section about consent

Example

The coach of a Finnish baseball team sends the parents of children who join the team a link to a form asking for information on the child’s illnesses or medication which the coach should be aware of during training to ensure the child’s health and safety. The baseball club has instructed coaches to collect the players’ health data with the form in question, so that the children’s health information will be obtained in the manner specified by the club and only the appropriate coaches who need to process the data can do so.

The child’s custodian logs into the form with two-factor authentication. The form asks the custodians to only report illnesses and medication that the coaches need to know about to ensure the child’s health and safety during training. The form also asks for consent for the processing of health data and states that the consent can be withdrawn at any time. Since consent for processing the child’s health data is being requested with an electronic form, the baseball club will be able to demonstrate that the custodian has given their consent for the processing of the child’s health data and that the club has a basis for processing the data in question.

What should you take into account when publishing photos and videos?
What should you take into account when disclosing personal data in hobby activities? 
The logo of the Office of the Data Protection Ombudsman.
The logo of TIEKE Finnish Information Society Development Centre.

The European Union flag, with the text "Funded by the European Union" on its right-hand side.

Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Commission. Neither the European Union nor the granting authority can be held responsible for them.

Information on the website

The site contains material that provide information on data protection legislation and the protection of personal data, especially for children and young people aged 13–17, their parents, and associations that organise hobby activities. The website has been developed in the GDPR4CHLDRN – Ensuring data protection in hobbies project (2022–2024) implemented by the Office of the Data Protection Ombudsman and TIEKE.

Feedback about the site can be given by e-mail to the address tietosuoja@om.fi. In the message field, you must mention tietosuojaharrastuksissa.fi, so that the feedback is directed to the correct address.

  • Data protection on the website
  • Accessibility statement
Guiding materials
  • Board of the association
  • Coaches and instructors
  • Parents
  • Children and young people

© 2024 Office of the Data Protection Ombudsman and TIEKE. The site uses free Font Awesome icons. The icons have not been changed. License: CC BY 4.0

Touched by Hutcode