Blacklion Golf Club

Privacy & Data Protection Policy (incorporating CCTV Policy)

Data Controller: Blacklion Golf Club Ltd (Company No. 22817), Toam, Blacklion, Co. Cavan.

Updated: August 1, 2026. Version: 2.0.

Who we are

Blacklion Golf Club Ltd is a registered company (No. 22817) with its registered office at Toam, Blacklion, Co. Cavan. For the purposes of data protection law, Blacklion Golf Club is the registered data controller. This policy governs how the Club collects, uses, maintains and discloses information collected from members, visitors and users (each a "User") of our premises, our website (the "Site") and all products and services we offer.

We process personal data in line with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

How to contact us

For any data protection query, to update your details, or to exercise your rights, contact the Hon. Secretary at blackliongc@gmail.com, or by post at Blacklion Golf Club, Toam, Blacklion, Co. Cavan.

Information we collect

Depending on your relationship with the Club, we may collect and hold the following:

Name, address and contact details (including email address and phone number).

Date of birth and gender.

Golf handicap and playing record.

Bank/payment details (for subscriptions, green fees and orders).

CCTV recordings (see the CCTV Policy below).

Health information relating to the use of buggies (special category data — see "Special category data" below).

We collect this information when Users interact with the Club or the Site — for example when joining, renewing, placing an order, booking, subscribing to the newsletter, responding to a survey, or filling out a form. You may visit the Site anonymously. We only collect personal information that you voluntarily provide, though withholding certain information may prevent you from taking part in some activities.

Non-personal information: we may also collect technical information when you use the Site, such as browser type, device type, operating system and internet service provider.

Our lawful basis for processing

Under GDPR we must have a lawful basis for each use of your personal data. We rely on:

Contract — to administer your membership, process orders and bookings, and manage handicaps and competitions.

Legitimate interests — to run the Club efficiently, communicate with members, protect our premises, and secure the safety of members, staff and visitors (including CCTV).

Legal obligation — to meet accounting, tax and other statutory requirements.

Consent — for marketing communications you have opted into, and for the health information described below. You may withdraw consent at any time.

Special category data (health information)

Health information relating to buggy use is "special category" data under Article 9 GDPR and receives extra protection. We process it only on the basis of your explicit consent, which you provide in writing (for example through a buggy/medical exemption form). We use it solely to assess and record buggy eligibility, we restrict access to authorised officers only, and we delete it when it is no longer needed. You may withdraw your consent at any time by contacting us.

How we use your information

To administer membership, subscriptions, competitions and handicaps.

To respond to customer service requests and support needs.

To process payments and confirm orders and bookings (a confirmation email is sent following receipt of payment).

To send you information and updates relating to your order, and to respond to your enquiries.

To send periodic emails and newsletters where you have opted in.

To understand, in aggregate, how Users use the Site and to improve our services.

Keeping your information accurate

The accuracy of your information is important to us. If your details change, or you want to update anything we hold, please contact us at blackliongc@gmail.com or by post at the address above.

Cookies

Our Site may use cookies to enhance your experience. Under the ePrivacy Regulations, we ask for your consent before placing any non-essential cookies (for example analytics or advertising cookies); strictly necessary cookies do not require consent. You can manage or refuse cookies through our cookie banner or your browser settings, though some parts of the Site may not function properly if you do.

How we protect your information

We apply appropriate collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction of your personal data. Where we take card payments through the Site, we use a provider that is compliant with PCI-DSS standards.

Sharing your information

We do not sell, trade or rent your personal information. We may use trusted third-party service providers to help us operate the Club and the Site (for example to send newsletters or surveys, or to process payments), and we share your information with them only to the extent necessary to provide that service and under appropriate data protection terms. We may share aggregated, non-identifying information with partners. We may disclose personal data where required to do so by law or to An Garda Síochána.

Transfers outside the European Economic Area

Personal data within the European Economic Area (EEA) is protected by EU data protection law. Some online tools we use may store data outside the EEA. Where that happens, we ensure an appropriate safeguard is in place before transferring your data — for example, transferring only to countries with an EU adequacy decision, to US providers certified under the EU-US Data Privacy Framework, or under the European Commission's Standard Contractual Clauses.

Your rights

Under GDPR you have the right to:

Access the personal data we hold about you.

Have inaccurate data corrected (rectification).

Have your data erased in certain circumstances.

Restrict or object to our processing of your data.

Data portability, where applicable.

Withdraw consent at any time, where we rely on consent.

To exercise any of these rights, contact us at blackliongc@gmail.com. We will respond within one month.

How long we keep your information

Member information is retained on our systems and in document form for seven years after a member exits, to meet legal and financial obligations. Visitor information is retained until the visitor asks us to remove it (opt out). CCTV footage is retained as set out in the CCTV Policy below. We securely delete or anonymise information once it is no longer needed.

Data breaches

We will report any personal data breach to the Data Protection Commission and, where required, to the individuals concerned, without undue delay.

Third-party websites

Our Site may contain links to other websites. We do not control and are not responsible for the content or privacy practices of those sites. Browsing and interaction on any linked website is subject to that website's own terms and policies.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the date at the top. We encourage you to review this page periodically.

Complaints

If you have a concern, please raise it with us first at blackliongc@gmail.com. You also have the right to complain to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 — www.dataprotection.ie.

Blacklion Golf Club — CCTV Policy

Version: 1.1 Effective date: 1 August 2026

1. Purpose

This policy explains how Blacklion Golf Club ("the Club") operates its closed-circuit television (CCTV) system in line with the GDPR and the Data Protection Act 2018. CCTV footage that can identify individuals is personal data, so it is processed lawfully, fairly and transparently.

2. Objectives of the system

The Club operates CCTV only for the following purposes:

Preventing, deterring and detecting crime, vandalism and anti-social behaviour.

Protecting the safety and security of members, staff, visitors and the public.

Safeguarding Club property, equipment and premises.

Checking course access and payment of green fees before access to facilities.

Footage is not used for routine monitoring of staff performance or member conduct.

Note: The green-fee/course-access purpose is an operational rather than a security use, and does involve observing members and visitors. It is defensible under legitimate interests, but keep it proportionate and make sure signage and this policy make clear it is one of the stated purposes.

3. Lawful basis

The Club relies on legitimate interests (Article 6(1)(f) GDPR) — the security and safety purposes above — as balanced against the rights of individuals. Where CCTV involves staff, obligations under employment and data protection law are also observed.

4. Areas covered

Cameras are located at: Front car park, side clubhouse and greenkeeper area, Caddy Shack, and First Tee.

Cameras are positioned to capture only what is necessary and do not cover areas where individuals have a heightened expectation of privacy (e.g. toilets, changing rooms). Audio recording is not used.

5. Signage

Clear signs are displayed at entrances and monitored areas stating that CCTV is in operation, the purpose, the identity of the Club as data controller, and contact details for data queries.

6. Retention

Footage is retained for 28 days and then automatically overwritten or securely deleted, unless it is required for an ongoing investigation, legal claim or a request from An Garda Síochána, in which case the relevant footage is retained for as long as necessary for that purpose.

7. Access and disclosure

Access is restricted to authorised personnel only: elected officers of the golf club.

Footage is stored securely and protected against unauthorised access.

Footage may be disclosed to An Garda Síochána or other authorities where lawfully required. A log of any disclosure is kept.

8. Individuals' rights

Any individual recorded has the right to request access to footage of themselves (a subject access request), and rights to rectification, erasure and to object, subject to the conditions in GDPR.

To make a request, contact the Hon. Secretary at blackliongc@gmail.com. The Club responds within one month. Requesters should provide enough detail (date, time, location) to locate the footage; footage of other identifiable people may be redacted or blurred.

9. Data Protection Impact Assessment (DPIA)

Where CCTV involves large-scale or systematic monitoring (including of staff areas), the Club completes a DPIA before deployment and reviews it periodically.

10. Responsibility and review

The person responsible for this system and policy is the Hon. Secretary. This policy is reviewed at least annually and updated as required.

11. Complaints

Concerns should first be raised with the Club at blackliongc@gmail.com. Individuals also have the right to complain to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 — www.dataprotection.ie.