Platform · Data protection
GDPR & privacy
The federation's data protection console — consent age, erasure requests and retention rules. Changes are audited.
The federation's art. 8 consent age — the age at which a child can give their own data-processing consent. This is not the age of majority at 18 (membership/licence).
Consent age (art. 8)
Reference — consent age per nation
| Country | Consent age | Basis |
|---|---|---|
| SE | 13 years | Section 13 of the Swedish Data Protection Act |
| FR | 15 years | LIL art. 45 |
| DE / NL | 16 years | EU ceiling (art. 8.1) |
Two distinct thresholds — never mixed. The consent age (13–16) governs own data-processing consent. The contractual age of majority at 18 governs membership/licence. A 14-year-old in Sweden gives their own data consent but needs a guardian to take out a licence.
Art. 17 requests. A request is never granted automatically — you decide via the approval flow. Self-service gets a 30-day grace period.
AllAwaiting decisionGrace periodIn progressDoneRejected
| # | Person | Source | Requested | Status | |
|---|---|---|---|---|---|
| DR-1042 | Elin Karlsson | Self-service | 2 Jul | Awaiting decision | Open → |
| DR-1041 | Omar Ali | Self-service | 30 Jun | Grace period · erased in 27 d | Open → |
| DR-1039 | Sven Berg | Club admin (on behalf of member) | 28 Jun | In progress | Open → |
| DR-1035 | [removed] | Self-service | 20 May | Done · evidence created | Open → |
| DR-1030 | Lisa Nord | Self-service | 12 May | Cancelled by the user | Open → |
| DR-1028 | Kari Vik | Supervisory authority | 2 May | Rejected · ongoing investigation | Open → |
📭
No erasure requests in this view.
⏳
Loading requests…
Supervisory/cross-tenant requests arrive via the platform's DSAR tracker.
How long each data category is stored, with legal basis. Categories with a statutory minimum override art. 17 erasure.
Active · v4 · reviewed 12 Jun| Category | Subcategory | Retention (days) | Legal basis | Overrides Art. 17 | |
|---|---|---|---|---|---|
personal_data | — | 0 (as long as the account exists) | Contract / consent | — | ✎ |
competition_results | — | 0 (kept de-identified) | Legitimate interest | — | ✎ |
financial_records | — | 2 555 (7 years) | Swedish Accounting Act | 🔒 Yes | ✎ |
accounting_records | — | 2 555 (7 years) | Swedish Accounting Act | 🔒 Yes | ✎ |
audit_logs | — | 3 650 (10 years) | Accountability | — | ✎ |
consent_records | — | 365 | Compliance | — | ✎ |
media | — | 730 (2 years after inactive) | Consent | — | ✎ |
discipline_records | — | per decision / legal hold | Legal obligation | 🔒 Yes | ✎ |
health_special_category | — | per national health law | Art. 9 condition | 🔒 Yes | ✎ |
whistleblower_records | not_investigated | 730 (~2 years after closure) | EU 2019/1937 | — | ✎ |
whistleblower_records | investigated | per national law / legal hold | Legal claim | 🔒 Yes | ✎ |
gdpr_notifications | — | 1 825 (5 years, Art. 33(5)) | Art. 33(5) | 🔒 Yes | ✎ |
Edit rule · whistleblower_records
Statutory minima are enforced automatically; the retention sweep purges/anonymises expired rows via the same path.