June 15, 2026

GDPR and data protection for children at a karate dojo

GDPR for a karate dojo isn't just a formality for large companies — any school that collects names, ages, emergency contacts, or medical notes about children falls directly under the regulation. The difference between a dojo that takes this responsibility seriously and one that ignores it isn't visible day to day, but becomes very visible the moment a parent asks what data is stored about their child, or requests that it be completely deleted. This guide explains what data protection concretely means for a dojo.

What data about a child does a dojo actually collect?

Beyond name and age, an active dojo frequently collects: the parent's emergency contact, medical notes relevant to the child's safety during training, consent (or refusal) for photos published on social media or the website, and attendance and progress history. Each of these categories has a different level of sensitivity — a name and current belt are relatively public within the dojo, but medical notes and emergency contacts are truly private data that shouldn't be visible to just anyone on the team.

Many schools collect this data correctly at enrollment, but then store it carelessly — on paper, in Excel files emailed around, with no real access restrictions.

Who should have access to a student's sensitive data?

The basic GDPR rule is access minimization: only people who genuinely need a piece of information should be able to see it. For a dojo, that means medical data and emergency contacts should be visible to the instructor directly responsible for that student, the school's admin, and the parent — not to any other instructor or assistant working with a different group.

This separation is often hard to implement manually (a single Excel file can't have different permissions per row), which is why most dojos, out of convenience, treat all data the same way — which in practice means excessive exposure of private information.

What does a data access or deletion request concretely involve?

Under GDPR, a parent has the right to request a complete copy of the data stored about their child (the right of access) and the right to request its complete deletion (the right to erasure), for example when the child leaves the dojo for good. A dojo that keeps records scattered across different files — Excel, WhatsApp, paper notes — can't fully respond to such a request, because the information is spread across different places, held by different people.

A correct response to a deletion request means removing the data from every place it exists: the student's profile, attendance history, belt history, messages, fee records — not just deleting a row from a main table.

What happens to the data when a student or instructor leaves?

A student leaving the dojo doesn't automatically mean their data must be deleted immediately — a dojo can have legitimate reasons to keep a minimal history (for financial records, for example). But if the parent explicitly requests complete deletion, the dojo must be able to actually carry out that request, not just hide the student from active lists.

The same discipline applies in reverse: when an instructor leaves the team, their access to student data must be revoked immediately, not left active "just in case" — an old, forgotten-but-active account is exactly the kind of vulnerability a GDPR audit flags.

Dojo Master separates students' sensitive data (emergency contact, medical notes, photo consent) into a restricted-access area, distinct from the general profile visible within the dojo, and offers a complete export and permanent deletion of a student's data — from every collection, in one place — at the request of a parent or admin. It's exactly the workflow described above, but automated, rather than manually reconstructed from scattered files.

Request access for your dojo
← Back to the blog