The league now asks for evidence.
Rule J.9 and Appendix 11 expect a club to show how it protects critical systems and data, not simply state that it does.
AccountabilityContracts, medical files, scouting data, ticketing and broadcast agreements now sit inside a rulebook that demands proof, not intention. Offline Secure Storage® holds a copy of everything the club cannot lose on dedicated hardware with no standing network path, released only to a verified named user, with every session logged as evidence. Deadlines are already running.
Premier League clubs now face 22 mandatory information security control areas under Rule J.9 and Appendix 11. Our explainer sets out the requirements, the deadlines and the UK GDPR exposure that sits behind them in plain English.
Rule J.9 and Appendix 11 expect a club to show how it protects critical systems and data, not simply state that it does.
AccountabilityIf the copy the club depends on sits on a reachable network, an attacker who owns the network owns the recovery plan too.
RecoveryTurnstiles, safety systems and broadcast obligations do not wait while a club decides how to contain an incident.
ContinuityRegistrations, medical files and commercial agreements must remain retrievable long after the people who filed them have moved on.
RetentionWe map our controls to the outcomes clubs are being asked to evidence. We do not claim certification on a club's behalf, and a vault is not a substitute for the club's wider security programme.
Use this as the shortlist before the compliance deadline. Each row states what a club has to show and what a physically disconnected copy contributes.
Recovery → Access → Evidence → Suppliers → Containment → RetentionWhat clubs must show: Clubs must hold recoverable copies of critical data and prove they can restore after an incident.
How OSS helps: A physically disconnected copy of the club's critical records that ransomware on the club network cannot reach, encrypt or delete.
What clubs must show: Access to club systems and data must be controlled, verified and reviewed.
How OSS helps: One vault, one named user. Every session begins with identity verification and ends with the drives physically disconnected again.
What clubs must show: Clubs must be able to show who accessed what, and when.
How OSS helps: Every retrieval records the user, the device, the files and the timestamp, giving the club an evidence pack for the league and the ICO.
What clubs must show: Clubs are accountable for the suppliers, agencies and platforms that hold club data.
How OSS helps: Contracts, player records and commercial agreements held offline under the club's sole control, rather than spread across supplier clouds.
What clubs must show: Clubs must be able to contain an incident and keep operating on a match day.
How OSS helps: Firevault Control adds a governed physical disconnect, so a compromised path is severed without waiting for somebody to reach the hardware.
What clubs must show: Player, staff and supporter data carries UK GDPR obligations and retention duties.
How OSS helps: Long-retention records, medical files and academy paperwork stored offline for the retention period, with access on request only.
Keep live match-day, training and commercial platforms exactly where they are. Offline Secure Storage is for the smaller category of club information that must survive an incident, prove a position or satisfy a retention duty.
Contracts, registrations, medical files, scouting reports and academy paperwork that must survive any incident.
Football operationsSponsorship contracts, image rights, broadcast schedules and settlement paperwork held offline until they are needed.
CommercialHistoric ticketing, membership and hospitality records that no longer need to sit on a live, internet-facing platform.
Supporter dataConfiguration records, plans and evidence for access control, turnstiles, safety systems and match-day operations.
Match dayA club rarely buys storage. It buys the ability to answer a question from the league, an auditor, a regulator or a board, with a record rather than an assurance.
Evidence that the club can demonstrate the required control areas before the compliance deadline.
A recovery set the club actually controls, plus a physical containment option for match day.
Registrations, contracts and league correspondence retained and retrievable on request.
Player medical and performance data held offline under strict access rules.
Session-level access evidence for UK GDPR Article 32 and ICO enquiries.
Sponsorship and broadcast agreements protected from exposure during a supplier incident.
A club should not have to become a security vendor. Firevault changes the state of the selected data itself, so the evidence follows from the design.
Club records are held on physical storage allocated to the club rather than pooled cloud capacity.
When the vault is closed there is no standing network path to the selected club data.
Access is linked to a verified named user, not a shared departmental account.
Each session is logged, so the club can answer league, auditor and regulator questions with a record.
At Firevault, we have developed a control blueprint that is designed to physically sever power, taking physical control of the network in under six milliseconds. On a match day, that is the difference between a contained incident and a stadium operating blind.
The goal is a defensible position on the records that matter most, not simply more storage.
Online when the club needs it. Offline when it does not. Our team will scope the capacity, the users and the jurisdiction with you.