PASP
SAFEGUARDING POLICY

PASP Safeguarding Policy — Institutional Framework for the Protection of Footballers

This Policy sets out the position, governance structure, principles and commitments of PASP in relation to abuse, harassment and any form of mistreatment in football, and brings together, as one coherent whole, all the individual documents, procedures and tools of the safeguarding system — serving as a complete institutional shield for both footballers and the Association itself.

Statement of Commitment

The Pancyprian Footballers' Association (PASP) is committed to ensuring an environment in which every footballer — male and female — can pursue their profession safely, with dignity and respect.

This Safeguarding Policy sets out PASP's position, obligations and the principles that govern every action PASP takes when it becomes aware of abuse, harassment, bullying, discrimination or any other form of mistreatment. It also serves as PASP's institutional shield, protecting both the individuals it supports and the Association itself, together with everyone who acts in good faith on its behalf.

1. Purpose and Scope

The purpose of this Policy is to set out clearly PASP's position on abuse and mistreatment in football, the obligations of everyone involved, and the principles underpinning every operational action taken by the Association.

This Policy applies to:

  • all PASP members;
  • PASP staff and associates;
  • members of the Board of Directors and the Safeguarding Committee;
  • any person acting on behalf of PASP.

This Policy covers any concern or report involving physical, sexual, psychological or emotional abuse, harassment, grooming, bullying, discrimination, retaliation, exploitation, digital abuse, threats, child-protection matters, and any other form of conduct that endangers a person's safety or dignity in the context of football.

PASP is, first and foremost, a footballers' association. Where a report concerns a person who is not a member (for example, a young academy player), PASP will offer a first hearing, an initial risk assessment, and guidance towards the appropriate external agencies, to the extent of its capacity and resources — without this amounting to PASP assuming the role of a statutory child-protection agency or other public authority.

What this Policy is NOT

PASP is not an investigative, judicial or disciplinary authority. This Policy does not replace criminal justice, the competent state authorities, or the disciplinary bodies of football governing bodies (the Cyprus Football Association, FIFA, UEFA).

PASP's role is to listen, support, assess risk, refer and accompany the footballer — not to determine anyone's guilt.

2. Definitions

For the purposes of this Policy and all accompanying documents in PASP's safeguarding system, the following terms have the meaning set out below:

Safeguarding The set of preventive, detection and response actions aimed at protecting individuals from abuse, harassment or mistreatment in the context of football.
First Responder Any person (staff, official, Board member) who first receives a report or a disclosure of concern.
Designated Safeguarding Lead The designated person who holds institutional responsibility for the management of PASP's safeguarding cases.
Grooming The gradual building of a relationship of trust with the aim of exploiting or abusing a person, often a minor.
Retaliation Any adverse treatment of a person because they made a report, disclosed a concern, or cooperated with an investigation.
Need-to-Know Principle Access to case information is granted only to persons with a genuine operational need to know.
Data Subject The natural person to whom personal data being processed relates.
Member / Non-Member A Member is a footballer registered with PASP; a Non-Member is any other person (e.g. an academy athlete, a former member, a third party) involved in a report.

3. Fundamental Principles

Every action taken under this Policy is governed by the following principles, applied consistently across all documents, procedures and forms in PASP's safeguarding system:

  • Player-Centred approach: the needs, safety and dignity of the individual come first.
  • Trauma-Informed approach: understanding how trauma affects memory, behaviour and communication.
  • Do No Harm: avoiding actions that could re-traumatise or expose the person to further risk.
  • Confidentiality & the Need-to-Know principle: information is shared only with those who have a genuine operational need to know.
  • Never alone: no case is ever managed by a single person.
  • Objectivity and impartiality at every stage of the process.
  • Duty of Care towards every person involved, including the staff managing the case.
  • Timely, coordinated response, without delays that could increase risk.

4. Prevention and Standards of Conduct

Safeguarding is not only a response to incidents — it is, first and foremost, prevention. PASP sets the following minimum standards of conduct for anyone acting on its behalf who is in contact with footballers, particularly minors:

  • Avoiding unjustified one-to-one contact with a minor without the presence or knowledge of a third adult.
  • Communicating through official, recorded channels; avoiding personal messaging with minors outside a professional context.
  • Respecting boundaries around physical contact, privacy (e.g. changing rooms), and photographing/filming minors.
  • Reporting promptly any observed conduct by a colleague that departs from the above standards — silence protects no one.

To the extent legally possible and reasonably proportionate, PASP encourages member clubs to carry out basic background/criminal-record checks (where provided for by law) for individuals who work regularly with young athletes, and to obtain a signed declaration of acceptance of the standards of conduct set out in this Policy.

5. Governance Structure and Responsibilities

Implementation of this Policy relies on a clear allocation of roles, so that every person knows what is expected of them, and so that both the footballer and the staff member managing the case are protected.

PASP Board of Directors Approves the Policy and the resources required for its implementation. Is informed of serious cases without identifying details, where necessary.
Executive President Approves external communications and statements on active cases. Decides on exceptional cases involving full support for non-members.
Safeguarding Committee (three members) Assesses risk using the Risk Assessment Matrix, oversees active cases, convenes review meetings, and maintains the Risk Register.
Designated Safeguarding Lead Receives same-day internal escalation, decides on opening a case file, approves the Case Action Plan and referrals.
Deputy Safeguarding Lead Deputises for the Safeguarding Lead and takes part in risk assessment and review meetings.
Data Protection Officer (DPO) Oversees lawful processing of personal data, breach notifications to the Cyprus Commissioner for Personal Data Protection, and data subject access requests.
First Responders Any staff member, Board member or associate who may receive a report — listens, supports, assesses immediate risk, and escalates the same day.
Legal Department / Legal Counsel Provides legal assessment, explains the options available and any reporting obligations, without replacing independent legal representation where that is needed.

The composition and the names of the persons holding the above roles are kept in a separate internal register, which is updated by the Board of Directors.

6. Reporting in the Event of a Conflict of Interest

If a concern or complaint involves the Safeguarding Lead, the Deputy Safeguarding Lead, a Board member or the Executive President, the person reporting may — and is encouraged to — approach any other member of the Safeguarding Committee, Legal Counsel, or, where necessary, the competent external authorities directly. The person involved is automatically excluded from any stage of assessment, decision-making or management of that specific case.

7. The Reporting and Case Management Process

The full operational procedure is set out in detail in the document 'PASP Safeguarding Case Management Procedure'. This section presents the summary flow, so that everyone has a clear, overall picture:

  1. Receipt of the report — from any person, through any channel, including anonymously.
  2. First Response — the First Responder listens, supports, and applies the SAFER model.
  3. Immediate safety check — identifying any immediate risk.
  4. Emergency protective measures, where required (call 112 wherever there is a risk to life).
  5. Same-day internal escalation to the Safeguarding Lead.
  6. Opening of a case file, with a unique case reference number.
  7. Determining the process applicable, based on the person's status (member, non-member, anonymous, third party).
  8. Initial risk assessment, within 24 hours, using the Risk Assessment Matrix.
  9. Explaining consent and confidentiality to the person.
  10. Drawing up a Case Action Plan.
  11. Activating referrals for legal, psychological or social support.
  12. Legal assessment, where required.
  13. Implementing protective measures.
  14. Deciding on any external report to the competent authorities.
  15. Ongoing monitoring of the case and checking for any indications of retaliation.
  16. Review meetings, where required.
  17. Closing the case once PASP's institutional role has been completed.
  18. Reviewing lessons learned and improving policies and procedures.

Every stage of the above process is documented using the standardised forms listed in Annex A of this Policy, ensuring consistent, complete and secure record-keeping from start to finish of every case — documentation that is also the primary evidence that PASP acted promptly, prudently and in accordance with this Policy.

8. Risk Assessment

PASP systematically assesses the risk of every incident through the PASP Risk Assessment Matrix (v2.0), which is maintained and updated by the Safeguarding Committee. The methodology combines four dimensions:

  • Likelihood (1–5): how likely the incident is to occur or recur.
  • Severity (1–5): how serious the consequences are for the individual.
  • Vulnerability (1–3): whether the person is a minor or belongs to a vulnerable group.
  • Impact (1–5): the potential effect on the team, the club, public image, or at legal/regulatory level.

This combination produces two separate outputs: an Action Plan for the individual (Matrix A) and a Handling Plan for the organisation (Matrix B). Every incident is categorised into one of the following levels:

LOW 1–4 Acceptable risk. Annual review.
MODERATE 5–9 Action within 30 days. Monthly monitoring.
HIGH 10–14 Urgent action within 7 days.
CRITICAL 15–25 Immediate action. Escalation to the Board / Police / Commissioner for Personal Data Protection, as applicable.

The initial, qualitative risk estimate is made during First Response (through the Immediate Safety Check), and the formal, quantitative scoring is completed by the Safeguarding Lead within 24 hours, using the Risk Assessment Form and the Matrix. The Risk Register also tracks risk at the organisational level — both safeguarding risks and data-protection and operational-capacity risks — and is reviewed regularly by the Safeguarding Committee.

9. Zero-Tolerance Policy on Retaliation

PASP applies a zero-tolerance policy towards any form of retaliation against a person who makes a report, discloses a concern, cooperates with an investigation, or refuses to take part in abusive conduct. Any indication of retaliation is treated as a separate, high-risk incident, triggering immediate review of the risk assessment.

  • Protection from retaliation also covers staff or officials who report a concern about the conduct of a colleague or a superior (whistleblowing).
  • No adverse consequence is permitted against a person who reported in good faith, even where the concern is ultimately not substantiated.
  • Conversely, deliberately false or malicious reports are not covered by this protection and are addressed separately, without this discouraging good-faith reports that later turn out to be inaccurate.

Full details are set out in the standalone document 'Anti-Retaliation Policy', which forms an integral part of this Policy.

10. Confidentiality and Data Protection

Managing safeguarding incidents necessarily involves the processing of particularly sensitive personal data. PASP is committed to the following fundamental principles, which are further elaborated in the GDPR & Confidentiality Procedure:

  • Data minimisation: only the information strictly necessary to manage the case is collected and recorded.
  • Need-to-know access: every access to a case file is logged in the file's Access Log.
  • Lawful basis for processing: processing relies, depending on the circumstances, on the legitimate interest of protecting the individual, vital interest in cases of immediate risk, a legal reporting obligation, or the person's consent.
  • Retention period: data is retained only for as long as necessary, in accordance with the periods set out in the GDPR & Confidentiality Procedure.
  • Breach notification: any personal data breach is notified to the Cyprus Commissioner for Personal Data Protection within 72 hours, where required.
  • Data subject rights: every person has the right to access their data; requests are answered within 30 days.
  • Point of contact: PASP's Data Protection Officer (DPO) is available for any query concerning data processing.

This section sets out the fundamental commitments. Their detailed implementation (who sees what, exact retention periods, deletion procedures, lawful bases per scenario, breach notification) is described in the standalone document 'GDPR & Confidentiality Procedure', which forms an integral part of this Policy.

11. What You Can Expect from PASP — Support for Footballers

If you are experiencing or are aware of an incident of abuse, harassment or mistreatment, PASP is here to support you in the following ways:

Someone to listen to you

You can speak to any PASP staff member or official, in person, by phone, or in writing (including SMS/email/messaging) — even anonymously. You do not need to have decided what you want to do; support does not require a formal complaint.

Psychological support

PASP can refer you to a psychologist, psychiatrist, or trauma specialist, and coordinate your access to these services.

Legal guidance

You will be clearly informed of the legal options available to you — what you can do, what mandatory procedures apply (if any), and where to seek independent legal representation. PASP will never pressure you to pursue a particular legal route, unless required by law.

Procedural support

You will be given a step-by-step explanation of what will happen, who will be informed and why, and what the limits of confidentiality are. You will never be left without updates on the progress of your case.

Information on risks and available resources

PASP will inform you of resources you may use, such as:

  • Emergency number: 112 — in the event of immediate danger.
  • FIFPRO — the international players' union.
  • The competent protection or disciplinary body of the Cyprus Football Association (CFA), as well as of FIFA/UEFA where applicable.
  • Social welfare services, child-protection services, or domestic-violence support services.
  • Consular authorities, where the matter relates to residence status or a foreign national.

Our aim is for you to have a full picture of your options, so that you — informed and supported — can decide what you want to do next.

12. Communications and Media Handling

No information relating to an active or closed safeguarding case is disclosed publicly, to the media, or on social media, by anyone other than the Executive President, and always in consultation with the Safeguarding Lead, Legal Counsel and the DPO. Any public enquiry about a safeguarding case is referred to the Executive President, in order to avoid exposing the affected person, undermining ongoing investigations, or exposing PASP to legal risk.

13. Equality and Non-Discrimination

This Policy applies equally to every person, regardless of gender, nationality, religion, disability, sexual orientation, gender identity, or any other personal characteristic. PASP recognises that certain groups may face greater barriers to reporting concerns, and is committed to ensuring accessible, easily understood reporting channels for everyone.

14. Support for Individuals Acting in Good Faith

Individuals who act in good faith and within the bounds of this Policy (First Responders, Safeguarding Committee members, the Safeguarding Lead, Board members) are fully supported by PASP, including — where such cover exists and is applicable to the specific case — appropriate insurance or institutional liability cover for actions taken in good faith in the course of their duties. The precise scope and terms of any insurance/institutional cover are determined by the Board of Directors and set out in a separate internal document.

15. Limits of this Policy

PASP recognises the limits of its institutional role and does not seek to substitute for responsibilities that belong elsewhere:

  • PASP does not conduct criminal investigations, does not interrogate, and does not determine anyone's guilt.
  • PASP does not maintain permanent, in-house legal or technical staff specialised in every aspect of safeguarding or data protection; for this reason it works with external experts (legal counsel, the Data Protection Officer, psychologists) so that the Policy is applied correctly, practically, and in a way everyone can understand.
  • No commitment in this Policy exceeds what applicable law provides; where the law requires a specific action (for example, mandatory reporting in a case involving a minor), that requirement prevails over any other provision of this Policy.
  • This Policy is applied with foresight and ease of understanding, so that it is practically usable by people who are not lawyers or technocrats, without this reducing its seriousness or completeness.

16. Training and Awareness

All staff, Board members and Safeguarding Committee members receive regular training in the Ready to Respond framework, the SAFER model, trauma-informed practice, and the use of the forms and the Risk Assessment Matrix. The need for further training is reviewed after every serious case, as part of the lessons-learned review.

17. Review and Improvement of the Policy

This Policy is reviewed by the Board of Directors at least once a year, as well as immediately following any serious case, any change in legislation, or the identification of a gap during the lessons-learned review of a case.

Version Date Description
v1.0 Initial approval of the Safeguarding Policy.

Annex A — Related Documents of the Safeguarding System

This Policy is the central reference document of a single, unified system. It operates together with the following documents, which should be read as a whole:

PASP Ready to Respond Handbook Guidance on First Response, the SAFER model, and the trauma-informed approach.
Safeguarding Case Management Procedure The full operational procedure in 25 stages, from receipt of the report to closure of the case.
Anti-Retaliation Policy The zero-tolerance policy on retaliation.
Safeguarding Reporting Form Initial record of the report.
Disclosure & Incident Record Form Guided, live-use recording form for use during the conversation with the individual — also covers written/asynchronous disclosure.
Risk Assessment Form & PASP Risk Assessment Matrix (v2.0) Detailed risk assessment and scoring, per incident and at Risk Register level.
Case File Opening & Case Action Plan Form Opening of the case file and the case management plan.
Referral Form Referrals to external support services or authorities.
Case Monitoring & Retaliation Log Ongoing monitoring of the case and of any indications of retaliation.
Case Closure Form Closure of the case.
Case File Cover Sheet & Access Log Case file cover sheet and access log — ensures a full audit trail.
GDPR & Confidentiality Procedure Detailed procedure on data access, retention and deletion, lawful bases for processing, and breach notification.

Approval and Effective Date

Version
Date Approved by the Board of Directors
Effective Date
Next Scheduled Review Date
Executive President, PASP — Signature & Date
Safeguarding Lead — Signature & Date
Data Protection Officer (DPO) — Signature & Date

Prepared by Cerberus Data Protection Services

|