arrow_back All policies

AI Use Policy

How we use artificial intelligence tools, and the rules that protect our members when we do.

Version 0.1 DRAFT · 12 August 2026 · Draft for Board approval

pending Draft — pending Board adoption

1. Who we are and why we have this policy

1.1 Tenpin Ireland is the National Governing Body (NGB) for tenpin bowling in Ireland. As an NGB, we hold personal data on members, volunteers, officials and juniors, and we are accountable for how that data is handled, including where artificial intelligence (AI) tools are involved in our work.

1.2 This policy exists because our Governance Audit & Gap Analysis identified a specific gap in our governance library: an AI Use Policy, referenced in our own governing framework and an emerging Sport Ireland and EU AI Act expectation, was absent. This document closes that gap.

1.3 The gap has become more pressing because the EU AI Act's main transparency and high-risk obligations became applicable on 2 August 2026. While Tenpin Ireland is a small NGB and not an operator of high-risk AI systems (see section 8), we are expected to have a documented, proportionate policy governing our use of AI, and to be able to show our members and our regulators that we have one.

1.4 This policy is document 10 in our Data Protection Suite, alongside our Privacy Policy, Children's Data Policy, Parental Consent Form, Data Breach Procedure, SAR Procedure, Retention Schedule, ROPA and Privacy Policy in Plain English. It should be read together with those documents, not in isolation.

2. Scope

2.1 This policy applies to the Board, all sub-committees, officers, employees, volunteers and any contractor acting on Tenpin Ireland's behalf, whenever they are using AI in connection with Tenpin Ireland business.

2.2 It applies to every AI tool we use, whether a paid business subscription or a free consumer tool, including but not limited to AI assistants such as Anthropic's Claude, AI-assisted writing or design tools, and AI features embedded in other software we use.

2.3 Anyone covered by this policy who uses AI in Tenpin Ireland work is expected to have read it. This is how we meet our obligation under Article 4 of the EU AI Act to ensure a sufficient level of AI literacy among people acting on our behalf.

3. What we use AI for — and what we never use it for

3.1 AI assistants currently assist us with three main categories of work. First, drafting: documents, correspondence, governance papers and website content, always subject to human review and approval by a responsible officer before anything is used or published. Second, building administrative tooling, such as the rollout kit developed for our digital membership card project. Third, supporting the administration of the organisation itself — including helping the Treasurer keep track of Tenpin Ireland's own accounts and payments in and out, and preparing core grant material. In all cases, AI is a drafting and productivity aid — it does not act, decide, or publish on our behalf.

3.2 We never use AI to make decisions about people. Team selection is carried out by human selectors against published selection criteria. Membership approval and discipline are handled by the relevant human officers and committees under our existing rules. AI plays no role in selection, membership approval, discipline, or any other decision that would produce a legal or similarly significant effect on an individual. This mirrors the protection GDPR Article 22 gives individuals against solely automated decision-making, and we apply it as a matter of principle even where Article 22 might not strictly bite.

4. Personal data in AI tools — the stripped-dataset rule

4.1 Our starting principle, consistent with data minimisation under GDPR Article 5(1)(c) and data protection by design under Article 25, is that AI tools should see the minimum personal data needed to do the job, and ideally none at all.

4.2 We must never enter special category data, children's data, or vetting/Garda-related data into an AI tool, under any circumstances. The same prohibition applies to members' financial data, such as bank account or card details. For the avoidance of doubt, this restriction protects the personal data of individuals — it does not prevent AI being used to help administer Tenpin Ireland's own organisational accounts, as described in section 3.1.

4.3 Our digital membership card project, documented in "Digital Membership Cards — Data Protection Statement" (9 July 2026), is the model for how we apply this in practice. For that project, a stripped extract was created carrying only surname, first name, membership number and membership type. Dates of birth, home addresses, email addresses, phone numbers, guardian details and emergency contacts never entered the card system at all. Email addresses needed for the rollout were held in a separate working file, outside the card dataset, and used only at send time; the send log retains membership numbers only, and the separate email file is deleted once the rollout is complete. Benefit partners such as Lanetalk and Tenpin Toolkit received no membership data, and the cards themselves use random, non-guessable tokens rather than identifiable references. This "stripped dataset, built for purpose" approach — take only what the task needs, and no more — is the standard we expect for any future project involving AI and member data.

4.4 Where a proposed use of AI would require anything beyond name and membership-number level data, it must first be signed off by the DPO.

5. Children first

5.1 The age of digital consent in Ireland is 16, under section 31 of the Data Protection Act 2018, and children's personal data receives specific protection under our Children's Data Policy.

5.2 Children's personal data must never be entered into an AI tool, in any form and for any purpose. Correspondence relating to junior members continues to be addressed to parents or guardians, as set out in our Children's Data Policy, and this does not change because AI is used to help draft the correspondence.

6. Accuracy and honesty

6.1 AI tools can produce fluent, confident text that is nonetheless wrong. Anything published under Tenpin Ireland's name must be factually accurate, and facts published on our website or in official communications must come from Tenpin Ireland's own records or other verified sources. AI must never be used to invent names, dates, prices, results or contact details.

6.2 The responsible officer who approves a piece of AI-assisted content for use or publication is accountable for its accuracy, in the same way they would be for content they drafted entirely themselves. AI assistance does not reduce that accountability, it sits alongside it.

7. Transparency

7.1 Using AI to help draft documents, correspondence or website content is now normal practice at Tenpin Ireland, in the same way a template or a spellchecker is a normal drafting aid. It does not need to be labelled or disclosed on the finished document, provided section 6 has been followed and a human has reviewed and approved the result.

7.2 Imagery is different. We have replaced AI-generated imagery on our website and in our materials with real photographs of Tenpin Ireland events, and we intend to keep it that way. Any AI-generated image that could be mistaken for a real person or a real event must either be clearly labelled as AI-generated or, preferably, not used at all.

7.3 If Tenpin Ireland ever proposes to deploy a chatbot or similar interactive AI system for members or the public, users must be clearly and directly informed that they are interacting with AI, in line with Article 50 of the EU AI Act.

8. Our position under the EU AI Act

8.1 Under the EU AI Act, Tenpin Ireland is, at most, a deployer of general-purpose AI tools provided by others (such as Claude). We are not a developer of AI systems, and we do not operate any high-risk AI system. We do not use biometric identification, emotion recognition, AI-based recruitment tools, or AI-based athlete-scoring or ranking systems.

8.2 If any officer or committee ever proposes a use of AI that would touch a high-risk category listed in the EU AI Act, or that involves a chatbot as described in section 7.3, that proposal cannot proceed on the say-so of one officer. It requires prior Board approval, a data protection impact assessment, and review by the DPO before any work begins.

8.3 Our obligation under Article 4 of the AI Act to ensure AI literacy among our people is met by requiring every officer, volunteer or contractor who uses AI in Tenpin Ireland work to have read this policy, as set out in section 2.3.

9. Security and incidents

9.1 Where practical, AI tools should be accessed through business accounts rather than personal ones, and before any member data is put anywhere near an AI tool, we check the provider's terms to confirm an appropriate processor agreement is in place, consistent with our obligations under GDPR Article 28.

9.2 If anyone suspects that a personal data incident has occurred involving an AI tool — for example, personal data entered where it should not have been, or an AI-generated output disclosing personal data incorrectly — it is handled exactly as any other suspected data breach, following our Data Breach Response Procedure.

9.3 Subject access requests relating to AI-assisted processing follow our existing SAR Procedure. Retention of any personal data that does end up connected to AI-assisted work follows our Retention Schedule.

10. Roles and review

10.1 The Board owns this policy and is responsible for approving any proposed use of AI that falls outside the everyday drafting and administrative uses described in section 3.

10.2 The DPO monitors compliance with this policy, provides sign-off under section 4.4, and is the first point of contact for any question about whether a particular use of AI is appropriate.

10.3 The President maintains this policy and keeps it aligned with our other governance documents and with developments in the law.

10.4 This policy will be reviewed annually, or sooner if the regulatory position changes.

Contact

By post: Tenpin Ireland, Irish Sport HQ (NGB Building), National Sports Campus, Blanchardstown, Dublin 15.
DPO email: [email protected]

Prepared by the President for the Executive Board · 12 August 2026