Sunday, 23 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in

TechRadar ·
Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in

With the 2026-27 season kicking off this weekend, Premier League football teams are facing a new set of rules.

But these ones aren’t enforced on the pitch, they’re being enforced by the Premier League board.

As the Premier League has adapted to a new era of fan engagement and interaction, teams are holding huge amounts of personal data, including names, email addresses, credentials, and even financial information.

These place them at greater risk of data leaks and make them a primary target for cyber attacks.

In order to ensure teams take the necessary steps to protect both their data and the data of their fans, the board can impose fines of up to £100,000 for teams that don’t meet the requirements across backups, incident response, risk management, security assurance and much more.

What do the new rules mean for Premier League teams? The teams previously had to align with a non-prescriptive security baseline issued in 2024, but the new rules place requirements on teams with deadlines for their implementation.

If these deadlines are not met, the teams can be subject to the aforementioned fine, or referred to an independent commission. (Image credit: Future) Got an opinion for us? Here’s how you can submit your perspective The teams will be required to meet the first set of requirements by April 30, 2027, with further requirements to be met in April 2028 and April 2029.

The teams will also have to assess their own compliance by January 10 each year, with a final assessment and evidence submitted to the Premier League board by April 30.

The board can also request additional detail and evidence where needed to track a team’s progress in adhering to the new rules.

If a team does not meet requirements during the interim stage it must submit a plan on how it aims to become compliant within 28 days.

Expert perspectives on Premier League cybersecurity rules Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress: The Premier League introducing mandatory cybersecurity standards is the right move, but the detail is where the questions start. £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.

The phased timeline, April 2027, 2028, 2029, is pragmatic but slow given the threat environment.

Waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link. £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.

That said, the direction is unambiguously right.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›