Confidentiality and security in TMS

Table of contents

This article refers to the following provision of the FIFA regulations:

Introduction

When accessing TMS, clubs and Member Associations must maintain the confidentiality of all data in the system, exercise the highest degree of care to protect it and use confidential data only to complete player transfers in which they are directly involved. They must also ensure that only their appointed authorised TMS users access TMS on their behalf.

To comply with these obligations, each user must read and agree to the “Terms of use of FIFA services” and the “TMS service descriptions” before accessing TMS to ensure that the information accessed via the system is kept confidential.

In this regard, TMS users must not provide screenshots or data extracts from TMS to any party that does not have the same level of access as the TMS user responsible for the information. Likewise, TMS users must take particular care regarding social media and ensure that no information, documents, or images from TMS are shared on any platform.

Data accessed through TMS may be used only to complete player transfers in which the TMS user is directly involved and for no other purpose.

Clubs and Member Associations that breach their obligations as TMS users may be fined up to CHF 30,000 under the administrative sanction procedure and other sanctions may be imposed by the FIFA Disciplinary Committee.


Security measures in TMS

TMS users can also contribute towards making the system even more secure by following these security tips:

  • Do not leave papers lying around: avoid printing or downloading documents from TMS.
  • Do not write your password down: choose a good password you can remember or store it in a password safe.
  • Do not share your password: your password is personal. Never share it with anyone.
  • Keep your computer up to date: talk to your IT administrator about activating automatic operating system and application updates.
  • Protect your computer: make sure you have firewall and antivirus software installed and active.
  • Be diligent: do not click blindly on links sent to you by email. Only open documents you expect and receive from people you trust. Be suspicious and verify that the email was sent by the apparent sender.
  • Use a secure network connection: avoid accessing TMS from public wireless connections.
  • Stick to safe locations: avoid accessing TMS from home, cyber cafés or your mobile device whenever possible.
  • Make sure your building or office space is secure: fingerprint, badge access, or locks should be used to control access to the workspace.
  • Know your employees: conduct a background check before hiring anyone.

To continuously improve the security of the system, FIFA has adopted many security measures, including, but not limited to:

  • Security management: a process has been implemented to constantly improve the security of TMS.
  • User monitoring: TMS accounts that have been inactive for over 18 consecutive months may be deactivated.
  • Security testing: TMS is regularly assessed and tested by external security experts, and any vulnerabilities identified are resolved.
  • High-security infrastructure and firewall: FIFA has opted for Europe’s leading hosting provider, which holds a security certificate according to ISO 27001 and applies the highest information security standards.
  • User background checks: all appointed users undergo a thorough background check by FIFA to ensure that they are suitable for the role. FIFA reserves the right to reject a new user request if the user is deemed to be unsuitable.
  • Access control: access to documents and data in TMS is granted on a need-to-know basis only to the parties involved.
  • Short session duration: after 15 minutes of inactivity in TMS, the user will be automatically logged out of TMS.
  • Watermarks on documents uploaded to the system: once a document is uploaded in TMS, a FIFA watermark is applied to the document.
  • Password policy: when users activate their TMS account for the first time, they must choose a password in line with our security policy: the password must be at least eight characters long and include at least one capital letter, one lower-case letter, one number and one special character. The system prompts the user to change their password in TMS at regular intervals.
  • Secure connection to TMS: a user’s browser connects to TMS servers over a secure and encrypted connection using an official certificate.
  • Database backup: point-in-time and weekly backups of the database are stored in a secure location to prevent data loss.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article

Back to top