Many non-profits assume the GDPR only concerns businesses. It does not: as soon as an organisation keeps a membership list — even a simple spreadsheet — it is processing personal data, and the regulation applies. The good news: for an ordinary association, compliance comes down to a handful of common-sense measures.
A membership list is “processing”
Name, address, email, telephone, joining date, dues paid: all of that is personal data. Handling it — collecting it, storing it, using it to send out the notice for the annual meeting — is processing under the GDPR. Consent is not needed for most of it: managing members rests on the performance of the membership agreement. That basis, however, only covers what is necessary to run the organisation.
The five obligations that matter
1. Keep a record of processing activities
A simple document listing what you do: membership management, newsletter, tax receipts, and so on. For each one: purpose, data used, who has access, how long it is kept. Supervisory authorities publish templates; for an association, two pages are often enough.
2. Collect only what you need
Is the date of birth useful to how you operate? The occupation? If you cannot answer “yes, because…”, delete the column. Pay particular attention to special category data: health, religion, opinions. Some organisations need it by their very nature (a religious body, a patients' association) — the rules there are stricter.
3. Set retention periods
The rule: a member's data is kept for the duration of membership, then deleted or archived. In practice:
- current member: kept as normal;
- former member: up to three years after the last contact (for renewal approaches);
- accounts and tax receipts: ten years (accounting obligation);
- attendance list from a general meeting: as long as the resolutions can be challenged.
4. Inform people and honour their rights
The membership form must say, in one sentence, who processes the data, why, for how long, and how to exercise one's rights. Any member may ask to see their data, to correct it or to have it erased (within the limits of legal obligations — an accounting entry cannot be deleted).
5. Secure the file
This is the most often neglected point, and the most concrete:
- the Excel spreadsheet emailed to the whole committee is the worst case: uncontrolled copies, diverging versions, no record of who saw what;
- a central management tool with named accounts and rights by role (the treasurer sees payments, the branch organiser sees their own branch) settles most of it;
- backups must be automatic, and the provider hosted in Europe.
What about the newsletter? And photographs?
Two cases that fall outside the membership agreement:
- Newsletter to non-members: their consent is required (a tick box, not pre-ticked) and an unsubscribe link in every message.
- Photographs of members on the website: image rights come on top of the GDPR — written permission is needed, particularly for minors.
What to take away
GDPR compliance for an association is not a mountain: a simple record, a minimal and well-kept file, decided retention periods, a sentence of information on the membership form, and a tool that traces who accesses what. The right tool does half the work — the rest is a matter of collective discipline.
The membership management tools we build have these requirements designed in from the start: rights by role, access history, configurable retention periods. Let's talk.