Guides · 2026-07-25
GDPR and Membership Data: A UK Club Guide
Every UK club holds personal data: names, email addresses, phone numbers, often dates of birth for junior sections, sometimes medical notes. That makes your club a data controller under the UK GDPR, whether or not anyone on the committee has ever used the phrase. This is a practical guide to GDPR and membership data for UK clubs — what you're actually required to do, and what a membership system should do for you.
General guidance, not legal advice. For anything contentious — a data breach, a complaint to the ICO, children's data at scale — take proper advice.
Yes, it applies to your club
A common misreading is that GDPR is for businesses. It applies to any organisation processing personal data, including unincorporated members' clubs, charities and volunteer-run societies. There is no small-club exemption. What varies is proportionality: the ICO expects a 200-member rugby club to do less than a bank, but not nothing.
Most clubs also need to pay the ICO's annual data protection fee — a modest amount, but worth checking on the ICO's own site rather than guessing.
The six things that actually matter
- Know what you hold and why. A one-page list of what data you keep, where it lives, and what it's for. Most clubs discover their data is in four places: a spreadsheet, a membership system, someone's email, and a WhatsApp group.
- Have a lawful basis. For membership administration this is usually contract (you need the data to provide membership) or legitimate interests. Marketing to non-members is where you generally need consent.
- Collect only what you need. If you don't use date of birth for anything, don't ask for it. Data minimisation is the cheapest compliance measure there is.
- Keep it secure. A membership spreadsheet emailed between committee members is the single most common weak point in UK club data handling.
- Delete it when you're done. Set a retention period — say two years after membership ends — and actually apply it.
- Be able to answer a request. Members can ask what you hold about them, ask for a copy, and ask you to delete it.
The spreadsheet problem
Be honest about how most clubs run: a membership list in a spreadsheet, emailed around, copied to personal laptops, with three versions in circulation and no idea which is current. Under GDPR that's a problem on several axes at once — security, accuracy, retention, and your ability to honour a deletion request. You cannot delete a member from a spreadsheet that exists in five inboxes.
Moving membership data into one system with access control isn't just tidier; it's the step that makes the other obligations achievable.
What to look for in a membership system
| Obligation | What the system should do |
|---|---|
| Security of data at rest | Encrypt personal fields, not just the connection |
| Subject access request (Art. 15) | Export everything held on one member |
| Data portability (Art. 20) | Export in a machine-readable format such as CSV |
| Right to erasure (Art. 17) | Genuinely delete a member and their cards |
| Consent | Record when consent was given or withdrawn |
| Accountability | An audit trail of who did what |
Digital Cards Club provides these directly: member fields are encrypted at rest, you can export a single member's data or the whole membership, delete a member and cascade that deletion to their wallet passes, anonymise instead of deleting where you need to keep aggregate records, and record consent and withdrawal against a member. Audit logs come with the Pro plan.
Erasure has to reach the wallet pass too
A detail most people miss. If a member asks to be erased and you delete the database row but leave their name sitting in a wallet pass file on a server somewhere, you haven't erased them. Deletion has to cascade — the member, their passes, and any cached copies of those passes. It's worth asking any supplier this question specifically, because "we deleted the record" and "we deleted the data" are not the same sentence.
Your supplier is a processor — get that in writing
If you use any membership platform, they process personal data on your behalf. You remain the controller; they're the processor. You should have a written data processing agreement, know where the data is stored, and know who else can see it. Ask any supplier for these before you upload a membership list, and treat vagueness as an answer.
Junior sections need extra care
Children's data attracts additional protection. In practice, for a club with a junior section: collect through the parent or guardian, keep only what the activity genuinely requires, be careful with photographs, and set a shorter retention period than for adults. If you hold medical or safeguarding information, that's special category data and needs a stricter basis and tighter access — usually restricted to named welfare officers rather than the whole committee.
A realistic first afternoon
- Write down every place membership data currently sits. Include inboxes.
- Consolidate into one system with named committee members having access, and delete the stray copies.
- Write a short privacy notice — what you collect, why, how long, and who to contact — and put it on the club website and the membership form.
- Set a retention period and diarise an annual purge.
- Check whether you need to pay the ICO fee.
That's most of the way there for a typical club, and it's an afternoon's work rather than a project.
A membership system that takes this seriously
Start free — five cards, no card details needed. Your members' data is encrypted, exportable and deletable from day one, on the free plan as much as the paid ones. Plans from £0, and see how to digitise club membership cards for moving off the spreadsheet.
Keep reading
- Membership Renewals and Expiry Reminders Done Right Cut lapsed memberships: put the expiry date on the card, segment your renewal emails by who actually turned up, and reissue in a day.
- Reduce Membership Admin with Digital Cards Which membership admin jobs digital cards remove, which they do not, and what a 200-member UK club gets back in volunteer hours.
- Digital Wallet Passes Explained for UK Small Businesses What digital wallet passes are, what UK small businesses use them for, and how to start — memberships, loyalty, tickets and more.