Log in

GDPR for associations

GDPR for associations, explained so the board can act on it

What the data protection rules practically require of a Danish association, and how to keep members' information gathered, secured, and under control.

What GDPR practically requires of an association

An association processes personal data the moment it keeps a member list, collects dues, or sends an email. As soon as names and contact details are involved, the data protection rules apply, whether the association is large or small. It's not something only businesses have to deal with.

The core idea boils down to a few principles. You need a reason to process the information, typically because it's necessary to run the membership or has been agreed with the member. You should keep only the information you actually need, and not hold on to it longer than necessary. And you should store it securely, so only the right people have access.

Only what's necessary, and no longer than necessary

Data minimisation means you shouldn't gather information just because you can. Does the association need the member's national ID number, or are name, address, and year of birth plenty? The fewer sensitive details you store, the less can go wrong, and the easier it is to comply with the rules.

The same goes for time. When a member resigns, their information shouldn't sit gathering dust forever. Some things may need to be kept for a while for the sake of, say, accounting, but the rest should be deleted once the purpose is gone. A fixed cleanup routine is easier to live up to than a case-by-case judgement, and it's far easier when the information lives in one place rather than spread across spreadsheets and inboxes.

The pitfall: data spread across spreadsheets and private inboxes

The most common weakness in associations isn't bad intent, but spread. The member list sits in a spreadsheet on the treasurer's computer, a copy has been sent as an attachment in an email thread, a former chair still has last year's version, and nobody knows anymore which one is the correct one.

The problem is that no one has an overview of where the members' information is, who can see it, or when it should have been deleted. If a member wants access to or deletion of their information, you don't even know where all the copies are. That's the situation the rules are first and foremost trying to prevent.

One system, controlled access, and a data processing agreement

The simplest thing many associations can do is gather members' information in one place instead of in scattered files. When the member register, dues, and communication live in the same system, there's one place to clean up, one place to search, and one place to give a member access to or delete their information.

A single system also brings access control: you decide who can see what, so not every volunteer has access to all information. And when you use a supplier to store member data, there should be a data processing agreement describing that the supplier only processes your data on your instructions. Medlemsplatformen gathers the information, gives you control over access, and provides a data processing agreement, so the practical foundation is in place.

Sensitive minutes and incidents need extra care

Some of the information an association handles is more sensitive than an address. A set of board minutes may contain a personnel matter, and an incident report may concern an injury or an unpleasant episode. That kind of thing shouldn't be freely available to all members or float around in private emails.

So it matters that sensitive content can be kept internal and seen only by those it concerns. In Medlemsplatformen you can keep minutes internal to the board and publish a public version when it's ready, and incidents follow a fixed process where sensitive information is handled responsibly. This page is general guidance, not legal advice. If you're in doubt about your specific situation, seek qualified advice or read more at the Danish Data Protection Agency (Datatilsynet).

Frequently asked questions

Does GDPR even apply to a small association?

Yes. As soon as you keep a member list with names and contact details, you're processing personal data, and the rules apply regardless of the association's size. For most associations, though, it comes down to a few principles and ordinary decency, not heavy legal work.

What is a data processing agreement, and do we need one?

It's an agreement with the supplier that stores your member data, stating that they may only process data on your instructions. If you use a system to hold member information, a data processing agreement should come with it. Medlemsplatformen provides one.

How long may we keep information about former members?

Only as long as you have a legitimate purpose. Some things may be kept for a while for the sake of, say, accounting, but the rest should be deleted once the purpose is gone. A fixed cleanup routine is easier to live up to than a case-by-case judgement.

Is this legal advice?

No. It's general guidance meant to make the principles concrete for an association. If you're in doubt about your own situation, seek qualified advice or read more at the Danish Data Protection Agency (Datatilsynet).

Get members' data gathered and under control

See how Medlemsplatformen gathers your member information in one place with controlled access and a data processing agreement, so you stand on solid ground with personal data.