General Data Protection Regulations (GDPR)

Does GDPR apply to our club or association?


The GDPR applies to you if you collect any personal data in running your club/association (which you definitely will do if you have any members). This includes searchable paper records. GDPR refers to data controllers (those who own and control the data) and data processors (anyone who processes data on behalf of a data controller). 

Data must be:

  • used fairly and lawfully
  • used for limited, specifically stated purposes
  • used in a way that is adequate, relevant and not excessive
  • accurate and kept for no longer than is absolutely necessary
  • handled according to people’s data protection rights
  • kept safe and secure
  • not transferred outside the European Economic Area without adequate protection

Things to consider