Privacy notice for a membership organisation
A privacy notice for a club, association, society, professional body or trade body, drafted for the organisation with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.
Privacy notice for a membership organisation
Buy now, £595A membership organisation holds data about its members for the membership, communicates with them constantly, publishes directories and event lists that show members to each other, passes data to a national body or affiliates, and is run by volunteers who hold the records on their own laptops. The privacy notice has to state the basis for the membership (the contract and, for a not-for-profit, the condition that covers members' special category data), draw the line between the communications a member expects and marketing, deal with directories and events, explain the flow to the national body, and address the committee and the records. The business receives the privacy notice, the cookie notice and consent guidance within five working days for a fixed £595.
Who this is for
Sports clubs, societies, associations, professional and trade bodies, alumni networks, faith and community organisations and other membership bodies in England and Wales, whether incorporated or run by a committee.
What matters in a membership organisation privacy notice
Members, applicants, lapsed members and the committee
Being the controller, the business is required by Article 13 of the UK GDPR to tell each person whose data it holds what it does with it, and a membership body's notice should address applicants (the application, any vetting or references), members (contact and membership details, subscriptions and payments, participation, communications, any disciplinary records), lapsed and former members (what is kept and for how long), committee and office holders (their roles, the records of their decisions, their details published as the constitution requires), and guests and visitors at events; the organisation's constitution or rules decide much of what the notice must reflect, and the notice should refer to them.
The membership contract, legitimate interests and the not-for-profit condition
The membership is a contract, so the processing the membership requires rests on Article 6(1)(b) of the UK GDPR, the organisation's own administration and its communications with members on legitimate interests under Article 6(1)(f), and legal obligation under Article 6(1)(c) for the records the Companies Act 2006 or the Charities Act 2011 require where the body is incorporated or charitable; where membership itself reveals special category data (a political party, a trade union, a religious body, a body for people with a particular condition), Article 9(2)(d) permits a not-for-profit body with a political, philosophical, religious or trade union aim to process its members' and regular contacts' data for its legitimate activities without consent, provided it is not disclosed outside the body without consent, and the notice should state that condition where it applies.
Communications to members and the line between service and marketing
Communications a member expects as part of membership (renewals, meeting notices, the newsletter the constitution provides for, event information for members) are service messages that rest on the membership, but promotions of third parties' goods and services, sponsors' offers and marketing of the organisation to non-members are marketing, and under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, marketing by email or text to an individual needs consent, or the soft opt-in; the notice should say which communications are which, give members control over the optional ones, and ensure that sponsor messages are sent by the organisation rather than by giving the sponsor the list, because a membership list given to a sponsor is a disclosure the notice did not permit.
Directories, events and the data members see about each other
A members' directory, a results list, a team sheet, an event attendee list, a photograph of the annual dinner and a committee page on the website each disclose members' data to other members or the public, and the notice should say what is published, where, on what basis (legitimate interests for the running of the organisation, consent for anything optional or public), what a member may opt out of, and how photographs at events are handled (notice at the event, the right to ask not to be photographed, consent for named publication); a professional body's register may be published as the law or the body's rules require, which the notice should state.
The national body, affiliates and the data that flows upward
Many clubs and branches pass member data to a national governing body, a federation or a parent association for affiliation, insurance, competitions, licensing or the national database, and the notice should explain what is shared, with whom, on what basis (the membership terms, the affiliation agreement) and that the national body is a separate controller with its own notice; the organisation should hold the affiliation terms, should know whether the national body's systems transfer data outside the United Kingdom under Article 46 of the UK GDPR, and should not pass data the affiliation does not require.
Volunteers, committee members and the records of the organisation itself
The notice should state who holds the organisation's data (the membership system, the treasurer's spreadsheet, the secretary's email), the organisation's rules for committee members and volunteers handling it (the organisation's accounts and systems rather than personal ones where possible, secure handling, return on leaving office), the retention (membership records for the period after membership ends that the constitution, the accounts and limitation periods justify, with the minutes and the historic records kept as the organisation's archive), how an individual exercises the rights of access, correction, erasure, restriction, portability and objection, the one-month limit on the response, and the right to go to the Information Commissioner's Office; the notice can record the business's registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018, with the exemption for some not-for-profit bodies checked against the Regulations.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Do we need members' consent to send them the newsletter?
Not where the newsletter is part of membership under the constitution: it is a service message resting on the membership. Sponsor promotions and marketing of third parties are different and need consent or the soft opt-in. The notice draws the line.
Can we publish a members' directory?
On the basis of legitimate interests for the running of the organisation, with members told what is published, where, and how to opt out of the optional parts. A professional register required by the rules is published as the rules say.
Our committee keeps the membership list on personal laptops. Does the notice cover that?
It states the rules for committee members and volunteers: the organisation's systems where possible, secure handling, return on leaving office. The practical steps are in the operational note that comes with the documents.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Privacy notice for a charity
- Privacy notice for a gym or fitness business
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.