What counts as members' data, and why it matters
A name, an address and an email address are personal data, because together they can identify a living person. Holding a membership list, a mailing list for a newsletter or a contact sheet for the committee means an organisation is processing personal data, and that brings a set of legal responsibilities that apply regardless of size.
Who this applies to
The law does not carve out an exception for small clubs or committees run by volunteers. A five-a-side league with forty members on a spreadsheet has the same basic obligations as a large charity, even though what is expected of it in practice is much narrower. The scale of the organisation affects what a reasonable committee needs to do.
What counts as members' data
- Names and contact details collected at sign-up or renewal
- Postal addresses used for mailings, subscriptions or membership cards
- Email addresses used for newsletters, fixture lists or committee communications
- Any notes held about individual members, such as payment history or dietary requirements for an event
Where the website stores or displays any of this, the obligations described here extend to the site itself. That point is covered on its own further down this page, and it stops there.
What the ICO expects of a small club
The list below covers what the Information Commissioner's Office actually asks of a small organisation holding members' data. It does not cover fundraising or charity regulation.
-
Know what you hold
List the personal data your organisation keeps on members, such as names, addresses, email addresses and payment details, and where each item is stored.
-
Have a reason for holding it
Each piece of data should be there because the organisation needs it to run, such as sending renewal notices or contacting members about events.
-
Tell members what you do with their data
A short statement, on the website or in the membership form, saying what is collected and why is usually enough for an organisation of this size.
-
Keep it secure
Membership lists should not sit on a personal laptop with no password or be emailed around the committee as an open spreadsheet.
-
Delete data you no longer need
Former members' details should not stay on file indefinitely once there is no reason to keep them.
-
Know what to do if data goes missing
A lost membership list or a mis-sent email is a data breach, and the ICO has guidance on when it needs to be reported.
-
Check whether you need to register
Some small organisations are exempt from paying the ICO's data protection fee, but the exemptions are specific and worth checking against your own circumstances (ICO guidance for small organisations, ico.org.uk, checked September 2026).
This is the short list. Organisations with more complex data, such as health information about members, should read the ICO's fuller guidance at ico.org.uk or take independent advice.
Where data protection touches the website, and where it doesn't need to go further
A club or society website usually touches data protection in a handful of specific places, and it is worth knowing where those are and where they stop. The website itself is one channel among several. Data protection law does not treat it differently from a paper membership list or a spreadsheet on someone's laptop, but the website often makes people think about it for the first time.
Where the website is involved
The obvious point is a contact or membership form that collects names, email addresses or other details. Anything submitted through the site is personal data from the moment it lands in an inbox or a spreadsheet, whether it stays on the website or gets copied out immediately.
A second point is anywhere the site publishes information about identifiable people: a committee list with home addresses, a fixture list naming junior players, photographs from an event. Publishing is a form of processing, and it needs the same thinking as collecting.
A third is any newsletter sign-up or mailing list plugin connected to the site. If it stores addresses on a third-party service, that service is processing the data on the organisation's behalf, and the committee is still responsible for what happens to it.
Where it stops
What the website does not do is create separate data protection obligations of its own. The rules are the same whether a member's email address sits in a form submission, a paper register or a treasurer's phone. A page about the website is not the place to work through the full range of what a small organisation has to do with members' data generally: that is covered in its own section below, and it names the regulator directly.
Keeping this distinction in mind saves a committee from either ignoring the website because "that's a data protection question, not a website one," or trying to solve every data protection question by fiddling with the site. Neither is right. The site is a channel. The obligations sit with the organisation, and they travel with whoever is handling the data at the time, which is part of why a proper handover matters when someone leaves the committee.