Guide · Data protection
GDPR for associations. No panic, with a plan.
Data protection sounds like a big hurdle in volunteering, but it is mostly a matter of order. Here is what obligations an association really has, what people ask most often, and where technology takes the work off your hands.
Why it matters
An association handles more data than it realises.
A membership list, subscriptions, an email distribution list, photos from the summer party, and in social and advisory federations also health and counselling data: as soon as personal data is processed regularly, the GDPR applies, to the registered association just as much as to the small initiative. A fine is rarely the real risk; the real risk is the loss of trust when member data ends up in the wrong hands.
The good news: for most associations, data protection is not a major legal building site but order with a system, knowing which data you hold, who may access it, and what happens when someone leaves or asks. Clear responsibilities and the right technology are exactly what help with that.
The obligations
Six things an association should sort out.
Summarised plainly, each with the relevant provision. This gives you orientation, but it is no substitute for legal advice in an individual case.
Know what you process
Record of processing activities · Art. 30 GDPR
Membership list, subscription management, email, photos from the club party: record in writing which personal data you process and for what purpose. For most associations this is manageable, but mandatory as soon as processing happens regularly.
Limit and secure access
Technical and organisational measures · Art. 32 GDPR
Only those who need data for their role should see it; accounts should be protected and transfers encrypted. Who may access what should be traceable.
Contracts with service providers
Processing on behalf · Art. 28 GDPR
As soon as a service provider processes data on your behalf, such as the provider of your email or cloud solution, you need a data processing agreement (DPA) and should know where the data is held.
Answer requests from members
Data subject rights · Art. 15–21 GDPR
Members may request access, rectification, erasure, restriction, data portability and objection. You must be able to find, export and delete a person’s data.
Report data breaches
Notification duty · Art. 33/34 GDPR
If a mailbox is lost or a membership list ends up in the wrong hands, a notification to the supervisory authority within 72 hours may be required. A log of who had access and when helps to assess the situation.
Store only as long as necessary
Storage limitation · Art. 5(1)(e) GDPR
Former members, old applications, completed requests: data should be deleted when the purpose no longer applies and there is no remaining retention obligation (for example, for tax). Accounts that come to an end should be closed cleanly.
Where technology helps
What software takes on, and what it doesn’t.
You have to do the organisational part yourself (the record, the deletion policy, training). For the technical part, Connecteeva provides the foundation:
Rights by role
Every level manages its own people and sees only what it is meant to see, the local branch not half the regional federation.
What that looks likeTraceable
Administrative actions are logged, in every account. So if in doubt, you can show who had access and when.
More on securityEncrypted and in Germany
Transmission encrypted, email using PGP and S/MIME, hosting in German data centres with no US parent company (no CLOUD Act).
Where the data is heldA clean departure
When a role ends, the account is closed in one place, for all services at once, no forgotten account.
Role handoverExport and erasure
Data can be exported and kept for at least 30 days after cancellation, then deleted, in open formats.
How leaving worksDPA and technical measures
We provide the data processing agreement and the technical and organisational measures on request.
Ask usNo software makes an association “automatically GDPR-compliant”, and this guide is no substitute for a legal review. It is meant to help you ask the right questions and choose the technical foundation carefully.
Common questions
What associations ask about data protection.
Five answers on the data protection officer, special data, US providers and the right of access, short and without legalese.
Does our association need a data protection officer?
Not automatically. A data protection officer is only mandatory above a certain number of people constantly involved in data processing, or where processing is especially high-risk (Art. 37 GDPR, § 38 BDSG). Many small associations do not need one, but the remaining obligations still apply. If in doubt, clarify this with expert advice.
Does member data count as “special” data?
Name and address usually do not. But as soon as you process health, ideological or similar information, for example in counselling or at a social federation, that falls under special categories under Art. 9 GDPR, with stricter requirements for access and protection.
May we use Microsoft 365 or Google Workspace for member data?
You may use it, but you bear the responsibility: US providers are subject to the US CLOUD Act, and US authorities can demand the release of data, even from data centres in the EU. Anyone who wants to rule that out chooses a provider based and hosting in Germany. More on this on our security page and in the Microsoft-365 comparison.
What must we do when a member requests access?
On request, you must tell the person which data you process about them and, if they wish, provide it in a common format (Art. 15 GDPR). To do that, you need to be able to bring a person’s data together in the first place, and an administration where everything is tied to one account makes that easier.
How does Connecteeva help with data protection, and where not?
Connecteeva provides the technical foundation: rights by role, logging in every account, encryption using PGP and S/MIME, hosting in Germany and the clean closing of accounts. The organisational part, the record, the deletion policy, training your volunteers, no software takes off your hands. And this guide is no substitute for a legal review.
Who writes here
From federation practice, not from a textbook.
This guide comes from czichos.net GmbH in Berlin, the team behind Connecteeva. For many years we have looked after the IT of Germany’s largest social federation, where data protection is not theory but lived every day with real counselling and member data.
And yes, we offer one of the solutions that appear here. That is why we say openly what technology can do and what it cannot. More about us is on our About page.
Unsure where you stand? Let’s talk about your association.
Tell us briefly what data you manage and what you use today. You will get an honest assessment of where the technical foundation already fits and where it doesn’t, with no sales pressure.
No contract and no payment details. You decide whether it stays an enquiry or you try Connecteeva right away.
Prefer to reach us directly? Send an email · call 030 994048000