Guides

Guide · Data protection

GDPR for associations. No panic, with a plan.

Data protection sounds like a big hurdle in volunteering, but it is mostly a matter of order. Here is what obligations an association really has, what people ask most often, and where technology takes the work off your hands.

Why it matters

An association handles more data than it realises.

A membership list, subscriptions, an email distribution list, photos from the summer party, and in social and advisory federations also health and counselling data: as soon as personal data is processed regularly, the GDPR applies, to the registered association just as much as to the small initiative. A fine is rarely the real risk; the real risk is the loss of trust when member data ends up in the wrong hands.

The good news: for most associations, data protection is not a major legal building site but order with a system, knowing which data you hold, who may access it, and what happens when someone leaves or asks. Clear responsibilities and the right technology are exactly what help with that.

The obligations

Six things an association should sort out.

Summarised plainly, each with the relevant provision. This gives you orientation, but it is no substitute for legal advice in an individual case.

Know what you process

Record of processing activities · Art. 30 GDPR

Membership list, subscription management, email, photos from the club party: record in writing which personal data you process and for what purpose. For most associations this is manageable, but mandatory as soon as processing happens regularly.

Limit and secure access

Technical and organisational measures · Art. 32 GDPR

Only those who need data for their role should see it; accounts should be protected and transfers encrypted. Who may access what should be traceable.

Contracts with service providers

Processing on behalf · Art. 28 GDPR

As soon as a service provider processes data on your behalf, such as the provider of your email or cloud solution, you need a data processing agreement (DPA) and should know where the data is held.

Answer requests from members

Data subject rights · Art. 15–21 GDPR

Members may request access, rectification, erasure, restriction, data portability and objection. You must be able to find, export and delete a person’s data.

Report data breaches

Notification duty · Art. 33/34 GDPR

If a mailbox is lost or a membership list ends up in the wrong hands, a notification to the supervisory authority within 72 hours may be required. A log of who had access and when helps to assess the situation.

Store only as long as necessary

Storage limitation · Art. 5(1)(e) GDPR

Former members, old applications, completed requests: data should be deleted when the purpose no longer applies and there is no remaining retention obligation (for example, for tax). Accounts that come to an end should be closed cleanly.

Where technology helps

What software takes on, and what it doesn’t.

You have to do the organisational part yourself (the record, the deletion policy, training). For the technical part, Connecteeva provides the foundation:

Rights by role

Every level manages its own people and sees only what it is meant to see, the local branch not half the regional federation.

What that looks like

Traceable

Administrative actions are logged, in every account. So if in doubt, you can show who had access and when.

More on security

Encrypted and in Germany

Transmission encrypted, email using PGP and S/MIME, hosting in German data centres with no US parent company (no CLOUD Act).

Where the data is held

A clean departure

When a role ends, the account is closed in one place, for all services at once, no forgotten account.

Role handover

Export and erasure

Data can be exported and kept for at least 30 days after cancellation, then deleted, in open formats.

How leaving works

DPA and technical measures

We provide the data processing agreement and the technical and organisational measures on request.

Ask us

No software makes an association “automatically GDPR-compliant”, and this guide is no substitute for a legal review. It is meant to help you ask the right questions and choose the technical foundation carefully.

Common questions

What associations ask about data protection.

Five answers on the data protection officer, special data, US providers and the right of access, short and without legalese.

Does our association need a data protection officer?

Not automatically. A data protection officer is only mandatory above a certain number of people constantly involved in data processing, or where processing is especially high-risk (Art. 37 GDPR, § 38 BDSG). Many small associations do not need one, but the remaining obligations still apply. If in doubt, clarify this with expert advice.

Does member data count as “special” data?

Name and address usually do not. But as soon as you process health, ideological or similar information, for example in counselling or at a social federation, that falls under special categories under Art. 9 GDPR, with stricter requirements for access and protection.

May we use Microsoft 365 or Google Workspace for member data?

You may use it, but you bear the responsibility: US providers are subject to the US CLOUD Act, and US authorities can demand the release of data, even from data centres in the EU. Anyone who wants to rule that out chooses a provider based and hosting in Germany. More on this on our security page and in the Microsoft-365 comparison.

What must we do when a member requests access?

On request, you must tell the person which data you process about them and, if they wish, provide it in a common format (Art. 15 GDPR). To do that, you need to be able to bring a person’s data together in the first place, and an administration where everything is tied to one account makes that easier.

How does Connecteeva help with data protection, and where not?

Connecteeva provides the technical foundation: rights by role, logging in every account, encryption using PGP and S/MIME, hosting in Germany and the clean closing of accounts. The organisational part, the record, the deletion policy, training your volunteers, no software takes off your hands. And this guide is no substitute for a legal review.

Who writes here

From federation practice, not from a textbook.

This guide comes from czichos.net GmbH in Berlin, the team behind Connecteeva. For many years we have looked after the IT of Germany’s largest social federation, where data protection is not theory but lived every day with real counselling and member data.

And yes, we offer one of the solutions that appear here. That is why we say openly what technology can do and what it cannot. More about us is on our About page.

Unsure where you stand? Let’s talk about your association.

Tell us briefly what data you manage and what you use today. You will get an honest assessment of where the technical foundation already fits and where it doesn’t, with no sales pressure.

We set up a trial and usually send the login details to your contact email within one working day.

No contract and no payment details. You decide whether it stays an enquiry or you try Connecteeva right away.

Prefer to reach us directly? Send an email · call 030 994048000

Address czichos.net GmbH
Königsweg 220
14129 Berlin