GDPR basics for community groups
What data protection actually requires from a small volunteer-run group — in plain terms.
1. Know what personal data you hold
Start by simply listing it out — most groups are surprised how much they actually hold once they look:
- A membership list (names, contact details, maybe dates of birth for age-graded sport)
- An email or mailing list for newsletters and updates
- Event sign-up sheets, including any emergency contact or medical information
- Photos and video from events, particularly any that identify children
- Messages in a WhatsApp or Facebook group
- Financial records that include members’ names (payments, membership fee records)
2. Understand the two things GDPR actually asks of you
In plain terms, GDPR asks two things of any organisation, including a small volunteer group: have a legitimate reason for holding each piece of personal data, and handle it responsibly once you have it (don’t over-collect, keep it reasonably secure, don’t keep it forever, and be honest with people about what you’re doing with it).
It is not primarily a paperwork exercise — a group that genuinely follows those two principles is in a strong position, even with minimal formal documentation. The steps below turn that into something concrete.
3. Have a lawful basis for each piece of data
For most community groups, one of these two lawful bases will cover almost everything you do:
- "Legitimate interest" — covers the ordinary running of the group: keeping a membership list, emailing members about meetings and events, keeping basic financial records
- "Consent" — needed for things that go beyond the ordinary running of the group, most importantly: photos of identifiable individuals (especially children) used publicly, and any marketing-style communication to people who aren’t yet members
4. Don’t collect what you don’t need
A simple, useful discipline: before adding a field to a sign-up form, ask "what would we actually use this for?" If there’s no real answer, don’t collect it. A date of birth is only needed if you actually use it (age-graded sport, insurance requirements) — don’t ask for it "just in case."
5. Write a short privacy notice
A few sentences, given to new members or published on your website, explaining what data you collect, why, and who might see it — for example: "We collect your name, phone number and email to manage your membership and contact you about club activities. Your details are seen only by committee members, and are shared with our insurer only if required to process a claim."
This doesn’t need to be long or legalistic — clear and honest, in language an ordinary member would actually understand, is what matters far more than length or formal wording.
6. Handle photos and children carefully
Get explicit permission before photographing children at events, and before posting any identifiable photos of children online — including on your own group’s Facebook page or Instagram. A simple sign-up sheet or consent tick-box at the start of the season covers this for most events, rather than asking at every single one.
Consider using first names only, or no names at all, in public captions — and always respect a parent or guardian who declines photo consent, applying it consistently rather than only when it’s convenient.
7. Keep data secure and don’t keep it forever
Restrict who has access to the full membership or contact list — ideally just the Secretary and/or Treasurer, not the whole committee by default. Avoid emailing a full membership spreadsheet around as an attachment; use BCC for group emails rather than exposing everyone’s address to everyone else.
Delete or archive records for people no longer involved with the group after a reasonable period, rather than holding everything indefinitely "in case it’s useful." A good rule of thumb: review and clear out old contact lists annually, around AGM time.
8. Know what to do if something goes wrong
If personal data is lost, stolen, or sent to the wrong person — a common real-world example is a membership spreadsheet accidentally emailed to the wrong distribution list — tell the committee immediately rather than hoping it goes unnoticed.
Serious breaches that pose a real risk to people’s rights and freedoms (for example, financial or medical information being exposed) may need to be reported to the Data Protection Commission (DPC) within 72 hours of the group becoming aware of it. Even if you’re unsure whether a particular incident meets that bar, err on the side of checking the current guidance at dataprotection.ie rather than assuming it doesn’t apply to a small group — the obligation applies regardless of size.
Note: this guide is general information for volunteer-run community groups, not legal or financial advice. For anything charity-specific, check charitiesregulator.ie; for data protection, check dataprotection.ie.
