GDPR
What it asks of an association
- Knowing which data you hold and where
- Telling people why you collect it (a privacy policy on the website)
- Keeping only what is useful, for as long as needed
- Limiting access to those who need it
- Answering a person who asks for their data or its deletion
Common mistakes
The spreadsheet shared with everyone, the mailing list without unsubscribe, photos of beneficiaries published without consent. A well-configured CRM and a website with its privacy policy fix most of it.
In Kern4Good
Every delivered website includes a privacy and cookie policy written on verified facts, and no tracker is set without consent. The CRM scoping sets the access and retention rules.
Must a small association appoint a data protection officer?
Generally no, unless it processes sensitive data at scale. A contact person who keeps the inventory is enough in most cases.
Can we publish photos of our activities?
Yes with the consent of recognisable people, preferably written, and with particular care for minors. Plan the checkbox in your registrations.
