Data protection basics for membership sites

Membergate Support -

Run a membership site and you become the keeper of other people’s information. Names and email addresses, of course, but also payment history, lesson progress, forum posts, private messages, and sometimes more sensitive details: the health conditions a yoga member mentions, the family trees a genealogy society member uploads, the business figures a coaching client shares on a call.

Data protection laws in many parts of the world, such as GDPR in Europe, give people rights over that information and place duties on the businesses that hold it. The details vary by country and state, and this article is general guidance rather than legal advice, so check the rules that apply to you with a qualified professional. The principles, though, are broadly shared, and following them is simply good practice for any membership business.

Start with a map of the data you hold

You cannot protect information you do not know you have. A data inventory is simply a list of what personal information you hold, where it lives, who can see it and why you have it. It sounds formal, but for a small membership it fits on one page.

Here is an example for a hypothetical family history society with a few hundred members:

  • Membership platform: names, emails, addresses, membership level, login history, forum posts, uploaded family trees. Access: owner and two volunteer admins. Reason: running the membership.
  • Payment processor: billing names, payment history, card details held by the processor, not the society. Access: owner and treasurer. Reason: taking payments.
  • Email service: names, emails, newsletter preferences, open and click activity. Access: owner. Reason: member communications and, with consent, event promotions.
  • Treasurer’s laptop: a spreadsheet exported for the annual accounts. Access: treasurer. Reason: accounting.
  • Shared inbox: member support emails, some containing ancestry details. Access: owner and one volunteer.

Nearly every inventory turns up a surprise, like the exported spreadsheet above that nobody remembered. Those forgotten copies are where problems usually start.

Have a clear reason for everything, and ask properly for consent

A core data protection principle is that you should have a legitimate reason for each piece of information you hold and use it only for that purpose. Much of what you collect is needed simply to deliver the membership someone paid for. Other uses, such as marketing emails about other products, often require the person’s agreement.

Where you rely on consent, it should be:

  • Freely given, not a condition of joining unless it is genuinely needed for the service.
  • Specific, so agreeing to membership terms is separate from agreeing to marketing.
  • Active, with an unticked box or a clear choice, never a pre-ticked one.
  • Recorded, so you can show when and how someone agreed.
  • Easy to withdraw, as easy as it was to give.

Tell members all of this in plain terms in your privacy policy, and keep that policy in line with what you actually do.

Members’ rights: access, correction and deletion

Many data protection laws give people the right to ask what you hold about them, to have it corrected and, in many situations, to have it deleted. You may receive only a handful of these requests, but a calm, prepared response makes them easy.

  1. Confirm who is asking. Reply to the email address on the account, or ask the person to make the request while logged in. Never send data to an address you cannot link to the member.
  2. Log the request with the date received, because laws often set a deadline for responding.
  3. Gather the data from every place in your inventory, not just your membership platform.
  4. Respond clearly, sending a copy of the data or confirming what you changed or deleted.
  5. Explain anything you must keep. Financial records often have to be retained for tax purposes even after an account is closed.

Deletion has some nuances for membership sites. Removing a former member’s forum posts can leave conversations that make no sense, so many sites anonymize the posts instead, replacing the name with “Former member.” Whatever you decide, be consistent and explain it. Here is a reply you might adapt:

Hi Priya, thanks for your request. We have closed your account and deleted your profile, uploaded files and email preferences from our membership site and our email service. Your forum posts remain but now show as “Former member” with no name or photo. We are required to keep records of your past payments for our accounts, and these will be deleted when that period ends. If you have any questions, just reply to this email.

Keep only what you need, for as long as you need it

Another shared principle is that you should collect no more than you need and keep it no longer than necessary. Every extra field on a form and every old export on a laptop is something that could leak. In practice, that means asking what each piece of information is for and setting a sensible point at which old records are deleted, such as a set period after a membership ends.

Look after the data you keep

Data protection also means security. Most of it is ordinary good practice:

  • Give each person their own login and only the access their role needs.
  • Use strong, unique passwords and two-factor authentication for every account that can see member data.
  • Avoid emailing member spreadsheets around. If an export is needed, delete it when you are done.
  • Choose service providers who explain how they protect data, and keep a list of which ones hold member information.
  • Know what you would do if something went wrong, including who you would need to tell.

Your data protection starter checklist

  1. Write your one-page data inventory, including spreadsheets, inboxes and laptops.
  2. Note the reason you hold each type of information, and remove anything without one.
  3. Check that marketing consent is separate, unticked by default and recorded.
  4. Write a short procedure for access, correction and deletion requests, with reply templates.
  5. Decide how you handle a former member’s posts and payment records.
  6. Delete old exports and review who has access to member data.
  7. Ask a qualified professional to confirm which laws apply to you and your members.

0 Comments

Comments are reviewed before they appear.