Data protection for community groups

I’ve come across several instances of misunderstanding of data protection rules for small community groups. By small, I mean groups of 40 or 60 that may meet regularly and may know each other by first name. Many of these organisations are not likely to have even registered with the ICO and have a fear of sharing email addresses with each other for fear of breaking the law since GDPR came in to force in 2018. I think there needs to be a level of common sense rather than hiding behind some misconception that “Big Brother” ICO is going to come knocking on your door if you give a member’s emai address to another member to follow up something mentioned in one of your meetings. If the individuals consent to having their emails shared this is sufficient.

“It is not necessarily a GDPR violation if you request and use email addresses from your social group members to organize an event, but you must have a lawful basis for processing their data, such as consent, and be transparent about how their data will be used. “

GDPR Compliance Considerations:

  • Lawful Basis: Under GDPR, you need a lawful basis for processing personal data, like email addresses. The most relevant basis here is likely consent. You need to obtain explicit consent from individuals to use their email addresses for event-related communications. 
  • Transparency: You must be transparent with your group members about how their email addresses will be used. This includes clearly explaining the purpose of collecting their email addresses (e.g., to send event information) and informing them that they can withdraw their consent at any time, according to the Resource Centre
  • Consent: Consent must be freely given, specific, informed, and unambiguous. It should be collected through a clear affirmative action, such as an opt-in checkbox or a separate consent form. A pre-ticked box or silence from the individual is not considered valid consent, according to White Fuse
  • Purpose Limitation: You should only use the email addresses for the specific purpose for which consent was obtained (e.g., event communication) and not for unrelated marketing or other purposes. 
  • Security: Implement appropriate security measures to protect the email addresses from unauthorized access, loss, or misuse. 
  • Withdrawal of Consent: Ensure that individuals can easily withdraw their consent at any time and that you have a mechanism in place to stop using their email addresses for event communications if they do so, says the ICO

In summary: You can request and use email addresses for event organization if you obtain explicit consent for that specific purpose, are transparent about how the data will be used, and ensure individuals can withdraw their consent. 

Why register with the ICO?

Registering with the Information Commissioner’s Office (ICO) is a legal requirement for most organisations that process personal data, and it also demonstrates a commitment to data protection. Paying the data protection fee and being listed on the ICO’s register shows that a organisation takes data protection seriously, which can build trust with members and partners. 

Here’s a more detailed explanation:

Legal Obligation:

  • The UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 require most organisations that process personal data to pay a data protection fee to the ICO. 
  • This fee funds the ICO’s work in enforcing data protection laws and providing guidance to organizations. 
  • Failure to pay the fee when required can result in a fine. 

Building Trust and Reputation:

  • Being listed on the ICO’s register of fee payers signals to members, partners, and the public that an organisation is committed to data protection. 
  • This transparency can enhance an organization’s reputation and build confidence in its handling of personal information. 
  • Conversely, failing to register when required could damage an organization’s reputation and create concerns about its commitment to data privacy. 

Other benefits:

  • Registration demonstrates that an organization is aware of its data protection obligations and takes them seriously. 
  • It also shows that the organization is willing to be contacted by the ICO if needed. 
  • While registration is a legal requirement, it also makes good business sense by promoting trust and transparency. 

Important considerations:

  • Not all organisations are required to register. There are exemptions for certain types of processing, such as staff administration, advertising, and not-for-profit purposes. 
  • Organizations should carefully assess whether they meet the criteria for an exemption. 
  • The ICO provides a self-assessment tool on its website to help organisations determine if they need to register. 

How to find out if an organisation is registered with the ICO

Here’s how to do it:

  1. Go to the ICO website: Navigate to the ICO’s search page for the register of fee payers
  2. Search the register: You can search using the organisation’s name, registration reference, or address (including postcode). I would just search for the name.
  3. View the results: The search results will display whether the organisation is registered, along with details such as their name, address, registration number, and other relevant information. 

Here is an example of my former community council registration at https://ico.org.uk/ESDWebPages/Entry/Z2559495 .
Check to see if your community council is registered with the ICO >>
Simply enter the name of your commmunity council in the [Name] field.

If your community or social group leaders present the arguement that they are not giving out your fellow club member’s email address to arrange a bowling night or music event then ask the group organiser or secretary if they are registered with the ICO and has a full understanding of consent. Perhaps mention the following 4 points:

  1. Being listed on the ICO’s register of fee payers signals to members, partners, and the public that an organisation is committed to data protection. 
  2. This transparency can enhance an organisation’s reputation and build confidence in its handling of personal information. 
  3. Failing to register when required could damage an organisation’s reputation and create concerns about its commitment to data privacy. 
  4. You may also point out that you have your fellow member’s permission to share (if he/she hasn’t given his/her email address to you already by ruthlessly slashing through that red tape!)

Bear in mind, however, it is possible that your organisation may be exempt from registering and paying a fee. Although, many not-for-profit organisations register anyway for the first and second points listed above. The current fee for most small and medium-sized businesses and charities is only £1 a week, paid annually at £52. Is you organisation exempt?

To find out fill, out the self assessment >>

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top