GDPR for Clubs, Charities and Schools
Members, volunteers, children's photos and the club WhatsApp — data protection for the organisations that run on goodwill.
Community organisations process a surprising amount of personal data — membership records, children's details, medical notes for activities, vetting records, photos, fundraising lists — usually through volunteers, spreadsheets and WhatsApp. The GDPR applies to all of it (an organisation processing members' data is not within the household exemption), but it applies proportionately, and a community organisation's compliance is well within volunteer reach once the few real rules are known.
Members and volunteers
Membership administration rests comfortably on contract and legitimate interests: you can hold the data needed to run the club and communicate about its activities. The disciplines that matter: collect only what you need, keep the register somewhere controlled rather than in five committee members' personal accounts, retire data when members leave (subject to any records you genuinely must keep), and hand over cleanly when officers change — the outgoing secretary's laptop is the community sector's classic data protection failure.
Volunteers' data, including Garda vetting outcomes, deserves particular care: vetting records are sensitive, access should be restricted to those who need it, and retention should follow the relevant vetting guidance rather than accumulating forever.
Children's data and photos
Clubs and schools hold children's data constantly, and the photo question dominates in practice. The workable approach: a clear photo consent obtained at registration, offering genuine choices (team photos, website, social media as separate permissions), a system everyone actually follows for knowing who is opted out, and restraint in what is published — names with faces of children on public social media rarely serve any purpose the activity needs.
Medical information gathered for trips and activities is special category data: collect it for the activity, restrict who holds it, and delete it when the activity ends rather than archiving it indefinitely.
The WhatsApp problem
WhatsApp groups run Irish community life, and they create real issues: every parent's number visible to every other parent, children's information and photos circulating without control, and departed members retaining everything. Proportionate fixes: use broadcast or announcement-style channels where members do not see each other's numbers for general communications, keep children's medical or welfare matters out of groups entirely, get consent to the communication channel at registration, and prune groups when seasons end.
Fundraising, lotteries and mailing lists
Fundraising communications follow the marketing rules: electronic messages to individuals need consent or the narrow existing-supporter footing, every message needs an opt-out, and lists borrowed from other organisations are where complaints start. Church-gate collections need no data law at all — which is a reminder that the cheapest compliance is often collecting less data in the first place.
When something goes wrong
The community-sector breach is usually human: the spreadsheet emailed to the full list, the lost phone with the registration file, the vetting outcome mentioned where it should not have been. The same law applies as to any organisation — contain, assess risk, notify the DPC within 72 hours unless risk is unlikely, tell affected people if risk is high, record it — and the same preparation helps: knowing where the data is, and having one named person who owns the response. Our breach response guide and on-device checklist are written to be usable by a volunteer secretary at ten in the evening.
Frequently asked questions
Does GDPR really apply to our small club?
Yes — an organisation processing members' data is outside the household exemption regardless of size. But compliance is proportionate: controlled records, sensible consents, WhatsApp discipline and a breach plan cover most of what a club needs.
Do we need consent to photograph children at events?
You need a lawful, transparent footing and in practice that means clear photo consent at registration with genuine granular choices — and a working system for honouring opt-outs, especially on public social media.
Can the team WhatsApp group include all the parents?
It can, but every member sees every number, so tell people at registration and prefer broadcast-style channels for general communications. Keep children's medical and welfare information out of group chats entirely.
How long should we keep Garda vetting records?
Follow the retention guidance applicable to your vetting arrangements — the principle is restricted access and defined retention, not indefinite accumulation. Vetting outcomes are sensitive and should be held by as few people as possible.
A committee member emailed the membership list to the wrong people. Is that a breach?
Yes — an unauthorised disclosure is a personal data breach. Contain it, assess the risk, document it, and notify the DPC within 72 hours unless the breach is unlikely to result in a risk to those affected.
Related pages
Talk to a GDPR solicitor
Mary Molloy Solicitors acts for individuals and organisations across Ireland on data protection matters — access requests, breaches, compensation claims, complaints and compliance. All enquiries are handled through our Dublin office.
Contact us — 01 5827148This page contains general information about Irish law and practice. It is not legal advice, it may not reflect your circumstances, and reading it does not create a solicitor–client relationship with Mary Molloy Solicitors. We do not advise on taxation; please speak to your accountant or Revenue. In contentious business, a solicitor may not calculate fees or other charges as a percentage or proportion of any award or settlement.