Running your organisation

Member data: what to collect, and what you are now responsible for

Every field you add to a membership form is a small promise. Indonesia's personal data law made those promises legal ones. Here is the plain version for a small organisation.

23 July 2026 8 min read
Member data: what to collect, and what you are now responsible for

Every field you add to a membership form is a small promise. You are saying: I will keep this, I will use it for something reasonable, and I will not let it end up somewhere it should not. For years those promises were entirely social - you kept them because breaking them would be embarrassing. Indonesia's personal data protection law, UU 27/2022, made them legal ones, and it applies to organisations of every size, not just to companies with compliance departments.

This is not a legal article and you should take proper advice if you are doing anything unusual. But the practical version for a club or association is simpler than the law sounds, and most of it is things you would want to do anyway.

Collect less, on purpose

The single most effective privacy measure is not collecting things. Every extra field is a small liability, a thing to keep accurate, and a thing that has to be protected.

Most membership forms ask for more than the organisation will ever use, because the form was designed by imagining what might be handy rather than what will actually be needed. Go through yours field by field and ask, for each one: what will we actually do with this? If the answer is "it might be useful", delete it. A date of birth is genuinely needed if you have age-restricted categories or run junior sessions; it is not needed so you can send birthday greetings you will never get round to sending.

Be especially careful with the categories the law treats as sensitive - health information, religious belief, and anything about children. There are legitimate reasons for a sports club to hold a medical note or for a faith organisation to record a congregational role, but hold those deliberately, with a clear reason, and not as a default field on a general form.

The test for any field on your form: name the specific thing you will do with this data in the next twelve months. If you cannot, you are collecting it because it seemed sensible, which is exactly the collection the law is aimed at and exactly the data that will be sitting in a spreadsheet nobody remembers when something goes wrong.

Say what you are collecting it for, in plain language

Consent has to be informed, which in practice means a member should be able to see, at the moment they hand over their data, what it is for. This does not require a lawyer's privacy policy nobody reads. A short, honest paragraph next to the form does most of the work: what you collect, what you use it for, who can see it, how long you keep it, and how to ask for it to be removed.

The part organisations most often get wrong is bundling. Joining the organisation and agreeing to receive a monthly newsletter are two different things, and consent to one is not consent to the other. Keep them as separate choices - and make the newsletter one genuinely optional rather than a pre-ticked box that technically counts.

Decide who can see what

In a small organisation, "who has access" is usually whoever happens to have a copy, which is a problem that grows quietly. The member spreadsheet gets emailed to a committee member for one job, and now it lives permanently in the sent folder of an account nobody controls.

Two decisions fix most of this. First, agree who genuinely needs to see the full member list - typically the secretary and the treasurer, not every committee member and definitely not every volunteer. Second, stop sending copies. If somebody needs the data for a task, give them access to the one copy or give them the extract they need for that job, rather than the whole file forever.

This is one of the clearest practical arguments for a system over a shared spreadsheet: access is a permission you can grant and revoke, rather than a file that has already been copied to four laptops. Our guide on moving off the spreadsheet covers what that involves.

Directories and photos, where consent gets forgotten

Two areas cause more genuine upset in membership organisations than anything else, and both come from treating a member's data as the organisation's to display.

A member directory shared with other members is a publication, not an internal record. Somebody who gave you their phone number so you could contact them did not thereby agree to give it to two hundred other people. Make directory inclusion opt-in, let members choose which fields appear, and never make it public to the internet. Our piece on whether you should have a directory at all goes into this in more detail.

Photographs are the other one. Posting event photos to social media is normal and mostly welcome, but not universally - people have professional situations, family situations, and simple preferences you know nothing about. A quiet, standing way to say "please don't post pictures of me" costs nothing and prevents the one incident that genuinely damages trust. For photos of children, ask the parent, every time.

Keep it accurate, and let it go

Two obligations that are easy to overlook. Members have a right to see what you hold about them and to correct it, so make that easy - a member portal where they can update their own details satisfies this and reduces your admin at the same time.

And data should not be kept forever by default. A member who left four years ago does not need to remain in your active list, and their old phone number is no use to anyone. Decide a retention period, write it down, and actually apply it - keeping what you need for your records and history, removing the rest. This is the obligation organisations most consistently ignore, and it is the one that turns a small breach into a large one, because the file that leaks contains fifteen years of people rather than this year's members.

Basic security, which is mostly unglamorous

You do not need enterprise security. You need the small things: the member list should not be on a personal laptop with no password; it should not be shared through a public link; accounts that hold it should have two-factor authentication switched on; and when a committee member leaves, their access should actually be removed rather than politely forgotten.

If something does go wrong - a list sent to the wrong recipient, an account compromised - tell the affected members promptly and plainly. Beyond the legal position, it is the thing that determines whether members trust you afterwards. An organisation that says "this happened, here is what we have done" recovers. One that hopes nobody noticed does not.

Read next

Run your whole membership in one place

Anggota keeps your members, renewals, payments and events together, so the admin looks after itself and you can get back to the community. Have a go - it is free to start, no credit card.