GDPR and Ledenbeheer
Last updated 7 days ago
GDPR legislation
Is Ledenbeheer GDPR-compliant?
Yes.
Ledenbeheer is a data controller and processor. Personal data is always processed in line with privacy law and the General Data Protection Regulation, European Regulation 2016/679 of 27 April 2016 on the protection of personal data.
Ledenbeheer collects, records and processes personal data from customers and users of our services. People provide details when they contact us, register on our platform or use Ledenbeheer services.
Personal data is processed lawfully, fairly and transparently for a specified, explicit purpose. Processing is limited to what is necessary, and personal data is kept only as long as needed for those purposes.
Alongside our privacy statement, terms and conditions and cookie statements, we have taken extensive measures to secure all data.
Am I automatically GDPR-compliant when I use Ledenbeheer?
No, but it is a step in the right direction.
Ledenbeheer processes the data, but as a club you remain responsible for the data you collect.
That means you are responsible for what you ask members, with whom you share the information and how you handle it.
When used correctly, Ledenbeheer helps you meet several requirements:
Members can view and update their own information.
Members can exercise their right to be forgotten on Ledenbeheer.
All data is stored on a secure platform.
You ask permission to keep the data, and members agree to your GDPR statement and terms and conditions when registering.
Emails and newsletters are kept separate. Members receive no newsletters without their consent. What is the difference?
A detailed permissions system lets you restrict sensitive information to administrators.
There are also basic rules for keeping data:
Keep only what you need.
Identify the legal basis for keeping it.
Explain clearly to everyone whose data you use what you do with it, through your privacy statement.
Keep data secure. Choose a partner such as Ledenbeheer that follows GDPR requirements.
Stop spreading Excel lists across Dropbox, OneDrive and ten computers. The more people who can access a file, the greater the risk of a data breach.
Keep the information in Ledenbeheer and give access only to administrators who need it.
Required documents
Every organisation that systematically processes personal data must prepare the following documents.
Record of processing
A record listing your processing activities and answering required questions about the source, use and protection of personal data.
Privacy statement
People have a right to know what happens to their data from the moment they give it to you. Your organisation must explain this clearly in a privacy statement. Whenever you first collect information, such as for membership, a show ticket, a cycle tour or a raffle form, people must know why you need it and what you will do with it. You can briefly explain the purpose on each form and link to the full privacy statement on your website.
Agreements
Every organisation shares data with processors it asks to handle that data: for example, a cloud storage provider, an email service or a local printer receiving an address list. Work only with companies that comply with the GDPR. Large providers will probably send you an agreement; keep it on file. Ask other providers for one or arrange an agreement yourself.
These agreements should show that data is secured, is not passed on for commercial purposes, is stored on appropriate servers in Europe or countries with suitable arrangements, that you are told about problems at the processor, and that the processor helps with data breaches.
Privacy statement
The GDPR requires informed consent. Add a checkbox to contact forms saying “I accept the privacy policy” so people understand that they are consenting to the processing of their data.
“By clicking Register, you agree to the Terms and Conditions” is not enough. Use a checkbox for explicit consent. Implied consent, such as a preselected checkbox, is not valid. Users must be able to read the privacy policy and select the checkbox themselves.
That is why Ledenbeheer includes the required field “I agree to the club's privacy policy and terms” on the registration form. It is a fixed mandatory question that every member must select when registering.
Add your privacy policy and terms and conditions under “Settings > Terms”.
Portrait rights
Portrait rights can restrict the use of someone's image. A person depicted may object to publication of their portrait when they have a reasonable interest in doing so. Examples include:
The portrait infringes their privacy.
The person is publicly ridiculed.
The way the person is shown harms them.
You cannot use every photograph freely in a commercial setting. For example, do not use someone's portrait in advertising without their explicit consent.
Overview photos taken at public events are generally not treated as an infringement of portrait rights. It may be difficult for recognisable people in a broad scene to object. If a photo clearly focuses on one or a few people, they may invoke their right to privacy. The context in which you use the image also matters.
Ask about portrait rights on your registration form
Under "Contacts > Contact details", you can create questions for the registration form.
Click “Add category” at the top right to group privacy and portrait-rights questions on the form.
Add a category named “Privacy (GDPR) and portrait rights”.
Then click “Add question” to create a new question. A YES/NO question works best.
You may require members to answer a yes/no question without forcing them to agree, which the law does not permit.
Create a portrait-rights question
Name: Portrait rights
Question type: Multiple choice (radio buttons).
Category: Privacy (GDPR) and portrait rights.
Options: Yes, No.
Required: Yes.
We suggest the following wording:
Question: I agree that photographs may be taken and published.
Help text below the question: Photos showing the atmosphere in classes, performances, workshops, dance camps and similar activities. If you object to a published photograph, please contact us so we can change it.
Once you have created the questions, add them to your registration form: read how to do this here.
Newsletters
As the owner of a list of email addresses, you must be able to show that people opted in or consented to the management and processing of their data.
The opt-in proves that someone wants to receive your communication. Record each opt-in so you can show how it was collected and demonstrate its validity.
What is the difference between an email and a newsletter? Read about it here.
Members are asked by default whether they want to receive the newsletter. You do not need to set this up.
What should you do when processing children's data?
The GDPR does not ban the processing of children's data, but it sets specific requirements.
Information about personal data must be clear and easy to understand. This matters even more for children and adolescents.
Take the age of your audience into account and make your data-processing policy understandable to children and teenagers. Avoid legal language, and consider icons or other visual aids.
Consent to receive information from your organisation
What if your organisation wants to provide online information or services to children? Examples include digital music purchases, streaming subscriptions, online gaming and social media.
In Belgium, children under 13 need the agreement of a parent or legal representative in this situation. It is best to ask for this on the Ledenbeheer registration form.
If your services are not offered directly to a child, the question of the digital age of consent does not apply. For example, an online shop selling children's clothes does not have to ask for this consent.
When processing registrations, make sure the following is in place. Ledenbeheer already provides for it:
Write information in a style children and teenagers can understand.
Ask each user whether they have reached the required age, between 13 and 16.
If a user says they are below the required age, a parent or guardian must register them.
Right to erasure
Even when a parent has agreed to data processing, that consent is not permanent. The parent and child can withdraw it and request deletion of past data at any time. The request must be handled within a month. You must also pass it on to any partners that received the child's data so they can delete it too.
These rules emphasise that children's data is not a commodity and that children need protection. The Data Protection Authority also acts against GDPR infringements. Review your GDPR policy carefully and take practical steps to avoid fines or other penalties.
Source: European Commission: Can personal data about children be collected?
Frequently asked questions about GDPR
Does the GDPR apply to my association?
Does the GDPR apply to my association?
Yes. Informal associations and non-profit organisations also have to comply with the GDPR.
This applies if you process personal data. Almost every organisation does, even on a small scale or when records are kept only on paper.
What must my organisation do to comply with the GDPR?
Three key actions: inform, document and secure.
Inform
Explain to members, activity participants, partners and others whose personal data you use why you collect and use it, including when you store, publish or share it.
Give this information clearly when you first collect their data, usually when someone joins an association or registers for an activity. If you have a website, publish a privacy statement and link to it from your registration forms. We recommend briefly explaining on those forms why you request the data and how you handle it. When you ask for consent, do so when people first give you their data. Consent applies only to the purposes you specify.
Document
Everyone in your organisation who sees or uses personal data has a role in GDPR compliance. Involve your colleagues. Document and keep records of every step and decision you make about participants' and members' privacy.
Use a clear record of processing activities for this. Every organisation must keep such a record for membership, activities and newsletters.
Secure
Every organisation is responsible for handling members' personal data carefully and protecting it. Here are some suggestions.
Delete data you no longer need.
Do not leave lists lying around. Agree on clear handling rules with volunteers, leaders and board members.
Encrypt
Protect medical forms in a locked case and documents stored on laptops.
Do not post photos online without thought. Use restricted spaces and prevent images from being downloaded freely.
Do we need consent for newsletters?
Do we need consent for newsletters?
Consider what you put in a newsletter and who receives it before deciding whether to ask everyone for consent.
Promotional emails
If your emails or newsletter encourage people to buy something, purchase a ticket or reserve a place, they are direct marketing. E-commerce law applies alongside the GDPR.
This law says you may not send unsolicited promotional emails, except to customers for similar products or with their consent. Since 25 May 2019, that consent must be unambiguous, freely given, active, verifiable and specific. An unsubscribe option alone is not enough.
Practical and informational emails
If your emails are purely informative, relevant to recipients and necessary for running your organisation, rather than promotional or commercial, you may be able to rely on legitimate interests. You must be able to justify that basis.
These emails must not be unwanted or bothersome to recipients. Explain why they are necessary to run your activities. You can still send practical arrangements and relevant information about the activities people registered for.
For example:
Information and arrangements about your activities sent to current members may be acceptable under legitimate interests because members expect and need them.
Promoting a performance to people outside your association is more likely to be promotional, so e-commerce rules also apply.
Tip: Clean up your mailing lists and distinguish which kinds of information you send to each audience. Ledenbeheer keeps promotional emails separate from practical information.
May I share members' data with third parties such as sponsors?
May I share members' data with third parties such as sponsors?
With whom may I share members' data?
With whom may I share members' data?
More in Getting started with Ledenbeheer
Getting started with LedenbeheerOnboardingThe dashboardLicence and billingStill need help? Ask the team