GDPR and Ledenbeheer
Last updated About 1 hour ago
GDPR legislation
Is Ledenbeheer GDPR-compliant?
Yes.
Ledenbeheer is a data controller and processor. Personal data is always processed in line with privacy law and the General Data Protection Regulation, European Regulation 2016/679 of 27 April 2016 on the protection of personal data.
Ledenbeheer collects, records and processes personal data from customers and users of our services. People provide details when they contact us, register on our platform or use Ledenbeheer services.
Personal data is processed lawfully, fairly and transparently for a specified, explicit purpose. Processing is limited to what is necessary, and personal data is kept only as long as needed for those purposes.
Alongside our privacy statement, terms and conditions and cookie statements, we have taken extensive measures to secure all data.
Am I automatically GDPR-compliant when I use Ledenbeheer?
No, but it is a step in the right direction.
Ledenbeheer processes the data, but as a club you remain responsible for the data you collect.
That means you are responsible for what you ask members, with whom you share the information and how you handle it.
When used correctly, Ledenbeheer helps you meet several requirements:
Members can view and update their own information.
Members can exercise their right to be forgotten on Ledenbeheer.
All data is stored on a secure platform.
You ask permission to keep the data, and members agree to your GDPR statement and terms and conditions when registering.
Emails and newsletters are kept separate. Members receive no newsletters without their consent. What is the difference?
A detailed permissions system lets you restrict sensitive information to administrators.
There are also basic rules for keeping data:
Keep only what you need.
Identify the legal basis for keeping it.
Explain clearly to everyone whose data you use what you do with it, through your privacy statement.
Keep data secure. Choose a partner such as Ledenbeheer that follows GDPR requirements.
Stop spreading Excel lists across Dropbox, OneDrive and ten computers. The more people who can access a file, the greater the risk of a data breach.
Keep the information in Ledenbeheer and give access only to administrators who need it.
Required documents
Every organisation that systematically processes personal data must prepare the following documents.
Record of processing
A record listing your processing activities and answering required questions about the source, use and protection of personal data.
Privacy statement
People have a right to know what happens to their data from the moment they give it to you. Your organisation must explain this clearly in a privacy statement. Whenever you first collect information, such as for membership, a show ticket, a cycle tour or a raffle form, people must know why you need it and what you will do with it. You can briefly explain the purpose on each form and link to the full privacy statement on your website.
Agreements
Every organisation shares data with processors it asks to handle that data: for example, a cloud storage provider, an email service or a local printer receiving an address list. Work only with companies that comply with the GDPR. Large providers will probably send you an agreement; keep it on file. Ask other providers for one or arrange an agreement yourself.
These agreements should show that data is secured, is not passed on for commercial purposes, is stored on appropriate servers in Europe or countries with suitable arrangements, that you are told about problems at the processor, and that the processor helps with data breaches.
Privacy statement
The GDPR requires informed consent. Add a checkbox to contact forms saying “I accept the privacy policy” so people understand that they are consenting to the processing of their data.
“By clicking Register, you agree to the Terms and Conditions” is not enough. Use a checkbox for explicit consent. Implied consent, such as a preselected checkbox, is not valid. Users must be able to read the privacy policy and select the checkbox themselves.
That is why Ledenbeheer includes the required field “I agree to the club's privacy policy and terms” on the registration form. It is a fixed mandatory question that every member must select when registering.
Add your privacy policy and terms and conditions under “Settings > Terms”.
Portrait rights
Portrait rights can restrict the use of someone's image. A person depicted may object to publication of their portrait when they have a reasonable interest in doing so. Examples include:
The portrait infringes their privacy.
The person is publicly ridiculed.
The way the person is shown harms them.
You cannot use every photograph freely in a commercial setting. For example, do not use someone's portrait in advertising without their explicit consent.
Overview photos taken at public events are generally not treated as an infringement of portrait rights. It may be difficult for recognisable people in a broad scene to object. If a photo clearly focuses on one or a few people, they may invoke their right to privacy. The context in which you use the image also matters.
Ask about portrait rights on your registration form
Under "Contacts > Contact details", you can create questions for the registration form.
Click “Add category” at the top right to group privacy and portrait-rights questions on the form.
Add a category named “Privacy (GDPR) and portrait rights”.
Then click “Add question” to create a new question. A YES/NO question works best.
You may require members to answer a yes/no question without forcing them to agree, which the law does not permit.
Create a portrait-rights question
Name: Portrait rights
Question type: Multiple choice (radio buttons).
Category: Privacy (GDPR) and portrait rights.
Options: Yes, No.
Required: Yes.
We suggest the following wording:
Question: I agree that photographs may be taken and published.
Help text below the question: Photos showing the atmosphere in classes, performances, workshops, dance camps and similar activities. If you object to a published photograph, please contact us so we can change it.
Once you have created the questions, add them to your registration form: read how to do this here.
Newsletters
As the owner of a list of email addresses, you must be able to show that people opted in or consented to the management and processing of their data.
The opt-in proves that someone wants to receive your communication. Record each opt-in so you can show how it was collected and demonstrate its validity.
What is the difference between an email and a newsletter? Read about it here.
Members are asked by default whether they want to receive the newsletter. You do not need to set this up.
What should you do when processing children's data?
The GDPR does not ban the processing of children's data, but it sets specific requirements.
Information about personal data must be clear and easy to understand. This matters even more for children and adolescents.
Take the age of your audience into account and make your data-processing policy understandable to children and teenagers. Avoid legal language, and consider icons or other visual aids.
Consent to receive information from your organisation
What if your organisation wants to provide online information or services to children? Examples include digital music purchases, streaming subscriptions, online gaming and social media.
In Belgium, children under 13 need the agreement of a parent or legal representative in this situation. It is best to ask for this on the Ledenbeheer registration form.
If your services are not offered directly to a child, the question of the digital age of consent does not apply. For example, an online shop selling children's clothes does not have to ask for this consent.
When processing registrations, make sure the following is in place. Ledenbeheer already provides for it:
Write information in a style children and teenagers can understand.
Ask each user whether they have reached the required age, between 13 and 16.
If a user says they are below the required age, a parent or guardian must register them.
Right to erasure
Even when a parent has agreed to data processing, that consent is not permanent. The parent and child can withdraw it and request deletion of past data at any time. The request must be handled within a month. You must also pass it on to any partners that received the child's data so they can delete it too.
These rules emphasise that children's data is not a commodity and that children need protection. The Data Protection Authority also acts against GDPR infringements. Review your GDPR policy carefully and take practical steps to avoid fines or other penalties.
Source: European Commission: Can personal data about children be collected?