GDPR: keeping an association's membership file
Minimal collection, information, access, retention period, handover: the GDPR rules for a student association's membership file in France.

A student association handles a lot of personal data: names, email addresses, phone numbers, student numbers, sometimes photos. The GDPR (RGPD in French) applies to it as it does to any organisation, whatever its size. The good news: for a membership file, the obligations come down to a few simple rules.
What the GDPR asks of an association
The association is the data controller for its members' data. It must:
- collect only what is necessary;
- inform members of what it does with their data;
- protect the file;
- keep the data only for as long as necessary;
- allow everyone to exercise their rights: access, rectification, erasure, objection.
It also keeps a record of processing activities: a simple list of what it does with data (membership file, ticketing, newsletter…), with, for each one, the purpose, the data involved, who has access and how long it is kept.

Collect only what is strictly necessary
To manage a membership, you generally need: surname, first name, email address, and the date and status of the membership fee. A phone number can be justified for the people in charge of an activity. A date of birth, only if you need to check that someone is over 18. Everything else must have a specific reason.
Be wary of "just in case" fields. Data you do not collect is data you do not have to protect.
Inform, and ask for consent when it is needed
The membership form states what the data is used for, who has access to it, how long it is kept, and how to exercise one's rights (a contact address is enough).
Managing the membership does not require consent: it is necessary in order to be a member. However, sending messages unrelated to the membership, passing contact details on to a partner or publishing photos requires the agreement of the people concerned.
Who has access to the file
Limit access to the people who need it: president, secretary, treasurer. Avoid the spreadsheet shared with everyone in read-only mode, exports sent by email, and files stored on a personal computer. Protect accounts with strong, different passwords.
How long to keep data, and how to delete it
According to the recommendations of the CNIL (the French data protection authority), a member's data is kept for the duration of their membership, then placed in limited archiving. Other periods follow from legal obligations: accounting documents, for example, are kept for ten years.
Set a rule and apply it once a year, for example at the start of the academic year: members who have not renewed for more than a year are removed from the active file.

The handover: passing the file on properly
When the board changes, the outgoing members' access is removed and the incoming members' access is created. The file does not leave on a USB stick or as an email attachment. See the board handover.
With toGaether
In toGaether, the membership file is not a shared spreadsheet: each person accesses it according to their role in the association, and outgoing members' access is removed at the handover without losing anything. The data is hosted in Paris (see our data hosted in France), and each member can request the deletion of their account from the app.
This article gives general guidance; for a specific processing activity, consult the CNIL's resources for associations.


