Last updated 20 July 2026.
Reviewed on 20 July 2026 against ICO guidance on data minimisation, special category data and children's information, and the current text of the UK GDPR and Data Protection Act 2018 on legislation.gov.uk, including the seventh lawful basis added by the Data (Use and Access) Act 2025 and in force from 5 February 2026. To the best of our knowledge at the time of writing. Guidance changes, constitutions differ, and safeguarding practice varies by setting. For decisions about your specific organisation, talk to a solicitor, your designated safeguarding lead, or the ICO directly.
Two events, one form, and the gap where members get lost
Ask a committee when somebody becomes a member and you will usually get two different answers in the same room. One person says when they send the form. Another says when the subscription clears. Your constitution or rules probably say something more specific, often that membership rights such as voting at a general meeting depend on the subscription being paid up. That distinction matters at exactly one moment, which is the moment somebody wants to vote, stand for the committee, or claim a member rate, and by then it is too late to decide. The practical problem is simpler than the constitutional one. A form and a payment are two records, they arrive at different times, they usually arrive through different channels, and unless something joins them together a person can exist in one and not the other. Every group has both failure modes: the enthusiastic new member who filled in the form in September and has never paid a penny, and the long-standing member whose standing order has run since 2019 and who has never appeared on any list because nobody wrote them down.
Every field needs a sentence explaining why it is there
The data minimisation principle in UK GDPR Article 5(1)(c) requires personal data to be adequate, relevant and limited to what is necessary in relation to the purposes it is processed for. That is a useful discipline rather than a bureaucratic one, because it forces a question most forms have never been asked: what would we actually do with this answer. Membership forms accumulate. A field gets added one year for a specific reason, the reason goes away, the field stays, and eight years later a volunteer is collecting home addresses for an organisation that has not posted anything since 2017. The test is not whether the information might one day be interesting. It is whether you have a present use for it, and whether you would be comfortable explaining that use to the person filling the form in.
Name, email address, a phone number, membership category, emergency contact, and what the person wants to be involved in. These map directly onto things you do.
Access requirements, dietary needs for catered events, availability for rehearsals, relevant skills, and any qualification your activity genuinely requires.
Full date of birth for adults, home address where nothing is ever posted, occupation, employer, marital status, and a second phone number nobody would ever ring.
A necessary field with an awkward feature nobody mentions
If you run rehearsals, performances, workshops or trips, you need to be able to reach somebody when a member is taken ill or injured. That is a straightforward and defensible purpose, and it is why almost every membership form has the field. The awkward part is that the person named has not filled anything in, has not agreed to anything, and in a surprising number of cases has no idea their name and mobile number are in your records at all. Their details are still their personal data, and you did not get them from them. UK GDPR Article 14 deals with the information you provide to people whose data you obtained from somebody else, and the transparency principle in Article 5(1)(a) sits behind it. That is a duty, not a courtesy, and the relief from it runs through the exemptions in Article 14(5) rather than through custom. The one most often reached for is Article 14(5)(e), where providing the information would involve a disproportionate effort. It is not a blanket exemption for small organisations: Article 14(6) says whether the effort is disproportionate turns on factors including the number of people involved, the age of the data and any safeguards you apply, and Article 14(7) requires you to take appropriate measures to protect their rights if you rely on it, including by making the information publicly available. That assessment is yours to make on your own facts and to be able to justify. What the guide can say is that groups commonly pair whatever they conclude with two practical habits: say on the form that the member should tell the person they have been listed, and keep what you collect to the minimum that lets you make the call. A name, a relationship and one phone number does the job. A full address, a date of birth and a second contact does not.
Special category data, collected on a form filled in at a rehearsal
Groups collect health information for good reasons. A dance school needs to know about an injury. A choir touring abroad needs to know about a condition that could become an emergency. A society running a residential weekend needs to know about allergies. The reasons are real, and the answer is not to stop asking. It is to understand what you have taken on. Information about somebody's health is special category data under UK GDPR Article 9, which prohibits processing unless one of the conditions in Article 9(2) applies, and that condition is required in addition to a lawful basis under Article 6. Article 6 now provides seven bases: consent, contract, legal obligation, vital interests, public task, legitimate interests, and the recognised legitimate interests basis inserted by section 70(2)(b) of the Data (Use and Access) Act 2025 and in force from 5 February 2026, which applies only to a closed list of purposes in a new Annex 1. Some Article 9 conditions also require a policy document under Schedule 1 of the Data Protection Act 2018. This guide cannot tell you which condition applies to your group, and any source that offers to without knowing your circumstances is overreaching. What it can tell you is the practical shape of a defensible approach: ask only what you need in order to keep somebody safe during your activity, say on the form exactly who will see the answer, and keep the answers separate from the general membership list.
A different signatory, a different set of obligations
For members under 18, the person completing and signing the form is normally a parent or carer with parental responsibility, and that shift changes several things at once. The contact details you hold are theirs as well as the child's. The agreement to your membership terms and code of conduct is theirs. Any photography permission is theirs, and should be a separate decision rather than part of the joining bundle. ICO guidance stresses that children's data needs particular care and must be kept safe and not given to anyone who should not have access to it. UK GDPR Article 8 sets a specific rule for consent where information society services are offered directly to a child, with the UK threshold at 13, but that provision is narrower than the general question of who signs a membership form and it does not answer it. Alongside data protection sits safeguarding, which is a separate obligation with its own requirements: who may contact a child directly, what the ratios are, who holds the register, and what happens on the night. Satisfying one does not satisfy the other, and in a youth theatre or a dance school the safeguarding side usually asks for more than data protection alone would.
A link is not a record, and a living document is not a version
Most membership forms deal with the rules by putting a link on the page. Tick to confirm you have read our code of conduct, with the code living in a shared document or a page on the website. It looks fine, and it fails at exactly the moment you need it. What you have recorded is that somebody ticked a box next to a link. You have not recorded what was behind the link, whether they opened it, or which version was there that day. If the code has since been rewritten, and codes of conduct are usually rewritten precisely because something happened, then every previous sign-off now appears to point at wording those people never saw. It is also worth separating three acts that organisations habitually record identically. Having read something, acknowledging that you have understood it, and agreeing to be bound by it are not the same, and the difference is the first thing anybody will ask about when a code of conduct is invoked.
That a named person ticked a box on a particular date. Almost every organisation has this much, and it is the easy part.
Which wording was in front of them. Once the document is edited, older sign-offs stop describing what those people actually agreed to.
Freeze the wording shown at the moment of sign-off, give it a reference, and attach the record to that version rather than to a document that keeps moving.
The one moment each year when the records can be made true
Committees think of renewal as collecting money, and it is, but the money is the least interesting thing that happens. Renewal is the only point in the year when every member is prompted to look at what you hold about them and tell you whether it is still right. Email addresses change. Phone numbers change. Emergency contacts stop being the right person. Access requirements change. Somebody moved house eighteen months ago and never mentioned it because nothing you send goes by post. Renewal is also the moment the membership list becomes true again, because it is the only time somebody has to actively confirm they are still involved. The accuracy principle in UK GDPR Article 5(1)(d) requires personal data to be accurate and, where necessary, kept up to date, and an annual prompt is the most practical mechanism a volunteer-run organisation has for meeting it. Treating renewal as a payment run wastes the one occasion where updating the record costs you nothing extra.
The honest current answer in most groups is forever, on a laptop
UK GDPR does not set retention periods. The storage limitation principle in Article 5(1)(e) says personal data must be kept in a form permitting identification for no longer than is necessary for the purposes it is processed for, and the accountability principle in Article 5(2) means the burden of justifying your period sits with you. That is a decision you make and record, not a number you look up. The status quo in most community organisations is not a decision at all. Membership records live in a spreadsheet that has been passed between four secretaries, contains every member since 2011, has never had a row deleted, and exists in several partial copies across personal laptops and email attachments. Nobody chose that. It happened because deleting things takes effort and keeping them takes none. The way out is to separate what you need from what you want. A full membership record, with contact details, emergency contacts and any health information, has a short useful life after somebody leaves. A minimal historical record, often just a name and the years somebody was a member, may reasonably be kept much longer, because societies genuinely do want to know who was in the 1998 production.
Somebody has to turn an answer into a record, and that somebody is a volunteer
Most groups solve the form and stop. The form is fine. It asks sensible questions, people fill it in, and the answers arrive in a tidy list. Then a volunteer opens that list next to the membership record and starts copying. That step is where the work actually is, and it is where the errors are: names typed differently in two places, people entered twice, a payment matched to the wrong person, a new member who never made it across at all because the transfer happened in two sittings and the second one never came. It is also where the delay lives. Somebody who joined in September may not appear as a member until whenever the volunteer next had a free evening, which is why the answer to how many members do we have is so often as at whenever I last did the list. A form that produces a list to retype has done half the job. The half it has not done is the half that takes the time.
The recurring failures, in roughly the order they happen
None of these come from carelessness. They come from membership admin being handled by whoever had time, in whatever tool was to hand, in an organisation where the committee changes every couple of years and the handover is an email attachment. Reading your own setup against this list will catch most of them before they matter.