Committee4 min read

GDPR for angling club committees: the short version

What GDPR actually asks of a volunteer-run angling club, in plain English. Not a legal opinion, just the things that come up on every committee.

By Alex Baker, Tadpole

Most angling clubs in Ireland are run by volunteers who took the job because they like fishing. Nobody joined a committee to think about data protection law, and the guidance that exists is mostly written for companies with a compliance department.

Here is the short version, from a club that had to work it out. It is not legal advice and we are not lawyers. If your club has anything unusual going on, get proper advice. But this covers what actually comes up.

Yes, it applies to you

The most common thing we hear is that GDPR is for businesses. It is not. It applies to any organisation holding personal data about living people, and a membership list is personal data. Size does not exempt you. Being unincorporated does not exempt you. Being run by volunteers does not exempt you.

The good news is that a fishing club's obligations are modest, because what you hold is modest.

What you are actually holding

Take five minutes at the next committee meeting and write down every place member data lives. For most clubs it is longer than expected:

  • The membership spreadsheet

  • The previous secretary's copy of the membership spreadsheet

  • A WhatsApp group with everyone's phone numbers in it

  • Emails going back years, in a personal Gmail account

  • A shoebox of paper application forms in someone's garage

  • The Facebook page's message inbox

  • Whoever handles the insurance

  • The junior members' parental consent forms, wherever they ended up

That inventory is the single most useful thing you can do. Most of the risk in a club is not in the system it uses, it is in the six copies scattered across committee members' personal devices, including people who left the committee years ago.

The five things that matter

Know why you hold it. You hold member data to run the club: memberships, permits, insurance, safety. That is a legitimate reason and you do not need anyone's permission for it. You do need permission to use it for something else, which mainly means marketing.

Only hold what you need. A club needs a name, contact details, membership status and payment record. It does not need a date of birth for an adult member unless there is a reason. Every extra field is something to protect.

Do not keep it forever. A member who left in 2014 should not still be on the list in 2026. Agree a period, write it down, and stick to it. Two years after membership ends is a reasonable place to start.

Keep it somewhere sensible. A spreadsheet emailed between four committee members is the most common arrangement in Irish clubs and it is the weakest. Every copy is another place it can leak, and you have no idea who has which version.

Junior members need more care. Anyone under eighteen requires parental consent, tighter handling, and separate thought about photographs. If your club runs a juvenile section, this is the part to get right first.

Members' rights, in practice

Any member can ask what you hold about them, ask you to correct it, or ask you to delete it. You have a month to respond.

For a well-organised club this is a five-minute job. For a club with data in six places it is a genuine problem, because you cannot honestly answer a question you cannot look up.

That is the practical argument for getting this tidy: not the fine, which is vanishingly unlikely for a small club acting in good faith, but the Tuesday evening when a member asks a reasonable question and nobody can answer it.

Photographs

The one that catches clubs out. A photo of a member holding a fish, posted on the club Facebook page, is personal data.

For adults, in a club context, this is usually fine and rarely objected to. But if someone asks you to take a photo down, take it down without a debate. For juniors, get parental consent in writing before anything is posted, and keep the consent.

Emailing members

Emailing your members about club business, matches, work parties, renewals, is straightforward. That is running the club.

Emailing them about something commercial is different and needs consent. If your club has a sponsor who would like to reach the membership, that is the sponsor's marketing, not your club business, and it needs a tick box.

Where to start

If you do one thing, do the inventory. Write down every place member data lives and who has a copy. Most committees find something they had forgotten about, usually a spreadsheet on a laptop belonging to somebody who stood down two years ago.

Getting it into one place, with a record of who accessed what, is most of the job. Everything else follows from that.


Tadpole keeps club data in one place with an audit trail, handles junior members separately, and lets a secretary answer a member's question in about thirty seconds. Five Irish clubs run on it today, with four more onboarding.

See how member data works →

Encrypted & Isolated
GDPR Built In
Junior Protection
Full Audit Trail
How we protect your data