Skip Navigation
link050 Home
  • Board Desk
  • Businesses
  • Workshops
Create accountLog in

Contact

  • Herestraat 100, 9711 LM Groningen, Nederland
  • info@link050.nl
  • 050 – 3051 900

link050

  • For volunteers
  • For organisations
  • For businesss
  • FAQ
  • About-us
  • Opening hours

Join

  • Opportunities / trainings
  • Discover Organisations
  • Create organisation
  • Create account
  • Login
  • Help
  • Policies
  • Privacy Policy
  • Terms
  • Cookies

Powered by Deedmob tools ·
By clicking "Accept", you agree to the storing of cookies on your device to enhance site navigation and analyze site usage. For more information, view our Privacy Policy.

GDPR & privacy

Knowledge Center: Legislation & Regulations

GDPR and privacy: what do volunteer organizations need to arrange?

The General Data Protection Regulation (GDPR) applies to everyone who processes personal data—including volunteer organizations. That may sound daunting, but in practice, it mostly comes down to common sense and a few concrete measures.

What is personal data?

Personal data is any information that allows you to identify a person, either directly or indirectly. This includes names, addresses, phone numbers, and email addresses, as well as photos, membership numbers, or medical information.

If you maintain a membership list, register sign-ups, or send out a newsletter, you are processing personal data.

What does the GDPR require of you?

You don’t need to be a legal expert, but you must be able to demonstrate that you handle data with care. In practice, this means:

Collect only what you need

Do not ask for more information than is strictly necessary. Do you need a volunteer's year of birth? Then ask for the year of birth—not the full date of birth.

Document how you use the data

Use data only for the purpose for which it was provided. You should not use an email address collected for newsletters for any other purpose without permission.

Do not keep data longer than necessary

Clean up old data. Former volunteers from five years ago do not need to remain on your active membership list.

Secure the data

Password-protect your files and devices. Do not share lists containing personal data via unsecured channels, such as standard email attachments.

Privacy statement

Do you have a website or do you send emails? If so, you are required to have a privacy statement. In it, you explain what data you collect, the purpose of collection, how long you retain the data, and how people can access their data or have it deleted. Free templates are available that you can customize to your specific situation.

Processors and third parties

If you use external tools—such as a sign-up system, email software, or cloud storage—you are processing data via a third party. In that case, you need a data processing agreement. Many major providers (Google, Mailchimp, etc.) offer these as standard.

What if something goes wrong?

You must report a data breach—such as a stolen laptop or an email accidentally sent to the wrong person—to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if there is a risk to the individuals involved. This must be done within 72 hours. You do not need to report minor breaches that do not involve sensitive data, though you should still log them internally.

Next step

The GDPR doesn’t have to be a headache. Start with the basics: know what data you hold, what you use it for, and how you have secured it. For most small organizations, that is more than enough.

Back to the theme page: Laws & Regulations