Member systems

Manage member data with clear purpose and access

Choose necessary fields, identify who can use them and set retention decisions that reflect your co-op’s actual obligations.

In this guide

A membership record should help the co-op administer membership accurately without becoming a collection of everything anyone has ever learned about a person. Start by defining the decisions and tasks the record supports. Then decide what information is necessary, who may use it and when it should be reviewed.

Your legal form, rules and activities may create particular record-keeping obligations. Confirm these with the appropriate adviser. A technology template cannot determine every field or retention period for all co-ops, and an application's default settings are not an organisational policy.

Define the minimum useful record

The ICO's data-minimisation guidance requires personal information to be adequate, relevant and limited to what is necessary. Translate that principle into a short field register.

  • Field: what information is being recorded?
  • Purpose: which defined task or obligation needs it?
  • Source: who supplies or verifies it?
  • Access: which roles need to view or change it?
  • Review: what event triggers a correction, review or deletion?

An illustrative basic record might include a membership reference, name, relevant contact details, membership status, key decision dates and required share or subscription information. This is a design example, not a statement of the statutory register requirements for your legal form.

Keep free-text notes constrained. “Difficult member” is an unhelpful judgement; an appropriately recorded factual action may be necessary for a particular case. Separate confidential casework from the ordinary membership list and identify its own access and retention rules.

Separate purposes and access

Decide which system holds the authoritative membership status. Other tools may need limited subsets, such as a mailing platform receiving only contact details and communication preferences. Avoid copying the complete register into every service merely because an import accepts it.

Membership administration, workforce records, equality monitoring and marketing can involve different purposes and requirements. Assess the relevant lawful basis and any additional conditions where needed. Give people clear information about your actual use of their data, using the ICO principles guidance as a starting point.

Use role-based file and system access. A person preparing the newsletter may need a mailing segment, while the membership secretary needs status and correspondence. Neither role automatically needs personnel records or confidential complaints.

Document the permitted export process. If an authorised officer needs a temporary spreadsheet for a defined task, record where it is held, how it is protected and when it will be removed. Account for copies on local devices and attachments as well as the main system.

Make retention decisions by record and purpose

The ICO's storage-limitation guidance explains that personal data should not be kept longer than necessary. There is no single universal retention period to apply to every member record. Consider the specific purpose, applicable legal requirements, relevant claims and any legitimate reason to preserve particular records.

Use a schedule with the record type, retention rationale, trigger event, review owner and disposal method. For example, an unsuccessful application and a required membership register entry may need different decisions. Record those decisions rather than choosing an arbitrary number of years for the whole database.

Include backups and restored data in the process. A restore should not accidentally make old, corrected information authoritative again. Explain how expired or superseded material is handled within your recovery arrangements.

Run a small data review

  1. Select one member journey, such as joining or changing contact details.
  2. Trace the information through forms, inboxes, spreadsheets and the main record.
  3. Identify unnecessary fields, duplicate copies and unclear owners.
  4. Verify access with fictional test records.
  5. Check how a correction reaches connected systems.
  6. Assign retention and cleanup actions to named owners.

Check marketing permissions separately using the newsletter guide. Capture the resulting system ownership and access decisions in the digital handover tool so the next membership officer inherits a usable process.

Suggest a correction or improvement →