Last Tuesday, the outgoing president of a 90-member running club handed over the login credentials for their membership spreadsheet. Username: the club’s Gmail. Password: “running123.” The spreadsheet had names, home addresses, phone numbers, emergency contacts, and partial credit card numbers for every member going back six years.
Nobody had ever changed the password. Three former board members still had access. One of them hadn’t been involved with the club since 2022.
This isn’t unusual. It’s standard.
You’re Collecting More Data Than You Think
Most club leaders picture their data as “just a list of names and emails.” Pull up your digitalized records and count what’s there.
Names. Email addresses. Phone numbers. Home addresses. Birthdays. Emergency contacts. Payment card details or bank account info. Transaction histories. Notes about medical conditions for event planning. Photos from club events with faces and sometimes children. Login credentials for your website or member portal. Communication archives with personal conversations.
That’s not a mailing list. That’s a personal dossier on every member. And if you’re using a shared Google Sheet, a Dropbox folder, or a group email account to manage it all, multiple people can access that dossier right now, possibly including people who left the board years ago.
Would your members be comfortable knowing all of that was sitting in an unprotected spreadsheet that six people can open?
Why This Actually Matters Now
Five years ago, a small club could get away with sloppy data handling because nobody was paying attention. That window is closing.
State privacy laws are expanding fast. California’s CCPA gives residents the right to know what data organizations collect about them, request deletion, and sue over certain breaches. It originally targeted large businesses, but amendments and enforcement patterns are widening its reach. Virginia, Colorado, and Connecticut all have consumer privacy laws that took effect in 2023. Texas, Oregon, and Montana followed in 2024, and several more states are now enforcing their own. More are in the pipeline.
Most of these laws have revenue or data-volume thresholds that exempt small clubs. But the direction is clear: the legal expectation around handling personal data is tightening everywhere. And some state attorney general offices have signaled interest in complaints against any organization, regardless of size, when mishandling is egregious.
Beyond the law, there’s a simpler reason. Trust. Members hand you their personal information because they trust you’ll take care of it. One breach, one leaked spreadsheet forwarded to the wrong person, one disgruntled ex-treasurer with grudge access, and that trust evaporates. Good luck collecting dues after that.
If your club follows basic nonprofit compliance rules, data privacy should be part of the picture.
The Password Problem
The single biggest vulnerability for most clubs isn’t a sophisticated hack. It’s a weak password shared among too many people.
How many of your board members use “clubname2024” or something close? How many accounts share the same password? How many people know the login to your club email, your website admin panel, your payment processor, your social media accounts?
Fix this first. Everything else is secondary.
Use a password manager. Tools like 1Password, Bitwarden, or Dashlane let you generate strong unique passwords for every account and share them securely with authorized board members. When someone leaves the board, you revoke their access in one step. Most password managers cost $4-8 per user per month for a team plan. Bitwarden’s Teams plan at $4/user/month is one of the cheapest options for a small board.
Turn on two-factor authentication everywhere. Every service your club uses, email, website, payment tools, bank accounts, should have two-factor authentication enabled. This means that even if someone gets the password, they can’t log in without a second verification step. It takes 10 minutes to set up across all your accounts. It blocks the vast majority of unauthorized access attempts.
Stop texting passwords. Never share credentials through text messages, group chats, or email. Use the password manager’s sharing feature. That’s what it’s for.
Limit Who Has Access to What
Not every board member needs access to everything. The social media coordinator doesn’t need the full membership database. The events chair doesn’t need payment records.
Apply a simple rule: each person gets access only to the data they need for their actual role.
In practice, this means:
- Treasurer gets access to payment records and financial accounts
- Membership chair gets access to the member directory and contact info
- President and VP get broader access, but not necessarily to raw payment data
- Committee chairs get access to relevant member lists for their committees, not the whole database
- General members see only the information the club actively shares, like a member directory with names and emails (if members opt in)
This isn’t about trust. Your board members are volunteers doing their best. But the fewer people who can access sensitive data, the smaller the surface area for mistakes. Accidental sharing, lost laptops, compromised personal email accounts. Reducing access reduces risk.
When Someone Leaves the Board
Board transitions are the most dangerous moment for club data security. And most clubs handle them terribly.
When a board member’s term ends or they resign, you need a checklist:
- Change shared passwords for any accounts they had access to (this is why a password manager matters, it makes this painless)
- Remove their access from the password manager, cloud storage, email accounts, website admin panels, and any membership tools
- Confirm they’ve deleted any local copies of member data, downloaded spreadsheets, saved PDFs, exported contact lists
- Update authorized signers on bank accounts and payment processors
- Transfer ownership of any accounts registered under their personal email
Do this within a week of the transition. Not “when we get around to it.” Not “at the next board meeting.” Within a week.
The most common data exposure at small clubs comes from a former volunteer who still has a downloaded copy of the member spreadsheet on their personal laptop, sitting in their Downloads folder next to vacation photos, completely forgotten.
How Long Should You Keep Old Records?
Your club probably has member records stretching back years. Maybe a decade. Every name, every email, every payment, still sitting in your files. Do you actually need all of that?
Data retention gets overlooked, but it matters. The more old data you store, the more you have to protect, and the bigger the fallout if something goes wrong.
A sensible approach:
- Active member records: Keep current for as long as the membership is active. Obviously.
- Lapsed member records: Keep basic info (name, email, membership dates) for 2-3 years in case they want to rejoin. Delete payment details and other sensitive info after the membership lapses.
- Financial records: Keep for at least 7 years for tax purposes. The IRS requires a minimum of 3 years after filing, but most accountants and nonprofit advisors recommend 7 years as a safe default. This means transaction summaries and receipts, not full credit card numbers.
- Event records: Keep attendance lists for 1-2 years for planning purposes. Delete detailed personal information (dietary restrictions, medical notes, emergency contacts) after the event.
- Communications: Don’t archive every email thread forever. Set a retention period, 1-2 years, and clean up regularly.
Write this down as a simple policy, even if it’s just a paragraph in your bylaws or board handbook. “We delete lapsed member payment data after 12 months and archive financial summaries for 7 years.” That’s enough.
What Happens If You Have a Breach
Nobody plans for a breach. But the worst time to figure out your response is while it’s happening.
A “breach” for a small club usually looks like one of these:
- A board member accidentally emails the full membership spreadsheet to the wrong person or to a public mailing list
- A shared account gets compromised and someone downloads member data
- A laptop with club data gets stolen or lost
- A former board member misuses data they still have access to
If any of these happens, don’t panic. But do act quickly.
Step 1: Contain it. Change passwords for any compromised accounts immediately. Revoke access for any unauthorized users. If a device was lost, remotely wipe it if possible.
Step 2: Figure out what was exposed. What data was in the file or account? Names only? Emails? Payment info? The severity of your response depends on what was actually exposed.
Step 3: Notify affected members. Be honest and specific. Tell them what happened, what data was involved, and what you’ve done to fix it. Don’t spin it. Don’t minimize it. People respect honesty more than polish.
Step 4: Notify authorities if required. Most state breach notification laws have thresholds based on the type of data exposed and the number of people affected. If payment card data, Social Security numbers, or other financial info was exposed, you may be legally required to notify your state attorney general’s office. Check your state’s requirements. Many states maintain a simple online form for breach notifications.
Step 5: Fix the gap. Figure out how it happened and close that door. Change the process, change the tool, change the access controls. Document what you changed and why.
State Privacy Laws: The Basics for Clubs
You don’t need a law degree to understand what applies to your club. A few key concepts cover most of it.
CCPA (California): Applies to organizations that meet certain revenue or data-volume thresholds. Most small clubs fall below those thresholds. But if you have California members, you should still follow the spirit of the law: tell people what you collect, let them opt out of data sharing, and delete their data if they ask.
State breach notification laws: Almost every state has one. If you experience a breach involving personal information, you’re likely required to notify affected individuals and potentially the state. Thresholds and definitions vary, but the obligation exists nearly everywhere.
General principle across all states: If someone asks you to delete their personal data, do it. You don’t need a legal requirement to do the right thing. If a member leaves and asks you to remove their information, remove it. All of it.
The membership software market is moving toward built-in compliance features, which is one less thing volunteer leaders need to figure out on their own.
Build a Basic Privacy Policy
Your club doesn’t need a 20-page legal document. It needs a clear, short statement that tells members three things:
- What data you collect and why
- Who can access it within the club
- How members can request changes or deletion
Here’s a starting template you can adapt:
[Club Name] Member Data Policy
We collect your name, email address, phone number, and mailing address to manage your membership and communicate club activities. If you pay dues online, your payment is processed by [processor name], and we don’t store your full payment details.
Your information is accessible only to current board members who need it for their roles. We don’t share your data with outside organizations, sell it, or use it for anything beyond club operations.
When you leave the club, we retain your basic contact info for up to two years in case you’d like to rejoin. After that, we delete it. Financial transaction records are kept for seven years per tax requirements.
To update your information, request a copy of what we’ve stored, or ask us to delete your data, contact [membership chair email].
Put this on your website. Include it in your new member welcome packet. Review it once a year when the board turns over.
That’s it. Not a legal fortress. A simple promise to your members that you’ll handle their information carefully.
A Quick Checklist
If you do nothing else from this post, do these five things this month:
- Set up a password manager for your board and move all shared credentials into it
- Enable two-factor authentication on every club account
- Audit who has access to your membership data and revoke access for anyone who doesn’t currently need it
- Delete old data you don’t need, especially payment details for lapsed members
- Write a one-paragraph privacy policy and put it on your website
None of this requires a budget. None of it requires technical expertise. A motivated board member can knock out the entire list in a single afternoon.
Your members trusted you with their personal information. That trust came free. Keeping it costs almost nothing. Losing it costs everything.
Protecting member data starts with the tools you use to manage it. Somiti gives your club role-based access controls, secure payment processing, and automatic data management, so your volunteers can focus on running the club instead of worrying about spreadsheets and shared passwords.