"Do we actually need to worry about GDPR? We're just a village hall committee" — this comes up on committee WhatsApp groups constantly, usually right after someone's tried to set up an online sign-up form. The honest answer: yes, GDPR applies to you, the same as any organisation holding personal data about anyone — a membership list or a "join us" form both count. The reassuring part: for a small group, actually complying is genuinely not hard once you know what's required.
What GDPR actually asks of a small group
Only collect what you need. If your sign-up form asks for a date of birth and address you never actually use, you're holding data you have no reason to have — that's the bit that creates risk, not the paperwork.
Tell people what you're doing with their data. A privacy policy doesn't need to be a wall of legal text — a short, honest page works: what you collect, why, how long you keep it, who (if anyone) it's shared with.
Get real consent for anything beyond the obvious. Someone giving their email to receive fixtures is fine. Adding them to an unrelated mailing list needs genuine opt-in, not a pre-ticked box.
Let people ask what you hold, and let them leave. A "what data do you have on me" or "please delete my details" request should be actionable in minutes for a club with a spreadsheet and an inbox — but you do need a named person who handles it.
Cookies need consent too. If your website uses analytics or tracking cookies, UK PECR rules require genuine opt-in before those cookies load — not a banner that tracks regardless of what's clicked. This is one of the most commonly missed rules, since many website builders' default banners are decorative.
A realistic setup for a small committee
You don't need a data protection officer. A proportionate setup: a short honest privacy policy, a sign-up form that only asks for what you use, a named person (usually the secretary) who handles data requests, a cookie banner that actually blocks tracking until accepted, and membership data kept somewhere reasonably secure — not a spreadsheet still accessible to three former committee members.
Where this gets missed
Almost always at the website layer. Committees write a sensible privacy policy, then use a builder whose cookie banner is decorative, or whose sign-up form has no real way to action a deletion request. The policy says the right thing; the site doesn't back it up.
Where Natterio fits
Every Natterio site is UK-hosted on Cloudflare infrastructure, with cookie consent that genuinely blocks non-essential cookies until accepted, and a real, working way for members to export or delete their own data. It won't write your constitution for you, but it closes the gap between what your privacy policy promises and what the website actually does. Build a GDPR-compliant club site, free.