Privacy and GDPR by design

Your data is not our product.

Your organization works with personal data every day: members, volunteers, donors and everyone around them. That data deserves care, so privacy is not a feature we added later. It is built in from the beginning.

  • Collect only what you need
  • Give access only when needed
  • Keep data only as long as necessary

What privacy by design means in practice.

You should not need to be a privacy expert to run a membership administration responsibly. These are the principles the application is built on, and how each one shows up in daily use.

  1. Collect only what you need

    Personal data should not be collected just because it might be useful one day. Your organization decides which information it really needs, and member records stay limited to that.

    • Name
    • Email address
    • Membership status

    Less data means less data to protect.

  2. Privacy-friendly defaults

    Privacy should not depend on difficult settings. The application starts from the safest sensible position, so personal information is not exposed unless someone deliberately opens it.

    • A member sees their own contributions and details, not those of other members.
    • A volunteer only gets access to what their role needs.
    • Administrative data can be restricted to authorized users.
    • Sensitive information can be limited to specific roles.

    The starting point is simple: access only what you need to do your job.

  3. Clear roles and permissions

    Not everyone in an organization needs access to everything. Access follows responsibility, so it is clear who can see and change what.

    Member
    Their own information and contributions
    Volunteer
    What is needed for their volunteer work
    Coordinator
    What is needed to organize activities and volunteers
    Board member
    Administrative and organizational information within their permissions
    Administrator
    System and administrative functions
  4. Your organization stays in control

    The data belongs to the relationship between your organization and the people involved. Milenia is the tool for managing it, not the owner of it.

    When personal data is processed on behalf of your organization, the organization remains the data controller and Milenia acts as the data processor.

    Those responsibilities belong in a processing agreement between your organization and the party processing the data.

  5. Security is built into the application

    Personal data has to be protected against unauthorized access, loss and misuse. Security is part of the architecture, not something added on top.

    • Encrypted connections
    • Secure authentication
    • Role-based access control
    • Restricted access to personal data
    • Secure data storage
    • Audit and activity logging
    • Backups and recovery
    • API security
    • Protection against common application attacks

    Measures are chosen according to the type of data and the risks involved.

  6. Know who did what

    For important administrative actions it helps to know what happened, and who did it. Those actions can be recorded in an audit log.

    • Administrator changed a member's email address.
    • User removed a membership record.

    That gives your organization better control, and a clear answer when someone asks.

  7. Keep data only as long as necessary

    Personal data should not be kept forever by default. Retention, deletion and anonymization can be applied where appropriate.

    Active member
    Information is actively used for the membership
    Former member
    Handled according to your organization's retention policy
    Data no longer required
    Deleted or anonymized where appropriate

    This is the GDPR principle of storage limitation.

  8. Help people exercise their rights

    People have rights over their own personal data. The application is designed to help your organization answer those requests.

    • Access to personal data
    • Correction of incorrect information
    • Data export
    • Deletion where applicable
    • Withdrawal of consent, where consent is the legal basis
  9. Know why you are collecting data

    Knowing a name and an email address is only part of the story. For every processing activity, your organization should be able to answer these questions.

    • Why are we collecting this information?
    • Which information are we collecting?
    • Who needs access to it?
    • How long should we keep it?
    • What is the legal basis for processing it?

    The GDPR offers several legal bases, including consent, contract, legal obligation and legitimate interests. Which one applies depends on the activity and the circumstances.

  10. Privacy starts with the design

    Privacy should not be something you think about only after something goes wrong. These are the questions we ask while building a feature.

    • Do we really need this personal data?
    • Who actually needs to see it?
    • Can we reach the same result with less data?
    • How long should it be kept?
    • What happens when someone asks to access or delete their data?
    • What happens if an account is compromised?

GDPR by design, at a glance

The principles of the GDPR, and what each one means for the way the application works.

Principle
Principle What it means in Milenia
Lawfulness, fairness and transparency Processing activities have a documented purpose and a legal basis.
Purpose limitation Data is collected for membership administration, and not reused for anything else.
Data minimization Only the fields an organization actually needs are collected.
Accuracy Members and treasurers can correct information, and changes are logged.
Storage limitation Retention, deletion and anonymization can be applied per organization.
Integrity and confidentiality Encrypted connections, role-based access, secure storage and audit logs.
Accountability Roles, permissions and an audit trail show who did what, and when.

Read more

The European Data Protection Board publishes the official guidance behind these principles.

This page explains how the application supports your organization's privacy work. It is not legal advice, and it does not replace your own assessment or that of your data protection adviser.

Privacy is built in, not bolted on.

Start with your first statement and see how the defaults hold up in daily use.

Back to the homepage