Data protection · · 8 min read
Member data: the consent traps in club marketing
Clubs hold unusually intimate data: who dines with whom, what someone drinks, which events they attend, what they cannot eat and why. The rules that catch operators out are mostly not in the UK GDPR.

Two regimes, not one
The UK GDPR governs the processing of personal data generally. The Privacy and Electronic Communications Regulations, still universally called PECR, govern electronic marketing and cookies specifically. Where they overlap, PECR takes precedence and its rules are stricter.
This matters because a club can have an entirely valid lawful basis under the UK GDPR for holding a member's email address and still be prohibited by PECR from sending marketing to it.
The soft opt-in, and why clubs misapply it
PECR permits marketing by email or text to an individual without prior consent only where three conditions are met together. The address was obtained in the course of a sale or negotiations for a sale, the marketing relates to the trader's own similar products or services, and a simple means of refusing was offered when the address was collected and in every message since.
All three are needed. An address collected from a guest at someone else's event, or from an enquiry that never became a membership, will usually fail the first. Promoting a third party's offer fails the second. An unsubscribe link added later does not repair the absence of an opt-out at collection.
Members and prospects are different populations
Existing members with a current subscription generally sit comfortably within the soft opt-in for communications about the club's own offering. Lapsed members, waiting lists and enquiry lists are more delicate, and the risk grows with time and with how far the content strays from what the person originally engaged with.
Sponsor and partner promotions are the clearest failure point. Marketing another business's products to your list needs the member's consent, and that consent must be specific and informed rather than buried in the membership terms.
Special category data hides in ordinary fields
Article 9 data includes health, religious belief, ethnicity and sexual orientation. Clubs collect it constantly without noticing. A dietary preference can reveal religion. An access requirement reveals health. A note that a member's partner attends reveals relationships.
Processing this needs an Article 9 condition on top of a lawful basis, and for most clubs that means explicit consent. The better engineering answer is to reduce what you hold: record that a member requires a nut-free meal without recording the diagnosis, and record that step-free access is needed without recording why.
Access requests come from disputes
Subject access requests rarely arrive from the contented. They tend to follow a disciplinary matter, a rejected application or a billing dispute, and they are broad: committee minutes, staff emails, incident notes, complaint records.
Two habits make this survivable. Write internal notes as though the subject will read them, because they may. And keep a retention schedule that is actually applied, so a request in 2026 does not require review of a decade of correspondence nobody needed to keep.
A short audit
- For each marketing list, can you evidence how the address was obtained and what opt-out was offered at the time?
- Do sponsor communications rely on consent rather than the soft opt-in?
- Are dietary and access needs recorded without recording the underlying reason?
- Is there a retention schedule, and has anything ever actually been deleted under it?
- Does the privacy notice describe CCTV, door records and guest data, not just the membership form?