Membly
All guides

Your association on Facebook — what GDPR actually requires

Almost every small Swedish association has a Facebook group. Sooner or later the board asks whether that is acceptable — legally and practically. The answer is more nuanced than yes or no: the group is not unlawful, but there are things the association is obliged to be able to do that cannot be done there.

Why so many associations ended up on Facebook

There is a simple explanation, and it is not that anyone was careless. When your association needed a way to reach its members, Facebook was free, everyone was already there, and nothing reasonable existed that was built for a thirty-person choir. Membership systems cost money and were designed for federations with thousands of members. In practice the choice was a Facebook group or a mailing list nobody read.

So the group became the calendar, the noticeboard, the member list and the archive all at once. It worked. For many it still works.

What has changed is not that Facebook got worse, but that the obligations on the association got clearer. The GDPR applies to you exactly as it applies to a company, and the Swedish Authority for Privacy Protection (IMY) is explicit: if you process personal data in your association — for example details about your members in a membership register — you must comply with the GDPR. There is no exemption for being non-profit, and none for being small.

This guide covers what that means for a Facebook group in practice: who is responsible for the data, what can and cannot be done there, and what you should do whether or not you change tools.

Who is responsible for the personal data in the group?

The first question a board needs to be able to answer is easy to ask and uncomfortable to answer: if a member asks tomorrow for everything you hold about them, who responds?

Not Facebook. The association.

1. The association is the data controller

When you collect names, phone numbers, email addresses or records of who takes part, the association is the controller for that processing. Responsibility follows from what you do with the data, not from where you happen to store it. Keeping the data in someone else's service does not move the responsibility there.

IMY summarises the core requirements concisely. Collect data only for specified and legitimate purposes; collect only what is adequate, relevant and not excessive; and keep member data only for as long as it is needed. Protect the data with reasonable security measures — IMY names login controls, access restrictions, firewalls, encryption and backups.

You must also maintain a record of your processing activities. Article 30 carries an exemption for smaller organisations, but it rarely reaches an association: the exemption covers processing that is only occasional, and membership administration is regular.

There is one further obligation that tends to surprise boards: if you discover a personal data breach, it must be reported to IMY within 72 hours of discovery. That clock runs regardless of which tool you use.

2. What the Court of Justice actually held

It is worth being precise here, because this ruling is often repeated carelessly.

In Case C-210/16, Wirtschaftsakademie Schleswig-Holstein, the Court of Justice of the European Union held on 5 June 2018 that the administrator of a Facebook fan page is a joint controller together with Facebook for visitors' data. The reasoning was that the page administrator takes part, by its definition of parameters, in determining the purposes and means of the processing. Joint control is governed by Article 26 GDPR. The responsibility need not be evenly divided, but both parties answer to the supervisory authority and to the data subject.

The ruling concerns pages, not groups. It never addressed Facebook groups, and it would be wrong to claim otherwise.

But the reasoning is hard to dismiss as irrelevant. A group has an administrator who decides who is admitted, what may be posted and which settings apply — while Facebook simultaneously processes data about participants for its own purposes. That is the same structure the Court examined in the page case. Our assessment, and we are explicit that this is an analogy rather than a holding, is that a board is well advised to assume it does not carry sole responsibility for what happens to members’ data in the group.

3. Where the data goes

Meta is a US company, and transfers of personal data to the United States require a legal basis. One exists today: the European Commission's adequacy decision for the EU–US Data Privacy Framework, adopted on 10 July 2023, is in force. Using US services is therefore not unlawful, and anyone claiming otherwise is wrong.

What is reasonable to weigh is that the framework is under pressure from several directions at once. The General Court dismissed a challenge to the decision on 3 September 2025, but the appeal is undecided — it has been before the Court of Justice as Case C-703/25 P since 31 October 2025. On 29 June 2026, the US Supreme Court held in Trump v. Slaughter that statutory limits on the President's power to remove Federal Trade Commission members are unconstitutional. That matters here because the adequacy assessment rests in part on the existence of independent supervisory authorities in the receiving country, and the FTC is one of them. On 31 July 2026 the Chair of the European Data Protection Board, Anu Talus, wrote to Commissioner Michael McGrath asking the Commission to assess what the ruling means for the framework.

The conclusion is not that you are doing something impermissible. It is that the basis for these transfers is under active review, and that an association placing all of its member communication with a single US platform takes on a risk it has little ability to steer.

Seven things you cannot do in a Facebook group

The strongest arguments against running an association from a Facebook group are practical rather than legal. They concern things the association is obliged — or would reasonably want — to be able to do, and that the group simply is not built for.

  • Erase data on request: A member has, in many cases, the right to have their data erased. You can remove someone from the group, but you cannot erase their data from Meta's systems. The obligation is the association's; the ability is not.
  • Answer a subject access request: A member has the right to know what you process about them. You cannot assemble a complete picture of what exists about one person across years of posts, comments and reactions.
  • Sign a data processing agreement: You cannot negotiate terms with Meta on the association's behalf. You accept the platform's terms as they are, or you do not use it.
  • Reach every member: Anyone without a Facebook account, or who has left the platform, is excluded from the association's official channel. That is an accessibility and equal-treatment problem before it is a privacy one.
  • Keep the archive: The group belongs in practice to whoever created it. If that person leaves the board after a disagreement, or simply stops logging in, the association can lose access to its own history.
  • Show that a notice reached members: The feed is algorithmic. The board cannot demonstrate that a notice was actually shown to members, which becomes a real question when the notice convenes an annual general meeting whose decisions need to stand.
  • Use the member list as a membership register: A list of group participants is not a membership register. It has no membership types, no fees, no roles, no guardians, and none of the structure that makes a register useful to a board.

None of this means Facebook is badly built. A group is designed to let people talk to each other, and it does that well. It is not designed to let a board discharge a duty of stewardship, which is a different thing entirely.

The membership register is not the problem

A belief circulates in Swedish association life that a membership register is itself problematic under the GDPR, and that a closed Facebook group solves it. That belief is precisely backwards, and worth correcting carefully, because it leads boards to do exactly the wrong thing.

4. What the rule actually says

A membership register is not prohibited. It is presupposed. An association that collects fees, convenes annual meetings and maintains a roll of members has to know who its members are — you cannot run an association without processing data about them.

What is restricted is something else: publishing the register on the internet. IMY writes that publishing a membership register online requires a basis in the GDPR, and notes that in its experience many members do not want their addresses and phone numbers published on the internet. That is a rule about publication, not about keeping records.

So the phone number may sit in the register. It should simply not be openly available on the web, and should not be accessible to more people within the association than need it.

5. Two registers that get confused

Part of the confusion comes from the GDPR using the word "record" for two entirely different things.

One is the membership register — your list of who the members are, with contact details, membership type and fee status.

The other is the record of processing activities under Article 30, which IMY describes as keeping a record of your processing. That is internal documentation of what personal data processing the association carries out, why, and how long data is retained. It contains no member data at all.

You need both, and they solve different problems. The claim that a membership register conflicts with the GDPR almost always rests on these two being conflated.

One more point that is often misunderstood: consent is not the obvious basis for a membership register. Someone joining and accepting the terms is not the same as consent in the GDPR’s sense — IMY is explicit that accepting contractual terms is not the same as giving consent to the processing of personal data. For an ordinary membership register, contract or legitimate interests are usually the more durable basis. If you process sensitive data at scale — IMY names religious, political, disability and LGBTQ associations — you may additionally be required to appoint a data protection officer.

If you stay on Facebook: five things to do now

Many associations will keep using their group, and that is a legitimate choice. The group is where the members already are, and moving a community is harder than moving data. If that is your decision, do at least the following — it takes an evening and removes most of the risk.

6. Move the membership register out of the group

Let the group be a room for conversation, not the association's register. Keep the actual membership roll somewhere you control access, and can erase and export from. Even a password-protected spreadsheet on a shared drive with restricted permissions is better than a participant list you do not govern.

7. Send notices through a channel you control

Notices of annual general meetings, statute amendments and anything else with formal legal effect should go out in a way you can evidence afterwards — email to registered addresses, or a system that logs the send. Use the group as a reminder by all means. Do not use it as proof.

8. Appoint more than one administrator

Make sure at least two people on the board hold full administrator rights, and that the minutes record who they are. This is the most common and most practical disaster: an association loses its group because one person stopped answering the phone.

9. Be deliberate about what you post

Avoid national ID numbers, home addresses, health information and details about children in the group. Do not post complete participant or contact lists. Photographs of members, particularly children, deserve a considered position rather than a habit.

10. Write down what you do

Produce the Article 30 record of processing, even if it runs to a single page. Write down what data you process, why, where it lives and how long it is kept. Decide who on the board responds if a member gets in touch. It takes an hour, and it is the single biggest difference between an association that has this under control and one that does not.

When Facebook is no longer enough

For some associations the list above is sufficient. For others it becomes clear over time that the problem is not primarily privacy, but that administration cannot be run inside a feed: notices that disappear, a member list nobody trusts, fees tracked in a spreadsheet alongside, and a history held by the wrong person.

That is when an association system or association app becomes relevant — not because Facebook is forbidden, but because a tool built for the everyday work of an association does the things a group was never meant to do. A membership register with roles and fees, events with RSVPs, a chronological feed with no algorithm, and a clear allocation of responsibility for personal data.

Membly is built for this, and we are bound by everything this guide asserts: our privacy policy and our data processing agreement set out what we process, where it is stored and what you can require of us. Please read them critically — that is exactly the scrutiny you should apply to any supplier, ourselves included.

And if you conclude the group is enough: do the five things in the previous section anyway. They apply whichever tool you choose.

Frequently asked questions

Is it unlawful to run an association through a Facebook group?

No. There is no prohibition on an association using a Facebook group, and anyone claiming otherwise is mistaken. The problem is different: the association is the controller for its members' personal data, and several of the obligations that come with that role cannot be discharged inside a group. You cannot, for example, erase a member's data from Meta's systems on request, and you cannot produce a consolidated subject access response. The obligation remains even when the tool cannot meet it.

Who is the data controller for a Facebook group?

The association is the controller for its own processing of member data — responsibility follows from what you do with the data, not where it is stored. Beyond that, joint controllership is likely. In Case C-210/16 (5 June 2018) the Court of Justice held that the administrator of a Facebook page is a joint controller together with Facebook. The ruling concerns pages rather than groups, but the structure is similar, and a board is well advised to assume it is not solely responsible.

Can we keep members’ phone numbers in a membership register?

Yes. A membership register with contact details is permitted and in practice necessary to run an association. What is restricted is publishing the register openly on the internet, which requires a basis in the GDPR — and IMY notes that many members do not want their addresses and phone numbers published. Keep the register internal, grant access only to those who need it, and retain the data only as long as it is needed.

Do all members have to consent to being in the membership register?

Usually not. Consent is only one of several legal bases, and rarely the most suitable one for a membership register, because consent can be withdrawn at any time — and an association cannot very well stop knowing who its members are. Contract or legitimate interests are normally more durable. Note also that the terms of membership do not themselves constitute consent: IMY is clear that accepting contractual terms is not the same as giving consent to the processing of personal data.

What happens to the association's information if the administrator leaves the board?

In a Facebook group, the answer may be that the association loses it. The group is controlled by its administrators, not by the association as a legal person, and there is no authority to appeal to for restored access. Always appoint at least two administrators from the board, record who they are in the minutes, and keep the membership register and formal communications in a system the association itself controls.

Sources

Read next

Ready to bring your association together?

Get started for free in under two minutes. Completely free for all members.

No credit card required