Book a demo

Keeping member data safe under Australian privacy law

Many small clubs fall under the Privacy Act's small business exemption, which generally covers organisations with an annual turnover of $3 million or less, but there are exceptions and every club should check its own position. Whether or not the Act applies, the same good habits protect members: collect only what you need, limit who can see it, keep it accurate and secure, and delete what you no longer need.

Last updated

General information, not legal advice. Check the official sources listed at the end of this page, and get advice for your club’s own situation.

The short answer

This guide is general information, not legal advice. Your club should check its own position with the Office of the Australian Information Commissioner (OAIC) or a lawyer.

The Privacy Act 1988 applies to many organisations, but the OAIC says most small businesses and not-for-profits with an annual turnover of $3 million or less are not covered, unless an exception applies. Many motor vehicle clubs will be below that figure. Whatever the legal position, members trust the committee with their details, and good practice protects them either way.

The OAIC statements in this guide were checked 4 October 2026, on the OAIC pages listed in the sources at the end. The law and the OAIC’s guidance can change, so check the current pages before relying on them.

What personal information clubs hold

A motor vehicle club holds more personal information than most committees realise. Personal information is information about an identifiable person.

A typical club holds:

Kind of recordExamples
Contact detailsNames, home addresses, phone numbers, email addresses
MembershipMembership type, join date, renewal history, status
MoneyInvoices, payments, amounts owing
VehiclesPlate, make, model, year, VIN, engine details, linked to an owner
Scheme recordsLog books issued, MR334 forms, reports to the Registrar
Authorised personsNomination details, including full name, address and SA client or licence number (the Code, clause 2.9)
Meetings and eventsMinutes, attendance, RSVPs, photos

Some of this is sensitive in practice even when it is not in law. A list linking names, home addresses and valuable historic vehicles is the kind of information a thief would value. Treat it with care.

The Privacy Act and the Australian Privacy Principles

The Privacy Act 1988 is the main federal privacy law. The OAIC describes it as introduced “to promote and protect the privacy of individuals and to regulate how Australian Government agencies and organisations with an annual turnover of more than $3 million, and some other organisations, handle personal information”.

The heart of the Act is the 13 Australian Privacy Principles (APPs). The OAIC describes them as principles-based law, which gives organisations flexibility to fit them to how they work. They apply to any organisation or agency the Act covers.

The APPs a club committee would recognise most easily are:

PrincipleWhat it covers (OAIC summary)
APP 1Open and transparent management of personal information
APP 3Collection of solicited personal information
APP 5Telling people about certain matters when you collect their information
APP 6Use or disclosure of personal information
APP 7Direct marketing
APP 10Taking reasonable steps to keep information accurate, up to date and complete
APP 11Taking reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure
APP 12Giving people access to information held about them
APP 13Correcting information held about people

The full list and the OAIC’s guidelines on each principle are on the OAIC website.

Does the Act apply to your club?

It depends mainly on your club’s annual turnover, and also on what the club does. The OAIC’s guidance points to the questions below. Work through them, then confirm your answer with the OAIC or a lawyer.

The small business exemption

The OAIC says the Privacy Act applies to a not-for-profit if its annual turnover is greater than $3 million. For this purpose, the OAIC says annual turnover “includes all income from all sources. It does not include assets held, capital gains or proceeds of capital sales”.

So a club’s turnover includes membership fees, event income and any other income, not only subscriptions. A club that owns valuable assets, such as a clubroom or a collection, does not count those assets as turnover.

Exceptions that bring smaller clubs under the Act

Being under $3 million does not settle it. The OAIC says a not-for-profit must also comply with the Act if it is:

  • a contracted service provider for an Australian Government contract
  • an organisation providing health services
  • a business that sells or purchases personal information or trades it for a benefit
  • related to a larger body corporate that is subject to the Act

The OAIC’s guidance for sporting clubs makes a similar point: many smaller clubs may be covered “because they are related to a larger organisation or because they provide a health service and hold health information”. The OAIC’s small business page lists further circumstances that apply to some businesses.

Most motor vehicle clubs will not provide health services or trade in members’ information. But a club that is part of a larger body, or that does something unusual, should check carefully.

Opting in

A club that is not covered can choose to be. The OAIC says small businesses and not-for-profits with an annual turnover of $3 million or less can opt in, provided they are not health service providers and do not trade in personal information.

According to the OAIC:

  • the club completes the OAIC’s opt-in application form
  • it must provide its privacy policy (applications without one are declined)
  • there is no fee for opting in or opting out
  • once approved, the club’s trading name and ABN go on a public opt-in register
  • the club then becomes subject to the APPs and is treated as covered for complaints and enforcement
  • it can opt out later by notifying the OAIC in writing

The OAIC describes opting in as a public commitment to good privacy practice. It is a decision for the committee, and possibly for a general meeting, rather than something to do in passing.

Data breaches

A data breach is when personal information is lost, or someone accesses or discloses it without authority. The OAIC gives examples such as lost or stolen devices, hacked databases, and personal information sent to the wrong person by mistake.

For clubs covered by the Act, the Notifiable Data Breaches scheme applies. The OAIC says any organisation or agency the Privacy Act covers must notify affected individuals and the OAIC when a data breach is likely to result in serious harm.

The OAIC says a breach is an eligible data breach when:

  1. there is unauthorised access to or disclosure of personal information, or a loss of personal information, that the organisation holds
  2. this is likely to result in serious harm to one or more individuals
  3. the organisation has not been able to prevent the likely risk of serious harm with remedial action

If quick action (such as remotely wiping a lost device) means serious harm is no longer likely, the OAIC says the breach is not an eligible data breach. Where an organisation suspects an eligible breach, the OAIC says it must take all reasonable steps to complete its assessment within 30 calendar days.

A notification to members must include the organisation’s name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for the steps people can take.

Clubs not covered by the Act are not bound by the scheme. Telling members promptly and honestly when their details have gone astray is still the right thing to do.

Good practice for every club

These habits are good practice, whether or not the Privacy Act applies to your club. They are not a statement of what the law requires.

Collect only what you need

Ask for information the club will actually use. If you never post anything, you may not need a home address for every member. If you do not need a date of birth, do not ask for one. Every field you collect is a field you must protect.

Tell members why

On the membership form, say what you collect, why, and who will see it. A short paragraph is enough. Members are more relaxed about sharing when they understand the reason.

Limit access by role

Each volunteer should see what their job needs. The treasurer needs payment records; the events helper usually does not. The registrar needs vehicles and log books; the newsletter editor may need only names and postal addresses. Fewer people with access means fewer chances for a mistake. Our page on roles and the activity log shows how MemberCrew handles this.

Keep it secure

Avoid emailing whole member lists as attachments. Avoid keeping the register on one volunteer’s personal laptop or a USB stick. Use strong passwords, and change access when committee members change. Our committee handover checklist includes passwords and access.

Keep it accurate

Wrong details cause real problems: renewal notices to old addresses, log books recorded against the wrong vehicle. Give members an easy way to update their details, and correct errors when you find them.

Delete what you no longer need

Do not keep personal information forever just in case. The OAIC says indefinite retention is unlikely to comply with the APPs. Set a review each year, perhaps after the AGM, and securely delete records the club no longer needs.

Plan for a breach

Decide now who does what if something goes wrong: who contains it, who assesses it, who speaks to members. A one-page plan agreed by the committee is far better than working it out in a hurry.

Scheme records and the five-year rule

Clubs on the Conditional Registration Scheme must keep some records for five years, which sits alongside the good practice of deleting what you no longer need. The Code requires recognised clubs to keep records of MR334 vehicles, duplicate MR334 forms, log books issued to financial members, and other Scheme administration documents, including membership records and minutes, for five years from the date of the document (the Code, clause 2.39). The Department may audit those records (the Code, clause 2.40).

In practice, that means:

  • keep the records the Code lists for the full five years, even for members who have left
  • after five years, review them and securely delete what the club no longer needs
  • keep records that are not Scheme related only as long as the club needs them

For clubs covered by the Act, the OAIC’s APP 11 guidelines say the duty to destroy or de-identify information no longer needed does not apply where the organisation is required by or under an Australian law, or a court or tribunal order, to keep it. Whether that exception applies to the Code’s record-keeping rule is a question for your own advice. Our Scheme guide explains the wider record-keeping duties.

How MemberCrew helps

MemberCrew is built to make these habits easier. Club data is stored in Australia (Sydney). Each committee member only sees what their role allows: an events editor, for example, sees no money or contact details. Every change is recorded in an activity log showing who did what and when.

The club owns its data. Committees can download a full export of all their records at any time, from reports and exports. If a club leaves, it gets a complete export, and its data is deleted on request once the club confirms it has the export.

See security and privacy for the detail, and our privacy policy for how MemberCrew handles information.

Common questions

Does the Privacy Act apply to our club?

It depends on your club's annual turnover and on other factors. The OAIC says the Act applies to a not-for-profit with an annual turnover of more than $3 million, and to some smaller organisations in particular circumstances, such as providing a health service or trading in personal information. Check your own position with the OAIC or a lawyer.

What counts as turnover for the $3 million threshold?

The OAIC says annual turnover for the Privacy Act includes all income from all sources. It does not include assets held, capital gains or proceeds of capital sales. If your club is anywhere near the threshold, get advice.

Can a small club choose to be covered by the Privacy Act?

Yes. The OAIC says small businesses and not-for-profits with an annual turnover of $3 million or less can opt in, provided they are not health service providers or trading in personal information. The club applies on the OAIC's form, must have a privacy policy, and pays no fee.

What should we do if member data is lost or sent to the wrong person?

Act quickly to contain it: recover the information, change passwords, or ask the recipient to delete it. Then work out who is affected and how serious the harm could be. If the Privacy Act covers your club, the Notifiable Data Breaches scheme may require you to notify affected members and the OAIC.

How long should we keep records about former members?

Keep them only as long as you need them, unless another rule says otherwise. For Scheme clubs, the Code requires certain records, including membership records, to be kept for five years from the date of the document (the Code, clause 2.39). After that, review what you still need and securely delete the rest.

Can we share our member list with a sponsor or another club?

Be very careful. Members gave you their details to belong to the club, and most will not expect them to be passed on. If your club is covered by the Privacy Act, there are rules about use, disclosure and direct marketing. Ask members first, and get advice if unsure.

Should every committee member see every member's details?

No. Each volunteer should see what their role needs and nothing more. An events helper, for example, rarely needs members' home addresses or payment history. Limiting access reduces the chance of a mistake and the harm if one happens.

Do we need a privacy policy if the Act does not apply?

It is not always required, but it is good practice. A short policy tells members what you collect, why, who sees it and how to ask questions. If the club ever decides to opt in to the Act, the OAIC requires a privacy policy as part of the application.

See it with your own club in mind.

Bring whoever does the club’s paperwork. We will show you around and answer the committee’s questions.