Privacy and GDPR by design
Your data is not our product.
Your organization works with personal data every day: members, volunteers, donors and everyone around them. That data deserves care, so privacy is not a feature we added later. It is built in from the beginning.
- Collect only what you need
- Give access only when needed
- Keep data only as long as necessary
What privacy by design means in practice.
You should not need to be a privacy expert to run a membership administration responsibly. These are the principles the application is built on, and how each one shows up in daily use.
-
Collect only what you need
Personal data should not be collected just because it might be useful one day. Your organization decides which information it really needs, and member records stay limited to that.
- Name
- Email address
- Membership status
Less data means less data to protect.
-
Privacy-friendly defaults
Privacy should not depend on difficult settings. The application starts from the safest sensible position, so personal information is not exposed unless someone deliberately opens it.
- A member sees their own contributions and details, not those of other members.
- A volunteer only gets access to what their role needs.
- Administrative data can be restricted to authorized users.
- Sensitive information can be limited to specific roles.
The starting point is simple: access only what you need to do your job.
-
Clear roles and permissions
Not everyone in an organization needs access to everything. Access follows responsibility, so it is clear who can see and change what.
- Member
- Their own information and contributions
- Volunteer
- What is needed for their volunteer work
- Coordinator
- What is needed to organize activities and volunteers
- Board member
- Administrative and organizational information within their permissions
- Administrator
- System and administrative functions
-
Your organization stays in control
The data belongs to the relationship between your organization and the people involved. Milenia is the tool for managing it, not the owner of it.
When personal data is processed on behalf of your organization, the organization remains the data controller and Milenia acts as the data processor.
Those responsibilities belong in a processing agreement between your organization and the party processing the data.
-
Security is built into the application
Personal data has to be protected against unauthorized access, loss and misuse. Security is part of the architecture, not something added on top.
- Encrypted connections
- Secure authentication
- Role-based access control
- Restricted access to personal data
- Secure data storage
- Audit and activity logging
- Backups and recovery
- API security
- Protection against common application attacks
Measures are chosen according to the type of data and the risks involved.
-
Know who did what
For important administrative actions it helps to know what happened, and who did it. Those actions can be recorded in an audit log.
- Administrator changed a member's email address.
- User removed a membership record.
That gives your organization better control, and a clear answer when someone asks.
-
Keep data only as long as necessary
Personal data should not be kept forever by default. Retention, deletion and anonymization can be applied where appropriate.
- Active member
- Information is actively used for the membership
- Former member
- Handled according to your organization's retention policy
- Data no longer required
- Deleted or anonymized where appropriate
This is the GDPR principle of storage limitation.
-
Help people exercise their rights
People have rights over their own personal data. The application is designed to help your organization answer those requests.
- Access to personal data
- Correction of incorrect information
- Data export
- Deletion where applicable
- Withdrawal of consent, where consent is the legal basis
-
Know why you are collecting data
Knowing a name and an email address is only part of the story. For every processing activity, your organization should be able to answer these questions.
- Why are we collecting this information?
- Which information are we collecting?
- Who needs access to it?
- How long should we keep it?
- What is the legal basis for processing it?
The GDPR offers several legal bases, including consent, contract, legal obligation and legitimate interests. Which one applies depends on the activity and the circumstances.
-
Privacy starts with the design
Privacy should not be something you think about only after something goes wrong. These are the questions we ask while building a feature.
- Do we really need this personal data?
- Who actually needs to see it?
- Can we reach the same result with less data?
- How long should it be kept?
- What happens when someone asks to access or delete their data?
- What happens if an account is compromised?
GDPR by design, at a glance
The principles of the GDPR, and what each one means for the way the application works.
| Principle | What it means in Milenia |
|---|---|
| Lawfulness, fairness and transparency | Processing activities have a documented purpose and a legal basis. |
| Purpose limitation | Data is collected for membership administration, and not reused for anything else. |
| Data minimization | Only the fields an organization actually needs are collected. |
| Accuracy | Members and treasurers can correct information, and changes are logged. |
| Storage limitation | Retention, deletion and anonymization can be applied per organization. |
| Integrity and confidentiality | Encrypted connections, role-based access, secure storage and audit logs. |
| Accountability | Roles, permissions and an audit trail show who did what, and when. |
Read more
The European Data Protection Board publishes the official guidance behind these principles.
- Basic principles of the GDPR
- Data protection by design and by default
- Controller and processor
- Security of personal data
- Lawfulness of processing
This page explains how the application supports your organization's privacy work. It is not legal advice, and it does not replace your own assessment or that of your data protection adviser.
Privacy is built in, not bolted on.
Start with your first statement and see how the defaults hold up in daily use.