It's one of the most common things said in a committee room or a two-person office: "we're too small for GDPR to worry about." Usually it's said with real confidence, and usually it isn't right. UK GDPR doesn't carry a headcount threshold or a turnover test. If an organisation holds a membership list, a volunteer rota, a donor spreadsheet, or even a WhatsApp group used to run club business, it is processing personal data — and the obligations that come with that apply exactly the same whether the organisation behind it is a multinational or three people and a shared spreadsheet.

The confidence usually comes from somewhere real, though, which is part of why the assumption is so sticky. There genuinely is a size-related distinction in UK data protection practice — it's just a much narrower one than people think, and it isn't the one doing the work in most people's heads.

The exemption that does exist, and the one that doesn't

The actual carve-out sits in ICO registration, and it's more specific than most people assume. A not-for-profit organisation can be exempt from paying the ICO's annual data protection fee if it meets all of a fairly narrow set of conditions: it processes personal data only to establish or maintain membership or support, or to administer activities for members or people in regular contact with it; it only holds data on people it actually needs to process for those purposes; and it only processes what's necessary for them. There's no test in there about the volume of data involved or whether the processing happens electronically — a club with a well-run online membership database can still qualify, provided what it's actually doing stays within those conditions.

It's narrower in another way, too, and this is the part that trips people up: even a genuinely qualifying organisation falls outside the exemption for specific activities that sit outside plain membership administration. The ICO's own guidance is explicit that CCTV used for crime prevention takes an organisation outside the exemption regardless of everything else about it, and the same logic extends to things like a club shop processing payment card data, marketing sent to non-members, or analytics running on a public-facing website. Qualifying for the exemption isn't a single yes/no answer for the whole organisation — it can genuinely depend on which specific activity is being asked about.

Either way, this is an exemption from a registration fee, not from the substance of the law. An organisation can be entirely correct that it doesn't owe the fee for its membership administration, and still have other activity — that CCTV feed, that online shop — squarely inside GDPR's scope regardless.

That gap is where most of the actual exposure sits. Not usually in a dramatic enforcement action against a small club — in practice, enforcement against small organisations tends to follow something specific going badly wrong rather than a routine sweep — but in the ordinary, unglamorous fact of not having thought about any of this at all. No sense of what personal data is actually held, no idea who to point to if a member asks a direct question about their own information, no record of a decision that was in fact reasonable but was never written down anywhere.

What actually changes once the assumption is corrected

Getting this right doesn't mean a small organisation needs the same infrastructure as a regulated firm. It means something much more proportionate: a short, honest list of what personal data is actually held and why, who's responsible for it, roughly how long it's kept, and what happens if someone asks about their own data. For most clubs, societies, and small charities, that's an afternoon's work done properly once, not an ongoing programme — the failure mode isn't usually complexity, it's never starting because the starting assumption was that there was nothing to start.

That's also the shape of the assessment tooling built under this roof — priced on a tiered basis precisely because a volunteer-run club looking at this for the first time is not the same problem as an FCA-regulated firm with a dedicated compliance function, and shouldn't be treated, or priced, as though it were.