A member resigns, a volunteer steps down after a season, a donor's last gift was three years ago and nobody's heard from them since — and their record just sits in the membership spreadsheet or the donor database, unchanged, because nobody made an active decision to remove it and nobody made an active decision to keep it either. For a club, society, or charity run by a rotating committee, that's usually not a policy choice. It's what happens by default when retention was never actually assigned to anyone.
Two instincts pull in opposite directions here, and both are wrong on their own. The first is "they've left, so delete everything" — treating departure as an automatic trigger for erasure. The second is "we might need it one day," which quietly becomes never deleting anything at all. UK GDPR's storage limitation principle sits between those: personal data can't be kept indefinitely just in case it becomes useful, but leaving doesn't create an automatic right to erasure either. What actually governs the answer is why the data was held in the first place, and whether that reason still applies.
Why a blanket "delete on departure" rule doesn't hold up
Some of what a club or charity holds on a former member has a reason to outlive the membership itself. Gift Aid declarations and the records supporting them are the clearest example: HMRC requires charities to retain those records for a set number of years after the tax year or accounting period they relate to (and for a standing-order or other enduring declaration covering ongoing giving, that clock doesn't even start until well after the donor's final gift), which means a donor's giving history can't simply be wiped the moment they stop donating without the organisation losing its ability to justify a Gift Aid claim if HMRC ever asks. Safeguarding records involving a departed volunteer are another example that shouldn't be deleted on a fixed schedule tied to when they left — sector guidance such as NSPCC's recommends keeping allegations against a member of staff or a volunteer until they reach normal retirement age, or for 10 years, whichever is longer, and explicitly regardless of whether the person has since stopped being involved with the organisation. Financial records tied to a leaver's payments, and anything relevant to a dispute or an ongoing complaint, follow the same logic: the data's relevance is tied to the reason it was collected, not to whether the person is still a member.
None of that is a reason to keep everything, though — it's a reason to be specific. A record with a genuine ongoing purpose (a statutory retention obligation, a live dispute, a safeguarding history) can be kept for as long as that purpose lasts. A record with no remaining purpose — an old newsletter mailing preference, a contact number kept only because it was never deleted, notes from a role the person no longer holds — has nothing left justifying it, and holding it "just in case" is exactly the indefinite retention the storage limitation principle rules out.
What a workable policy actually looks like for a volunteer-run organisation
The ICO's own position for small organisations doing occasional, low-risk processing is that a full written retention schedule isn't always mandatory — but the data still has to be reviewed regularly, and deleted or anonymised once there's no remaining reason to hold it. In practice, for a club or charity, that review is far more achievable than a formal retention schedule with a line for every data category. It can be as simple as: when someone leaves, the person who manages membership or donor records goes through what's held on them and asks, category by category, whether there's a specific ongoing reason to keep it — a live Gift Aid year, an open safeguarding matter, an unresolved dispute — and removes what has no such reason attached.
The part that actually causes the drift into indefinite retention is the same structural gap that shows up elsewhere in volunteer-run governance: nobody owns the decision, so the default is to do nothing, and doing nothing quietly becomes the organisation's retention policy by accident rather than by design. Naming one role — not necessarily a person, since committees turn over — responsible for reviewing leaver records within a set window of departure closes that gap without requiring a formal document nobody will maintain.
If your organisation doesn't have a clear answer for what happens to a leaver's data, Varde's free GDPR assessment for clubs and charities gives you a RAG-rated view of where you stand in around 10–15 minutes. Try the GDPR assessment →