The Sector
Member data protection in 2026: what actually changed
The compliance diary for a UK membership body used to be short. Renew the ICO registration, keep the privacy notice current, answer the occasional subject access request inside the month. That diary no longer describes the job. Three regimes now bear on the same member database at once: a rewritten UK data protection statute, a regulator whose marketing fines have grown teeth, and a European AI law that reaches across the Channel. The work is manageable, but the order matters.
The Data (Use and Access) Act 2025 is now in force, PECR marketing fines have risen to UK GDPR levels of up to £17.5 million or 4% of worldwide turnover, and the EU AI Act applies in full from 2 August 2026. The working order: fix marketing consent first, then subject access discipline, then international transfers and AI contract terms at the next renewal.
What has the DUAA actually changed?
More than the headlines suggested, and the ICO confirms that the data protection and PECR provisions are all now in force. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and commenced in phases through late 2025 and into 2026, with the ICO’s DUAA hub tracking each tranche.
Five changes matter to a membership body. A statutory list of “recognised legitimate interests” (Schedule 4) puts several routine processing purposes beyond argument, trimming some balancing tests. Section 80 rewrites the automated decision-making rules, permitting more solely automated decisions provided safeguards (human review routes, the right to make representations) are in place. Section 78 puts the “reasonable and proportionate” standard for subject access searches on a statutory footing, which protects a body that searches properly from demands to search endlessly. A new duty requires every controller to run a complaints process, so members can complain to you before they complain to the ICO. And section 114 gives charities a soft opt-in for direct marketing email, which any membership body constituted as a charity should now have assessed against its renewal and legacies communications.
Is the ICO still enforcing against marketing?
Yes, and the ceiling has moved. DUAA raised the maximum PECR penalty from £500,000 to UK GDPR levels, £17.5 million or 4% of worldwide turnover, with the higher caps in force since February 2026. Enforcement has continued through 2026 on the familiar pattern: penalty notices for unsolicited marketing calls and texts, including six-figure fines this year for call campaigns to numbers registered with the Telephone Preference Service.
The read-across for membership bodies is direct. Few are cold-calling anyone. Most do send large volumes of marketing email on soft opt-in or legitimate interests, and the evidential standard is the same: who consented, when, to what, and where is the record. A body that cannot produce its consent basis for the last membership campaign is carrying GDPR-scale exposure on PECR conduct. This is why marketing consent sits first in the working order: it is the largest fine surface most membership bodies actually have.
Does the EU AI Act reach a UK membership body?
Sometimes, and 2 August 2026 is the date that matters. Under Article 113 of Regulation (EU) 2024/1689, the Act applies in full from that date, following the prohibited-practices rules in February 2025 and the general-purpose AI rules in August 2025. Article 2 gives it extraterritorial reach: it catches organisations outside the EU that place AI systems on the EU market, and those whose AI outputs are used in the EU.
For most UK membership bodies the duties, where triggered at all, are transparency-grade: labelling AI interactions, disclosing AI-generated content, keeping human oversight where decisions affect people. The high-risk regime (employment decisions, access to essential services, credit) touches few association workflows directly, though a body with EU members, an EU office or EU-facing services should map its AI use against the annexes rather than assume. Our news analysis of the August 2026 application date sets out the boundary cases. The proportionate position for a UK-only body is watchful rather than alarmed: know what you use, know where its outputs go, and keep the receipts.
What about member data processed offshore?
Every AMS contract now needs a transfer answer, in writing. The UK’s instruments remain the IDTA and the UK addendum to the EU standard contractual clauses, in use since March 2022, and DUAA Schedule 7 reframes the underlying rules around transfers approved by regulations and a data protection test. The EU’s adequacy decisions for the UK remain the cheapest route for bodies with EU operations, and their continued renewal is the macro risk to watch.
The procurement line is short enough to memorise: where is member data processed, under which transfer mechanism, and can you evidence it? A vendor whose answer is a region name rather than a mechanism has not done the work. This belongs in every AMS tender from now on, and it pairs with the ownership questions covered in our market analysis: who owns the supplier, and where under that owner’s group structure does your data actually sit.
What should “no training on member data” say in a contract?
Exactly that, plus the machinery around it. As AI features spread through membership software, the clause buyers are now insisting on has four parts. No use of member personal data to train, fine-tune or improve any model, whether the vendor’s own or a third party’s. A defined retention period for prompts and outputs, with deletion on exit. Full disclosure of subprocessors, including the model providers underneath the feature. And audit or questionnaire rights sufficient to check the first three.
A general “we comply with data protection law” sentence does none of this, because training on customer data can be perfectly lawful and still be something your board never agreed to. The clause converts a policy preference into a contractual fact. Put it in at renewal, when the other terms are on the table anyway.
What does good DSAR discipline look like in 2026?
Boring, logged and fast. The clock is still one month from receipt, extendable by two for complex requests, and DUAA now also requires a complaints route that a member must be offered before they escalate to the ICO. Good practice is a named owner for each request, a search scope recorded at the outset (which systems, which date ranges, why), and a search effort matched to the new statutory standard: reasonable and proportionate, documented as you go.
The failure mode is not malice but drift: a request that lands in a shared inbox, surfaces on day 24, and gets a panicked all-staff search. A membership body’s AMS holds most of the answer set, so the practical test is whether your team can run a complete member extract, including event history and communication preferences, in an afternoon. If it cannot, the fix is a data mapping exercise, and it is cheaper done before the request arrives than during it.
- PECR exposure is now GDPR-scale; trustees should see evidence of marketing consent bases, not verbal assurance that they exist.
- Every supplier contract touching member data needs a named transfer mechanism and a no-training clause, scheduled at renewal.
- DSAR performance (clock compliance, recorded search scope, complaints handling) should stand as a reported KPI, not an anecdote.