Keeping Member Data Safe in a Volunteer-Run Makerspace
When our makerspace network moved sign-ups off paper forms and onto our own community site, I realised how much personal data a small volunteer group quietly collects: names, emails, emergency contacts, which machines someone is trained on and who holds an access card for the front door. None of it is glamorous, but all of it needs looking after.
This is the checklist we now run through every spring. It isn't legal advice, just what works for volunteer-run spaces around Utrecht.
Collect less
Every field on a form is something you have to protect. We dropped date of birth, home address and "how did you hear about us" from our sign-up form. If we need an emergency contact for a laser cutter induction, we ask for it at the induction and keep it only while the person is an active member.
Give fewer people the keys
- Only three coordinators have admin rights on the site. Workshop leads get moderator rights for their own group and nothing more.
- Every admin account uses two-factor login.
- Access cards are logged in one place, and a lost card is switched off the same evening.
Clean up on a schedule
Once a year we remove accounts that haven't been active for 18 months, after sending a friendly heads-up first. Old volunteer rota sheets get deleted, not archived "just in case".
Practise the bad day
We keep backups, and twice a year someone actually restores one onto a spare laptop. The first attempt took four hours and two pots of coffee. Now it takes forty minutes.
A printable version of this checklist goes up in Local Makers Collective next week, for anyone running a space of their own.
Info
html
asdasdasd