Answer The Hate

COM · Organise the group

The list of people, and what you owe them

Where the membership list lives, who can see it, what you tell people when you take their details, and what to do on the day it goes wrong.

Any countryAn evening8 min read

A woman in a yellow football shirt raises one fist beneath a yellow scarf reading Emily is one of our own, held up across the frame by other hands.
Amanda Rose · May 2025

The short version

  1. Every column you add is a column you have to protect and later delete. Collect less than you want to.
  2. Two people can reach the list, always. One person's phone is not a place to keep other people's names.
  3. Tell people what you are recording, who sees it, and how to leave, at the moment you take their details.
  4. Set a deletion rule and run it. A list nobody prunes becomes a liability nobody owns.
  5. People on your list can lose work for being on it. Design around that rather than around convenience.
What you need3 items
  • Your current contact list, wherever it actually is
  • A blank sheet of paper
  • The name of one other person in the group you trust

You do not need permission to fix this, and you do not need to be technical. If you are holding other people’s names and numbers, you are already the person responsible for them. You can make this materially better today, in about ninety minutes.

Read this before you open anything. The most common way a list gets worse is being copied. Delete the old copy before you make another.

This guide cannot tell you your legal obligations. Those depend on where you are and where your members are, so it teaches the questions instead, following how to find out the law where you are.

The failures we have actually seen are ordinary: a lost phone, a share link set to anyone, a message sent with sixty addresses visible.

Collect less than you want to

Every interesting field is a field you have to protect, explain, and delete. Five rules, numbered so you can be asked about them later.

Rule 1. One column, one use. If you cannot name the message or decision a column feeds, remove the column.

Rule 2. Two hands on every list. Two named people can reach the current list at all times. Never one, rarely more than four.

Rule 3. Nothing you would not read back. If you would not read a field aloud to the person it describes, it does not belong in the file.

Rule 4. The ninety day sweep. Every ninety days, one named person deletes what is no longer needed. Diary entry, not intention.

Rule 5. Seven days to leave. Anybody who asks to come off is off within seven days, without being asked why.

The list specification

Six fields, smaller than what you are currently keeping, with no employer, age or address among them. One worked row, then the same grid blank with the rule printed in it.

Name Route Consent record Will do Group Last contact
Miriam Adler 07700 900412 14 Mar 2026, short form, Kingsway stall Stewarding, weekday evenings Stall team 2 Jul 2026
as they gave it one only date and form of words up to 15 words one tag a date

The fifteen minute audit

Do this now, before you change anything else.

  • Write down every place a copy exists: phones, laptops, cloud drives, sent email, printed sheets, an old group chat.
  • Risk item. For each copy, name the person who would act if that device were stolen tonight. If the answer is “nobody”, delete that copy first.
  • Read your column headings out loud. Delete every one that fails Rule 1 or Rule 3, and anything recording religion, ethnicity, political view or health.

What you tell them, and what you owe them

Four facts, at the moment of collection. What you are writing down. Who can see it. What you will send. How to get off.

“Name and number only, two of us see it, our events only, text REMOVE to come off.”

Use your own words, and keep the four facts.

And the exit clause, because a right nobody can quote is not a right:

“You can leave at any time by telling any of the named people. You do not have to give a reason. You are deleted within seven days, with one message confirming it.”

Where does the list live?

The specific, common failure is a list existing in exactly one place: one person’s phone, or one person’s personal email account. Before you move it anywhere: the move is finished when the old copy is gone, not when the new copy works.

One shared account that the group owns, not a person. A group email address or a group drive, with the password held by two named people. The test is whether the list survives any single member leaving.

Access by named person, written down, kept with the list. Editing is two to four people, because more editors is how a list quietly loses a hundred rows. Exports get deleted the same day.

When somebody with access leaves: remove their access, change the password, and ask them in writing to delete any copies they hold. You cannot force that deletion, so make it a normal part of leaving.

Are you holding special category information?

Read this before you add any column about a person’s background, beliefs, health or status. Which categories carry extra protection, and what comes with holding them, differs by country and you have to check yours.

You can hold sensitive information without ever creating a column for it. A list of the members of a Jewish community group implies religion for everybody on it. A list of people who attended a pro-Israel event implies political opinion.

Do not record what you were told in confidence. If somebody tells you they are frightened, or that their employer does not know they come, that is a conversation. It is not a field.

How long do you keep it?

What Kept for Deleted by
Active members While active, reviewed every 90 days List holder
No response for 12 months Ask once, then remove List holder
Event sign-ups 30 days after the event Whoever ran it
Access and dietary needs 7 days after the event Whoever ran it
Asked to leave Removed within 7 days List holder

Write the deletion date inside the file, in words: this list is pruned on 1 October 2026 by Rachel. Deleting means deleted, so check the archive, the trash and the exports too.

When it goes wrong

Read this now, not on the day. Each of these has a first hour that decides how bad it becomes.

A phone or laptop with the list on it is lost or stolen. From another device, change the password on the account that holds the list and sign out all other sessions. Write down what was on the device and how recent it was, then tell the other named holders within the hour.

A share link was set to anyone, or an email went out with the addresses in To or Cc. Set the link to off immediately. Do not send a second message to the same list by the same method, which is how this doubles. Write one apology, addresses in Bcc, saying what was exposed to whom. Then change the habit: Bcc, a mailing tool, or batches of one.

Somebody outside the group demands you hand the list over. Do not hand anything over in the moment, and do not refuse in the moment either. Say one sentence: “I am not the person who can answer that today. Put the request in writing and say what it is made under, and you will get a response.” Write down who asked, what for and when, and tell the other named holders the same day. A demand backed by a court order is different, and that is when you get advice from somebody who knows your jurisdiction.

The telling test. Could the exposure realistically cause somebody harm, including being identified at work? Is there anything they can do differently if they know? If either answer is yes, tell them what happened, what was exposed, and what you are doing next. People forgive the incident far more readily than the concealment.

How to find out what applies to you

The kind of body you are looking for is a data protection authority, an information commissioner, or a privacy commissioner. A directory is in the sources below. Three facts to find, each findable in an afternoon.

  1. The name of the body that regulates personal data where you are.
  2. Whether a group like yours has to register with it, and what that costs.
  3. What that body calls a personal data breach, whether you are expected to report one, and within how many hours.

Write down what you were told, by whom, and when.

Where this advice can backfire

Saying out loud what you are recording will lose you some sign-ups. Our judgement is that those people are exactly the ones you did not want to add unknowingly.

Hardening the list can destroy it. Password managers and restricted access have produced groups that lost the list outright, so every security step needs a second person who can get in. And naming your list holders publicly makes those two people visible: name them to members, and think hard before naming them anywhere public.

The fifteen minute audit

Two questions answered from memory. Who else can get into the list if you are unreachable for a fortnight? And what were people told about their data at the moment they gave it to you?

Then write two lines, because a plan with a real cue attached is what gets carried out.

If it is Tuesday 4 August and I have finished the school run, then I will open the contact list and run the fifteen minute audit.

Now yours. The second line decides whether the first happens.

If it is [day and time an outside observer could see happening], then I will [the specific first thing you will open or write].

If [the likeliest obstacle: no time, cannot find the list, nobody to be the second pair of hands], then I will [your pre-written response to it].

Sources3 cited

Sources

Where this page relies on somebody else, here they are, so you can check rather than take our word for it.

  1. Members of the Global Privacy Assembly, Members section, for finding the regulator in your country
    Global Privacy Assembly
  2. Surveillance Self-Defense
    Electronic Frontier Foundation
  3. Data protection
    Council of Europe