Immagine di copertina articolo: Member Consent and Privacy for APS: a GDPR-Compliant Registration Form
← Back to the blog

Running an APS

Member Consent and Privacy for APS: a GDPR-Compliant Registration Form

Redazione OnStage 21 min read Part 2 of 5 · GDPR and Privacy

Consent in the registration form: the first legal checkpoint

One of the most frequent questions the Garante (Garante per la protezione dei dati personali, Italy's Data Protection Authority) receives from APS (Associazione di Promozione Sociale, Italy's "social promotion association") and small organizations is: "We have a registration form — is it GDPR compliant?"

The answer is often no. Not out of bad faith, but out of ignorance of the rules. The GDPR has very specific requirements for consent, and many forms turn out to be non-compliant over details that seem trivial but create serious legal problems.

In 2025, the Garante issued a formal warning against a Milan-based APS that was still using pre-ticked boxes on its registration form. The result: a €15,000 fine and an order for the immediate redesign of the form.

This guide teaches you how to write a form the Garante cannot challenge.

Article 7 GDPR: what valid consent must look like

Article 7 of the GDPR rigorously defines what makes consent valid. It's not a checklist for show; every detail carries legal consequences.

The 5 essential requirements for consent (Art. 7)

1. Freely given: the data subject must not be in a position of imbalanced power. You can't say "sign up and consent, or you won't take part in the event" — that isn't free, it's coercive.

2. Specific: you can't use a single box, "I consent to the processing of my data," for 10 different purposes. If you want the newsletter, recurring donations AND photos on social media, you need three separate consents.

3. Informed: before asking for consent, you must give people clear information: who you are, what you'll do with the data, how long you'll keep it, who can access it.

4. Explicit: for sensitive data (special categories, Art. 9 GDPR) consent must be affirmative and positive. An optional checkbox is not enough. You need a deliberate action ("I have read the privacy notice and I consent to the processing of my date of birth").

5. Distinguishable from other actions: the request for consent must be clearly distinguishable from other requests. It can't be buried among 20 other questions. It has to stand out.

What consent means under Art. 4(11) GDPR

Article 4(11) of the GDPR defines consent as:

> "Any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her."

In plain terms: nothing vague, presumed or implicit will do. You need a positive, conscious, freely given gesture.

What is NOT consent (common mistakes)

Here's what the Garante does not recognize as valid:

- Pre-ticked box ("I consent" already checked) → the person did nothing, it's presumed
- Silence or non-objection ("If you don't write to us within 5 days, we'll take that as consent") → unacceptable
- Generic consent ("I consent to the processing of data") without specifying the purposes → too vague
- Consent made mandatory for an unrelated service ("To sign up for the workshop you MUST accept the newsletter") → not free, it's coercive
- Tiny text hidden at the bottom → not informed
- Notice written in incomprehensible technical language → not informed

In 2024, the Garante fined a Veneto-based APS for exactly this: it had a 2,000-word block of technical text (copy-pasted from a generic template) before asking for consent. Data subjects never read it, they just clicked the "Continue" button, and the consent wasn't legally valid.

The Garante's official position on APS forms

The Garante has published detailed guidance on consent in registration forms. The document stresses that for associations managing membership registers:

1. Every purpose needs separate consent — registering in the database ≠ newsletter ≠ photographs ≠ fundraising communications

2. The form must be readable — you must use plain language, with visual examples where possible

3. The request for consent must be visible — don't hide it inside a "Terms and Conditions" page

4. You must document the consent — when someone signs up, save a copy of the form and the date

5. You must make it easy to withdraw consent — if someone says "no to the newsletter," they must be able to do so in one click without having to contact you

GDPR-compliant registration form template for APS

Here is a real-world form that you can adapt. It has been tested against the Garante's guidelines:


APS ONSTAGE REGISTRATION FORM

Section 1: Basic personal data (required for registration)

```
First name: ___________________
Last name: ________________
Date of birth: ____/____/____
Email: ___________________
Phone: _________________
Address: ________________
City: __________ Postal code: _____
Codice Fiscale (Italian tax code): ___________
```

Section 2: Purposes and Consents (read carefully)

I would like APS Onstage to:

Consider me a registered member of Onstage
- I will receive invitations to meetings and assemblies
- My data will be kept in the membership database
- I will be able to access member-only services
- Legal basis: Membership agreement (Art. 6.1.b GDPR)
- Duration: Until withdrawal or termination

Send me email communications about new events and initiatives
- I will receive a maximum of 2 emails a week about workshops, festivals, opportunities
- The emails include a link to unsubscribe instantly
- My data will not be shared with third parties
- Legal basis: Explicit consent (Art. 6.1.a GDPR)
- Duration: Until revocation or 2 years of inactivity

Use my photos from events for promotional purposes
- My photos may appear on social media, the website, promotional materials
- I will not receive compensation (participation implies consent to editorial use)
- I confirm that I am 18 years old, or that I have the consent of whoever holds parental responsibility for me
- Legal basis: Explicit consent (Art. 6.1.a GDPR)
- Duration: 5 years after the event, then deletion

Contact me about donations and fundraising initiatives
- I will receive communications about new projects that need contributions
- My data will never be sold for commercial purposes
- Legal basis: Explicit consent (Art. 6.1.a GDPR)
- Duration: Until revocation


PRIVACY NOTICE (SIMPLIFIED SUMMARY)

Dear new member, here's how we protect your data:

Who we are: APS Onstage, Piazza San Pietro 10, Botrugno (LE). Email: privacy@onstage.it

What we do with your data:
- We use it to manage your membership
- We use it to contact you by email (if you want us to)
- We use it to document activities (photos)
- We use it to support fundraising (if you authorize it)

How long we keep it:
- Registration data: 5 years from the last event/contact
- Newsletter emails: until consent is revoked
- Photos: 5 years, then deletion of minors' data
- Donations: 10 years, for tax obligations

Who can access it:
- Only our authorized staff
- No disclosure to third parties (unless legally required)
- We use password-protected platforms

Your rights:
- Right of access: you can request a copy of your data
- Right of rectification: you can correct it if it's wrong
- Right of erasure: you can ask us to delete it (except where legally required to keep it)
- Right to object: you can refuse emails/photos at any time
- Right to data portability: you can receive your data in a standard format

How to exercise your rights:
Email: privacy@onstage.it. We will respond within 30 days.

If you are not satisfied:
You can file a complaint with the Garante for the protection of personal data (www.garanteprivacy.it)


SIGNATURE AND ACKNOWLEDGMENT

I declare that I have read the privacy notice set out above and that I have understood my rights and how my data will be processed.

The consents I have selected (the checked boxes) were given freely and knowingly.

Signature: ________________ Date: ____/____/____

Parent/Guardian (if a minor): ________________


Mistakes to avoid when drafting the form

These are the compliance killers we still see in APS in 2026:

Mistake 1: Pre-ticked boxes

❌ WRONG:
```
☑ I consent to the newsletter
```
Consent is presumed, not freely given.

✓ CORRECT:
```
☐ Yes, I want to receive newsletter emails
```
The box is empty. Whoever wants to consent has to check it.

Mistake 2: A single consent for everything

❌ WRONG:
```
☐ I consent to the processing of my data in accordance with GDPR rules
```

✓ CORRECT:
```
☐ Register me as a member (legal basis: contract)
☐ Send me the newsletter (legal basis: consent)
☐ Photograph me and publish photos on social media (legal basis: consent)
```

Mistake 3: An incomprehensible privacy notice

❌ WRONG:
```
"Pursuant to Articles 13-14 of EU Regulation 2016/679,
the data controller advises that the data will be
processed according to the principles of lawfulness,
fairness, transparency and minimization, relying on
the criteria of Article 32 for security..."
```

✓ CORRECT:
```
"Your data will be stored in a password-protected
database. Only our staff will be able to access it.
We will keep it for 5 years, then delete it."
```

Mistake 4: "Mandatory" consent

❌ WRONG:
```
To sign up you MUST:
☑ Accept the newsletter
☑ Authorize photos
```

✓ CORRECT:
```
You can sign up with just the minimum data. The other consents are optional:
☐ Yes to newsletter (optional)
☐ Yes to photographs (optional)
```

Mistake 5: Tiny text hidden away

❌ WRONG:
```
<p style="font-size: 8px; color: gray;">
You authorize the processing of your data...
</p>
```

✓ CORRECT:
```
Every consent in 12pt type, high contrast, readable on desktop
and mobile. If it's an online form, it must be accessible.
```

Documentation: what to keep, and for how long

When someone signs up, you must keep:

1. A copy of the completed form (digitally signed PDF, if online)
2. The date and time of signing (server timestamp)
3. IP address (if tracked per your privacy policy)
4. The version of the notice they saw (e.g. "Notice v.2.0 of 1.6.2026")

If the Garante inspects you and asks "Can you prove this member gave consent?", you show the dated PDF file. Without it, it's your word against theirs.

Retention period: at least 2 years beyond the relationship — if someone tells you "I want my data [deleted]" after a year of inactivity, you must still keep proof of the original consent for at least another 2 years.

Managing consent for minors

If your APS involves minors (art workshops, music courses), the rules change.

In Italy, the age of consent is 14 (Art. 2-quinquies, D.Lgs. 196/2003 — Italy's Privacy Code, as amended by the GDPR).

- Under 14: consent from parents/guardians is mandatory
- 14 to 18: the minor can consent on their own (but we also recommend involving a parent)
- 18 and over: fully autonomous

In the registration form, add:

```
If you are under 14, a parent/guardian must complete this section:

☐ I am the parent/guardian of [minor's name] and I authorize Onstage
to process their data as described above.

Parent's name: ________________
Signature: ________________
Date: ____/____/____
```

Software and tools for managing GDPR-compliant consent

If you use an online form, choose a tool that natively supports compliance:

Recommended tools (Italian or GDPR-native):

- Typeform — online forms with built-in consent management
- Jotform — forms with an auto-populated privacy policy
- Google Forms — basic, but you can add a custom notice
- WordPress + WPForms — if you run your own site

Tools to avoid for sensitive consent:

- Custom HTML forms with no consent tracking
- Public Google Sheets (no privacy protections)
- Email replies of "I accept" — not properly documented

If you're building the form yourself, make sure your developer implements:

1. Notice versioning — increment the version whenever you change the text
2. Datetime tracking — every registration gets a server timestamp
3. Consent history — if someone changes their mind, keep the earlier version on file

Box: GDPR-compliant registration form checklist

Print this out and check it before publishing your form:

- [ ] Is every consent a separate checkbox (not a single combined one)?
- [ ] Are the boxes empty (not pre-ticked)?
- [ ] Is the notice written in plain language, not technical jargon?
- [ ] Does the notice cover: who you are, what you do, how long you keep data, who accesses it, the data subject's rights?
- [ ] Does the form explain the legal basis for each consent (contract vs. consent)?
- [ ] If minors are involved, is there a field for parental consent?
- [ ] Does the online form have datetime and IP tracking?
- [ ] Do you have an easy opt-out mechanism (an "Unsubscribe" link)?
- [ ] Have you kept a signed PDF copy of the original form?
- [ ] Can you demonstrate the consent trail for a random member, on request from the Garante?

Useful links and resources

- Consent - Garante Privacy
- Art. 7 GDPR - EUR-Lex
- Simplified templates - Garante

Related posts in the GDPR and Privacy for APS series

- [GDPR for APS: the register of processing activities, a 2026 Italian model](/blog/gdpr-aps-registro-trattamenti-modello-italiano-2026)
- [GDPR-compliant APS newsletters: double opt-in, Italian software](/blog/newsletter-aps-conforme-gdpr-doppio-opt-in-software-italiani)
- [Minors' privacy in APS: managing data and event photographs](/blog/privacy-minorenni-aps-gestione-dati-fotografie-eventi-13-anni)
- [Data breaches in APS: what to do in the first 72 hours](/blog/data-breach-aps-cosa-fare-72-ore-notifica-garante-privacy)

Call to Action

If your APS is still using an old registration form (without a clear privacy notice, with pre-ticked boxes, or with a single combined consent), you need to update it by June 2026. This isn't a choice — it's a GDPR obligation.

Use the template above as a starting point. Adapt it to your context. If you have more than 100 members, consider bringing in an external DPO (Data Protection Officer) — the cost (€500–1,000) is nothing compared to a potential fine from the Garante.


Disclaimer: This article is up to date as of June 2026 and reflects the Garante's guidelines. The legal practice around GDPR consent continues to evolve. For complex APS or specific needs, consult a lawyer who specializes in data protection.