S-070 · Detailed guide · Theme 5

Email Group Review

Use Email Group Review to keep club data accurate, appropriately accessed and retained only for a clear purpose.

Where this idea came from

Playbook entry
S-070 · Email Group Review
Theme
Theme 5: Digital, Data & Systems · Subtheme 5: Data Governance
Source material
Current playbook index title and category plus an internally authored detailed-guide draft

Initiative-specific development wave

How this draft was developed

These sources support general principles for digital, data and systems, accessibility, privacy, safety, systems or responsible governance; they are not an endorsement of Email Group Review, a finding that it suits any club or approval of its local design.

Primary references consulted

  • Keeping charity records (Australian Charities and Not-for-profits Commission)
    Used for: Appropriate financial and operational records support governance, decision-making, financial management, risk management and public trust, subject to the organisation's actual obligations.
  • Chapter 3: APP 3 Collection of solicited personal information (Office of the Australian Information Commissioner)
    Used for: Personal-information collection should be lawful, fair, proportionate and minimised, with additional controls for sensitive information; each club must confirm how privacy law applies to it.
  • Chapter 11: APP 11 Security of personal information (Office of the Australian Information Commissioner)
    Used for: Entities covered by the Privacy Act must take reasonable steps to protect personal information and destroy or de-identify it when it is no longer needed, subject to lawful retention requirements.
  • Small business cyber security guide (Australian Signals Directorate's Australian Cyber Security Centre)
    Used for: A practical security baseline includes multi-factor authentication, software updates, regular tested backups and advice suited to the organisation's actual systems and risk.
  • Rotary Clubs (Rotary International)
    Used for: Rotary describes club participation through service, friendship, diversity, integrity and leadership, including online participation for people affected by schedules, mobility or distance.

Candidate District material consulted

These records remain draft evidence and still need a human source decision.

  • Theme_4_All_80_Initiatives_Complete
    The exact current-title crosswalk establishes a candidate legacy record for later comparison. No legacy code, unsupported claim or unchecked operational detail was copied into this draft; current official privacy, security, accessibility and governance controls take precedence.

Theme 5 source-assurance wave

What has been checked

  • 5 current primary pages used by this guide were reopened on 9 August 2026.
  • 5 attributed source claim(s) were mapped to their bounded use in this initiative.
  • Candidate District material remains separate and does not establish this result.
See each source's scope and limit
  • Keeping charity records
    Supports: The value of accurate operational and decision records and proportionate retention controls.
    Does not establish: That a Rotary club is an ACNC-registered charity or that a stated retention period applies to that club.
  • Chapter 3: APP 3 Collection of solicited personal information
    Supports: Data-minimisation, collection-purpose, proportionality and consent safeguards where the Privacy Act and APP 3 apply.
    Does not establish: Whether a particular Rotary club is an APP entity or whether a proposed collection is lawful in its actual circumstances.
  • Chapter 11: APP 11 Security of personal information
    Supports: Security, access, retention and disposal safeguards where the Privacy Act and APP 11 apply.
    Does not establish: That a club's controls are reasonable, that the Privacy Act applies or that a particular retention period is correct.
  • Small business cyber security guide
    Supports: A practical minimum cyber-security baseline for smaller organisations and volunteer-run systems.
    Does not establish: That the baseline is sufficient for a club's actual risk, system architecture, supplier arrangements or legal obligations.
  • Rotary Clubs
    Supports: Rotary club participation context and the value of accessible online or hybrid participation.
    Does not establish: Product configuration, legal compliance, local suitability or approval of a named initiative.

What still needs a person to confirm

  • Confirm which privacy, records, safeguarding and other legal duties apply to the club and this local design.
  • Confirm current ClubRunner or other platform features, permissions, licence settings and supplier instructions in the club's actual account.
  • Test accessibility and alternative participation routes with affected members rather than inferring conformance from the guide.
  • Confirm every local fact, starting point, measure, cost, owner and claim before the club decides to proceed.
  • Resolve any candidate District-source provenance and approval decision without treating the candidate as controlled authority.

The source-verification release gate remains closed.

Checks still on hold

Still an internal draft: source interpretation, local suitability, accessibility, governance and editorial approval remain open checks.

Why a club might use this

It reduces avoidable administration and makes club information easier to find, use and hand over.

It may suit: Members who use or maintain the club's information, communications and digital tools.

Use it when

  • Consider Email Group Review when information is stored in several places or the club cannot readily explain who can access it and why.
  • A club where the club has a defined user need, accountable owner, current platform information, proportionate data plan and a safe way to test and reverse the change.
  • A club with a real need for accountable data governance and capacity to support a bounded evidence review with defined inputs, participation gaps and interpretation limits.
  • A 90-day trial of Email Group Review with a starting point, named participants, a resource ceiling and a scheduled continue, adapt or stop decision.

Before the club starts

  • A board-approved brief naming which information assets, owners, permissions, retention and disposal rules the club needs, the local authority, people affected, fixed constraints, resource ceiling, decision date and stop conditions.
  • A starting-point record and participant plan suited to a bounded evidence review with defined inputs, participation gaps and interpretation limits, with accessible information, voluntary choices and a supported alternative route where needed.
  • Named delivery, evidence and decision owners, including a person authorised to pause Email Group Review when a safeguard, permission or boundary is not met.
  • A proportionate check of governing documents, privacy, information security, accessibility, conflicts, safeguarding, work health and safety, records, finance and referral duties for the actual local design.

Capacity guide

Likely cost
Moderate where systems or professional advice are required
Lead time
8–12 weeks for the first pass
People
A board sponsor, data governance lead and system or record owners

A useful club conversation

Questions worth asking

  1. Whose experience, authority, access or safety could be missed if Email Group Review is designed only by regular attendees, confident digital users or current leaders?
  2. What would make a dated findings summary that separates facts, experience, assumptions and unanswered questions credible enough for the club's decision, and what would still remain uncertain?
  3. What local adaptation would still respect this boundary: The club must confirm its actual legal and contractual obligations and cannot assume that volunteer status removes privacy or security responsibilities.

Common traps

  • Trying Email Group Review when A club with no open decision, no accountable owner, no capacity to act on a dated findings summary that separates facts, experience, assumptions and unanswered questions or no safe way to pause the trial.
  • Proceeding with Email Group Review when Email Group Review must not be used for collecting more data because it is possible, using live sensitive data for training, automating formal judgement or deploying an unowned system without privacy, security, accessibility and recovery controls. The club must confirm its actual legal and contractual obligations and cannot assume that volunteer status removes privacy or security responsibilities.
  • A volunteer-built workflow becomes unowned, inaccurate or impossible to recover. — Name a service owner, document dependencies, keep tested backups and rollback steps and schedule a maintenance decision.

A practical 90-day path

Three milestones for Email Group Review
WhenWhat the club doesEvidence to keep
Days 1–30: Agree the local designWrite the decision brief for Email Group Review: define which information assets, owners, permissions, retention and disposal rules the club needs, the starting evidence, people affected, local authority, resource limit, success signals and stop conditions. Identify users and non-users, map access and digital-confidence barriers, explain data use and permissions and retain an equivalent human or non-digital route where essential participation is involved. Apply this specifically to Email Group Review and record which relevant experiences or users are still missing.An approved decision and boundary brief A participant, access and information-handling plan
Days 31–60: Run and adjust the first versionBuild and test a bounded evidence review with defined inputs, participation gaps and interpretation limits for Email Group Review; complete the Email Group Review Diagnostic Evidence Matrix, rehearse the boundary wording and confirm who may decide, refer, pause, recover or close the work. Use synthetic or minimised test data, least privilege, versioned configuration, accessible instructions, exception handling and a rollback; do not expose live credentials or private member information. Capture only the evidence needed to judge whether Email Group Review advances accountable data governance.A tested diagnostic evidence matrix and delivery pack A controlled activity and evidence record
Days 61–90: Review the evidence and decideCompare the evidence with the starting point, validate meaning with affected participants or users, record gaps and unintended effects and prepare a dated findings summary that separates facts, experience, assumptions and unanswered questions without overstating what the trial proves. Make and record the authorised continue, adapt, refer, scale or stop decision for Email Group Review; explain the reason, complete every action, close unnecessary records and schedule the 90-day follow-up.A dated findings summary that separates facts, experience, assumptions and unanswered questions A published participant response, closed action register and next-step decision

Fit it to the club you have

Small club

Choose the smallest maintainable system, use shared role-based administration rather than one person's account and retain printable or telephone alternatives. Apply this specifically to Email Group Review, a bounded evidence review with defined inputs, participation gaps and interpretation limits and the club's actual capacity.

Larger club

Separate data, platform, content and approval roles, use staged permissions and keep a shared change and incident register. Apply this specifically to Email Group Review, a bounded evidence review with defined inputs, participation gaps and interpretation limits and the club's actual capacity.

Regional or rural club

Design for variable connectivity, older devices and limited local support, with offline continuity and clear escalation to a trusted specialist. Apply this specifically to Email Group Review, a bounded evidence review with defined inputs, participation gaps and interpretation limits and the club's actual capacity.

Metropolitan, hybrid or online club

Test across devices, assistive technology and channels, provide captions and accessible documents and keep equivalent controls for remote users. Apply this specifically to Email Group Review, a bounded evidence review with defined inputs, participation gaps and interpretation limits and the club's actual capacity.

Learn, adapt and know when to stop

Evidence worth keeping

  • Email Group Review produces a dated findings summary that separates facts, experience, assumptions and unanswered questions by the promised decision date, with evidence limitations, participation gaps and unintended effects stated.
  • People affected can explain the purpose, their choices, the boundary and how to raise an access, privacy, safety or governance concern.
  • The trial shows whether accountable data governance improved from the recorded starting point without shifting hidden workload, risk or exclusion elsewhere.

Change course when

  • The club proceeds with Email Group Review without respecting this boundary: the club must confirm its actual legal and contractual obligations and cannot assume that volunteer status removes privacy or security responsibilities. — Put the boundary in the brief and participant information, give the delivery lead stop authority and move any excluded matter to its responsible process.
  • The system excludes members or creates a single digital path for essential participation. — Test with varied users, provide accessible instructions and retain an equivalent supported alternative.
  • Permissions, integrations or exports expose more personal information than the purpose requires. — Minimise fields, use least privilege, test permissions, control exports and review access after the trial.

How to put it into practice

Detailed implementation steps for Email Group Review
StepActionSuggested ownerTimingEvidence or output
1Write the decision brief for Email Group Review: define which information assets, owners, permissions, retention and disposal rules the club needs, the starting evidence, people affected, local authority, resource limit, success signals and stop conditions.Board sponsor and information ownerWeek oneAn approved decision and boundary brief
2Identify users and non-users, map access and digital-confidence barriers, explain data use and permissions and retain an equivalent human or non-digital route where essential participation is involved. Apply this specifically to Email Group Review and record which relevant experiences or users are still missing.Board sponsor and information owner with the access and privacy contactsWeeks one and twoA participant, access and information-handling plan
3Build and test a bounded evidence review with defined inputs, participation gaps and interpretation limits for Email Group Review; complete the Email Group Review Diagnostic Evidence Matrix, rehearse the boundary wording and confirm who may decide, refer, pause, recover or close the work.System lead, privacy contact and access testerBefore the trialA tested diagnostic evidence matrix and delivery pack
4Use synthetic or minimised test data, least privilege, versioned configuration, accessible instructions, exception handling and a rollback; do not expose live credentials or private member information. Capture only the evidence needed to judge whether Email Group Review advances accountable data governance.System lead, privacy contact and access testerWeeks three to eightA controlled activity and evidence record
5Compare the evidence with the starting point, validate meaning with affected participants or users, record gaps and unintended effects and prepare a dated findings summary that separates facts, experience, assumptions and unanswered questions without overstating what the trial proves.System lead, privacy contact and access tester with an independent reviewerWithin seven days of the trialA dated findings summary that separates facts, experience, assumptions and unanswered questions
6Make and record the authorised continue, adapt, refer, scale or stop decision for Email Group Review; explain the reason, complete every action, close unnecessary records and schedule the 90-day follow-up.Service owner and independent reviewerBy day 90A published participant response, closed action register and next-step decision

Controls and safeguards

  • Check the idea with the people affected and confirm its purpose, owner and practical limits before putting it into use.
  • Name the system and data owners, restrict access, provide an accessible alternative and document how errors or failures will be recovered.
  • Collect only necessary data, state its purpose and retention, restrict access and provide a practical correction or withdrawal route.
  • The club proceeds with Email Group Review without respecting this boundary: the club must confirm its actual legal and contractual obligations and cannot assume that volunteer status removes privacy or security responsibilities. — Put the boundary in the brief and participant information, give the delivery lead stop authority and move any excluded matter to its responsible process.
  • The system excludes members or creates a single digital path for essential participation. — Test with varied users, provide accessible instructions and retain an equivalent supported alternative.
  • Permissions, integrations or exports expose more personal information than the purpose requires. — Minimise fields, use least privilege, test permissions, control exports and review access after the trial.
  • A volunteer-built workflow becomes unowned, inaccurate or impossible to recover. — Name a service owner, document dependencies, keep tested backups and rollback steps and schedule a maintenance decision.
  • The current Theme 5 index controls the code and title. The exact-title legacy Digital candidate is recorded only as attributed, unapproved evidence and does not replace current identity, controls or source authority.
  • The connected Drive refresh returned an internal error on 9 August 2026. No unseen file was inferred or promoted; the 7 August intake, duplicate decisions, quarantines, rights boundaries and public-write permission hold remain in force and no sharing was changed.
  • Before local delivery, the club must approve the decision, participant choices, access arrangements, privacy and records plan, role boundaries, referral or escalation routes, resource limit and the specific control for this boundary: the club must confirm its actual legal and contractual obligations and cannot assume that volunteer status removes privacy or security responsibilities.

What to measure

  • After 90 days, review Email Group Review. Look for named data owners, documented access, corrected records, working retention rules and completed requests for access or deletion.
  • Email Group Review produces a dated findings summary that separates facts, experience, assumptions and unanswered questions by the promised decision date, with evidence limitations, participation gaps and unintended effects stated.
  • People affected can explain the purpose, their choices, the boundary and how to raise an access, privacy, safety or governance concern.
  • The trial shows whether accountable data governance improved from the recorded starting point without shifting hidden workload, risk or exclusion elsewhere.
  • Every accepted action has an owner, due date and completion evidence, and the club records a reasoned continue, adapt, refer, scale or stop decision.

Follow-up: At the 90-day review, compare the recorded measures with the starting point, resolve the listed governance holds and tell participants whether Email Group Review will change, continue or stop.

Made for this initiative

Tailored supporting documents

These working documents use the decisions, safeguards and evidence needs of this initiative. Complete them with the people affected and keep the agreed version with the club's project record.

01

Email Group Review User Need and System Boundary Brief

Define the user problem, information flow and excluded uses.

Open supporting document
02

Email Group Review Data Inventory and Purpose Map

Link every field and transfer to a necessary purpose.

Open supporting document
03

Email Group Review Privacy, Consent and Notice Check

Make information handling and choices clear before collection or publication.

Open supporting document
04

Email Group Review Access and Permission Matrix

Apply least privilege and accountable access reviews.

Open supporting document
05

Email Group Review Accessible User Test Script

Test the real task with varied users and alternatives.

Open supporting document
06

Email Group Review Configuration and Change Register

Maintain a reviewable record of settings, integrations and releases.

Open supporting document
07

Email Group Review Incident, Exception and Recovery Card

Give volunteers a safe response route when the workflow fails or data is exposed.

Open supporting document
08

Email Group Review Handover, Backup and Maintenance Plan

Keep the service operable beyond one volunteer.

Open supporting document
09

Email Group Review Data Governance Delivery Check

Test whether Email Group Review genuinely advances accountable data governance within the subtheme boundary.

Open supporting document
10

Email Group Review Diagnostic Evidence Matrix

Compare the initiative's inputs consistently without turning a signal into a verdict.

Open supporting document
11

Email Group Review Evidence, Decision and Close-Out Record

Bring the evidence, limitations, participant response and final decision for Email Group Review into one accountable record.

Open supporting document

Related playbook entries

  • S-069
  • S-071

Before your club says yes

Does the idea fit?

Talk with the people it is meant to serve and check that the need is real.

Who can say yes?

Name the person or group that can approve the work, spending and any safety arrangements.

Are people protected?

Check privacy, consent and safety. Collect only the information you genuinely need.

Can everyone take part?

Check the language, format, place, technology and cost for barriers.

Are the facts and permissions right?

Check names, claims, images, quotations, partner references and Rotary branding.

How will we learn?

Note where things stand now, check in at 30, 60 and 90 days, and decide what to do next.