Use Digital Access Permissions Review to keep club data accurate, appropriately accessed and retained only for a clear purpose.
Where this idea came from
Playbook entry
S-080 · Digital Access Permissions Review
Theme
Theme 5: Digital, Data & Systems · Subtheme 5: Data Governance
Source material
Current playbook index title and category plus an internally authored detailed-guide draft
Initiative-specific development wave
How this draft was developed
These sources support general principles for digital, data and systems, accessibility, privacy, safety, systems or responsible governance; they are not an endorsement of Digital Access Permissions Review, a finding that it suits any club or approval of its local design.
Primary references consulted
Keeping charity records(Australian Charities and Not-for-profits Commission) Used for: Appropriate financial and operational records support governance, decision-making, financial management, risk management and public trust, subject to the organisation's actual obligations.
Chapter 3: APP 3 Collection of solicited personal information(Office of the Australian Information Commissioner) Used for: Personal-information collection should be lawful, fair, proportionate and minimised, with additional controls for sensitive information; each club must confirm how privacy law applies to it.
Chapter 11: APP 11 Security of personal information(Office of the Australian Information Commissioner) Used for: Entities covered by the Privacy Act must take reasonable steps to protect personal information and destroy or de-identify it when it is no longer needed, subject to lawful retention requirements.
Small business cyber security guide(Australian Signals Directorate's Australian Cyber Security Centre) Used for: A practical security baseline includes multi-factor authentication, software updates, regular tested backups and advice suited to the organisation's actual systems and risk.
Rotary Clubs(Rotary International) Used for: Rotary describes club participation through service, friendship, diversity, integrity and leadership, including online participation for people affected by schedules, mobility or distance.
Candidate District material
No candidate local guide was used for this version. The current initiative identity and the attributed primary references remain separate.
Theme 5 source-assurance wave
What has been checked
5 current primary pages used by this guide were reopened on 9 August 2026.
5 attributed source claim(s) were mapped to their bounded use in this initiative.
Candidate District material remains separate and does not establish this result.
See each source's scope and limit
Keeping charity records Supports: The value of accurate operational and decision records and proportionate retention controls. Does not establish: That a Rotary club is an ACNC-registered charity or that a stated retention period applies to that club.
Chapter 3: APP 3 Collection of solicited personal information Supports: Data-minimisation, collection-purpose, proportionality and consent safeguards where the Privacy Act and APP 3 apply. Does not establish: Whether a particular Rotary club is an APP entity or whether a proposed collection is lawful in its actual circumstances.
Chapter 11: APP 11 Security of personal information Supports: Security, access, retention and disposal safeguards where the Privacy Act and APP 11 apply. Does not establish: That a club's controls are reasonable, that the Privacy Act applies or that a particular retention period is correct.
Small business cyber security guide Supports: A practical minimum cyber-security baseline for smaller organisations and volunteer-run systems. Does not establish: That the baseline is sufficient for a club's actual risk, system architecture, supplier arrangements or legal obligations.
Rotary Clubs Supports: Rotary club participation context and the value of accessible online or hybrid participation. Does not establish: Product configuration, legal compliance, local suitability or approval of a named initiative.
What still needs a person to confirm
Confirm which privacy, records, safeguarding and other legal duties apply to the club and this local design.
Confirm current ClubRunner or other platform features, permissions, licence settings and supplier instructions in the club's actual account.
Test accessibility and alternative participation routes with affected members rather than inferring conformance from the guide.
Confirm every local fact, starting point, measure, cost, owner and claim before the club decides to proceed.
Resolve any candidate District-source provenance and approval decision without treating the candidate as controlled authority.
The source-verification release gate remains closed.
Checks still on hold
The current Theme 5 index controls the code and title. No unverified or close legacy Digital crosswalk was used as initiative evidence.
The connected Drive refresh returned an internal error on 9 August 2026. No unseen file was inferred or promoted; the 7 August intake, duplicate decisions, quarantines, rights boundaries and public-write permission hold remain in force and no sharing was changed.
Before local delivery, the club must approve the decision, participant choices, access arrangements, privacy and records plan, role boundaries, referral or escalation routes, resource limit and the specific control for this boundary: the club must confirm its actual legal and contractual obligations and cannot assume that volunteer status removes privacy or security responsibilities.
Formal human review has not started. Digital Access Permissions Review remains an internal initiative-specific draft until all 1,000 initiatives reach the Full-Corpus Review Build and every source, editorial, local-suitability, accessibility and governance gate is resolved.
Still an internal draft: source interpretation, local suitability, accessibility, governance and editorial approval remain open checks.
What could this idea change?
It protects trust by making safer system and information habits part of everyday club work.
It may suit: Members who use or look after club systems and information, including people who need extra help.
Could this work in our club?
Consider Digital Access Permissions Review when information is stored in several places or the club cannot readily explain who can access it and why.
A club where the club has a defined user need, accountable owner, current platform information, proportionate data plan and a safe way to test and reverse the change.
A club with a real need for accountable data governance and capacity to support a bounded evidence review with defined inputs, participation gaps and interpretation limits.
A 90-day trial of Digital Access Permissions Review with a starting point, named participants, a resource ceiling and a scheduled continue, adapt or stop decision.
Before you start
A board-approved brief naming which information assets, owners, permissions, retention and disposal rules the club needs, the local authority, people affected, fixed constraints, resource ceiling, decision date and stop conditions.
A starting-point record and participant plan suited to a bounded evidence review with defined inputs, participation gaps and interpretation limits, with accessible information, voluntary choices and a supported alternative route where needed.
Named delivery, evidence and decision owners, including a person authorised to pause Digital Access Permissions Review when a safeguard, permission or boundary is not met.
A proportionate check of governing documents, privacy, information security, accessibility, conflicts, safeguarding, work health and safety, records, finance and referral duties for the actual local design.
At the end: At the 90-day review, compare the recorded measures with the starting point, resolve the listed governance holds and tell participants whether Digital Access Permissions Review will change, continue or stop.
Made for this initiative
Tailored supporting documents
These working documents use the decisions, safeguards and evidence needs of this initiative. Complete them with the people affected and keep the agreed version with the club's project record.
01
Digital Access Permissions Review User Need and System Boundary Brief
Define the user problem, information flow and excluded uses.