AI PRACTICES5 August 2026
Keeping Member Data Out of the Machine
What never belongs in a consumer chatbot, why the electoral roll answers to a different law, and when self-hosting earns its keep.

Most public anxiety about AI concerns what the machine might produce: the fabricated fact, the uncanny image. For a membership organisation the sharper risk runs the other way. It's what your people type in. A chat window feels like a private scratchpad, and that feeling is doing a lot of unexamined work — because what goes into a consumer tool leaves your building, lands on someone else's infrastructure, and falls under someone else's terms.
What never goes into a consumer chatbot
Three categories should stay out of any consumer AI tool as standing policy, however convenient the moment makes it. Member personal information: names attached to phone numbers, addresses, health details, union membership, anything a person gave you in trust. Donor records: amounts, histories, contact details — material the ACNC's governance standards expect a management committee to safeguard as carefully as money itself. And internal strategy: the campaign plan, the target list, the negotiating position. Not because any vendor is malicious, but because once submitted, that information sits outside your control, and no delete button changes where it has already been.
The workable habit is de-identification. A tool can sharpen a fundraising email without knowing a single real name; it can find the pattern in a season of doorknocking notes without the addresses attached. If a task genuinely requires the identifying details, that is the signal you've outgrown consumer tooling.
Vet the vendor, then narrow the door
Before anything sensitive touches a tool, someone in your organisation should be able to answer four questions from the vendor's own documents: is our data used to train models, and can we switch that off; how long is it retained, and can we delete it; where is it stored, and who inside the vendor can read it; and what happens to it if we leave. These are the same questions the Australian Privacy Principles push any organisation to ask before handing personal information to a third party — the machine doesn't get an exemption for being clever.
The same discipline applies to connected tools. Modern assistants can be wired into inboxes, drives and calendars, and every connection is a door. Grant the least access the task needs: one folder, not the whole drive; a shared pilot inbox, not the director's. An assistant that can read everything is one compromised account away from a very bad week.
The electoral roll answers to a different law
Electoral roll data deserves its own paragraph in any security conversation, because it is not ordinary data your organisation happens to hold. Access to it is provided under electoral law, for defined purposes, with strict statutory conditions on use and disclosure — and penalties attached. No mainstream AI vendor wrote its terms of service with those conditions in mind. The safe reading is blunt: roll data does not go into general-purpose tools at all, and any processing of it happens inside systems your organisation controls and can account for. If a workflow seems to require otherwise, the workflow is wrong.
When the answer is to keep it in the building
For the most sensitive work there is a category of tooling that changes the question entirely: software you run yourself. An open-source automation platform can be self-hosted, so the data flowing between your systems never transits a third party. Speech-to-text tools that run their models on the device can transcribe an interview or a meeting without a single network request leaving the room. The trade-off is real — self-hosting needs someone with the technical capacity to maintain it, and on-device models trail their cloud cousins — but for the work you would least like to see leaked, scraped or subpoenaed, keeping it in the building is the only architecture that removes the vendor from the trust equation.
The machine on the other side of the line
The most dangerous AI in your organisation's life will probably be someone else's. Phishing written by a model is fluent, personalised and patient in ways the old scams never were, and voice synthesis has turned 'the director on the phone, urgently needing a transfer' from a thought experiment into a working attack. Staff and volunteers are the surface. The defences are old-fashioned: verify unusual requests through a second channel you initiated, agree on callback rules for anything involving money or credentials, and rehearse the awkwardness of saying no to a voice that sounds exactly like your boss.
And when you evaluate vendors, ask the question that separates marketing from practice: what independent security certification do you hold, and will you show us the audit report? A supplier that protects other people's member data for a living should be able to prove it. The ones that can't answer are answering.
SEE WHAT PROGRESS CAN DO IN YOUR CAMPAIGN
Book a demo and we'll show Progress working inside one of your own campaigns.
