A misplaced volunteer spreadsheet, a shared inbox with too many people able to see it, or a convincing phishing email can expose far more than an organisation realises. For charities, personal data is often tied to people who need support, donors who have placed their trust in you, and staff working hard with limited time. This charity data protection compliance guide focuses on practical habits that protect that trust without burying your team in jargon.
At Bees Knees IT, we’ve worked with charities and community organisations across Bradford, Leeds, Halifax and West Yorkshire to improve cyber security, manage Microsoft 365 environments and reduce GDPR-related risks. While every charity is different, the most common challenges we see involve excessive user permissions, unmanaged devices, shared accounts and uncertainty about where sensitive data is stored.
What is charity data protection compliance?
Charity data protection compliance means following UK GDPR and the Data Protection Act 2018 when collecting, storing, sharing and deleting personal information. Charities must protect donor, volunteer, employee and beneficiary data while ensuring individuals can exercise their rights. Good compliance combines clear policies, secure systems, staff training and regular reviews.
Charity GDPR Compliance Checklist
- Identify what personal data you hold.
- Record where data is stored.
- Define your lawful basis for processing.
- Restrict access to authorised users.
- Train staff and volunteers regularly.
- Create data retention policies.
- Prepare for subject access requests.
- Document breach response procedures.
- Review supplier contracts and security.
- Audit compliance at least annually.
Why Data Protection Matters for Charities
UK GDPR and the Data Protection Act 2018 apply to charities just as they apply to businesses. The rules are not there to make everyday work harder. They ask you to be clear about what information you hold, why you need it, how long you keep it and who can access it.
Charities can hold particularly sensitive information. This may include a beneficiary’s health details, safeguarding records, financial circumstances, ethnicity, religious beliefs or information about children. A fundraising database may hold contact details, donation history and payment information. Even a simple mailing list is personal data.
The right level of control depends on the size of your charity, the kinds of people you support and the systems you use. A small community group with a handful of volunteers will not need the same arrangements as a regional charity handling detailed casework. Both, however, need a clear and sensible baseline.
Start by knowing what data you hold
Many compliance problems begin because data has grown quietly over time. An old laptop, a former trustee’s personal email account, a paper filing cabinet or a cloud folder created during lockdown can all contain information nobody has reviewed for years.
Set aside time to map your data. This does not need to be a grand technical exercise. Record the types of information you collect, where it is stored, who uses it, why it is needed, who it may be shared with and when it should be deleted. Include paper records alongside files held in Microsoft 365, Google Workspace, case management systems, finance software and fundraising platforms.
This record gives you a useful starting point for your wider charity data protection compliance work. It also makes everyday questions much easier to answer. If someone asks for a copy of their information, for example, you will not be searching every volunteer’s inbox in a panic.
Be clear about your lawful basis
You need a lawful basis under UK GDPR before using personal data. Consent is one option, but it is not automatically the right one. For a donor newsletter, clear opt-in consent may make sense. For recording a service user’s details so you can deliver agreed support, legitimate interests or a contractual reason may be more appropriate, depending on the circumstances.
Where you process special category data, such as health or safeguarding information, you usually need an additional condition as well. This is an area where getting tailored advice is worthwhile. The key point is to avoid treating consent as a catch-all simply because it feels safest.
Your privacy notice should explain your approach in plain English. People should be able to understand what you collect, why you collect it, how long you retain it and how they can contact you about their rights.
Control Who Can Access Information
Good data protection is often less about expensive software and more about sensible access. A volunteer organising an event may need attendee contact details, but not a full beneficiary database. A trustee may need high-level reports, but not every staff member’s HR record.
Use individual accounts rather than shared logins wherever possible. Turn on multi-factor authentication for email, cloud storage, finance systems and fundraising platforms. Remove access promptly when a member of staff or volunteer leaves, changes role or finishes a project.
Shared inboxes and shared folders deserve special attention. They can be useful, but only if ownership is clear and permissions are reviewed. A folder labelled “everyone” is rarely a good long-term permission setting.
For charities in Bradford, Leeds, Halifax and across West Yorkshire, this is particularly relevant where teams are spread across offices, community venues and home working arrangements. Convenience matters, but it should not mean sensitive files are copied onto personal devices or sent through unsecured channels.
Unsure Whether Your Charity Is GDPR Compliant?
If you’re concerned about data security, Microsoft 365 permissions, email protection or staff access controls, Bees Knees IT can carry out a practical charity IT and security review to identify potential risks before they become compliance issues.
Build data protection into everyday staff habits
Your policies matter, but people need to know what they look like on a busy Tuesday morning. Give staff and volunteers short, relevant training when they start, then refresh it regularly. Use real situations they may face: sending a group email, discussing a case in a public place, using a personal mobile phone, receiving an unusual invoice or responding to a data request.
A few habits make a substantial difference:
- Check recipients before sending emails, and use BCC when contacts should not see one another’s addresses.
- Lock screens when stepping away, especially in shared offices and community spaces.
- Keep paper records in locked storage and use confidential waste collection or secure shredding.
- Never share passwords by email, text message or a note stuck to a monitor.
- Pause before opening unexpected links, attachments or requests for payment details.
Training should feel supportive, not punitive. Staff are more likely to report a mistake quickly when they know they will be helped to put it right rather than blamed.
Keep information for a reason, not forever
Holding data indefinitely creates risk without usually providing much value. Set retention periods for the different types of records you hold, based on legal requirements, operational needs and any safeguarding obligations.
Finance records may need to be retained for several years, while event enquiries or unsuccessful volunteer applications may have a much shorter useful life.
Once a retention period ends, delete digital records securely and destroy paper copies. Remember that deleting a file from a desktop does not always remove it from backups, shared drives or archived mailboxes straight away. Your retention policy should reflect how your systems actually work, not how you hope they work.
It is also sensible to review your suppliers. If an external provider hosts your email, website forms, donor database, payroll or cloud files, you remain responsible for choosing them carefully.
Make sure there is a suitable data processing agreement in place and understand where data is stored and how it is protected.
Prepare for Subject Access Requests and Data Breaches
Subject Access Requests
Individuals can ask for access to their personal data. These subject access requests must normally be handled within one month, so your team should know who receives them and what to do next. Do not assume a request must use formal wording. An email asking, “What information do you hold about me?” may be enough.
Data Breaches
A personal data breach is not limited to a cyber attack. It could be an email sent to the wrong person, a lost unencrypted mobile phone, a stolen paper file or unauthorised access to a shared system. Not every incident needs reporting to the Information Commissioner’s Office, but every incident should be recorded and assessed promptly.
Where a breach is likely to create a risk to people’s rights and freedoms, it may need reporting to the ICO within 72 hours of becoming aware of it. If the risk is high, affected individuals may also need to be told. Fast reporting internally is what gives your charity the best chance of containing the problem and making the right decision.
Write a simple incident process now: who staff contact, how access can be removed, who assesses the impact and how decisions are recorded. Run through it once a year. A calm rehearsal is far preferable to trying to invent a process during a difficult incident.
What should a charity do after a data breach?
If a charity discovers a personal data breach, it should:
- Contain the incident immediately.
- Assess what data was affected.
- Record the breach internally.
- Determine whether it must be reported to the ICO.
- Notify affected individuals if required.
- Review controls to prevent recurrence.
Strengthen Your Charity’s Cyber Security
Data protection and cyber security are closely linked. You can have a thoughtful privacy notice, but it will not help much if accounts are compromised because of weak passwords, unpatched devices or a successful phishing attack.
Keep operating systems, browsers and applications updated. Use managed antivirus or endpoint protection, maintain tested backups, and make sure backup copies cannot be altered by the same account that runs your day-to-day files. Encrypt work laptops and mobile phones, particularly where they contain sensitive casework or are regularly taken between sites.
Smaller charities sometimes worry that these measures are beyond their budget. Usually, the better question is which controls reduce the greatest risk first. Secure email, multi-factor authentication, managed updates, backups and clear staff training are sensible foundations before considering more complex tools.
We regularly help charities recover from issues that started with a simple phishing email or compromised Microsoft 365 account. In many cases, enabling multi-factor authentication and reviewing user permissions would have significantly reduced the impact of the incident.
Make compliance a regular conversation
Assign clear responsibility for data protection, even if the role sits alongside another job. Trustees should receive enough information to understand the main risks, significant incidents and any improvements needed. Your organisation may also need to pay the ICO’s data protection fee, unless an exemption applies, so check your position rather than assuming charity status removes the requirement.
Review your data map, privacy notices, retention schedule and access permissions at least annually, and whenever you introduce a new system or service. If a project is likely to involve higher-risk processing, such as large-scale sensitive data or new monitoring technology, consider a Data Protection Impact Assessment before it begins.
Data protection does not have to become another burden on an already stretched charity team. It is a way of showing people that their information is handled with the same care as the services you provide.
Frequently Asked Questions
Does GDPR apply to charities?
Yes. UK GDPR and the Data Protection Act 2018 apply to charities in the same way they apply to businesses and public sector organisations.
Do charities need to register with the ICO?
Many charities must pay the ICO data protection fee unless a specific exemption applies.
How long should charities keep personal data?
Retention periods depend on the type of information, legal obligations and operational requirements. Data should not be kept longer than necessary.
What happens if a charity suffers a data breach?
The incident should be recorded and assessed immediately. If individuals’ rights and freedoms are at risk, the breach may need to be reported to the ICO within 72 hours.
What is special category data?
This includes information such as health details, ethnicity, religious beliefs, biometric data and other sensitive personal information that requires additional protection.
How can charities improve data security?
Key steps include multi-factor authentication, staff training, secure backups, device encryption, access controls and phishing protection.
Need Help with Charity Data Protection and Cyber Security?
Compliance is easier when your technology supports it. Bees Knees IT helps charities across Bradford, Leeds, Halifax and West Yorkshire improve cyber security, secure Microsoft 365 environments, manage access controls and reduce GDPR risks.
Contact our team today on 01274 955509 for a friendly, jargon-free discussion about protecting your charity’s data.
About the Author
Craig Hawes is the Managing Director of Bees Knees IT and has spent years helping organisations across West Yorkshire improve their IT security, cyber resilience and compliance. Working closely with charities, SMEs and community groups, Craig focuses on practical solutions that reduce risk, strengthen data protection and make technology easier to manage without unnecessary complexity.
Leave A Comment