Data Protection for Charities in the UK

Alex Solo
byAlex Solo12 min read

Charities often collect more personal information than they first realise. A donation form, volunteer spreadsheet, event mailing list, safeguarding file, grant application and CCTV system can all bring data protection duties into play. The common mistakes are usually practical ones: copying supporter data into personal inboxes, sending fundraising emails without a clear lawful basis, and keeping sensitive records for years without a retention plan.

That matters because charities are trusted with personal information in situations that can be highly sensitive. You may hold donor details, beneficiary records, health information, children’s data, employee files and trustee documents, sometimes all at once. If your processes are loose, the legal risk is not just a regulatory problem. It can damage trust with donors, service users, staff and the public.

This guide explains what data protection for charities means in the UK, when the issue usually comes up, and what practical steps charities, social enterprises and purpose-led organisations should sort out before they collect more data, sign supplier contracts or launch a new campaign.

Overview

UK charities must handle personal information lawfully, fairly and transparently under the UK GDPR and the Data Protection Act 2018. The right approach depends on what data you collect, why you collect it, who you share it with, and how long you keep it.

Most charities need more than a privacy policy on a website. They also need clear internal processes, staff training and paperwork that matches what actually happens day to day.

  • Identify what personal data your charity collects, including donor, volunteer, employee, trustee and beneficiary information.
  • Work out your lawful basis for each activity, such as donations, service delivery, fundraising emails and safeguarding records.
  • Check whether you process special category data, criminal offence data or children’s data, which usually need extra care.
  • Put privacy notices, retention rules and data security measures in place.
  • Review who you share data with, including payroll providers, CRM platforms, email tools, fundraising agencies and grant partners.
  • Make sure contracts with third party processors contain the right data protection terms.
  • Set up a process for subject access requests, consent withdrawals, complaints and data breaches.
  • Train staff, volunteers and trustees so the written policy matches real practice.

What Data Protection for Charities Means For UK Businesses

Data protection for charities is about using personal information in a way that is lawful, clear and proportionate, while protecting the people behind the data. Even if you are a small charity with a handful of staff, the basic rules still apply.

In the UK, the main legal framework comes from the UK GDPR and the Data Protection Act 2018. A charity can be a data controller, a data processor, or sometimes both, depending on the activity. In plain English, if your charity decides why and how personal data is used, you are usually acting as a controller for that activity.

What counts as personal data?

Personal data is any information that can identify a living person, directly or indirectly. For charities, this often includes more than names and email addresses.

  • Donor names, contact details and giving history
  • Volunteer applications and rota details
  • Beneficiary case notes and service records
  • Trustee contact details and due diligence documents
  • Employee HR files, payroll and absence records
  • Photographs, video recordings and CCTV footage
  • Online identifiers such as IP addresses and cookie-related data

Some charity work also involves special category data, such as health information, ethnicity, religious beliefs, sexual orientation or trade union membership. That type of data usually needs an extra condition for processing, not just a general lawful basis.

Why charities face sharper risk

Charities often work in high-trust settings. Supporters may share financial details, while beneficiaries may disclose health, family or crisis-related information. That makes poor handling more serious, even where the organisation is small.

This is where trustees and senior managers often get caught. They assume good intentions are enough, but data protection law focuses on what you actually do with the information. A helpful purpose does not remove the need for proper records, security and transparency.

Lawful bases are not one size fits all

Your charity needs a lawful basis for each processing activity. You cannot simply pick one lawful basis for the whole organisation and move on. Different activities may rely on different legal grounds.

For example, a charity might process payroll data because it is necessary for employment obligations, keep donor payment records to meet legal and accounting duties, use volunteer contact details because of legitimate interests, and rely on consent for some direct electronic marketing.

The main risk is using consent where it is not suitable, or assuming consent covers everything. Consent must be specific, informed and freely given, and it must be easy to withdraw. In a care, support or safeguarding setting, consent may not be the best basis if the power balance is uneven or the service would be hard to provide without the data.

Transparency matters

People should not have to guess what your charity does with their information. Privacy notices should explain, in clear language, what data you collect, why you collect it, who receives it, how long you keep it, and what rights individuals have.

That applies offline as well as online. If you collect paper forms at a fundraising event, sign people up over the phone, or receive referrals from partner organisations, transparency still matters.

Accountability is a practical duty

Accountability means being able to show that your charity follows the rules. It is not enough to have a policy saved somewhere if staff and volunteers do not use it.

In practice, accountability often means keeping the following up to date:

  • A data inventory or record of processing activities
  • Privacy notices for different groups, such as donors, beneficiaries, staff and volunteers
  • A data retention policy and deletion rules
  • Internal breach reporting procedures
  • Data processing agreements with third party suppliers
  • Training records and governance minutes

When This Issue Comes Up

Data protection questions usually appear at ordinary operational moments, not only after a complaint or breach. The best time to deal with them is before you sign a contract, before you launch a new campaign, and before you spend money on setup that assumes you can use the data in a certain way.

Fundraising and donor communications

Fundraising is one of the most common trigger points. A charity may want to build a mailing list, profile donor behaviour, use social media audiences, or contact previous supporters about a new appeal.

That raises questions about lawful basis, consent for electronic marketing, suppression lists, data sharing with fundraising agencies, and how much profiling is fair and expected. Imported mailing lists and loosely documented opt-ins are where many organisations slip up.

Beneficiary services and case management

If your charity supports vulnerable people, families, children or people with health needs, the data protection stakes are higher. Case notes may include special category data, allegations, incidents, safeguarding concerns or referral information from third parties.

You need to be clear about what information is necessary, who can access it, when it can be shared, and how long it should be retained. This is especially important where staff use a mix of paper files, shared drives and cloud systems.

Volunteers, staff and trustees

People often forget that internal records are part of data protection too. Recruitment files, DBS-related information, references, emergency contacts, grievances and trustee onboarding documents all need proper handling.

Before you roll out a new HR platform or ask trustees to circulate spreadsheets by email, check what data is involved and whether your contracts and policies are ready.

Events, photography and community outreach

Charities frequently collect data at events, in sign-up sheets, through ticket platforms or by taking photographs for future promotion. Schools, faith groups and youth charities may also deal with children’s data.

You should think through notice wording, consent where needed, image use, event suppliers, and what happens to attendee details after the event ends.

Website, online donations and digital tools

An online donation page can involve cookies, analytics, payment providers, mailing list integrations and customer relationship management software. If those tools are bolted together without review, the privacy position can become messy very quickly.

Before you launch online, check the user journey from the donation form through to receipts, follow-up emails and database storage. The legal position needs to match the technical setup, including your privacy policy and cookie policy.

Sharing data with partners

Many charities work with local authorities, NHS bodies, schools, housing providers or other charities. Data sharing can be legitimate and necessary, but it should not be casual.

You need to know whether the arrangement is controller to controller, controller to processor, or a joint controller relationship. That affects what paperwork and notices are needed. A vague understanding can leave each party assuming the other is handling compliance.

Practical Steps And Common Mistakes

The most effective approach is to map your data first, then fix the documents, contracts and day to day practices around it. Charities that skip the mapping stage often end up with policies that look polished but do not match reality.

1. Map what you collect and why

Start with a practical data audit. Look at each area of the organisation and record what data comes in, where it is stored, who sees it, why it is used and when it is deleted.

Include less obvious sources, such as:

  • Email inboxes and shared mailboxes
  • Paper files and archived boxes
  • Trustee devices and volunteer-held spreadsheets
  • Cloud storage, messaging apps and form builders
  • CCTV, phone recordings and event photographs

This step often reveals duplicate systems, unnecessary data collection or old mailing lists with weak consent records.

2. Match each activity to a lawful basis

Once you know what you collect, work out the legal basis for each use. Keep this specific. “We are a charity” is not a lawful basis.

For special category data, identify the additional condition that applies. Health or safeguarding records often need careful analysis here. If children’s data is involved, make sure notices and processes are age-appropriate and that access controls are tight.

3. Write privacy notices people can actually understand

A charity may need different privacy notices for different audiences. A donor notice should not try to cover detailed beneficiary processing, and a volunteer notice should not be hidden inside a general website statement.

Good notices usually explain:

  • Who the organisation is and how to contact it
  • What information is collected
  • Why it is used and the lawful basis
  • Who it is shared with
  • Whether data is transferred outside the UK
  • How long it is kept
  • The person’s rights, including complaints

The common mistake is copying generic wording from another organisation, then using practices that are much broader than the notice says.

4. Check your marketing rules

Fundraising communications often raise both data protection and electronic marketing issues. Email and text campaigns need careful handling, especially when relying on consent.

Make sure sign-up language is clear, preference options are meaningful, and unsubscribe requests are acted on quickly. If you contact corporate supporters or individual donors in different ways, your rules may differ by channel and audience.

5. Put the right supplier contracts in place

If a third party handles personal data on your behalf, for example a payroll company, CRM provider, cloud host or mailing platform, you usually need a written contract with specific data protection terms. This is not just procurement admin. It helps define what the supplier can and cannot do with the data.

Before you sign, check:

  • What data the supplier will access
  • Whether the supplier uses sub-processors
  • Where the data is stored
  • What security standards apply
  • How incidents are reported
  • What happens to the data when the contract ends

Founders and managers often focus on price and functionality, then discover later that the legal terms are too thin or the provider’s data location creates extra issues.

6. Set retention periods and delete data properly

Many charities keep records indefinitely because storage is cheap and no one wants to make the deletion decision. That is risky. Data should not be kept for longer than needed, although some records must be kept for legal, regulatory, safeguarding or insurance reasons.

A useful data retention policy should distinguish between record types. Donor contact details, unsuccessful volunteer applications, employee records, safeguarding case files and financial records may all justify different periods.

7. Train people, not just managers

A policy will not help if volunteers use personal devices without rules, staff forward spreadsheets externally, or trustees keep outdated board packs forever. Training should be practical and role-specific.

Short reminders can cover topics such as:

  • How to spot a subject access request
  • What to do if an email goes to the wrong person
  • How to share case information safely
  • When to use blind copy fields
  • What not to store on personal devices

8. Prepare for data subject rights and breaches

People may ask for access to their data, ask for inaccuracies to be corrected, object to certain processing or withdraw consent. If your charity has no internal process, these requests can become disruptive.

The same goes for breaches. A lost laptop, a misdirected email, accidental publication of beneficiary information or a weak password can all create reportable issues. Staff should know who to tell, what details to record and how quickly to escalate the incident under a data breach response plan.

Common mistakes charities make

The same patterns come up repeatedly across small and medium organisations.

  • Collecting too much information “just in case”
  • Using one generic privacy notice for every activity
  • Assuming consent covers all processing
  • Sending marketing emails without clear records of opt-in
  • Letting volunteers store data on personal accounts without controls
  • Signing software contracts without data processing terms
  • Keeping old records forever because no retention schedule exists
  • Failing to document data sharing with partner organisations
  • Treating a breach as an IT issue only, rather than a legal and governance issue as well

FAQs

Do small charities have to comply with UK data protection law?

Yes. Size may affect what is proportionate, but small charities still need a lawful basis, privacy information, basic security and processes for rights requests and breaches.

No. Consent is important in some situations, especially for certain electronic marketing. But charities may rely on different lawful bases for different activities. The right answer depends on the type of contact, the audience and the channel used.

What if our charity handles health or safeguarding information?

That usually means you are processing special category data, and possibly very sensitive case information. You will need an appropriate lawful basis, an additional condition for processing, tighter access controls and clearer retention rules.

Do we need contracts with software providers and agencies?

Usually yes, where they process personal data on your behalf. The contract should include the required data protection terms and deal with security, sub-processors, reporting and end-of-contract data handling.

Can trustees be personally involved in compliance?

Yes. Trustees are responsible for governance and oversight, even if staff handle day to day administration. They should understand the main risks, approve key policies and make sure data protection is taken seriously in practice.

Key Takeaways

  • Data protection for charities in the UK is not just a website notice, it covers donor data, beneficiary records, volunteer files, HR information, events and digital tools.
  • Your charity should identify what data it collects, why it uses it, what lawful basis applies and whether any special category or children’s data is involved.
  • Privacy notices, supplier contracts, retention schedules and staff training should reflect what actually happens across the organisation.
  • Fundraising, case management, online donations, photography, partner data sharing and volunteer administration are common pressure points.
  • The biggest mistakes are usually operational, such as weak consent records, informal data sharing, over-collection and keeping records for too long.
  • Good governance means trustees, managers, staff and volunteers all understand their role before problems arise.

If your business is dealing with data protection for charities and wants help with privacy notices, supplier contracts, fundraising compliance, data sharing arrangements, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.

Build privacy controls around the real data flow

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Build privacy controls around the real data flow

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.