Data Protection Policies for Charities: A Practical Guide | LegalDocuments.co.uk
We're not a law firm — we help you find the right legal support. For advice on your situation, speak to a legal adviser or find a solicitor.
Staff data protection policy
The General Data Protection Regulation requires you to tell all people whose personal data you process about how you use that data.
£0 Free at Net Lawman checked 2026-07-05
Templates are provided by Net Lawman. We may receive a commission at no extra cost to you.
Overview
A data protection policy is the charity's written statement of how personal information is handled from the moment it comes in to the moment it is securely destroyed. It is an internal document rather than a public-facing notice, although it sits alongside the privacy notice you show to supporters and service users.
The policy explains the lawful bases the charity relies on, who is responsible for compliance, how data subject rights are dealt with, and the controls the organisation uses to keep information safe. For most charities it also covers training, supplier due diligence, retention periods and breach reporting.
A well-drafted policy does three jobs at once. It evidences accountability to the Information Commissioner's Office, which is a core requirement of the UK GDPR. It gives trustees comfort that they are meeting their governance duties. And it gives the people who actually handle the data, often volunteers with no formal legal training, a plain-English reference they can use when they aren't sure what to do.
Key steps
- Map what personal data the charity actually holds. Before writing a policy, list every category of personal information the charity processes and where it sits. Include donor databases, CRM systems, mailing lists, HR files, volunteer records, beneficiary case notes, CCTV and anything held by third-party processors. Without this picture, the policy will be generic rather than useful.
- Identify your lawful basis for each processing activity. Under the UK GDPR you need a lawful basis for every use of personal data, and a separate condition if special category data is involved (for example health or safeguarding information). Charities commonly rely on consent, legitimate interests, legal obligation or contract. Record the reasoning for each, because the ICO expects to see this.
- Set retention periods and deletion routines. Decide how long each type of record is kept and why. Gift Aid records have tax-driven retention rules, employment files have their own timelines, and safeguarding records often need to be held much longer. Build a schedule into the policy so information isn't kept indefinitely by default, which is a common audit finding.
- Define roles, training and breach response. Name the person accountable for data protection (a DPO if required, or a trustee lead if not), set out expectations for staff and volunteer training, and write a clear breach procedure covering internal escalation and the 72-hour ICO notification window where the threshold is met. Keep a breach log even for incidents that aren't reportable.
- Review, approve and refresh the policy regularly. The policy should be formally adopted by the trustees, communicated to everyone who handles data, and reviewed at least annually or whenever systems, suppliers or activities change materially. Treat it as a living document, a policy that never changes is usually a policy nobody is reading.
Template · England & Wales
Put a data protection policy in place
The General Data Protection Regulation requires you to tell all people whose personal data you process about how you use that data.
Templates are provided by Net Lawman. We may receive a commission at no extra cost to you.
Common questions
Get the paperwork right
Get the Staff data protection policy template
- Drafted for England & Wales
- Put a data protection policy in place
- Full details & price at Net Lawman
£0 Free at Net Lawman · checked 2026-07-05
Templates are provided by Net Lawman. We may receive a commission at no extra cost to you.
Sources
This guide is based on primary UK law and official guidance.
- Official SourceInformation Commissioner's Office, Guide to UK GDPRico.org.uk
- LegislationData Protection Act 2018legislation.gov.uk
- Guidance · UK GovCharity Commission, Guidance for trusteesgov.uk
- Official SourceICO, Guidance for charitiesico.org.uk
