Brad is on the roll of solicitors of England & Wales but does not hold a practising certificate and does not provide legal advice.
Updated June 2026 · England & Wales
Charities sit in a slightly unusual spot when it comes to data protection. You're mission-driven and often running lean, yet you handle some of the most sensitive personal information around, donor records, beneficiary circumstances, volunteer details, and employee files. Getting data protection right isn't just about dodging regulatory action from the Information Commissioner's Office; it's about protecting the trust that keeps supporters giving and beneficiaries engaging.
This guide walks trustees, charity directors and senior staff through what UK GDPR and the Data Protection Act 2018 actually require in a charity context. I've tried to keep it practical rather than academic, because in my experience trustees want to know what to do on Monday morning, not just what the law says in principle. Where the rules get fiddly, I'll flag it.
Overview
UK GDPR, sitting alongside the Data Protection Act 2018, is the framework that governs how organisations in this country handle personal data. It replaced the EU version after Brexit but kept most of the substance intact, so the obligations you may have read about pre-2021 still largely apply.
For charities, the law treats you the same as any other data controller, your not-for-profit status doesn't buy you a lighter touch. If you collect names, email addresses, giving history, medical details, safeguarding notes or employment records, you're processing personal data and the rules bite.
The framework covers how you gather information, what you tell people about it, how long you keep it, who you share it with, and how you respond when someone asks to see or delete what you hold. It also sets out special protections for sensitive categories such as health data, religious beliefs and children's information, all of which many charities handle routinely. Getting a clear grip on what you hold and why is the foundation everything else sits on.
Key steps
Map what personal data you actually hold. Before you can comply with anything, you need an honest picture of the information flowing through your charity. Walk through donor databases, Mailchimp lists, volunteer spreadsheets, CCTV footage, safeguarding files, HR records and anything sitting in trustees' personal inboxes. Note what you collect, where it lives, who can see it and how long it stays.
Identify a lawful basis for each processing activity. Every time you use personal data, UK GDPR requires one of six lawful bases, typically consent, contract, legal obligation, vital interests, public task or legitimate interests. Charities often rely on legitimate interests for fundraising communications and consent for marketing emails, but you need to document which basis applies to which activity and be ready to justify it.
Update your privacy notice and internal policies. People whose data you hold have a right to clear information about what you're doing with it. Your privacy notice should be written in plain English, cover each processing purpose, explain retention periods, and set out how someone exercises their rights. Back this up with an internal data protection policy that staff and volunteers actually read.
Build a process for data subject requests. Individuals can ask to access their data, correct it, delete it, restrict its use, or object to processing. You generally have one calendar month to respond, and getting it wrong is one of the most common triggers for ICO complaints. Decide now who handles these requests, how you'll verify identity, and where you'll look to gather the relevant records.
Strengthen security and plan for breaches. Technical and organisational measures need to be proportionate to the risk, encryption, access controls, secure disposal of paper records, staff training, and MFA on cloud accounts are all sensible starting points. Put a breach response plan in writing so that if something goes wrong, you know who decides whether to notify the ICO within the 72-hour window.
Common questions
Q Does our small charity really need to comply with UK GDPR?
Yes. Size doesn't exempt you. If your charity processes personal data, which almost every charity does, even a tiny one with a single volunteer coordinator, UK GDPR applies. The rules are meant to be proportionate to what you actually do, so a small local charity won't face the same expectations as a national one, but the core duties around lawful basis, transparency and security apply across the board.
Q Do we need to register with the Information Commissioner's Office?
Most charities that process personal data electronically must pay a data protection fee to the ICO unless a specific exemption applies. The fee tier depends on your size and turnover. There's a self-assessment tool on the ICO website to check your position, and it's worth doing early because failing to register when required can itself trigger enforcement action.
Q Can we still send fundraising appeals to our existing donors?
Usually yes, but the route depends on the channel. Postal appeals to existing supporters often sit under legitimate interests, while marketing emails and texts normally require consent under the Privacy and Electronic Communications Regulations. You should also honour the Fundraising Preference Service and make opting out genuinely easy in every communication you send.
Q When do we need to appoint a Data Protection Officer?
A formal DPO is mandatory only in specific circumstances, broadly, where your core activities involve large-scale processing of sensitive data or systematic monitoring. Many charities don't meet this threshold, but it's still sensible to designate someone at senior level who owns data protection internally. Trustees remain accountable either way, so don't treat the role as purely administrative.
Q What counts as a personal data breach we need to report?
A breach is any security incident that leads to accidental or unlawful destruction, loss, alteration, or unauthorised access or disclosure of personal data. Not every breach requires reporting, only those likely to risk people's rights and freedoms. If in doubt, lean towards reporting. The 72-hour clock to notify the ICO starts when you become aware, not when you've finished investigating.
Q How long can we keep donor and beneficiary records?
UK GDPR doesn't prescribe fixed periods, it requires that you keep data no longer than necessary for the purpose you collected it for. Gift Aid records have HMRC retention rules, employment records have their own timelines, and safeguarding files often need to be kept for extended periods. Set retention schedules for each data category and actually follow them rather than hoarding everything by default.
Q Are trustees personally liable if the charity breaches data protection law?
Monetary penalties from the ICO are usually issued against the charity as the data controller, not individual trustees. However, trustees are collectively responsible for ensuring the charity complies, and serious failings can attract Charity Commission scrutiny and reputational fallout that affects the whole board. Treating data protection as a standing governance item at trustee meetings is a sensible protection.
Sources
This guide is based on primary UK law and official guidance.
Brad is on the roll of solicitors of England & Wales but does not hold a practising certificate and does not provide legal advice. LegalDocuments.co.uk is not a law firm and does not provide regulated legal advice.
This article is for general information only. It is a tool to help you find your way — not legal advice, and not a substitute for speaking to a qualified adviser about your situation.