Skip to content
Serin, Empowering charities, CICs, & small businesses
Insights·Policies & Compliance5 Aug 20268 min read

Data protection basics for UK charities and CICs

You do not need a DPO to be GDPR-compliant. You do need a lawful basis, a privacy notice, a retention schedule and a breach process.

Quick answer

Every UK charity and CIC that holds personal data must register with the ICO (usually £40/year), maintain a privacy notice, define a lawful basis for each processing activity, and hold a written breach process.

Navigating Data Protection: A Practical Guide for UK Charities and CICs

Data protection might sound like a bureaucratic hurdle, but for UK charities and Community Interest Companies (CICs), it's a fundamental aspect of building trust, safeguarding vulnerable individuals, and operating legally. While the terminology – GDPR, ICO, lawful basis – can seem daunting, at its heart, data protection is about handling people's personal information responsibly and transparently. This guide breaks down the essentials into plain English, offering practical, actionable advice to help your organisation stay compliant without getting bogged down in jargon.

Many charities and CICs assume that compliance requires a dedicated data protection officer (DPO) or an extensive legal budget. The good news is that for most, this isn't the case. Instead, it’s about understanding a few key principles and embedding them into your day-to-day operations. This might involve creating a clear privacy notice, understanding why you're collecting certain data, or having a plan for what to do if data is accidentally disclosed. Getting these basics right is not only a legal requirement but also a powerful way to demonstrate credibility to your beneficiaries, donors, and partners.

Key Takeaways

  • Every UK charity and CIC handling personal data must register with the ICO, usually for £40 per year.
  • A clear privacy notice is essential, explaining what data you collect and why.
  • You need a 'lawful basis' for every piece of personal data you process.
  • Establish a written policy and process for handling data breaches.
  • You probably don't need a dedicated Data Protection Officer (DPO).
THE ROADMAP1Navigating DataProtection: APractical Guid2The Cornerstone:Registering with theICO3Establishing a LawfulBasis for Processing D4The Importance of aTransparent PrivacyNoti5Data Retention andSecure Disposal
How this guide is structured

The Cornerstone: Registering with the ICO

The very first step for almost every UK charity and CIC is to register with the Information Commissioner's Office (ICO). The ICO is the UK's independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. If your organisation processes personal data – which includes anything from supporter mailing lists to beneficiary records – you likely need to register.

This registration is not a one-off task; it's an annual commitment. Most charities and CICs will fall into 'Tier 1' or 'Tier 2' organisations, meaning the annual fee is typically £40 or £60. Failure to register can result in significant fines, and it's a quick, straightforward process that can be completed online. Don't be tempted to skip this vital step; it's the foundation of your data protection journey and signals your commitment to responsible data handling.

Data protection basics for UK charities and CICs illustration
Illustration by Serin

Establishing a Lawful Basis for Processing Data

Under the UK General Data Protection Regulation (GDPR), you cannot simply collect and use personal data without a legitimate reason. For every piece of personal data you process – whether you're collecting names for a newsletter, addresses for delivering services, or health information for support programmes – you must identify a 'lawful basis'. There are six main lawful bases, and understanding which one applies to specific activities is crucial.

The most common lawful bases for charities and CICs include:

  • Consent: The individual has given clear consent for you to process their personal data for a specific purpose. This must be freely given, specific, informed, and unambiguous.
  • Contract: The processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.
  • Legal Obligation: The processing is necessary for you to comply with the law (not including contractual obligations).
  • Vital Interests: The processing is necessary to protect someone's life. This is rarely used in a charity context beyond emergency situations.
  • Public Task: The processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law. This often applies to public sector bodies but can sometimes apply to charities delivering public services.
  • Legitimate Interests: The processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual's personal data which overrides those legitimate interests. This is often a flexible basis for charities but requires a careful balancing act and documentation.

Choosing the correct lawful basis is not a 'pick your favourite' exercise. It requires careful thought for each specific data processing activity. For instance, sending a general fundraising email might often be based on consent or legitimate interests, while processing payroll data for an employee is a contractual necessity.

"Effective data protection isn't just about avoiding penalties; it's about fostering trust. When beneficiaries and donors know their data is safe, they're more likely to engage and support your mission."

Serin Insight

The Importance of a Transparent Privacy Notice

Once you understand your lawful bases, the next step is to communicate this clearly to the individuals whose data you process. This is where your privacy notice (also known as a privacy policy) comes in. A privacy notice is a public document that explains how your organisation collects, uses, stores, and protects personal data. It must be easily accessible, written in plain language, and comprehensive.

Crucially, your privacy notice should include:

  • Your organisation's identity and contact details.
  • The types of personal data you collect.
  • The purposes for which you are processing the data.
  • The lawful basis for each processing purpose.
  • Who you share the data with (e.g., third-party service providers).
  • How long you will retain the data (data retention policy).
  • Information about individuals' rights (e.g., right to access, rectify, erase data).
  • How individuals can complain to the ICO.

Placing your privacy notice prominently on your website is standard practice. For data collected offline, such as on paper forms, you should either provide the full notice or a clear summary with instructions on how to access the complete version.

Data Retention and Secure Disposal

Holding onto personal data for longer than necessary is a common pitfall and a breach of data protection principles. Your organisation needs a clear data retention schedule that specifies how long different types of data will be kept and why. This schedule should be based on legal requirements, regulatory guidance, and business needs.

For example, financial records often need to be kept for six years for HMRC purposes, while consent for marketing might need to be refreshed more frequently. Once data is no longer needed, it must be securely disposed of. This means more than just deleting files from your computer; it includes shredding paper documents, securely wiping hard drives, and ensuring data is unrecoverable. Documenting your retention schedule and disposal methods demonstrates your commitment to responsible data management.

Preparing for the Worst: The Data Breach Process

Despite all precautions, data breaches can happen. A data breach is not just a hacker gaining access to your systems; it's any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed. This could be something as simple as sending an email to the wrong person, a laptop being stolen, or a paper file being misplaced.

Every charity and CIC must have a written process for identifying, responding to, and reporting data breaches. This process should outline:

  • Who is responsible for handling breaches.
  • How to identify a potential breach.
  • Steps to contain the breach (e.g., isolate systems, recover lost data).
  • Assessment of the risk to individuals' rights and freedoms.
  • When and how to report the breach to the ICO (within 72 hours if there's a risk to individuals).
  • When and how to inform affected individuals.
  • Post-breach review and learning.

Having this process in place and understood by staff is crucial. Timely reporting to the ICO can mitigate potential penalties and demonstrates your proactive approach to data security.

Do You Need a Data Protection Officer (DPO)?

A common misconception among charities and CICs is that they are legally required to appoint a Data Protection Officer. For most, this is not the case. You only need a DPO if you are a public authority or body (which typically doesn't include most charities, unless they're performing a public task based on law), or if your core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale, or if your core activities consist of large-scale processing of special categories of data or data relating to criminal convictions and offences.

For the vast majority of UK charities and CICs, a DPO is not mandatory. Instead, you can designate a responsible individual or team to oversee data protection compliance. This person should have a good understanding of GDPR principles and practical application, and be given adequate resources and authority to carry out their role effectively.

Practical Steps to Enhance Your Data Protection

Beyond the fundamental requirements, there are several practical steps your organisation can take to strengthen its data protection posture and build a culture of privacy.

Staff Training

Your staff are your first line of defence. Regular, engaging data protection training is vital. It doesn't need to be complex; focus on practical scenarios relevant to their roles, such as handling emails, using secure passwords, and recognising phishing attempts. This empowers your team to be vigilant and adhere to best practices.

Data Protection Impact Assessments (DPIAs)

For new projects or technologies that might involve 'high risk' data processing – such as extensive use of sensitive personal data or new surveillance technologies – you should conduct a Data Protection Impact Assessment (DPIA). This helps you identify and minimise data protection risks upfront, before they become problems.

Supplier Due Diligence

When you use third-party suppliers (e.g., CRM systems, email marketing platforms, cloud storage), you remain responsible for the data they process on your behalf. Always conduct due diligence to ensure they are GDPR compliant, and have a written contract (Data Processing Agreement) in place that outlines their responsibilities and your expectations regarding data security.

Regular Reviews

Data protection is not a 'set and forget' task. It requires ongoing attention. Regularly review your policies, procedures, and practices. Are they still relevant? Are there new technologies or activities that require updates? An annual review, or a review triggered by significant changes, is good practice.

Data Protection Key Areas Checklist
Area Action Points Notes for Charities/CICs
ICO Registration Annual check, pay fee Essential first step, usually £40/£60 for Tiers 1 & 2.
Privacy Notice Accessible, clear, comprehensive Review yearly, ensure it reflects all data processing.
Lawful Basis Document for each data type/activity Crucial for demonstrating compliance. Use assessment tool if unsure.
Data Retention Written schedule, secure disposal methods Avoid holding data longer than necessary; shred/wipe securely.
Breach Process Defined steps for identification, containment, reporting Train staff, understand 72-hour reporting rule for high-risk breaches.

Next Steps

By focusing on these core areas – ICO registration, lawful basis, privacy notices, retention, and breach processes – your charity or CIC can build a robust and compliant data protection framework. While the landscape of data protection might evolve, the fundamental principles of transparency, accountability, and respecting individuals' rights remain constant. Start with an internal audit of your current data handling practices, identify areas for improvement, and implement changes incrementally. Remember, good data protection is a journey, not a destination, and a continuous commitment will serve your organisation and its stakeholders well.

Step-by-step

How to do this, step by step

  1. Step 1

    Register with the ICO

    This is often the first and most fundamental step. If your charity or CIC processes personal data, you almost certainly need to register with the Information Commissioner's Office annually. The fee is typically £40-£60 for most smaller organisations and can be completed online. Failure to register can lead to significant penalties.

  2. Step 2

    Define Your Lawful Bases

    For every type of personal data you collect and every activity you perform with that data, you must identify and document a 'lawful basis' under GDPR. This means understanding why you need the data, and which of the six legal grounds applies (e.g., consent, legitimate interests, legal obligation). This is crucial for demonstrating compliance.

  3. Step 3

    Publish a Clear Privacy Notice

    Create and prominently display a comprehensive privacy notice (or privacy policy) on your website and wherever you collect personal data. This document must clearly explain what data you collect, why, who you share it with, how long you keep it, and individuals' rights regarding their data. Use plain, accessible language.

  4. Step 4

    Implement a Data Retention Schedule

    Develop a written policy that specifies how long different categories of personal data will be held and the secure methods used for its disposal once it's no longer needed. This prevents you from holding onto data unnecessarily, which is a breach of data protection principles.

  5. Step 5

    Establish a Data Breach Process

    Prepare for potential data breaches by creating a clear, written procedure outlining steps to take if personal data is accidentally or unlawfully accessed, lost, or disclosed. This includes who to notify internally, how to contain the breach, and when and how to report to the ICO (within 72 hours for high-risk breaches).

  6. Step 6

    Conduct Staff Training Regularly

    Your staff are key to data protection. Provide regular, practical training on data protection principles, secure data handling, identifying phishing, and your organisation's specific policies. This empowers them to act responsibly and reduces the risk of human error leading to breaches.

Practical examples

Example: New Fundraising Campaign Opt-in

A small charity, 'Hope for Herts', plans a new email marketing campaign to solicit donations. They create new online forms for sign-ups. For this activity, 'Hope for Herts' chooses 'consent' as their lawful basis. Their form clearly states: "Yes, I would like to receive updates and appeals from Hope for Herts by email." There's an unchecked box, and information on how to withdraw consent at any time. This specific, informed, and unambiguous opt-in allows them to build their mailing list robustly, knowing they have a clear lawful basis.

Example: Beneficiary Support Records

A CIC, 'Community Connect', provides mental health support services. They collect sensitive personal data, such as health information, from their beneficiaries. For this, their lawful basis is likely 'legitimate interests' combined with 'explicit consent' for special categories of data, or for tasks carried out in the public interest with a legal basis. Their privacy notice explicitly details how this health data will be used, who it will be shared with (with consent), and how long it will be retained, ensuring transparency and trust with vulnerable individuals.

Common mistakes to avoid

  • Failing to register with the ICO, leading to potential fines.
  • Not having a clear, accessible privacy notice that covers all data processing activities.
  • Collecting data without a defined lawful basis, or misapplying a lawful basis (e.g., assuming consent when another basis is more appropriate).
  • Keeping personal data for longer than necessary, without a clear data retention schedule.
  • Lacking a written data breach response plan, leading to panic and potential non-compliance during an incident.
  • Assuming GDPR compliance requires a dedicated DPO, when an appointed responsible person is usually sufficient.
  • Neglecting staff training, leading to human errors that cause data breaches.
  • Not having Data Processing Agreements (DPAs) in place with third-party suppliers who handle your data.
FAQ

Frequently asked questions

Does my small charity really need to register with the ICO?+

Yes, almost every UK charity or CIC that processes personal data (which includes donor records, volunteer data, or beneficiary information) is legally required to register with the ICO annually. This typically costs £40-£60 per year for smaller organisations. It's a foundational step for compliance.

What is a 'lawful basis' and why do I need one for my data processing?+

A 'lawful basis' is your legal justification under GDPR for collecting and using personal data. You cannot process data without one. It ensures transparency and accountability. Common bases for charities include consent, legitimate interests (e.g., for fundraising activities), or legal obligation (e.g., for employee payroll). You need to identify and document the correct basis for each data processing activity.

Do we need to hire a Data Protection Officer (DPO)?+

For most UK charities and CICs, a dedicated Data Protection Officer (DPO) is not mandatory. You only need one if you're a public authority, or if your core activities involve large-scale, systematic monitoring of individuals or large-scale processing of special categories of data. Most charities can designate an existing team member or a small team to oversee data protection responsibilities.

What constitutes a 'data breach' and what should we do?+

A data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This could be a lost laptop, an email sent to the wrong person, or a cyber attack. You must have a written process to identify, contain, and assess the breach. If there's a risk to individuals' rights and freedoms, you must report it to the ICO within 72 hours and potentially inform affected individuals.

How long should we keep personal data?+

You should not keep personal data for longer than is necessary for the purpose for which it was collected. This requires a 'data retention schedule' that outlines specific periods for different types of data (e.g., financial records for 6 years, consent lists for shorter periods). Once data is no longer needed, it must be securely deleted or destroyed.

Can we use 'legitimate interests' for fundraising without explicit consent?+

Yes, 'legitimate interests' can be a suitable lawful basis for some direct marketing activities by charities, including fundraising. However, you must conduct a 'Legitimate Interests Assessment' (LIA) to balance your interest against the individual's rights and freedoms. This typically applies to existing supporters or those who have shown a clear interest, and you must always provide an easy opt-out. For new contacts, consent is often the safer and clearer option.

Serin funding intelligence

Get funding intelligence tailored to your organisation

Serin turns insights like this one into a personalised funding plan, matched funders, readiness gaps and next steps for your charity or CIC. Join the waitlist and we'll be in touch when your workspace is ready.

Next step

Take the free Funding Readiness Assessment

5 minutes, 18 questions, personalised AI report, with a 30/60/90-day plan tailored to your organisation.