Skip to main content

    Team Safety Snapshot now live, 10 founding partner spots at £39. Claim yours →

    CyberSafe Coach+
    Something happening right now?Digital 999
    For charities

    GDPR Checklist for Charities

    UK charities hold donor, beneficiary and volunteer data, which makes them data controllers under UK GDPR exactly like any business. This free eight-step checklist from CyberSafe Coach+ covers what trustees actually need in place, written for people with no legal background and no data protection officer.

    Run the free readiness check

    5 minutes • Plain English • No sign-up to start

    What does a charity need to do to comply with UK GDPR?

    • 1Identify the personal data your charity holds, donors, beneficiaries, volunteers and staff
    • 2Document your lawful basis for processing each type of data
    • 3Write a plain-English privacy notice and publish it on your website
    • 4Keep a simple Record of Processing Activities (ROPA), a spreadsheet is fine
    • 5Set retention periods and delete data you no longer need
    • 6Check supplier contracts include data-processing terms (DPAs)
    • 7Train trustees, staff and volunteers on spotting phishing and reporting incidents
    • 8Have an incident plan, who to call, what to do in the first 72 hours

    Do small charities have to comply with GDPR?

    Charities sit in a tricky spot: you handle sensitive information about donors and beneficiaries, often with volunteers and a small staff team, and rarely with an in-house data protection officer. Generic GDPR templates assume a corporate setup with legal review baked in, most don't translate to a 10-person community group.

    Our checklist focuses on the steps the Information Commissioner's Office (ICO) and the Charity Commission actually expect to see: a documented lawful basis, a published privacy notice, a record of processing, sensible retention, and a calm plan for when something goes wrong.