Why donor data needs extra care
Your donors trust you with their personal information, names, addresses, payment details, and sometimes very personal reasons for giving. That trust is something worth protecting.
A data breach does not just risk fines or regulatory action. It can damage the relationship your charity has built with its supporters and make people hesitant to give in the future. Taking sensible steps to protect donor data is an investment in your charity's reputation and long term sustainability.
Secure collection principles
When collecting information from donors, keep these principles in mind:
- Only ask for what you need. If someone is making a one off donation, you probably do not need their date of birth or phone number.
- Use secure forms. If you collect donations or data online, make sure your website uses HTTPS (the padlock icon in the browser).
- Be transparent. Let donors know what you will do with their information at the point you collect it. A short, clear statement near your donation form goes a long way.
- Get proper consent for marketing. If you want to send updates, newsletters, or fundraising appeals, make sure donors have actively opted in.
Storage and access controls
Once you have donor data, keeping it safe is an ongoing responsibility:
- Limit who can access donor records. Not everyone in your charity needs to see payment details or personal notes. Give access only to those who need it for their role.
- Use strong passwords and two step verification on any systems where donor data is stored, including your CRM, email accounts, and cloud storage.
- Keep digital records secure. If you use spreadsheets, store them in a password protected or encrypted location, not on an open shared drive.
- Secure paper records. If you keep physical records (donation forms, Gift Aid declarations), store them in a locked location and dispose of them securely when no longer needed.
- Set retention periods. Decide how long you need to keep different types of donor data. Financial records may need to be kept for six years for tax purposes, but marketing preferences can be reviewed more regularly.
Breach response basics
If donor data is lost, stolen, or accidentally shared with the wrong person, act quickly:
- Contain the issue. Change passwords, revoke access, or take affected systems offline as needed.
- Assess the risk. What data was involved? How many people are affected? Could it cause harm?
- Report if necessary. If the breach is likely to result in a risk to people's rights and freedoms, you must report it to the Information Commissioner's Office (ICO) within 72 hours.
- Notify affected donors. If the breach poses a high risk to individuals, let them know what happened and what you are doing about it.
- Learn from it. After the immediate response, review what went wrong and what you can do to prevent it happening again.
Trust and transparency best practices
Building trust with donors goes beyond compliance. These practices show supporters that you respect their information:
- Publish a clear, accessible privacy notice on your website
- Make it easy for donors to update their preferences or ask questions about their data
- Respond promptly and kindly when someone asks to unsubscribe or have their data removed
- Train staff and volunteers on data protection basics at least once a year
- Review your data handling practices regularly, especially after any changes to your systems
- Be honest if something goes wrong, people appreciate transparency
Remember: Protecting donor data well is not just about following rules. It is about showing your supporters that you value their trust as much as their generosity. Small, consistent steps make a real difference.
Find your own gaps in five minutes
The free safety check turns this guide into a personal action list, with the three things worth fixing first.
