Skip to main content

    Team Safety Snapshot now live, 10 founding partner spots at £39. Claim yours →

    CyberSafe Coach+
    Something happening right now?Digital 999
    Back to guides

    GDPR Compliance Guide for Charities

    Plain English guidance on meeting UK GDPR requirements, written specifically for charities and non-profit organisations.

    12 min read6 sections
    01

    What GDPR means for your charity

    The UK General Data Protection Regulation (UK GDPR) is the law that governs how organisations collect, store, and use personal data. It applies to charities of all sizes, whether you have hundreds of staff or are run entirely by volunteers.

    Personal data is any information that can identify a living person. This includes names, email addresses, phone numbers, donation records, case notes, and even photographs where someone is recognisable.

    The good news is that GDPR is not about making things difficult. It is about treating people's information with care and respect, something most charities already aim to do.

    02

    Lawful bases explained simply

    Before you collect or use personal data, you need a lawful reason (called a "lawful basis"). There are six in total, but charities most commonly rely on these:

    • Consent, the person has clearly agreed to you using their data for a specific purpose. Common for marketing emails and newsletters.
    • Legitimate interests, you have a genuine reason to use the data, and it does not override the person's rights. For example, sending updates to existing supporters about your work.
    • Contract, you need the data to fulfil an agreement with the person, such as processing a regular donation.
    • Legal obligation, you are required by law to process the data, such as keeping financial records for HMRC.

    You should identify and record which lawful basis you are using for each type of data processing your charity carries out. This does not need to be complicated, a simple spreadsheet will do.

    03

    Data minimisation

    Only collect the personal data you actually need. It can be tempting to ask for lots of information "just in case," but GDPR asks you to keep things proportionate.

    For example:

    • If someone signs up for your newsletter, you need their email address. You probably do not need their home address or date of birth.
    • If you are registering a volunteer, collect only what is needed for safeguarding and contact purposes.
    • Review your forms regularly to remove fields you do not actually use.
    05

    Individual rights

    People whose data you hold have several rights under GDPR. The most relevant for charities include:

    • Right of access, anyone can ask to see what data you hold about them. You must respond within one month.
    • Right to correction, if their data is wrong, they can ask you to fix it.
    • Right to deletion, in some circumstances, they can ask you to delete their data (sometimes called the "right to be forgotten").
    • Right to withdraw consent, if you are relying on consent, they can change their mind at any time.
    • Right to object, they can object to certain types of processing, including direct marketing.

    Have a simple process in place so that whoever receives these requests knows what to do and who to pass them to.

    06

    Practical compliance checklist

    Use this checklist to review your charity's position. You do not need to do everything at once, work through it at a pace that suits you.

    • Identify what personal data your charity holds and where it is stored
    • Record the lawful basis for each type of data processing
    • Write or update your privacy notice in plain English
    • Review your consent mechanisms (forms, sign ups, tick boxes)
    • Ensure you only collect data you genuinely need
    • Set retention periods, decide how long you keep data and delete it when no longer needed
    • Train staff and volunteers on basic data protection responsibilities
    • Have a process for responding to data rights requests
    • Know how to recognise and report a data breach (you may need to notify the ICO within 72 hours)
    • Keep records of your data processing activities
    • Review your arrangements with third parties who handle data on your behalf
    • Consider whether you need to register with the Information Commissioner's Office (ICO)

    A note on proportionality: GDPR does not expect small charities to have the same systems as large corporations. What matters is that you take reasonable steps to protect people's data and can show you have thought about it. Start with the basics and build from there.

    Find your own gaps in five minutes

    The free safety check turns this guide into a personal action list, with the three things worth fixing first.