Charities – Have You Got the Right Data Protection Documents in Place?
Posted on in Data Protection, Charities & Social Enterprises
For many charities, data protection compliance can feel like one of those jobs that is always important, but rarely urgent – until a subject access request lands, a complaint is made, a new system is introduced, or someone asks where the organisation’s retention policy actually is.
The good news is that getting started does not need to mean doing everything at once. The best place to begin is with a clear, practical look at what your charity does with personal data, what documents and procedures you already have and whether those documents match what is happening day to day.
Data protection is not just a tick-box exercise
A privacy notice on your website is important, but it is only one part of the picture. Data protection compliance is about being able to show why you collect personal data, how you use it, who has access to it, how long you keep it, how you keep it secure and what employees and volunteers are expected to do in practice.
That is especially important for charities because personal data often sits across different teams and activities: fundraising, events, beneficiaries and service users, volunteers, employees, trustees, safeguarding, marketing, grant reporting and complaints. It is very easy for documents to say one thing while day-to-day practice has quietly moved on.
What has changed under the DUAA?
The Data (Use and Access) Act 2025 has introduced changes to the UK data protection landscape. For charities, one of the key practical messages is that compliance documents should not be treated as static. They need to be reviewed against the updated law, the organisation’s current activities and the way personal data is actually being handled.
Recent updates also sharpen the focus on data protection complaints. Charities should think carefully about whether data protection complaints are being identified, separated from general service complaints where needed, acknowledged properly, investigated appropriately and escalated to the right person internally. A general complaints process may not be enough if it does not recognise the statutory rights and regulatory risks involved.
So, where should a charity start?
Start with the basics. Not because they are simple but because they are the foundations everything else sits on. If you do not have a clear picture of what personal data your charity holds, why you hold it and who is responsible for it, it becomes much harder to respond confidently when something goes wrong.
- Training: Are personnel suitably trained? Would it be helpful for your organisation to receive bespoke training that’s not just another general compliance video? Or would general awareness training be helpful as a starting point?
- Map your personal data: What personal data do you collect about beneficiaries, supporters, donors, employees, volunteers, trustees and other contacts?
- Check your lawful basis: Have you recorded why you are allowed to use each category of personal data before you use it?
- Review your Record of Processing Activities (RoPA): Do you have one? It’s a legal requirement, so is it up to scratch? Does it reflect what is actually happening across the charity, or just what the organisation thinks is happening?
- Look at your privacy notices: Would someone understand how their personal data is collected, used, shared, stored and protected?
- Check retention periods: Are you keeping personal data because you still need it, or because nobody has made a decision about deleting it?
Why do subject access requests (SARs) cause so many headaches?
SARs are often where gaps in compliance become visible. If personal data is spread across inboxes, paper files, legacy systems, shared drives and third-party platforms, responding within the statutory timeframe can quickly become stressful and time-consuming.
Common pressure points include unclear ownership, poor search processes, uncertainty about exemptions, lack of training, over-retention of historic data and systems that were not designed with data subject rights in mind. An organisation cannot usually rely on poor internal systems as a reason for struggling to comply, so it is worth testing SAR readiness before a request arrives.
How we can help
We offer bespoke data protection support packages for charities who want practical help getting their compliance documents and procedures into shape. We are also offering free webinars on the following topics:
- Compliance documents and docu-don’ts – 11am on 23.09.26
A back-to-basics webinar which will discuss key documents to assist your compliance and common pitfalls.
- Why is my organisation struggling with SARs? 11am on 07.10.26
A guided webinar with action steps to help you move forward more confidently with SARs.
Or to speak to one of our data protection experts with a specific query, please get in touch with one of our team.
