Policy templates / Data Protection & Privacy Policy
Charity Data Protection & Privacy Policy Template (Free, UK)
Highlighted parts are yours to complete. A starting point to adapt, not legal advice.
1. Purpose and who this covers
[your charity] collects and uses personal information about people connected with us, such as supporters, beneficiaries, volunteers, staff, trustees and enquirers. This policy explains how we look after that information and keep to data protection law: the UK GDPR and the Data Protection Act 2018.1
It applies to every trustee, member of staff and volunteer who handles personal data on our behalf. It is a starting point to adapt to how we actually work. It is not legal advice.
2. Who is responsible, and registering with the ICO
Day-to-day responsibility for data protection sits with [name / role]. The trustees are collectively accountable for making sure we comply.
We have checked whether we must pay the annual data protection fee and register with the ICO, and we [have registered / are exempt because [reason]].5 Most charities have to register unless a narrow not-for-profit exemption applies, so check rather than assume.
3. The rules we follow
We handle personal information in line with the data protection principles.3 We:
- use it lawfully, fairly and in a way people would reasonably expect;
- use it only for the clear purposes we collected it for;
- collect only what we actually need;
- keep it accurate and up to date;
- keep it no longer than we need it; and
- keep it secure.
We can also show how we meet these rules. Being able to demonstrate that is itself part of the law (the accountability principle).
4. Our reason for using personal data, and marketing
Before we use personal information we work out why the law allows us to, our "lawful basis" (for example a contract, our legitimate interests, a legal obligation, or the person's consent).
For marketing by email, text or other electronic message, we rely on consent and make it easy to opt out at any time. We only mail lists where people have agreed to hear from us. We never send a marketing message to our whole contact list on the assumption that everyone has agreed. When someone opts out, we keep them on a do-not-contact (suppression) list rather than deleting them, so we do not contact them again by mistake.
Service and administration messages are not marketing and do not need fresh consent: a receipt, a thank-you, or an update about a service or event someone is already using.
We take extra care with sensitive information ("special category" data such as health, religion or beliefs) and only use it where the law specifically allows.
5. Keeping information accurate, and how long we keep it
We keep a simple record of the personal information we hold, where it came from, what we use it for and who we share it with. We correct information when we find it is wrong.
We keep personal data only as long as we have a clear reason to, then delete or anonymise it (the storage-limitation principle).3 Keeping records for ever is not a neutral choice: everything we still hold has to be searched when someone asks for a copy of their data, and it adds to the harm if we have a breach. So we decide up front when each type of record is deleted, rather than letting it pile up until a rights request or a breach forces the question.
Our set retention periods for supporter and donor records, volunteers, beneficiaries, unsuccessful applicants and accounting records live in one place, our Document Retention Policy, so each figure is only ever set once and the two policies cannot drift apart. [Name / role] runs a clear-out every year to delete or anonymise anything past its period.
6. Keeping personal data secure, and where it lives
We protect personal information with measures that fit our size and risk, for example:
- strong passwords and two-factor login on the systems we use;
- access limited to the people who need it;
- laptops and phones locked or encrypted, and care with any paper records;
- staff and volunteers told how to spot phishing and handle information safely.
Where charity data is allowed to live. We keep charity personal data only in [named systems and accounts, for example our CRM, our charity Google Workspace or Microsoft 365, our accounting tool]. Do not copy it onto a personal laptop or phone, or into personal email or messaging apps such as WhatsApp or Gmail, without approval from [name / role]. Using a personal phone for charity contact is fine when [name / role] has agreed how, for example an agreed app or a separate work account.
When someone leaves. On the day a trustee, member of staff or volunteer stops working or volunteering with us, [name / role] removes their access to our systems, including any online banking, and makes sure any charity personal data is deleted from their own devices and accounts. We do not leave this until the end of the week: lingering access is one of the most common ways charity data and money go missing.
Before we start using personal data in a significant new way, we think through the risks first. We only use reputable suppliers to store or handle data on our behalf.
7. Sharing data, using suppliers, and sharing with funders or partners
We do not sell personal information, and we do not share it without a lawful reason.
Before we share personal data with another organisation that decides for itself how it will use the data (for example a funder, a partner charity or a statutory body), we confirm our lawful basis, share only the minimum needed, and put a written data-sharing agreement in place for anything regular or sensitive.6 We are especially careful with special category data such as health, safeguarding or immigration information. We never share it without both a lawful basis and, where the sharing is ongoing, a written agreement.
Where a supplier handles data on our behalf (a processor), for example email, accounting, fundraising or CRM tools, we have a written contract that requires them to protect it and use it only on our instructions.
Where a supplier or partner is based outside the UK, we check the information is still properly protected before we use them.
8. People's rights over their information
People have rights over the information we hold about them. They can see it, correct it, ask us to delete it, or object to certain uses. Anyone can make a request to [contact name / email].
We respond within one month, and free of charge in most cases.3 If we cannot do what is asked, we explain why and tell the person they can complain to the ICO.
9. If something goes wrong (data breaches)
A personal data breach is when information is lost or stolen, sent to the wrong person, or seen or changed by someone who should not. Examples: a laptop is lost, a spreadsheet of supporters or beneficiaries is emailed to the wrong person, or an account is hacked. If you think one has happened, tell [name / role] straight away. Do not wait.
We act quickly to contain it (for example changing passwords, recalling the message, or locking the account) and we write down what happened, when we found out, and what we did. If the breach is likely to put people at risk, we report it to the ICO within 72 hours of becoming aware of it, and we tell the people affected where the law requires it.4 The 72-hour clock runs from when we became aware, and it includes weekends, so [name / role] makes the reporting decision quickly rather than waiting for the next meeting. A breach may also be a serious incident for the Charity Commission; if so we assess and report it under our Serious Incident Reporting Policy.
10. Review
The trustees review this policy at least annually (data protection is a higher-risk, statutory area, so we review it more often than our two-year default for other policies), and after any significant breach or change in the law. Approved by the board on [date]; next review [date].
More about this policy
When you need it
Data protection is a legal duty, not just good practice. Any charity that holds information about living people, whether supporters, beneficiaries, volunteers, staff or trustees, is a "data controller" and must follow the UK GDPR and the Data Protection Act 2018.[1] Trustees are collectively responsible, and most charities must also register and pay a fee to the Information Commissioner's Office (ICO) unless a narrow exemption applies.[5]
A written policy is not named in the law as a document you must have, but it is how you show you meet the "accountability" rule. The ICO expects one that fits your size and what you do. A small charity needs a short, usable policy, not a giant's manual. This is a starting point to adapt, not legal advice.
What it protects against5 examples
Supporter and beneficiary lists get emailed around as spreadsheets, saved on trustees' and volunteers' personal laptops and phones, and copied into personal WhatsApp and Gmail accounts. Nobody knows how many copies exist or who still has them when someone leaves.
The policy tells people where charity data is allowed to live (named systems and accounts), bans keeping copies on personal devices without approval, and says data comes off a device and access is removed the day someone stops volunteering or working there.
A laptop is lost, a spreadsheet is emailed to the wrong person, or a supporter account is hacked. The one person who noticed is not sure it counts, tells nobody, and the 72-hour window to decide whether to report to the ICO passes.
The policy makes clear that anyone who spots a possible breach reports it to one named person the same day, that person logs it and decides within 72 hours whether the ICO must be told, and staff know a near miss still gets reported.
The charity keeps everything for ever. Donor records from a decade ago, ex-volunteers, beneficiaries who left years back, and old job applicants all sit in the files because nobody ever agreed when to delete things.
The policy sets plain retention periods for each type of record and names who does the yearly clear-out, so old data is deleted or anonymised instead of piling up.
Marketing or newsletter emails go to people who never agreed or who opted out, because a volunteer pulled the whole contact list. This breaks PECR, not just GDPR, and can bring a fine and complaints.
The policy records the lawful basis and consent for each way you contact people, keeps opt-outs suppressed rather than deleted, and says only agreed lists are used for marketing.
Sensitive information about a beneficiary, such as health, a safeguarding concern, or immigration status, is shared with a funder, partner, or in a report without a lawful basis or any agreement about how the other side will handle it.
The policy flags special category data as needing extra care, requires a lawful basis and a written data-sharing agreement before it goes to a third party, and defaults to sharing the minimum needed.
Swipe or scroll for more
How to enforce it
Practical steps to make it live, not just filed:
- Name one person as the data protection lead (a trustee or a senior staff member, not usually a formal DPO). They keep a simple list of what personal data you hold, where it lives, and why, and they are the person everyone reports problems to.
- Do a data spring-clean once a year: go through each type of record, delete or anonymise anything past its retention date, and check who still has access to shared drives and accounts. Minute that it happened.
- Cover the policy in induction and give a short refresher once a year. Everyone who handles personal data reads it and signs to say so, so you can show the ICO your people were told.
- Have a written breach drill everyone knows: spot it, tell the lead the same day, log it, and the lead decides within 72 hours whether to report to the ICO. Keep the log even for near misses.
- Practise handling a subject access request before a real one lands. Know where you would search, who signs it off, and that you have one month to reply, so the first real request does not catch you out.
What larger charities add6
Pull one in only when it matches something you actually do:
- Our record of processing activities Mid-size (£1m to £10m)+
- Assessing risk in new projects Mid-size (£1m to £10m)+
- Training and awareness Mid-size (£1m to £10m)+
- Data Protection Officer Large (£10m+)+
- Transfers of data outside the UK Large (£10m+)+
- Assurance to the board Large (£10m+)+
What people get wrong
- Adopting a big charity's data protection manual. A pack with a DPO, a spreadsheet of processing records and international transfer agreements is unrunnable for a small charity, and an unused policy protects no one. Start with the 'small' clauses here, then add the mid and large ones only when your processing actually grows into them.
- Writing a one-line 'we comply with GDPR' statement. That does not meet the duty. You must actually name who is responsible, say what your lawful basis is, keep data secure, honour people's rights and know your breach steps. The ten 'small' clauses here are the genuine minimum, not optional extras.
- Assuming charities do not have to register or pay the ICO fee. Most charities must register and pay the data protection fee. The not-for-profit exemption is narrow, so check the ICO's guidance and register if you are not clearly exempt.
- Treating consent as the reason for everything. Consent is mainly for electronic marketing. Using volunteer or beneficiary data usually rests on a contract, a legal obligation or legitimate interests. Pick and record the right basis for each use rather than asking for consent you do not need.
- Letting supporter and beneficiary lists spread onto personal devices, then walk out the door. Say where charity data is allowed to live, keep it off personal laptops, phones and personal email or messaging without approval, and remove access and delete data on the day someone leaves. Set your retention periods in your Document Retention Policy and name who runs the yearly clear-out, so lists do not quietly copy themselves onto a leaver's own accounts and stay there.
- No one knowing who to tell, or the 72-hour breach clock. Name the person to report a breach to, and make sure people know the ICO deadline is 72 hours from becoming aware. The clock includes weekends. A breach nobody reports on time is how a small mistake becomes a fine.
Terms used here5
- ICO
- The Information Commissioner's Office, the UK regulator for data protection. Serious data breaches are reported to it within 72 hours.
- lawful basis
- The reason UK data-protection law allows you to use someone's personal data, for example consent, a contract or a legal duty.
- special category data
- More sensitive personal data, such as health, religion or ethnicity, that needs extra care and a stronger reason to hold.
- serious incident
- An event the Charity Commission expects trustees to report, such as significant harm, fraud or a major loss.
- PECR
- The Privacy and Electronic Communications Regulations, the rules for marketing by email, text and phone (alongside UK GDPR).
Sources7
Numbered to match the [n] citations in the template.
- Data Protection Act 2018 legal duty
- The essential trustee: what you need to know, what you need to do (CC3) legal duty
- A guide to the data protection principles (ICO) Commission guidance
- Personal data breaches: a guide (ICO) legal duty
- Guide to the data protection fee (ICO) legal duty
- Data sharing: a code of practice (ICO) Commission guidance
- Advice for small and medium organisations (ICO) Commission guidance