The rule: UK GDPR applies to every charity, in proportion
UK data protection law is the UK GDPR, the version of the EU General Data Protection Regulation retained in UK law after Brexit, read with the Data Protection Act 2018. It applies to any organisation that decides why and how to process personal data, which makes the charity a data controller for the personal data of its donors, members, volunteers, staff and beneficiaries. Size, income and charitable status do not change that. The Data (Use and Access) Act 2025 has amended both laws in stages; the ICO says the last of its data protection provisions came into force on 19 June 2026, and it is still revising its guidance, so check the date on any ICO page you rely on.
The law does not, in terms, require every organisation to have a document called a data protection policy. It requires the controller to put appropriate measures in place and to be able to demonstrate compliance, and it adds: "Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller." For a charity that holds any personal data about people it serves, a short written policy is the proportionate minimum, and it is the first thing a funder, an auditor or the ICO will ask to see.
Two administrative points catch small charities out:
- The data protection fee. Controllers must pay the ICO a fee unless they are exempt. One exemption is for processing only for not-for-profit purposes, which covers some small charities whose processing is limited to their own members and supporters; the ICO's self-assessment tells you whether it applies. For charities that do have to pay, the ICO says "Charities that are not otherwise subject to an exemption will only be liable to pay the tier 1 fee, regardless of size or turnover."
- The Charity Commission. The Commission's guidance lists discovering "a significant data breach or loss within your charity" among the incidents trustees should report to the Commission as a serious incident, separately from any report to the ICO. The data protection duty sits with the trustees, whoever does the work.
What personal data a small charity actually holds
Before writing a word of policy, list what the charity holds, where it is kept and who can see it. Most small charities find more than they expected:
- Donors and supporters: names, contact details, Gift Aid declarations, bank details for regular giving, and marketing preferences.
- Members: membership lists, subscription records, attendance.
- Volunteers: contact details, emergency contacts, availability, training, references and, for some roles, DBS check information, which is criminal offence data with its own rules. Our volunteer records guide covers what to keep.
- Staff: the usual HR records, payroll and sickness absence.
- Beneficiaries: referral forms, case notes, needs assessments, safeguarding records, photographs, and often health information.
- Trustees: eligibility declarations, the register of interests and contact details.
Some of that is special category data. UK GDPR gives extra protection to data revealing "racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership", genetic and biometric data, "data concerning health" and data about a person's sex life or sexual orientation. A mental health charity's case notes, a faith charity's membership list and a disability group's access needs are all special category data, and processing them needs a condition under Article 9 as well as a lawful basis under Article 6. There is a specific condition for not-for-profit bodies with a political, philosophical, religious or trade union aim processing data about their members, former members and people in regular contact with them, provided it is not disclosed outside the body without consent, but it does not reach everything such a charity does.
The list you have just made is also the core of the record of processing activities. UK GDPR exempts organisations with fewer than 250 employees from keeping a full record unless the processing is likely to result in a risk, "is not occasional", or includes special category or criminal offence data. A charity that runs a regular service for beneficiaries will usually fall outside the exemption for that processing, so keeping the list current is the practical way to comply.
What a small charity's data protection policy should contain
Everything in the policy hangs off the seven principles in Article 5 of the UK GDPR, which the ICO treats as the core of the law: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality, which means appropriate security measures; and accountability, the duty to be able to show you comply with the other six. A small charity's policy does not need to explain them at length. It needs to say how the charity meets each one in practice.
A proportionate policy for a small charity can be four to six pages. It should say who does what, rather than restate the law, and cover:
- Scope and responsibility. That the policy covers trustees, staff and volunteers; that the trustees are accountable; and who the named data protection lead (or data protection officer, if you have one) is.
- What the charity holds and why. A reference to the data list above, with the lawful basis for each main purpose: contract, legal obligation, consent or legitimate interests, and the Article 9 condition for special category data.
- Privacy notices. Where data subjects are told what the charity does with their data: on forms, the volunteer application and the website, where the notice is often headed privacy policy.
- Keeping only what is needed, for as long as needed. A retention schedule, which our data retention policy guide explains how to build.
- Security. Passwords and screen locks, who has access to which files, how paper is stored, what may and may not be held on personal devices, and what happens when a volunteer leaves.
- Sharing and processors. When data is shared with a local authority, a referral partner or a funder, and a written contract with every data processor, such as the mailing platform, the payroll bureau or the cloud storage provider. Reports to funders should use anonymised data wherever possible: truly anonymised figures are no longer personal data, but a case study that lets a reader recognise the family still is.
- Individual rights. How a request to see, correct or erase data is recognised and answered, including a subject access request, which normally has a one-month deadline.
- Complaints. From 19 June 2026 every organisation must have a process for data protection complaints; the ICO says organisations must "give people a clear way to raise a data protection complaint, acknowledge it within 30 days, investigate appropriately and communicate the outcome."
- Breaches. How a lost phone, a misdirected email or a stolen laptop is reported internally, who assesses it, and the rule that a notifiable breach goes to the ICO "without undue delay and, where feasible, not later than 72 hours after having become aware of it".
- Fundraising and marketing. The rules for email, text and phone marketing under the Privacy and Electronic Communications Regulations, including the charitable purposes soft opt-in the Data (Use and Access) Act introduced from 5 February 2026, and the Fundraising Regulator's Code.
- Training and review. Induction for volunteers who handle personal data, and an annual review by the trustees.
Templates from umbrella bodies are a sensible starting point, provided you replace the parts that describe an organisation you are not. A policy that promises a data protection impact assessment for every new project, in a charity that has never done one, is a list of breaches waiting to be found.
Does a charity need a data protection officer?
Most small charities do not, and appointing a DPO is not a legal requirement merely because a charity processes personal data. The ICO sets out the test: under the UK GDPR, you must appoint a DPO if
- "you are a public authority or body (except for courts acting in their judicial capacity);"
- "your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or"
- "your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences."
Charities are not usually public authorities for this purpose; the definition in section 7 of the Data Protection Act 2018 follows the Freedom of Information Act. The notable exception is an academy trust, which is a charity and a public authority, and must appoint one. Large-scale tracking of individuals is rare in the sector. The third test is the one to think about: a charity whose core activity is providing care, health or counselling services, or supporting people through the criminal justice system, may be processing special category or criminal offence data on a large scale. The ICO's factors for "large scale" are the number of people, the volume of data, the range of data items, the geographical extent and how long the processing lasts. A local bereavement group keeping notes on thirty clients is unlikely to meet it; a national helpline or a charity running several care homes may well.
If you conclude you do not need one, the ICO recommends recording the decision: "it's a good idea to record this decision to help demonstrate compliance with the accountability principle." A short minute of the trustees' reasoning is enough, and it is worth revisiting when the charity takes on a new service.
If you do appoint one, voluntarily or because you must, the same rules apply either way. The ICO says a DPO "must be independent, an expert in data protection, adequately resourced, and report to the highest management level", that the role can be an existing employee or externally appointed, and that several organisations can share one. The DPO must not have other duties that create a conflict of interests, which usually rules out the chief executive or whoever decides how the data is used. Many small charities and not-for-profit organisations that need to appoint one buy in a DPO service from a specialist or share one with other organisations.
Not needing a DPO does not mean nobody is responsible. Name a data protection lead among the staff or trustees, give them time to do it, and make them the person volunteers go to with data protection issues and when something goes wrong. The ICO's helpline and small organisations pages offer free data protection advice, and local infrastructure bodies often run training for voluntary organisations.

Making it real: the records that show the policy works
Accountability is about evidence, and for a small charity the evidence is a handful of short records rather than a compliance programme:
- the data list and record of processing, with lawful bases;
- privacy notices, dated, and the forms they appear on;
- a log of subject access and other rights requests, with dates received and answered;
- a log of data protection complaints and how each was handled;
- a breach log, including the incidents you decided were not reportable and why;
- processor contracts and data sharing agreements;
- training records for staff and volunteers who handle personal data;
- the trustees' minuted decisions: adopting and reviewing the policy, the DPO decision, and any serious incident report.
The breach log is the one most charities do not keep, and it is the most useful. Most incidents in a small charity are minor: an email to a group with everyone's addresses visible, a referral form left in a church hall, a volunteer's phone lost on the bus. Recording each one, with what was done and whether it was reportable, is how the trustees learn where the charity's data actually goes.
The personal data nobody decided to hold
Ask a small charity where its beneficiary data is kept and the answer will be the database, the shared drive and the locked cabinet. The data list will rarely include the place where most of it moves: the volunteers' messaging group. The coordinator posts the names of the families to be visited this week. A volunteer replies that one of them mentioned her husband is back in hospital. Someone shares a photo of a referral form so the next shift has the address. All of that is personal data the charity is processing, some of it special category, and none of it is on the data list, the retention schedule or the privacy notice.
The consequences arrive through the policy's own procedures. A beneficiary makes a subject access request, which covers information held for the charity wherever it is. A volunteer's phone is stolen, with a year of messages about the people the charity serves. A family complains about something a volunteer said in the group. In each case the charity needs to know what was held, and a consumer app whose messages are end-to-end encrypted between personal phones gives the organisation no copy and no way to search. Our guide to WhatsApp and GDPR at work sets out the duties that become hard to meet.
ComplyChat provides channels for work conversations that the charity owns. Everyone added is told the channel is on the record and can object or leave, a mobile number verified by SMS is the identity so volunteers without a work account can take part, messages are stored and processed in the UK, and they are recorded on the server as they are sent, so the charity can find what it holds. On paid plans, once the charity's Microsoft 365 tenant is connected, the lasting record files there under the charity's own retention rules. It is not a data protection compliance tool and does not make a charity compliant; the policy, the lawful basis and the retention decisions remain the trustees'. ComplyChat Free is personal messaging with one private group, direct messages and three calendar months of recent history, with no Microsoft 365 archive, and it is not a way to meet a retention duty.
A question for the next trustees' meeting: does the charity's data list include the messaging groups its volunteers use, and if a beneficiary asked for everything the charity holds about them, could anyone search those groups?
Official guidance and your next step
The ICO's advice for small organisations is written for exactly this reader. Its guidance on data protection officers, the data protection fee, how to deal with data protection complaints and documentation covers the points above in more depth. The Charity Commission's serious incident guidance covers data breaches from the regulator's side. Quotations are from those pages and from the UK GDPR as published on 25 September 2026; the ICO notes that several of its pages are under review following the Data (Use and Access) Act, so check the date on the page you read.
This guide is a practical summary for small charities, not legal advice. Where a charity processes sensitive data at scale, shares data with statutory services or has had a serious breach, take professional advice.
Then do one thing: spend an hour with whoever coordinates volunteers and write the charity's data list on one page, including every group chat, spreadsheet and paper file where names of real people appear. Every item on it needs an owner, a reason and a retention period, and anything that cannot be given all three is where the policy starts.
We build ComplyChat for the work conversations organisations need to keep. In a small charity, a great deal of personal data about beneficiaries moves through volunteers' messages, and a data protection policy only reaches the places the charity can find. Explore Free personal messaging, or compare the paid plans if your charity needs a lasting Microsoft 365 archive.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Advice for small organisations ico.org.uk
- Data protection officers ico.org.uk
- Data protection fee ico.org.uk
- How to deal with data protection complaints ico.org.uk
- Documentation ico.org.uk
- Serious incident guidance gov.uk


