If the phrase "GDPR" makes your board slightly nervous, you are in good company. Most small charities are doing more right than they realise: they keep donor details reasonably safe, they don't sell mailing lists, and they delete old files eventually. What they usually lack is the document that proves it — and a clear picture of which data protection paperwork is actually required by law, and which is simply expected good practice.
Here is the short answer. A privacy notice — the outward-facing explanation of what you do with people's data — is legally required under Articles 13 and 14 of the UK GDPR, and virtually every charity processes personal data, so virtually every charity needs one. An internal data protection policy is not named in the legislation in the same way, but Article 24 requires you to put in place appropriate measures to demonstrate compliance, "including the implementation of appropriate data protection policies" where proportionate. For any charity holding donor, beneficiary, staff or volunteer records, a short written policy is the proportionate response — and it is the first thing the Information Commissioner's Office (ICO) will ask to see if something goes wrong.
A charity data protection policy is an internal document, adopted by the trustees, that sets out how the charity collects, uses, stores, shares and deletes personal data, which lawful bases it relies on, and who does what when someone exercises their rights or a breach occurs. This guide explains precisely what the law requires, walks through every section a good policy needs, and gives you a free template written for small charities in England and Wales. It sits alongside our pillar guide to what policies a charity needs.
Is a data protection policy legally required for charities?
It helps to separate four different obligations, because they have four different legal statuses.
The privacy notice: legally required. Articles 13 and 14 of the UK GDPR require you to tell people, at the point you collect their data (or within a month if you got it from elsewhere), who you are, what you are doing with their information, your lawful basis, how long you keep it, and what rights they have. If your charity has donors, members, volunteers, staff or beneficiaries, this duty applies to you now. The ICO offers a free privacy notice generator with a specific charity and voluntary sector variant, updated in July 2026 for the Data (Use and Access) Act 2025.
The internal policy: required in substance, if not by name. Article 24 (the accountability principle) obliges every controller to implement "appropriate technical and organisational measures" to ensure and demonstrate compliance, including data protection policies "where proportionate in relation to processing activities". For a two-volunteer book club, a policy may genuinely be disproportionate. For a charity with a donor database, a payroll, and beneficiaries whose health or family circumstances it records, it is not. Notably, data protection is not one of the thirteen policies the Charity Commission's Annual Return asks about — but the legal footing here is stronger than for most of the policies that are.
Retention periods: effectively required. Article 5(1)(e) — storage limitation — says personal data may be kept "no longer than is necessary". You cannot comply with that principle without deciding, somewhere, how long you keep things. That decision written down is your retention schedule.
The ICO fee: required for most charities. Under the Data Protection (Charges and Information) Regulations 2018, organisations that process personal data as controllers must pay an annual fee to the ICO unless exempt. Charities that are not exempt pay only the tier 1 fee — £52 a year regardless of size or income, with a £5 discount for direct debit (the other tiers, £78 and £3,763, apply to businesses by size). Many very small charities are fully exempt, for example where all processing is only for staff administration, accounts and records, or not-for-profit purposes. The ICO's registration self-assessment takes five minutes and settles the question; paying the fee is not "registering for GDPR", and exemption from the fee never exempts you from the rest of the law.
Data protection policy vs privacy notice: know which is which
This is the single most common confusion, so it is worth being blunt. The policy faces inward: it tells your trustees, staff and volunteers how the charity handles data and what to do when a request or breach arrives. The privacy notice faces outward: it tells donors, beneficiaries, volunteers and staff what you do with their data, and it is the one the law explicitly demands. They should agree with each other — a notice that promises deletion after two years while your filing cabinet says otherwise is worse than no notice at all — but they are separate documents with separate audiences. This guide, and our template, cover the internal policy; use the ICO's generator for the notice and cross-check the two.
What your charity data protection policy must include
A good small-charity policy runs to four to eight pages. Here is the anatomy, section by section.
Purpose, scope and definitions. State that the policy applies to everyone processing personal data on the charity's behalf — trustees, employees, volunteers and contractors — and to all personal data the charity holds, in any format, including paper records. Define "personal data", "special category data" and "processing" in one plain-English sentence each, so a new volunteer doesn't need a law degree to follow the rest.
Roles and responsibilities. Name who leads on data protection. Most small charities do not legally need a Data Protection Officer (that duty falls mainly on public authorities and organisations doing large-scale processing of special category data, or large-scale, regular and systematic monitoring of individuals), but every charity needs a named data protection lead — often the secretary or a trustee — and the policy should say who that is and what reaches the board.
Lawful bases for processing. List the six Article 6 lawful bases and state which ones your charity actually relies on and for what. In practice, small charities lean on four: contract (paying staff, delivering member services), legal obligation (Gift Aid records for HMRC, payroll), legitimate interests (routine administration, and postal fundraising to existing supporters, with a brief balancing assessment recorded), and consent (email marketing outside the soft opt-in, photographs, case studies). Resist the reflex to treat consent as the default — it is often the weakest choice, because it can be withdrawn and must be demonstrable.
Special category data. Charities disproportionately hold sensitive data — beneficiaries' health conditions, disabilities, religion, or family circumstances; volunteers' criminal records checks. Processing it requires both an Article 6 basis and a separate Article 9 condition (with, in some cases, an additional condition under Schedule 1 of the Data Protection Act 2018). Your policy should flag which special category data the charity holds, the condition relied on, and the extra care it gets: tighter access, stronger security, shorter retention.
Privacy notices. Commit to maintaining accurate privacy notices for each audience (supporters, beneficiaries, staff and volunteers), reviewing them when processing changes, and providing them at the point of collection as Articles 13 and 14 require.
Individual rights and the SAR procedure. People have the right of access, rectification, erasure, restriction, portability and objection. The one that will actually land in your inbox is the subject access request. Your policy should set the procedure: a SAR is valid in any form and needs no magic words; the clock runs for one calendar month under Article 12A UK GDPR (inserted by the Data (Use and Access) Act 2025), starting from the day the request arrives — or, where identity reasonably needs verifying, from the day proof is received — and pausing while you await any clarification you have asked for; it is extendable by up to two further months for complex or numerous requests provided you tell the requester within the first month; no fee may be charged except for manifestly unfounded or excessive requests; and every SAR goes straight to the named lead on the day it arrives. A month evaporates quickly when the person who received the email is on holiday.
Personal data breach response. Set out the sequence: detect and report internally (anyone who spots a breach tells the lead immediately) → contain (recall the email, disable the account, recover the laptop) → assess the risk to individuals → report to the ICO within 72 hours of becoming aware, where the breach is likely to result in a risk to people's rights and freedoms (Article 33) → notify the affected individuals without undue delay where that risk is high (Article 34). The 72 hours includes weekends. Require a breach log recording every incident, reported or not — Article 33(5) expects one, and it is the evidence that your judgement calls were reasoned. Note in the policy that a significant breach may also be a serious incident reportable to the Charity Commission.
Retention schedule. Append a simple table: category of record, retention period, reason, what happens then. Common anchors for charities: Gift Aid declarations and records until 6 years after the end of the accounting period (or tax year) the claim relates to — and enduring declarations for as long as donations continue, plus 6 years; accounting records for at least 6 years; unsuccessful job applications around 6 months; safeguarding records substantially longer, per your safeguarding policy. The precise periods matter less than having defensible ones and following them.
Security measures. Proportionate, concrete commitments: password managers and two-factor authentication on email and the donor database, access on a need-to-know basis, encrypted or locked-away devices, no personal data lingering in personal email accounts, secure disposal of paper records. The National Cyber Security Centre's small organisations guide is the reference standard and is free.
Data sharing and processors. Distinguish other controllers (HMRC, the local authority) from processors acting on your instructions (your CRM, mailing platform, payroll bureau, cloud storage). Article 28 requires a written contract with every processor — for mainstream services the standard terms usually suffice, but someone should check. The policy should also state that international transfers only happen with appropriate safeguards in place.
Fundraising and direct marketing. This section earns its keep. Under the Privacy and Electronic Communications Regulations (PECR), electronic mail marketing — email, texts and social media direct messages — traditionally required consent. Since 5 February 2026, the Data (Use and Access) Act 2025 has extended the "soft opt-in" to charities: you may send electronic marketing that furthers your charitable purposes without prior consent, but only if you collected the person's details when they expressed an interest in, or offered support for, those purposes; you gave them the opportunity to opt out when you collected the details; and you offer the same simple opt-out in every subsequent message. Your policy should state whether the charity uses the soft opt-in, require opt-outs to be honoured promptly and suppressed permanently, and note that post and live phone calls can instead rely on legitimate interests with screening against the relevant preference services.
Training and induction. Everyone who touches personal data gets a short briefing at induction and a refresher when the policy changes. For most small charities, an hour built around this policy is proportionate; the point is that nobody handling a donor list has never heard of a SAR.
Review. State who owns the policy and when it will be reviewed — annually or biennially, and sooner if the law or your processing changes.
Download our free charity data protection policy template (Word) — openly licensed, written for small charities in England and Wales, and yours to adapt with no sign-up.
Adopting the policy properly
A policy the board has never seen protects nobody. Tailor the template first: name your data protection lead, strike out sections that do not apply (if you never use CCTV, say nothing about CCTV), and fill in the retention schedule with your real record types. Then put it to a trustee meeting, record the adoption decision in the minutes, and give the policy an owner and a review date. Under the accountability principle, the minute matters: it is your evidence that trustees engaged with the question, not just that a document existed on a shared drive. Trustee Meetings keeps policies, owners and review dates alongside your agendas and minutes and resurfaces each policy when its review falls due — see how it works.
While you are at it, check two housekeeping items: that your ICO fee is paid or your exemption confirmed, and that your privacy notices match what the new policy says you do.
Common mistakes charities make
Confusing the fee with compliance. Paying the ICO £52 is not a data protection policy, and an exemption from the fee is not an exemption from UK GDPR.
One document trying to be both policy and privacy notice. The audiences are different, the legal bases for each are different, and a hybrid usually does neither job. Keep them separate and consistent.
Consent for everything. Charities that put every activity on a consent basis discover, at re-permission time, that they have made half their supporter database unusable. Use consent where the law demands it and a better basis where it does not — and record the reasoning.
No SAR routing. The most common way charities blow the one-month deadline is not difficulty — it is that the request sat in a generic inbox for three weeks. The policy must say where SARs go on day one.
Forgetting paper and personal devices. The beneficiary files in the treasurer's spare room and the mailing list in a volunteer's personal Gmail are inside scope. Say so in the policy, and give people a compliant alternative.
Keeping everything forever "just in case". Indefinite retention breaches Article 5(1)(e) and makes every breach worse, because there is more to lose. A retention schedule that is actually applied is one of the cheapest risk reductions available.
How often should you review it?
Review the policy at least every two years — annually is better while data protection law is moving, as the phased commencement of the Data (Use and Access) Act 2025 shows. Trigger an early review whenever something material changes: a new database or CRM, a first employee, a new service collecting beneficiary data, a data breach or near miss, a SAR that exposed a gap, or fresh ICO guidance for the voluntary sector. Each review, however brief, should be minuted with a note of what changed. If review dates tend to slip past your board unnoticed, Trustee Meetings tracks them for you and is free to try — no card needed. The download link for our free template is above; adapt it, adopt it, and put the review date in the diary.
Data protection rarely stands alone on a small charity's risk register, and the neighbouring policies are worth reading together: our guides to the charity safeguarding policy (which governs some of your most sensitive records), the charity risk management policy and the charity complaints policy cover the natural companions, the pillar guide mentioned above maps the whole landscape, and a trustee action log is the simplest way to make sure the actions each review generates actually get done.