For many charities, a data breach is not simply an IT problem. It can affect supporters, disrupt operations, damage trust and trigger regulatory reporting obligations.

That risk was brought into sharp focus when copies of Beacon CRM databases containing customer information were downloaded by malicious actors. The platform is used by more than 1,000 charities, and the incident led a range of organisations to contact supporters and make serious incident reports to the Charity Commission.

The key lesson is that charities should prepare before an incident occurs. Below, we share practical considerations to help organisations manage cybersecurity risks and meet their data protection responsibilities.

Cybersecurity

Charities are often extremely reliant on their databases, as they contain key information around supporters, volunteers and service users. The electronic records of charities also contain key documents that are central to their day-to-day running and management, such as policies and governing documents. Without this information, many charities would have difficulty functioning. Regular back-up are essential, so that, in the event that these electronic records are compromised – whether that’s due to fire, flood or cybercrime – the data can be recovered and easily restored.

Protecting IT systems from malicious software or malware and avoiding phishing attacks are also important, as these are common ways that malicious actors can gain access to information. Keeping IT systems and devices up to date; installing and using anti-virus software; and training charity trustees, staff and volunteers on how to avoid inadvertently downloading malware, identify phishing attempts and using strong passwords are just a few ways in which charities can protect their organisations against these threats.

Data protection

Personal data is any information that can be used to identify a person, including indirectly if used in combination with other information. Most charities will hold personal data: about trustees, staff, volunteers, supporters and service users. The UK General Data Protection Regulation (UK GDPR) sets out the basis for how organisations, including charities, may collect, store and use personal data and the Information Commissioner’s Office (the ICO) is responsible for enforcing data protection law.

Under the UK GDPR, charities must have a lawful basis for collecting and processing personal data and must have appropriate security measures in place to protect it. Individuals must also be able to access their data, and have it rectified or deleted if required. Charities therefore need to have systems in place to manage personal data appropriately, along with up to date policies and privacy notices, so that it is clear what data is being collected, how this it is done and why it is being held. The rules around direct marketing and the basis on which this may be carried out have also changed recently (please see Blake Morgan’s Insight into DUAA 2025 here for more information on this).

Making sure that charities comply with their data protection responsibilities is crucial, as the consequences can be severe. There is a significant reputational risk should it be discovered and publicised that a charity is not complying with its data protection obligations. There are also financial penalties for breaches of data protection legislation imposed by the ICO. Charity Commission guidance on serious incident reporting also makes clear that cybercrime, data breaches or data losses are reportable incidents, as is any incident which results in, or risks harm to the charity’s work or reputation.

Practical steps

To manage cybersecurity risks and help to ensure data protection compliance, charities can:

  • Review the back-up and security policies and protocols for their IT systems
  • Review data protection policies and procedures and replace these if they are outdated
  • Consider training for trustees, staff and volunteers on cyber security and data protection

Blake Morgan can support with data protection compliance and advise on policies and procedures for charities, along with charity governance and serious incident reporting. Please get in touch with our charity lawyers for further information.

Data protection training

Book a place on our BCS accredited training course

Sign up here

Explore more insights