The Charity Commission is stressing that charities must get to grips with the General Data Protection Regulations (GDPR), which become law on 25 May 2018
The new data protection rules are designed to provide greater protection for individuals around the use of their personal data.
The regulator says that if a charity asks for, receives or holds personal information from others, for example, email addresses of users or staff, then these EU-wide regulations will apply.
The Information Commissioner’s Office (ICO) is the UK regulator for GDPR and charities must check ICO’s guidance for the latest information about the new requirements.
The ICO has produced a dedicated resource page specifically for charities, together with a helpline. This includes guidance from the Institute of Fundraising and the Fundraising Regulator.
GDPR will apply to all personal information a charity may acquire and hold about, including beneficiaries and users, donors, staff and volunteers.
It is important that charities know what data they hold and how it is managed. There is a GDPR guide for charities from the Charity Finance Group (CFG) to help with this.
Take action
The Charity Commission advises charities to get an action plan agreed with their trustees on how they plan to manage the data the charity holds or intends to get, in line with GDPR, and complete the ICO self-assessment to check on their state of readiness.
As well as data management, charities will also need to consider whether they need to put processes in place to deal with GDPR requirements around accountability, transparency and security.
As part of this process, the regulator is advising charities to make sure their details with the Charity Commission are up to date and to check that they have logged the correct information, including the names of current trustees and their contact details (including email addresses).
ICO guidance for charities about GDPR