Charity Data Protection Policy: Free Template + Guide

Every charity that handles personal data needs a written data protection policy, regardless of size, reflecting UK GDPR principles and the Data (Use and Access) Act 2025. Charities that process personal data must generally register with the ICO and pay the data protection fee unless a specific exemption applies. Retention periods should be justified by purpose rather than set to keep data indefinitely, and a basic data map can be completed in about 30 minutes.

What the policy must cover (UK GDPR + DUAA)

While building CharityIQ’s compliance module I read the ICO’s small-organisation guidance end to end; this guide closes the gap between what the law asks of a charity data protection policy and what most templates deliver. A charity data protection policy must cover the lawful bases you rely on, the categories of personal data you hold, who is responsible for compliance, how long you keep data, and what you do if there’s a breach, all consistent with UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025. The DUAA introduced changes to areas including automated decision-making rules, the legitimate interests framework, and complaints handling, so policies written before 2025 should be reviewed rather than assumed still accurate (our charity law tracker follows commencement).

At minimum, your policy should state: your charity’s name as data controller, the types of personal data processed (donor, beneficiary, volunteer, employee), your lawful bases for each main activity, retention periods, third-party processors used (such as CRM or email platforms), and how individuals can exercise their rights. This complements, rather than replaces, a separate GDPR compliance checklist; see our GDPR checklist for charities for the audit side of the same work — both live in our charity compliance handbook. The ICO’s data protection fee for charities is £52 a year (£47 by direct debit) — charities always fall in Tier 1 (ICO, 2026).

Free template, annotated

I wrote this template myself — it mirrors the policy I maintain at my own charity, tightened against what the ICO expects of small organisations. Copy the structure below into your own document, replacing the bracketed sections with your charity’s specifics. Each section is annotated so you understand why it’s there, not just what to fill in.

[Charity Name] Data Protection Policy
Last reviewed: [date] · Next review due: [date, typically 12 months later]

1. Purpose and scope
This policy explains how [Charity Name] collects, uses, stores and protects personal data belonging to beneficiaries, donors, volunteers, staff and trustees, in line with UK GDPR and the Data Protection Act 2018.

2. Data controller
[Charity Name], registered charity number [XXXXXX], is the data controller. Our ICO registration number is [XXXXXX].

3. What data we collect and why (lawful basis)
[List each category: e.g. donor contact details – consent/legitimate interests; beneficiary case records – legitimate interests/vital interests/consent depending on service; volunteer records – contract/legitimate interests; safeguarding records – legal obligation/vital interests.]

4. Who is responsible
[Named trustee or senior staff role] holds overall responsibility for data protection. Day-to-day queries go to [role/email].

5. How long we keep data
[Insert your retention schedule; see the retention section below.]

6. Who we share data with
[List processors: CRM provider, email platform, payroll provider, funders where required, statutory bodies where legally required.]

7. Individual rights
Individuals can request access, correction or deletion of their data by contacting [email/role]. We will respond within one month as required by UK GDPR.

8. Data breaches
Suspected breaches must be reported immediately to [role]. We will assess and, where required, report to the ICO within 72 hours.

9. Review
This policy is reviewed at least annually by [trustee board / named role].

This is also a lead magnet: grab the formatted version by joining the compliance module waitlist below, or use the on-page version above if you need to move fast today.

Roles: who’s responsible in a small charity

In a small charity without a dedicated data protection officer, responsibility for data protection should sit with a named trustee or senior staff member who understands the charity’s main data flows, not be left ambiguous across the whole board. Most small charities are not legally required to appoint a formal Data Protection Officer, but someone must still own the policy, handle subject access requests, and lead on breach response. At my own charity that named person is me; the difference is speed — a suspected breach needs an owner within hours.

Practical allocation:

  • One named trustee or senior manager as overall accountable owner.
  • A clear, published route for staff and volunteers to report a suspected breach immediately.
  • Annual sign-off by the board, recorded in trustee minutes.

From experience: data protection is the policy I see small charities over-engineer most. My own charity’s is deliberately short enough for the whole board to read before signing off; the parts I re-check yearly are the data map and retention schedule — they go stale fastest. The ICO cares more about whether you know what you hold and can respond to a breach than how many pages your policy runs to.

Data you hold: mapping in 30 minutes

A basic data map lists every place personal data enters, is stored, and leaves your charity, and most small charities can produce a first draft in about 30 minutes by working through their main systems one at a time rather than trying to capture everything at once. Start with your CRM or donor database, your email platform, your HR/payroll system, and any beneficiary case files, listing what’s held, why, and for how long. When I mapped ours, stray spreadsheets took longer than the named systems.

  1. List every system that holds personal data (CRM, email marketing tool, HR software, spreadsheets, paper files).
  2. For each, note: what data, whose data (donor/beneficiary/staff/volunteer), lawful basis, and who can access it.
  3. Flag anything you can’t justify keeping, that’s your first clean-up task.

Our data protection self-check checklist covers the same ground.

Retention periods that make sense

Retention periods should be set by genuine business or legal need, not a default of “keep everything indefinitely,” and should be written into your policy as a schedule rather than left as a vague statement. Common UK charity retention benchmarks include seven years for financial records (aligned to HMRC requirements), six years for standard contracts after they end, and shorter periods (often 12 to 24 months) for unconverted fundraising leads or marketing contacts who haven’t engaged. My test at my own charity: if I can’t say why we hold it, we shouldn’t.

Where a specific legal retention period applies, such as HMRC’s requirements for financial records, cite it directly; see HMRC’s guidance on keeping business records for the underlying rule your finance retention period should reflect.

Breach response basics

A data breach must be assessed as soon as it’s discovered, and if it’s likely to risk individuals’ rights and freedoms, reported to the ICO within 72 hours of your charity becoming aware of it. Your policy should name who leads this assessment, since delays often happen simply because no one is clearly responsible for making the call.

  • Contain the breach immediately (revoke access, isolate the system, recover lost data where possible).
  • Assess the risk to individuals: what data, how sensitive, how many people affected.
  • Report to the ICO within 72 hours if risk is likely; notify affected individuals directly if risk is high.
  • Log every breach, even ones not reportable to the ICO, as part of your accountability record.

Our data breach playbook walks those first 72 hours step by step. For the wider security context, see our related cyber security posts and CharityIQ’s compliance features for how this fits into ongoing monitoring.

What to do next

Download or copy the template above today, complete your 30-minute data map, and get the policy signed off by a named trustee or senior manager this month rather than leaving it open-ended. Then use the retention and breach sections to check your existing practice actually matches what the policy says.

Want CharityIQ to help monitor your data protection compliance ongoing? Join the compliance module waitlist →

Frequently asked questions

Yes, if you process any personal data (donor, beneficiary, volunteer or staff records), you need a written policy regardless of size. There is no small-charity exemption from UK GDPR's core accountability requirements.

Most charities that process personal data must pay the ICO's data protection fee and register, unless a specific exemption applies. Check the ICO's self-assessment tool to confirm your charity's exact position.

The DUAA 2025 updated aspects of UK data protection law including rules on automated decision-making and elements of the legitimate interests framework. Charities should check current gov.uk guidance for specific provisions and commencement dates.

At least annually, and immediately after any significant change such as a new CRM system, new funder data-sharing requirement, or a near-miss breach. Record every review in trustee or senior management minutes.

The policy is the governing document that states your rules; a checklist is an audit tool you use to check you're actually following them. Use both together for full coverage.