UK GDPR
Every charity holds personal data — supporter lists, beneficiary records, staff and volunteer files — so every charity has data protection duties. The UK GDPR, with the Data Protection Act 2018 and the marketing rules (PECR), sets out how you must collect, use, store and share that information, and the rights people have over it.
Under the Data (Use and Access) Act 2025, a new charity ‘soft opt-in’ came into force on 5 February 2026, letting charities send electronic marketing to people who have expressed interest in or supported their cause, without prior consent, where strict conditions are met. (Source: ICO, Data (Use and Access) Act 2025 guidance, accessed 9 July 2026.) The Act amends, rather than replaces, the UK GDPR.
Pay the ICO fee if you need to, handle personal data lawfully and securely, and report notifiable breaches within 72 hours — a serious breach can also be a serious incident. See the data-protection chapter of the UK Charity Compliance Handbook.