Do we need a data protection policy, and what goes in it?
- TimeNot established by the research for the writing itself; note the new statutory acknowledgement clock the policy has to describe (see the answer box).
- CostFree to write and adopt
- Doing itYou can do this yourself
The policy is your internal instruction manual — who does what, when — as distinct from the privacy notice, which is your promise to the outside world. Since 19 June 2026, your charity has had to have an accessible route for someone to complain to you directly about how you handle their data, with a duty to acknowledge that complaint within 30 days. Almost no small charity's policy mentions this yet, and it is cheap to fix.
Do this first
- running-04 (not yet published)
England and Wales: researched. Scotland: researched — data protection is reserved, so UK GDPR, the DPA 2018, PECR and the ICO apply identically. Northern Ireland: researched — reserved in exactly the same way.
A new complaint route your policy almost certainly doesn’t mention yet
★ This is the one genuinely new thing to put in the policy, and almost nobody has it yet. The Data (Use and Access) Act 2025 inserted new sections into the Data Protection Act 2018 creating a statutory right for an individual to complain to the controller directly — that is, to your charity, not only to the ICO. Organisations must have an accessible complaints process — the Act gives a complaint form that can be completed electronically as its example of what “facilitating” a complaint looks like — must acknowledge a complaint within 30 days, and must then respond, or tell the complainant the outcome, without undue delay.
This duty is not forthcoming; it is already live. It commenced on 19 June 2026, which means a charity without a working process is already non-compliant, not merely behind schedule. Because the change is recent and quiet, this is currently a near-universal gap across small charities — and it is a cheap one to close: name an owner, describe the route, and set the acknowledgement clock against the 30-day figure above.
What the policy is for, and what it is not
The policy and the privacy notice answer different questions, and the confusion between them is itself a common mistake. The notice is the outward promise: what UK GDPR requires you to tell the people whose data you hold. The policy is the internal instruction manual: who in the charity does what, and when, to make that promise true in practice — who handles a subject access request, who handles a breach, who handles a complaint under the new route above.
No Tier A source prescribes the content of a data protection policy in the way the law prescribes the content of a privacy notice. Say that plainly rather than implying a checklist exists: naming an owner, a review date, and the people responsible for each of the processes above is the safest structure the research supports, not a shorter version of a list that does not exist.
One thing worth checking while the policy is being written: UK GDPR now recognises 7 lawful bases for processing personal data, not six — a new basis, “recognised legitimate interest”, was inserted by the DUAA 2025 and has been in force since 2026-02-05. Any older training material or template that still says “six lawful bases” predates this change. If the policy names or explains lawful bases anywhere, check it against the current count rather than an older source.
Absence of basic policy and training is what enforcement actually turns on
★ The pattern the ICO itself keeps returning to across its charity enforcement cases is not the sophistication of an attack — it is the absence of basic written policy, training and governance. In the Information Commissioner’s monetary penalty notice against Central YMCA, the contributing failures named were the lack of a written email-security policy, a secure tool that existed but went unused, and training that was assigned but never checked for completion.
That is a useful gauge for whether this step is actually finished: an adopted document that nobody has been walked through is not much more protective than no document at all. Naming who is briefed on the policy — and recording it in the minutes — is part of the deliverable, not an optional extra.
Common mistake: having no accessible complaints route, or not acknowledging complaints in time
The duty is new and almost no small charity has noticed it yet. A statutory right to complain to the controller now exists, with an accessible route, an acknowledgement period, and a duty to respond without undue delay. It commenced before most charities’ policies were last reviewed, so a charity without a process is already non-compliant — a near-universal but cheap-to-fix gap.
Common mistake: expecting a statutory checklist of what the policy must contain
Privacy notice content is prescribed by UK GDPR, and the two documents get confused. No Tier A source prescribes the content of a data protection policy as distinct from the notice. The policy is the internal instruction manual; the notice is the outward promise. Say so rather than implying a checklist exists.
Common mistake: adopting the policy and never training anyone on it
The document gets treated as the deliverable in itself. The common thread the ICO emphasises across its charity enforcement cases is the absence of basic written policy, training and governance, not the sophistication of any attack — in its Central YMCA penalty, the named contributing failures were no written email-security policy, a secure tool available but unused, and training completion that was never monitored.
Worked example
Wrenfield Village Hall’s committee adopts a one-page data protection policy. It names an owner and a review date, and it assigns who handles a subject access request, who handles a breach, and who handles a complaint under the new route above, with acknowledgement inside the period the DUAA duty sets. It does not pad the policy with a content list the research cannot source. The outcome: an adopted policy with a named owner, a working complaints route, and a note in the minutes of who has been briefed on it.
What you should have at the end
An adopted data protection policy with a named owner and a review date.
The owner and the review date are what make the policy something the charity actually keeps current, rather than a document written once and never revisited as the law under it changes. A template is available: Data protection policy (planned).
Common questions
No, and it would be a poor idea in both directions. The notice has prescribed content that a policy will not cover, and the policy contains internal detail — who has access to what — that there is no reason to publish.
A named person who is actually around — usually a manager or the trustee with the operations brief. Charities often put "the board", which reads well and means nobody is doing it.
Terms on this page
Sources
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82)
- Data (Use and Access) Act 2025 (c. 18)
- What should we consider when responding to a request?
- Charities given new flexibility to contact supporters under data law change + итоговое руководство по прямому маркетингу электронной почтой
- Central YMCA — Monetary Penalty Notice