GDPR Training for Charity Staff and Volunteers
GDPR training is not a named legal requirement, but UK GDPR requires organisations to demonstrate 'appropriate' measures, and the ICO treats staff training as core evidence of that, so it is expected in practice of any charity handling personal data. Training must cover everyone who touches personal data, including volunteers and trustees, not only paid staff, and a properly structured 45-minute session can be run for free using the ICO's own resources. Records of who was trained, and when, should be kept as evidence.
Who needs training (staff, volunteers, trustees)
Get GDPR training wrong — or quietly skip it — and the consequence isn’t hypothetical: the ICO reprimanded and fined a charity £7,500 after a coordinator who hadn’t completed data protection training sent a bulk email in CC instead of BCC, exposing sensitive health data. Get it right and a free 45-minute session, properly logged, satisfies the regulator, reassures funders and cuts your breach risk. As a trustee of a small charity, I’ve had to work out what GDPR training for charities actually means when the trainer, the trainee and the policy owner are sometimes the same person — this guide, part of our charity compliance handbook, is the answer I landed on.
Start with who needs it: anyone who can access, handle, or make decisions about personal data, which in a small charity usually means everyone — paid staff, regular volunteers, sessional workers, and trustees. The ICO’s own training guidance is explicit that organisations should assess the training needs of “voluntary, temporary and contract staff,” not just permanent employees, so a 20-volunteer charity cannot treat training as a staff-only exercise.
In practice, break your people into three groups:
- Everyone with any data access (the majority of a small charity, including reception volunteers, helpline staff and befrienders) needs a general awareness session: what personal data is, how to spot a breach, and who to tell if something goes wrong.
- Staff and volunteers who process special category data (health information, safeguarding notes, financial hardship details) need more specific training on handling that data, because the ICO expects role-appropriate depth, not a generic one-size-fits-all overview.
- Trustees need enough training to discharge their governance duty. They are ultimately accountable for data protection compliance under charity law, even if day-to-day handling sits with staff, so at minimum they should understand your data protection policy and know what a reportable breach looks like.
I say that as a trustee myself: the board is often the group most likely to skip the session, and the group ultimately accountable when it goes wrong.
New starters and new volunteers should get induction-level training before they get access to personal data, not weeks afterwards. If you don’t already have a written data protection policy to train people against, put that in place first, training without a policy behind it has nothing to anchor to.
What it must cover (ICO expectations)
ICO expectations for “appropriate” training are that it is specific to each person’s role, covers the practical basics of lawful data handling, and can be evidenced if the ICO or a funder ever asks. The ICO’s own guidance states organisations should “be able to demonstrate that staff who handle personal data have been appropriately trained,” which means a single all-staff email about GDPR is not enough on its own.
At minimum, cover:
- What counts as personal data and special category data, in charity terms (donor details, beneficiary records, health or safeguarding notes, volunteer DBS information).
- The charity’s lawful basis for processing the data each person actually works with.
- Practical handling rules: password hygiene, not using personal email or personal devices for beneficiary data, and secure storage of paper records.
- The single most common real-world failure: sending group emails in “To” or “CC” instead of “BCC,” which the ICO’s own guidance on what to include in training flags repeatedly because it keeps causing breaches.
- How to recognise and report a suspected breach internally, and who the charity’s nominated contact is.
- Where to find the charity’s data protection policy and what it says.
You can also see what happens when this goes wrong. In April 2024 the ICO issued a formal reprimand and £7,500 fine to Central YMCA after a programme coordinator who had not completed mandatory data protection training sent an email to 264 recipients in CC rather than BCC, exposing the fact that recipients were on an HIV support programme. The ICO’s public statement on the case makes clear that a lack of completed, verified training was a central factor in the enforcement decision, not just the mistake itself.
A 45-minute session plan you can run (free)
You can run a legally credible, ICO-aligned training session in 45 minutes using free materials and no specialist facilitator, covering the legal basics, your own policy, and a live breach-reporting walkthrough. This is enough to cover new starters and to serve as an annual refresher for existing staff and volunteers. If you’re delivering it yourself, as I do at my own charity, treat the plan below as a script, not a syllabus.
| Time | Segment | What to cover |
|---|---|---|
| 0–5 min | Why this matters | One real example (e.g. the Central YMCA CC/BCC case above) to make the risk concrete, not abstract. |
| 5–15 min | The basics | What personal data and special category data are, using your own charity’s records as examples (donor list, beneficiary file, volunteer DBS record). |
| 15–25 min | Your policy, in practice | Walk through your data protection policy line by line: what staff must and must not do with data day to day. |
| 25–35 min | The CC/BCC drill | Live demo sending a test bulk email correctly with BCC, plus 2–3 other common mistakes (unencrypted attachments, leaving files open on shared screens, using personal WhatsApp for beneficiary details). |
| 35–42 min | Spotting and reporting a breach | What a breach looks like in your context, who to tell immediately, and your internal reporting deadline (should be well inside the 72-hour ICO notification window). |
| 42–45 min | Sign-off | Everyone signs (physically or digitally) to confirm attendance and date, for your training log. |
Slide outline to build this from: (1) title and purpose slide, (2) the real-world case, (3) what is personal data at our charity, (4) our policy in five bullet points, (5) the CC/BCC demo, (6) how to report a concern, (7) sign-off and next refresher date. Keep it to seven slides; the point is a working session, not a lecture.
Free and cheap training sources
Free, ICO-authored training resources exist and are sufficient for most small charities, meaning you do not need to buy a paid course to meet the “appropriate training” standard. Paid platforms add convenience (automated tracking, certificates, e-learning modules) but are not a legal requirement.
- ICO’s own resources: the ICO’s free training videos and its training and awareness toolkit are written specifically to help organisations meet this expectation, and are free to use and adapt.
- Sector-specific guidance: the ICO’s “what to include in your training” page is written for small organisations, including charities, and doubles as a free content checklist for the session plan above.
- NCVO and sector bodies: many infrastructure charities run low-cost or free data protection webinars for members; check your local infrastructure organisation or NCVO before paying for a course.
- Peer sharing: if another charity in your network has already built a training session against the ICO checklist, ask to adapt theirs, there’s no requirement that training materials be original.
One caveat: if a funder makes data protection training a condition of a grant, check that funder’s current published guidance rather than relying on this post — funder conditions change between rounds.
Recording training (evidence for funders/ICO)
You must keep a simple written record of who was trained, on what, and when, because both the ICO and grant funders increasingly ask to see evidence of training rather than accepting a verbal assurance that it happened. A spreadsheet is enough — that’s genuinely all I use for my own charity’s log; you do not need specialist software.
At minimum, your training log should capture:
- Name and role of each person trained (staff, volunteer, or trustee).
- Date of training and the format (in-person session, video, e-learning module).
- What was covered, ideally by referencing the same seven-part structure each time so it’s consistent and auditable.
- Signature or digital confirmation of attendance.
- Date the next refresher is due.
This record does double duty. It is exactly the kind of evidence the ICO looks for when assessing whether “appropriate” training happened, and it is increasingly requested by funders during due diligence or post-grant monitoring, particularly for grants involving beneficiary data. Keep the log itself somewhere secure but accessible to whoever manages compliance, and reference it directly from your data protection policy so the two documents work together rather than sitting in isolation.
From experience: Small charities over-worry about choosing the “right” GDPR course and under-worry about the training log. At my own charity, I make sure three things exist: a dated record of who was trained, a policy the session actually quotes, and the BCC habit — because those are what an ICO enquiry or a funder’s due-diligence list will actually ask about. No funder requirement I’ve read has ever asked which e-learning provider we used.
Refreshers: how often
Refresh data protection training at least annually as a baseline, with additional ad hoc refreshers triggered by a data breach, a near-miss, a new system, or a change in what data you handle. The ICO does not set one legally mandated interval, but its own guidance and sector practice converge on annual as the working minimum for most roles.
Practical triggers for an earlier-than-annual refresher:
- A breach or near-miss anywhere in the charity, even a small one, is the single strongest signal that a targeted refresher is needed immediately for the people involved.
- A new case management system, CRM, or fundraising database goes live, since new tools change how data actually moves through the organisation.
- Your data retention rules change, because staff need to know new deletion or archiving timeframes.
- New starters or new volunteers, who need induction-level training before, not after, they get data access.
The trigger I treat most seriously is the near-miss: a wrongly addressed email that didn’t quite become a breach is the cheapest training prompt you’ll get.
Refresher sessions don’t need to repeat the full 45-minute programme every time; a 15-20 minute update focused on what’s changed, plus a reminder of the core CC/BCC and breach-reporting basics, is enough to keep the log current and staff sharp.
What to do next
Start by confirming who actually needs training using the three-group breakdown above, then book 45 minutes in the diary using the session plan and slide outline, and set up a simple training log before the session so you can capture sign-off on the day. Finally, set a calendar reminder for the annual refresher now — our charity deadlines calendar can hold it — before it gets forgotten.
- List everyone with data access: staff, volunteers, trustees, sessional workers.
- Check your data protection policy is current; update it before you train against it (our data protection self-check checklist flags the gaps fastest).
- Run the 45-minute session using the plan above, and log attendance as you go.
- Review your wider compliance position, including your security basics and data retention rules, alongside training so the three work together.
Want CharityIQ to help you turn this into an ongoing compliance routine instead of a once-a-year scramble? Join the compliance module waitlist →
Frequently asked questions
There's no single law stating "you must run GDPR training," but UK GDPR requires organisations to take "appropriate" technical and organisational measures, and the ICO treats staff training as core evidence of that. In practice, any charity handling personal data is expected to train the people who handle it, and enforcement cases confirm the ICO checks for this.
Yes. The ICO's own guidance says organisations should assess training needs for "voluntary, temporary and contract staff," not only permanent employees. If a volunteer can see, handle, or discuss personal data, whether donor details or beneficiary records, they need training appropriate to that access before they start.
At least annually is the sector-standard minimum, reflecting ICO guidance that refresher training should happen "at appropriate intervals." Refresh sooner after any breach or near-miss, a new system going live, or a change to your data retention rules, since these events reveal or create new training gaps.
The ICO publishes free training videos and a full training and awareness toolkit designed for organisations of any size, including small charities. Combined with the ICO's own guidance on what to include in training, these are enough to build a credible, evidenced session without paying for a commercial course.
A data protection policy is the written rulebook: what your charity does with personal data and why. Training is how you make sure staff and volunteers actually know and follow that rulebook. You need both, and training should directly reference your policy rather than teach generic GDPR theory in isolation.
No. The ICO expects training to be role-appropriate and individually evidenced, meaning each person who handles personal data needs their own completed training record. A single trained data lead cannot substitute for awareness training across the rest of the team, since most breaches (like misdirected emails) come from everyday handling, not specialist data roles.