Charity data protection self-check checklist

How to use this: review each item and act on any gap. This is a starting review; for legal specifics, check ICO guidance or take advice.

Charities pay the ICO’s Tier 1 data protection fee — £52 a year, or £47 by direct debit — regardless of size, unless exempt (Source: ICO, “Data protection fee”, ico.org.uk, accessed 10 July 2026).

What data you hold

  • [ ] You know what personal data you hold, whose, and why (beneficiaries, donors, volunteers, staff).
  • [ ] You have identified any sensitive (special category) data and the extra care it needs.
  • [ ] You have a lawful basis for the data you process. [CHECK against ICO guidance]

Registration and policy

  • [ ] Registered with the ICO and data protection fee paid, unless exempt.
  • [ ] A data protection / privacy policy in place and current.
  • [ ] Someone responsible for data protection named.

Keeping data safe

  • [ ] Access limited to those who need it; strong passwords and two-factor authentication.
  • [ ] Devices encrypted; paper records secured.
  • [ ] Retention periods set — you do not keep data longer than needed.
  • [ ] Care taken before putting personal data into any external tool, including AI.

Rights and breaches

  • [ ] You know how to handle a request from someone to see or delete their data.
  • [ ] You know the duty to report certain breaches to the ICO within 72 hours.
  • [ ] You record all breaches, even those not reported.