Charity data protection self-check checklist
How to use this: review each item and act on any gap. This is a starting review; for legal specifics, check ICO guidance or take advice.
Charities pay the ICO’s Tier 1 data protection fee — £52 a year, or £47 by direct debit — regardless of size, unless exempt (Source: ICO, “Data protection fee”, ico.org.uk, accessed 10 July 2026).
What data you hold
- [ ] You know what personal data you hold, whose, and why (beneficiaries, donors, volunteers, staff).
- [ ] You have identified any sensitive (special category) data and the extra care it needs.
- [ ] You have a lawful basis for the data you process. [CHECK against ICO guidance]
Registration and policy
- [ ] Registered with the ICO and data protection fee paid, unless exempt.
- [ ] A data protection / privacy policy in place and current.
- [ ] Someone responsible for data protection named.
Keeping data safe
- [ ] Access limited to those who need it; strong passwords and two-factor authentication.
- [ ] Devices encrypted; paper records secured.
- [ ] Retention periods set — you do not keep data longer than needed.
- [ ] Care taken before putting personal data into any external tool, including AI.
Rights and breaches
- [ ] You know how to handle a request from someone to see or delete their data.
- [ ] You know the duty to report certain breaches to the ICO within 72 hours.
- [ ] You record all breaches, even those not reported.