Introduction
Data has become one of the most important assets held by non-profit organisations. It extends beyond figures and statistics to include information about beneficiaries, donors, employees, volunteers, and partners, as well as financial and administrative data used for planning, decision-making, and impact measurement.
As charities increasingly adopt digital platforms, donor and beneficiary management systems, applications, field data collection tools, and cloud services, they process larger volumes of information every day. These opportunities also bring greater responsibility to protect data from loss, disclosure, unauthorised access, or use beyond the purpose for which it was collected.
Data protection is not only about regulatory compliance. It is directly connected to trust and the prevention of harm.
A beneficiary who provides information about their social, health, or financial circumstances trusts that this information will not become a source of harm, stigma, or exploitation. A donor who provides personal and financial information expects the organisation to handle it responsibly and securely.
Data protection can therefore no longer be considered the responsibility of the IT Department alone. It is an institutional responsibility involving the Board, executive management, programmes, Human Resources, technology teams, employees, volunteers, and anyone who handles information.
A mature organisation does not wait for a data breach before considering protection. Instead, it asks from the moment a programme or service is designed:
What data do we need? Why do we need it? Who will have access to it? Where will it be stored? How long will we retain it? What could happen to people if it is misused?
This shift—from protecting data after collection to designing programmes around privacy and security from the outset—lies at the heart of modern data protection.
This article explores the principles and practical measures that can help charities protect beneficiary and donor data and manage it responsibly, while preserving the organisation's ability to use information for programme development, decision-making, and impact measurement. It builds upon the original article's framework concerning the data lifecycle, governance, security, and incident response.
First: What Is Personal Data?
Personal data is any information through which an individual can be identified directly or indirectly, whether that information is written, electronic, audio, or visual.
Within charities, this may include:
- Names and identification or residency numbers.
- Telephone numbers, email addresses, and addresses.
- Donor financial information.
- Beneficiary social and economic information.
- Photographs and videos.
- Health and educational information.
- Donation and contribution records.
- Location data where collected.
- Any information that can identify a person when combined with other information.
Not all data carries the same level of risk.
Disclosure of health, financial, or social information—or data relating to a child, displaced person, survivor of violence, or another person in a vulnerable situation—may cause significantly greater harm than disclosure of general information.
A simple principle should therefore guide how organisations handle data:
The greater the potential harm to an individual if their data is disclosed or misused, the stronger the level of protection that should be applied.
Second: Why Has Data Protection Become a Strategic Priority?
Data protection is no longer merely a technical measure for preventing cyberattacks. It has become an indicator of institutional maturity, governance quality, and the organisation's ability to manage risk.
Its importance stems from several factors.
Protecting Data Subjects
The consequences of a breach do not affect the organisation alone. Data exposure can cause direct harm to beneficiaries, donors, employees, or other individuals.
Maintaining Trust
The relationship between a charity and its stakeholders depends heavily upon trust. Failure to protect confidential information may reduce people's willingness to engage with the organisation in the future.
Compliance
Personal data processing is subject to legal requirements that vary according to jurisdiction, the organisation's activities, the type of data involved, and the individuals concerned.
Risk Management
Appropriate controls reduce the likelihood and impact of data leakage, loss, unauthorised alteration, and misuse.
Improving Management Quality
When an organisation understands what data it holds, where it is located, and who is responsible for it, information becomes better organised, more reliable, and more useful for decision-making.
Third: Data Protection and Information Security — Complementary but Different
The terms are sometimes used interchangeably, but there is an important distinction.
Data Protection concerns how personal data is collected, used, shared, retained, and managed, including respect for the rights of individuals and applicable legal requirements.
Information Security, by contrast, focuses on protecting information and systems against unauthorised access, loss, alteration, disclosure, or attack.
An organisation may therefore have highly secure technical systems while still using personal data inappropriately.
Likewise, it may have an excellent Privacy Policy while operating weak technical systems.
A mature framework requires both:
Lawful and responsible use of data + Appropriate organisational and technical protection.
Fourth: Before Collecting Data — Why Do We Need It in the First Place?
One of the most important developments in modern data protection is that the first question is no longer:
How do we protect all the data we have collected?
It begins earlier:
Do we need to collect it at all?
Every category of data should serve a clear and legitimate purpose, and the organisation should identify the appropriate legal or regulatory basis for processing it under the laws applicable to its operations.
Consent may be an appropriate basis in some circumstances. Other processing activities may rely upon a legal obligation, delivery of a service, performance of an agreement, or another basis permitted by applicable law.
Organisations should therefore avoid treating an “I agree” checkbox as an automatic solution for every data-processing activity.
The more important institutional questions are:
Why do we need this data? What allows us to process it? Could we achieve the same purpose using less data?
Fifth: Data Governance — Who Is Responsible for What?
Purchasing security tools alone is not enough to protect data. A charity needs a clear Data Governance framework defining the responsibilities, policies, and procedures governing the information lifecycle.
This includes:
- Defining responsibility and ownership for data.
- Maintaining data quality, accuracy, and currency.
- Classifying data according to sensitivity.
- Defining access permissions.
- Establishing rules for sharing, retention, and disposal.
- Monitoring compliance.
- Periodically reviewing and improving controls.
One of the most practical starting points is creating an inventory of data and processing activities.
In its simplest form, this can be a table answering:
| What do we hold? | Why do we collect it? | Where is it stored? | Who can access it? | Who receives it? | How long do we retain it? |
|---|---|---|---|---|---|
| Beneficiary data | Programme delivery | Beneficiary management system | Authorised team | Defined parties where necessary | According to retention policy |
| Donor data | Donation management and communication | CRM | Authorised employees | Selected service providers | According to purpose and requirements |
The value lies not in the format of the table, but in the organisation's ability to answer a fundamental question:
Where is our data, and who can access it?
Sixth: The Data Lifecycle — Protection from Collection to Disposal
Data passes through several stages within an organisation, each carrying its own risks and controls. The original article addressed this lifecycle from collection and use through sharing, storage, and disposal.
1. Collection
The organisation collects only the information necessary for a clear purpose and explains why it is being collected and how it will be used.
2. Use
Data is used for the defined and legitimate purposes for which it was collected, in accordance with the applicable basis and organisational policies.
3. Sharing
Where sharing is necessary, the principle should be:
Defined Purpose + Minimum Necessary Data + Authorised Recipient + Secure Transfer Method
4. Storage
Information should be stored in an environment appropriate to its sensitivity, whether electronic or physical.
5. Retention
Unlimited storage capacity should not mean indefinite retention.
Organisations need a Retention Schedule defining appropriate retention periods for different categories of records according to legal, contractual, and operational requirements.
6. Disposal
Once there is no longer a legitimate or required reason to retain information, it should be deleted or destroyed in a manner that reduces the possibility of recovery or misuse.
Seventh: Data Minimisation and Privacy by Design
The principle of Data Minimisation means collecting only the minimum amount of information necessary to achieve a defined purpose.
If a programme needs someone's age, does it need their full date of birth?
If it needs to know their area, does it require their complete address?
If a report requires aggregated statistics, does the recipient need beneficiary names?
Questions like these reduce risk before it arises.
This principle is complemented by Privacy by Design and by Default—integrating privacy into the design of programmes, systems, and processes from the beginning rather than adding it later.
When designing a new form, platform, or field programme, the organisation should therefore consider:
Purpose → Required Data → Risks → Access → Sharing → Retention → Deletion
Every piece of information that the organisation never collects is one less piece of information it must protect later.
Eighth: When Is a Deeper Risk Assessment Required?
Some activities carry greater privacy risks than others.
Where a new programme involves large volumes of sensitive data, new technologies, systematic monitoring, or people in particularly vulnerable circumstances, it may be appropriate—or legally required—to conduct a Data Protection Impact Assessment (DPIA) or an equivalent risk assessment.
This should not necessarily be viewed as a complex legal document.
At its core, it asks practical questions:
What data will we process?
↓
Why do we need it?
↓
What could happen if it is misused?
↓
Who could be harmed?
↓
How can we reduce the risks before launch?
Privacy therefore becomes part of programme risk management rather than merely a response after something goes wrong.
Ninth: Transparency and the Rights of Data Subjects
Individuals should be informed clearly and understandably about:
- Why their data is being collected.
- How it will be used.
- Who may access it.
- Whether it will be shared with other parties.
- How long it will be retained.
- How they can contact the organisation about their information.
- What rights are available to them under applicable law.
This information should be presented in language appropriate to the intended audience rather than buried in lengthy legal wording that is difficult to understand.
Organisations should also maintain procedures for responding to data-related requests, such as access, correction, or deletion where such rights apply under the relevant legal framework.
Transparency is therefore not simply a Privacy Policy published on a website. It is reflected in how the organisation interacts with people and handles their information.
Tenth: Data Classification — Not Every File Is Equal
A charity can classify its information into levels appropriate to its operations, for example:
Public Data
Information that can be disclosed without reasonably expected harm.
Internal Data
Information intended primarily for internal organisational use.
Confidential Data
Information whose disclosure may cause harm to the organisation or individuals.
Highly Sensitive Data
This may include certain health, financial, social, beneficiary, and vulnerable-person data.
Classification only becomes useful when it is connected to actual controls:
Who can access the information? Where can it be stored? How can it be transmitted? Does it require encryption? How long should it be retained?
Eleventh: Access to Data — The Least Privilege Necessary to Perform the Role
Employees should not automatically have access to all organisational information simply because they work for the organisation.
The principles of Need to Know and Least Privilege require individuals to receive only the level of access necessary to perform their responsibilities.
Good practices include:
- Assigning access according to role.
- Reviewing permissions periodically.
- Using Multi-Factor Authentication (MFA) for important systems.
- Protecting accounts and devices.
- Logging significant activities in sensitive systems where appropriate.
- Immediately modifying or revoking access when an employee changes role or leaves.
The last point is particularly important.
An account belonging to a former employee that still provides access to the CRM, Google Drive, or beneficiary management system represents a preventable organisational risk.
Twelfth: Physical and Electronic Records Both Require Protection
Many charities continue to use physical records alongside digital systems. Protection should therefore cover both.
Controls for physical records may include:
- Secure storage and locked cabinets.
- Restricted access.
- Controlled borrowing and archiving procedures.
- Preventing sensitive files from being left in public or unattended areas.
- Secure destruction after the applicable retention period.
For electronic information, important controls include:
- Keeping systems and software updated.
- Using MFA.
- Applying encryption where appropriate to the sensitivity and risk.
- Regular backups.
- Device protection.
- Monitoring unusual activity.
- Access control.
One principle is particularly important:
Having a backup does not necessarily mean that the data can actually be restored.
Organisations should therefore test restoration procedures periodically rather than simply confirming that backups have been created.
Thirteenth: Sharing Data with Suppliers and Partners
Charity data rarely remains entirely within the organisation's own systems.
An organisation may use a CRM, cloud services, email and messaging platforms, fundraising systems, programme-management tools, or payment processors.
Whenever a third party processes organisational data, the charity should understand:
- What data will the provider receive?
- Why does the provider need it?
- Where will it be stored?
- What security controls are applied?
- Who can access it?
- Will additional parties process the information?
- What happens to the data when the relationship ends?
Appropriate data protection and security obligations should be documented within contractual arrangements according to the nature of the service and applicable requirements.
Where information is stored or transferred across national borders, organisations should also consider the legal requirements applicable to international data transfers.
Using an external service provider does not remove the organisation's responsibility for information entrusted to it.
Fourteenth: What Happens When a Data Breach Occurs?
No organisation can guarantee that an incident will never happen.
A file may be sent to the wrong recipient, a device may be lost, an account may be compromised, or information may accidentally be shared.
Organisations therefore need a Data Breach / Incident Response Plan that determines in advance:
Who receives the initial report?
Who leads containment?
Who assesses the affected information and individuals?
Who determines applicable legal obligations?
Who is authorised to communicate externally?
When an incident occurs, the response will generally include:
Detection and Reporting
↓
Containment
↓
Assessment of Data and Impact
↓
Incident Documentation
↓
Notification Where Required by Applicable Requirements
↓
Root Cause Analysis
↓
Corrective Action
Practical Example
A field employee accidentally sends a file containing information about hundreds of beneficiaries to a group that was not authorised to receive it.
The response should not end with deleting the message.
The organisation should record the incident, attempt to contain it, determine who may have accessed the file, assess the sensitivity of the information and potential harm, determine whether notification requirements apply, and address the underlying weakness that allowed the file to be shared in this way.
The first objective is not to find someone to blame. It is to protect people, contain the harm, understand the cause, and prevent recurrence.
Fifteenth: People Are Part of the Security Framework
An organisation may invest in sophisticated systems, but a simple human error can bypass many technical controls.
Data protection must therefore become part of everyday organisational behaviour.
This may include:
- Training employees and volunteers.
- Raising awareness of phishing and social engineering.
- Teaching secure methods of sharing files.
- Explaining rules for handling sensitive information.
- Avoiding shared accounts unless necessary and appropriately controlled.
- Providing a clear channel for rapidly reporting errors and incidents.
A punitive culture should not discourage people from reporting incidents.
If an employee is afraid to report a mistake made at 9:00 a.m. and waits until the end of the day, a small and containable incident may become a much larger problem.
Sixteenth: How Do We Know Whether Data Protection Is Improving?
Written policies alone are insufficient. Organisations should monitor a focused set of indicators.
These may include:
- Percentage of personnel completing data protection training.
- Number and causes of data incidents.
- Average time to detect and contain incidents.
- Percentage of access permissions reviewed.
- Compliance with retention and disposal schedules.
- Percentage of critical systems protected by MFA.
- Results of data protection and security reviews.
- Percentage of corrective actions completed.
An increase in recorded incidents does not necessarily mean that the organisation has become less secure. It may sometimes indicate that the reporting culture has improved.
Indicators should therefore be interpreted in context rather than viewed as isolated numbers.
Seventeenth: How Can a Donor Know That a Charity Actually Protects Data?
During an institutional assessment, it is not enough for an organisation to state:
“We respect the privacy of our beneficiaries.”
A donor or partner may look for practical evidence such as:
- Data Protection and Privacy Policies.
- Data and processing inventories.
- Data classification arrangements.
- Retention Schedules.
- Access-control matrices.
- Procedures for granting and revoking access.
- Data Breach / Incident Response Plans.
- Incident logs and corrective actions.
- Staff training records.
- Backup and restoration controls.
- Data protection arrangements with service providers.
- Secure disposal procedures.
- Risk assessments or DPIAs where appropriate.
This demonstrates the difference between an organisation that has a Privacy Policy published on its website and one that operates an evidenced data protection system in practice.
The latter is what strengthens institutional readiness and donor confidence.
Eighteenth: Data Protection and Governance — Protecting Trust Before Protecting Files
Data protection is closely connected to governance because it reflects how an organisation exercises accountability, manages risk, and respects the rights of stakeholders.
A charity that manages data effectively can:
- Strengthen beneficiary and donor trust.
- Improve information quality and decision-making.
- Reduce legal and operational risks.
- Protect its reputation.
- Strengthen relationships with partners.
- Improve readiness for institutional assessments and donor requirements.
The ultimate objective, however, goes beyond compliance.
Much of the information held by charities does not belong to the organisation in any meaningful ethical sense. It consists of information that real people have entrusted to the organisation.
Protecting data therefore means protecting those people before protecting the database itself.
Before Moving to the Next Article...
A charity does not need to begin with a large cybersecurity programme.
It can start by:
✓ Identifying what data it holds and where it is stored.
✓ Defining why each type of data is collected.
✓ Removing unnecessary fields from forms.
✓ Classifying data according to sensitivity.
✓ Defining who genuinely needs access.
✓ Enabling MFA on important systems.
✓ Reviewing user permissions periodically.
✓ Establishing retention and disposal periods.
✓ Reviewing service providers that process organisational data.
✓ Preparing a clear Incident Response Plan.
✓ Training employees and volunteers on data protection.
✓ Testing backup restoration procedures.
Quick Self-Assessment
Ask yourself:
□ Do we know where all beneficiary and donor data is stored?
□ Can we explain why each piece of information we request is necessary?
□ Do we know the appropriate basis for processing the data?
□ Do we collect only the minimum data necessary?
□ Do we know who can access each category of information?
□ Do we know all external parties that receive or process our data?
□ Is there a clear retention period for important categories of records?
□ Are employee access rights revoked immediately when they leave?
□ Are sensitive systems protected with MFA and appropriate access controls?
□ Have we tested whether our backups can actually be restored?
□ Do employees know what to do if they accidentally send sensitive information to the wrong person?
□ Do we have a documented Incident Response Plan?
□ Could we provide evidence of these controls if requested by a donor?
If the answer is “No” to several of these questions, the organisation should not begin by purchasing additional security tools.
It should first understand what data it holds, why it holds it, where it is stored, who can access it, and what harm could occur if it were misused.
Conclusion
Data has become one of the most valuable resources available to non-profit organisations. It supports programme design, needs assessment, donor relationship management, impact measurement, and informed decision-making. The original article correctly positioned this responsibility as part of governance, trust, and institutional sustainability rather than as an isolated technical responsibility.
But the value created by data carries an equivalent responsibility.
Every piece of information collected by an organisation should have a justifiable purpose. The organisation should be capable of protecting it, controlling access to it, managing it throughout its lifecycle, and securely disposing of it when there is no longer a legitimate need to retain it.
A mature organisation therefore does not measure data protection success only by the number of breaches that have not occurred. It measures maturity by its ability to demonstrate that privacy and security have become part of programme design, organisational decision-making, systems, and everyday staff behaviour.
This begins with simple questions:
Do we need this data?
Have we clearly explained to the individual what we will do with it?
Can only those who need it access it?
Are we protecting it according to the level of harm that disclosure could cause?
And do we know what to do when something goes wrong?
When a charity can answer these questions through clear procedures and documented evidence, data protection moves beyond a written policy and becomes an institutional system for protecting people, trust, and reputation.
In the non-profit sector, where beneficiaries and donors provide information to organisations on the basis of trust, protecting data is not merely a technical or legal obligation.
It is part of the duty of care and responsibility an organisation assumes toward every person who entrusts it with their information.