Charities – are you aware of your data protection obligations?

Wake Smith Solicitors 17 April 2018

As part of the data protection reform coming into effect from 25 May this year there will be new notification and registration procedures.

It is important that all organisations check the requirements and the fees payable.

At the recent Data Protection Practitioners conference the Information Commissioners Office (ICO) was keen to ensure that charities were aware of their obligations.

Holly Dobson, solicitor at Wake Smith Solicitors, looks at the ramifications for charities and GDPR.

“It is important to be clear about the notification and provision of information required to the ICO under GDPR as some charities can benefit from a reduced fee or be wholly exempt from the charges.

“Unless the ICO is likely to know from information it already holds that an organisation is a charity, or a charity provides information to the ICO to evidence its charitable, there is a default annual fee of £2,900.”

GDPR was designed to end big business’ complacency with regards to safeguarding our personal information. The legislation’s potential high penalties for poor data protection practices means these establishments will be forced to take data protection more seriously.

Holly added: “However, for charities and small businesses, the GDPR has brought a hefty new piece of legislation to comply with.

“Now every organisation, whether it is a small business, one-man-band, charity or voluntary organisation, that holds data on its customers, irrespective of its size, must abide by its rules.

“Under the GDPR, they have to provide evidence for every contact on their lists to prove opt-in status. Obviously, many charities, who gain supporters information from a variety of sources, will struggle to provide this information for a large proportion of their database.

“If the charity cannot determine how everyone on the list came to be there, they will have to seek their re-approval. If only half of respondents reply, under GDPR, they may have to delete half of their database. This has serious ramifications for charitable funding and for the knock-on effect this will have on the lives the charity supports.

“A potential solution for the opt-in dilemma faced by charities is the Legitimate Interest provision in the GDPR.

“Charities can refer to Legitimate Interest as a lawful basis of processing to the extent that such activity is necessary (for the purpose of the Controller’s or a Third Party’s Legitimate Interests).

“So, in theory, a charity can use Legitimate Interest to make the case that maintaining a database of donors for fundraising purposes is a necessary activity for them.

“This may serve as a workaround for the opt-in requirement, however, since this is still a grey area, I would advise charities continue to offer the ability for donors to opt out at every opportunity.”

The ICO has offered the following recommendations for charities, giving guidance on the minimum expected from them under the GDPR:

  • Tell people what you are doing with their data and who it will be shared with
  • Make sure your staff are adequately trained on how to store and handle personal information
  • Use strong passwords (we would recommend always using a random password generator)
  • Encrypt all portable devices such as memory sticks and laptops
  • Only keep people’s information for as long as necessary

For further advice on GDPR  contact Holly Dobson at Wake Smith Solicitors on 0114 266 6660 or at [email protected]

Tags

Archive

April 20241March 20247February 20242January 20248December 20236November 20232October 20235September 20232August 20234July 20232June 20235May 20238March 20234February 20235January 20233December 20225November 20224October 20224September 20223August 20221June 20221May 20227April 20223March 20223February 20223January 20224December 20214November 20213October 20215September 20216August 20212July 202111June 20218May 20216April 20212March 20218February 20218January 20219December 20208November 202013October 20209September 20208August 20203July 20208June 202016May 202013April 20209March 202016February 20209January 202011December 20199November 20199October 201911September 20195August 20194July 20196May 20198April 20196March 20193February 20195January 20194December 20186November 20185October 20182September 20185August 20184July 20189June 20184May 201810April 20185March 20184February 20184January 20183December 20175November 20178October 20177September 20179August 20175July 20176June 201710May 20176April 20178March 201711February 20176January 201712December 20169November 20167October 201610September 201610August 20166July 20167June 20163May 20162April 20166March 20162February 20164January 20165December 20153November 20155October 20156September 20156August 20157July 20157June 20157May 20156April 20159March 20156February 201510January 20156December 20145November 20144October 20142September 20143May 20144March 20146February 20144January 20142December 20132November 20133September 20134July 20132June 20132May 20133April 20131March 20133February 20133January 20136December 20121November 20123October 20122August 20122July 20128June 20123April 20123March 20121January 20124December 20112November 20111October 20112September 20113August 20113July 20117June 20119May 20117April 20115March 20119February 20118January 20111December 20101October 20102September 20102August 20103July 20106June 20101May 20102April 20106March 20102February 20103January 20102December 20095November 20092October 20092September 20092August 20091July 20095June 20095May 20093April 20093March 20093February 20091January 20092November 20082October 20082September 20081August 20083July 20081January 20082

Featured Articles

Contact us