IT & Cyber Security Compliance Guide for Charities
Charities hold supporter and beneficiary data, handle donations, and often rely on volunteers, shared devices and tight budgets. Criminals know it, and funders and regulators increasingly expect charities to take cyber security seriously.
Trustees are responsible
Trustees carry responsibility for protecting the charity's assets, data and reputation, and that includes managing cyber risk proportionately. You don't need enterprise tooling, but you do need to be able to show you've taken sensible, documented steps.
Serious incidents and reporting
The Charity Commission expects trustees to report serious incidents, which can include significant fraud, theft or loss of funds and data, and cyber crime that has a material impact. Having an incident plan in place means you can recognise and report these quickly.
Supporter data, UK GDPR and fundraising
Charities are data controllers for supporter, donor, volunteer and beneficiary data. That brings duties to keep it secure, hold it lawfully, and report notifiable breaches to the ICO within 72 hours. Separate rules apply to electronic marketing and fundraising communications, so check consent and preferences carefully.
Volunteers, shared devices and funders
- Give volunteers their own accounts with only the access they need, and remove it when they leave.
- Avoid shared logins and unmanaged personal devices holding supporter data.
- Many funders and local authorities now ask for Cyber Essentials, so certification can unlock grants and contracts.
- Eligible charities may be able to access discounted or donated Microsoft licences through Microsoft's nonprofit programme, subject to its eligibility rules.
Your practical checklist
- Multi-factor authentication on email, donor databases and finance systems
- Individual accounts for staff and volunteers, with prompt removal on leaving
- Backups of donor, finance and case data, with restores tested
- Endpoint protection and automatic updates on every device
- Phishing and fraud awareness for staff and trustees, including fake payment requests
- A basic written incident plan, including who decides whether to report to the Charity Commission
- Clear consent records for fundraising communications
- Secure disposal of old devices and records
- A trustee-level review of cyber risk at least annually
- Cyber Essentials certification where funders or partners expect it
Go to the source
- Charity Commission
Regulates charities in England and Wales, including serious incident reporting.
- NCSC Small Charity Guide
Free, practical cyber security guidance written for small charities.
- Information Commissioner's Office (ICO)
UK GDPR, data protection and electronic marketing rules.
This guide is general information, not legal advice. Requirements change and depend on your circumstances, so check with your regulator or professional adviser.
Want your IT to stand up to scrutiny?
We help regulated firms put the right controls in place and keep the evidence ready.