Short answer: somewhere in your charity - probably in a spreadsheet, a shoebox, or three different people's inboxes - sits a list of the people who trust you most: their names, their emails, how much they have given, maybe a note about a difficult conversation. That list is one of your most valuable assets and one of your biggest responsibilities, because every name on it belongs to a real person who trusted you with their details. Data protection can sound like a wall of jargon and legal threats, but at its heart it is something a charity already believes in - treating people with respect. This guide makes donor data and privacy, including the ideas behind laws like the PDPA, simple and doable for a charity with no legal team and not much time. We will cover what counts as personal data, the handful of principles that really matter, how to get consent properly, and what to do when something goes wrong.
Why donor data is really a matter of trust
Start with why this matters, because if you see data protection only as red tape you will always resent it, whereas if you see it as trust you will get it right naturally. When someone gives you their name, their email, or their card details, they are handing you a small piece of themselves and trusting you to look after it, and how you treat that trust shapes your whole relationship. A donor who feels respected - never spammed, sold on, or surprised by how you use their data - gives again and tells their friends, while one who feels their privacy was handled carelessly walks away and rarely comes back. Good data practice is not a burden bolted onto fundraising; it is fundraising, the quiet, everyday keeping of a promise, and it quietly underwrites donor retention. Protect people's data as you would protect their goodwill, because in the end they are the same thing.
What actually counts as personal data
Before you can protect personal data you need to know what it is, and the definition is broader than most people expect. Personal data is simply any information that can identify a living person, so it is not just names and addresses but emails, phone numbers, donation history, photographs, and even a note you jotted about someone's circumstances. Some of it is more sensitive than the rest - details about someone's health, their beliefs, or their finances deserve extra care, because misuse could genuinely harm them. The useful habit is to look at everything you hold about your supporters and beneficiaries and ask: could this identify a real person, and if so, it deserves protection. Once you see how much personal data quietly flows through even a charity - in forms, emails, and spreadsheets - you understand why a little care matters so much.
The few principles that really matter
Data protection law can look enormous, but underneath it sits a handful of common-sense principles you can actually remember. Be fair and open, so people know what you are doing with their data and are not surprised by it. Have a clear reason for holding what you hold, and do not gather things just in case. Keep it accurate, keep it only as long as you genuinely need it, and keep it secure. And respect people's rights over their own information, including the right to see it, correct it, and ask you to stop. That is the spirit of laws like the PDPA in plain English - not a maze of clauses but a short list of decent behaviours. Get these few principles into your bones and most of the detail takes care of itself, because you will be doing the right thing by instinct rather than by rulebook.
Get consent the honest way
Consent is where many charities trip up, so let us make it simple: real consent is a clear, freely given yes, not a pre-ticked box or an assumption. When you collect someone's details, tell them plainly what you will use them for and how they can change their mind. If you want to email them your newsletter and appeals - which matters every time you grow your email list - ask them, rather than quietly adding them because they once bought a raffle ticket. Keep a record of what people agreed to and when, so you are never guessing, and remember that consent is not forever: people can withdraw it, so make that easy and honour it quickly. Honest consent may shorten your mailing list at first, but the people who remain actually want to hear from you, and a smaller list of willing supporters is worth far more than a big one full of people quietly resenting you.
Collect only what you truly need
There is a quiet temptation, when you build a form, to ask for everything you can imagine ever wanting, but the wiser rule is the opposite: collect only what you truly need right now. Every extra field is another piece of data you must protect, keep accurate, and one day delete, so more is not safer - more is more risk. Before adding a question to a form, ask whether you genuinely need that information to do the task in front of you, and if not, leave it off. This restraint protects your supporters, because data you never collected can never be lost or misused, and it protects you, because a lean, purposeful set of data is far easier to look after than a bloated one. When it comes to personal data, the safest information is the information you chose not to gather in the first place.
Keep it accurate, tidy, and secure
Data is not a thing you collect once and forget - it decays, as people move, change email, change name, or sadly pass away - so part of protecting it is simply keeping it accurate and tidy. Wrong data is not harmless: it means letters to the wrong address, a painful appeal sent to someone recently bereaved, or a donor annoyed by mistakes that suggest carelessness. Build gentle habits of updating records when people tell you things have changed, and clean your list every so often, correcting what is wrong and removing what you no longer need - the same tidy discipline that sits behind a well-kept simple donor database. Then keep it safe, which for a charity is mostly about sensible habits rather than expensive technology: strong, unique passwords and two-factor login, limiting who can see what, being careful with that innocent-looking spreadsheet emailed around or left on a personal laptop, and locking away paper records. A culture of care protects your supporters better than any single fancy tool.
Make it easy to opt out
A supporter's right to say stop is not an inconvenience to be buried; it is a promise to be honoured cheerfully, so make opting out genuinely easy. Every marketing email should carry a clear, working unsubscribe link, and if someone asks by phone or in person to be taken off your list, act on it promptly and completely - across every list, not just the one they happened to mention. Resist any temptation to make leaving difficult, because a supporter forced to fight their way out remembers the fight, not the cause. Honouring opt-outs quickly and gracefully actually protects your reputation, showing that you respect people even when they step back, and people who leave feeling respected sometimes return, while those who leave feeling trapped tell everyone. Let people go easily, and you keep their goodwill even as you lose their subscription.
Have a plan for when it goes wrong
Even careful charities have accidents - an email sent to the wrong person, a lost laptop, a spreadsheet shared too widely - so do not wait for the moment to happen before you think about it. Decide in advance who to tell inside your charity, how you will contain the problem, and how you will judge whether it is serious enough to report to the authorities or the people affected, because some breaches must be disclosed, and quickly. Keep a simple note of what happened and what you did, both to learn from it and to show you took it seriously. Above all, do not panic or hide it, because a breach handled honestly and promptly does far less damage than one covered up and discovered later. Knowing roughly what you would do turns a frightening emergency into a manageable, if uncomfortable, procedure you can follow calmly.
Write one simple policy and name an owner
You do not need a thick legal manual, but you do need two simple things: a short written policy and one person who owns this. A one or two page policy, in plain language, that says what data you collect, why, how you protect it, how long you keep it, and how people can exercise their rights, is enough for most charities and worth its weight in calm. Then name someone - even a volunteer - as the person responsible for data protection, not because they must be an expert, but because when something is everyone's job it is nobody's. That person keeps an eye on your habits, answers supporters' questions, and makes sure promises are kept. With a simple policy written down and one clear owner, data protection stops being a vague worry hanging over everyone and becomes a normal, manageable part of how your charity runs.
Frequently asked questions
What counts as personal data for a charity?
More than most people expect. Personal data is any information that can identify a living person, so it covers names, addresses, emails, phone numbers, donation history, photographs, and even a note you jotted about someone's circumstances. Some of it is more sensitive - details about health, beliefs, or finances - and deserves extra care, because misuse could genuinely harm someone. The simplest test is to look at anything you hold about a supporter or beneficiary and ask whether it could identify a real person; if it could, it deserves protection. Once you notice how much personal data flows through even a charity, in forms and emails and spreadsheets, the case for a little care becomes obvious.
How do we get donor consent properly?
Real consent is a clear, freely given yes, not a pre-ticked box or a quiet assumption. When you collect someone's details, tell them plainly what you will use them for and how they can change their mind, and if you want to send newsletters and appeals, actually ask rather than adding people because they once interacted with you. Keep a record of what each person agreed to and when, so you are never guessing later. And treat consent as something people can withdraw at any time - make that easy and honour it quickly. Honest consent may shorten your list at first, but the people who stay genuinely want to hear from you, which is worth far more.
Does a charity really need a data protection policy?
A short one, yes - but it need not be a thick legal manual. A plain-language page or two covering what data you collect, why, how you protect it, how long you keep it, and how people can exercise their rights is enough for most charities. Just as important is naming one person - even a volunteer - as the owner, because when data protection is everyone's job it quietly becomes nobody's. That person watches your habits, answers supporters' questions, and keeps the promises the policy makes. Together, a simple written policy and one clear owner turn a vague worry into a normal, manageable part of how you run.
What should we do if data is lost or leaked?
Do not panic, and do not hide it. Decide in advance who to tell inside your charity, how you will contain the problem, and how you will judge whether it is serious enough to report to the authorities or the people affected - because some breaches must be disclosed, and quickly. Keep a simple note of what happened and what you did, both to learn from it and to show you took it seriously. A breach handled honestly and promptly does far less damage than one covered up and discovered later. This is educational guidance only, and reporting duties differ by country and change over time, so check the rules that apply to you and seek proper advice where appropriate.
Want a free look at your charity's online presence?
We'll review how your charity shows up online — your site, your search visibility, and where donations leak away — and send you a plain, practical plan. No cost, no obligation.
Get my free analysis →Educational only. This channel is not affiliated with or endorsed by any platform, tool, agency, or program, and nothing here is legal, data-protection, privacy, or compliance advice. Requirements around personal data, consent, the PDPA and other data-protection laws, breach reporting, and marketing contact differ by country and change over time, so verify the current requirements with the official source, and seek proper advice where appropriate, before you rely on them. Because every charity and donor is different, results vary and nothing here is guaranteed.
