GDPR preparation for charities

GDPR preparation for charities

There has been an overwhelming amount of research and surveys undertaken that are all reaching the same conclusion - the vast majority of organisations have not started to put the necessary steps and procedures in place in preparation for the launch of the General Data Protection Regulation (GDPR). With under a year to go, organisations should be thinking now about implementing the appropriate compliance updates to their current data protection and acquisition strategies to ensure they are 100% ready in time for when the 25th May 2018 rolls around.

According to the Information Commissioners Office (ICO), failure to comply will result in fines up to £17million or 4% of the annual turnover - whichever the organisation would consider most severe. In direct comparison, under the current Data Protection Act which GDPR is replacing, the absolute maximum fine is £500,000. This alone is clear indication that GDPR will involve a stricter approach in regards to data protection. 

It is also important to note that charities are not exempt from historical or future data legislation, with equally heavy fines in place for those who seriously breach this new piece of legislation.

In the last year alone, we saw 13 charities identified by ICO with £181,000 worth of fines being amassed for breaching the current Data Protection Act. Household names such as Cancer Research UK, Macmillan Cancer Support and Oxfam were amongst those charged:

  • Both Cancer Research UK and Macmillan Cancer Support were found guilty of profiling their donors based on wealth without their consent. For instance, between 2010-2016, Cancer Research UK managed to capture the wealth data of 3,523,566 individual donors. And in 2014 Macmillan Cancer Support wealth screened 2,188,508 individuals. The most obvious reason for practicing this would be to source the most valuable donors to target for their respective causes. According to the ICO, another motivator for this practice would to seek out those who would be likely to leave donations in their will. 
  • Beyond that, all 3 of the charities also sourced additional data on their donors that they did not provide themselves to strengthen their donor databases. This is categorised as a breach as the donor did not have the opportunity to select what exact data they wanted to give away. This data could be used as another direct contact avenue to ask for more donations.

The key takeaway here is that charities remain accountable under the new legislation. In light of these offences and the sheer number of investigations conducted, it can be assumed that ICO will be keeping a watchful eye over charities and scrutinising their future data protection competencies.

Back in February of this year, the Fundraising Regulator and the Charity Commission released a consent guidance document which stated that:

Charities must have a clear understanding of the basis on which they will justify their collection and use of personal information for their direct marketing purposes…communications should include a mechanism to withdraw consent easily at any time."

ICO does advocate that an ‘opt-in’ feature is the best and safest way forward for both charities and businesses alike. Many charities and private sector organisations are relying on ‘legitimate interests’ clauses, however this does not prove that the data itself was gathered in a lawful way. If consent is not actively received then charitable organisations cannot assume it has been given, noting that a previous donation is not considered consent. Ultimately, changing the ways in which charities collect and use a donor’s personal information, including in any direct marketing approaches.

To avoid a repeat of the ICO charity investigations and subsequent fines, we recommend that all businesses start auditing their current data protection and acquisition procedures and consider seeking out expert assistance to guarantee GDPR compliance.

Here at French Duncan, we can help simplify and strengthen your knowledge surrounding the changes in legislation.

To learn more about how French Duncan could help or to arrange a free consultation, visit here.


要查看或添加评论,请登录

Andrew Guy的更多文章

  • FD Intelligence - review of 2022

    FD Intelligence - review of 2022

    Last year was a momentous one for FD Intelligence, as we reached several major milestones that we are extremely proud…

    5 条评论
  • SMEs unclear which way to turn on fraud

    SMEs unclear which way to turn on fraud

    A common theme of cybercrime is that victims of online fraud, such as online money transfer fraud, often struggle to…

    1 条评论
  • GDPR – The importance of accountability

    GDPR – The importance of accountability

    GDPR will affect every aspect of business, from operations to sales, marketing and your supply chain. Nothing will be…

  • GDPR – What does it mean for SMEs and how do you prepare?

    GDPR – What does it mean for SMEs and how do you prepare?

    The General Data Protection Regulations will be implemented on the 25th of May 2018. These regulations will have a huge…

    1 条评论
  • The importance of GDPR compliance within the hotel industry

    The importance of GDPR compliance within the hotel industry

    An investigation by Verizon noted that the hotel industry is extraordinarily appealing to would be hackers, due to the…

    1 条评论
  • GDPR - how to be prepared

    GDPR - how to be prepared

    It is less than nine months until the new GDPR rules come in to effect – that may sound like a long time but it will be…

  • Six Data Processing Principles of GDPR

    Six Data Processing Principles of GDPR

    The six data processing principles set out the fundamental conditions for collecting, processing and managing personal…

    3 条评论

社区洞察

其他会员也浏览了