top of page
Search

GDPR Guidance for Charities and CIOs

  • OASIS Blogger
  • Aug 14
  • 7 min read
Brass padlock securing a door.

Everyone responsible for using personal data has to follow strict rules called ‘data protection principles’ unless an exemption applies.


Data protection legislation controls how personal information is used by organisations, including businesses, government departments, charities and other organisations.

In the UK, data protection is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


In this guidance, we address frequently asked questions about GDPR for charities and CIO's using OASIS for case management.




Disclaimer


The answers below are intended as general guidance only and should not be relied upon as legal advice. IT Works (Scotland) Ltd cannot provide legal advice. Charities and CIOs should seek independent professional advice where necessary.


This guidance is based on Information Commissioner's Office (ICO) guidance and Gov.UK resources relating to UK GDPR, data protection, accountability, information sharing and individual rights.




1. Does UK GDPR apply to charities and CIOs?


Yes. UK GDPR applies to organisations that process personal data about living individuals, regardless of their size. This includes charities, CIOs, voluntary organisations and community groups that hold information about beneficiaries, supporters, volunteers, employees or other individuals.


Organisations must comply with the data protection principles and be able to demonstrate accountability.



2. What is personal data?


Personal data is information relating to an identified or identifiable living individual. In a charity setting this may include information about:


  • beneficiaries

  • volunteers

  • trustees

  • supporters

  • contractors

  • employees



Examples include:


  • names

  • addresses

  • telephone numbers

  • email addresses

  • beneficiary records

  • volunteer details

  • employment records

  • payroll information

  • case notes - where an individual can be identified directly or indirectly.



3. Is information stored in OASIS covered by UK GDPR?


Where information held in OASIS relates to identifiable living individuals, it is personal data and UK GDPR applies. Depending on the services provided by the charity, OASIS may also contain special category data that requires additional protection and safeguards.



4. Do charities always need consent to collect or share information?


No. The ICO makes clear that consent is only one of six lawful bases for processing personal data. Many charities rely on other lawful bases depending on the purpose of processing.


Organisations should identify the most appropriate lawful basis before processing personal data and document their decision.



5. Can a charity share information without consent?


Yes, in some circumstances. The ICO explains that information can be shared where there is an appropriate lawful basis for processing. Depending on the circumstances, this may include contract, legal obligation or legitimate interests.


Information sharing should be:


  • necessary

  • proportionate

  • transparent

  • appropriately documented



6. What is a lawful basis?


A lawful basis is the reason recognised under UK GDPR for processing personal data. ICO guidance includes lawful bases such as:


  • Consent

  • Contract

  • Legal obligation

  • Legitimate interests

  • Vital interests

  • Public task


Charities should identify and record the lawful basis that applies before collecting or using personal data.



7. What are legitimate interests?


Legitimate interests may be appropriate where processing is necessary for the organisation's legitimate purposes and those interests are not overridden by the rights and freedoms of the individual.


The ICO describes this as a balancing exercise that takes account of the impact on the individual and what they would reasonably expect.


Organisations relying on legitimate interests should document their assessment.



8. What is special category data?


Special category data is personal data that requires extra protection because it is particularly sensitive. ICO guidance includes information such as:


  • Health information

  • Ethnic origin

  • Religious or philosophical beliefs

  • Political opinions

  • Trade union membership

  • Genetic data

  • Biometric data used for identification

  • Sexual orientation


Charities and CIOs may process special category data relating to both service users and employees. For example, HR records may contain information about health conditions, occupational health support, equality monitoring, or trade union membership.


Additional conditions and safeguards are required when processing this information.



9. Can safeguarding information be recorded in OASIS?


Yes. Where safeguarding information is necessary for providing support, protecting individuals or meeting safeguarding responsibilities, charities may need to process and record such information.


Organisations should ensure they identify the appropriate lawful basis, apply suitable access controls, and follow their information governance procedures. The ICO also provides guidance on data sharing for safeguarding purposes.



10. How much information should we collect?


The data minimisation principle requires organisations to collect only the personal data that is necessary for their specified purpose.


Charities should ensure information collected through OASIS is relevant, adequate and limited to what is needed for service delivery, safeguarding, reporting or other identified purposes.



11. How long should we keep records in OASIS?


The ICO does not prescribe a single retention period for all records. Retention periods should reflect the purpose for which information was collected and any legal, regulatory, operational or safeguarding requirements that apply.


Charities should maintain documented retention and disposal procedures.



12. Can we keep information indefinitely?


Generally, no. The storage limitation principle requires organisations to keep personal data only for as long as necessary for the purpose for which it was collected.


When information is no longer needed, it should be securely deleted or anonymised in accordance with organisational policies.



13. What should staff be able to see?


Access to information should be restricted according to business need and role responsibilities. This is particularly important where OASIS contains sensitive, safeguarding or special category data.


Appropriate security measures and governance controls should help ensure that only authorised individuals have access to relevant information.



14. What happens if someone asks to see their information?


Individuals have rights under UK GDPR, including the right to access their personal data through a Subject Access Request (SAR).


Charities should have procedures in place to recognise, manage and respond to requests within the applicable legal timescales.



15. Do we need a privacy notice?


Yes. The ICO advises organisations to be transparent about how they use personal data. Privacy information should explain what information is collected, why it is used, the lawful basis relied upon, who it may be shared with, how long it is retained and the rights available to individuals.


Many charities and CIOs choose to provide separate privacy notices for different groups, such as beneficiaries, volunteers, donors, trustees and employees, reflecting the different purposes for which information is processed.



16. What employee information can charities and CIOs keep?


Charities and CIOs acting as employers will usually need to process personal data about their staff to meet employment, payroll, health and safety, pension and legal obligations.


Examples of employee information that organisations commonly hold include:


  • Name and contact details

  • Date of birth

  • National Insurance number

  • Tax and payroll information

  • Qualifications and employment history

  • Employment contract detail

  • Pay, benefits and working hours

  • Holiday and absence records

  • Training records

  • Health and safety incident records

  • Disciplinary and performance records

  • Emergency contact details


Some employment records may contain special category data, such as health information, ethnicity, religion, trade union membership or biometric information used for identification purposes. Where this applies, charities should ensure they have an appropriate lawful basis and condition for processing and apply suitable security measures.


Organisations should only collect information that is necessary, keep it accurate, restrict access to those who need it, and retain it only for as long as it is required.

Employees also have data protection rights, including the right to request access to their personal data held by the organisation. Charities and organisations should have processes in place to recognise and respond to these Subject Access Requests (SARs)



17. How should we handle special category data?


Special category data is personal data that is particularly sensitive and requires additional protection. This includes information about:


  • Health or medical conditions

  • Mental health and wellbeing

  • Racial or ethnic origin

  • Religious or philosophical beliefs

  • Political opinions

  • Trade union membership

  • Genetic data

  • Biometric data used for identification

  • Sexual orientation


Many charities process special category data as part of supporting beneficiaries, delivering services, safeguarding individuals, managing employees, or meeting equality and inclusion obligations.



When handling special category data, charities and CIOs should:


  • Be clear about why the information is needed.

  • Identify a lawful basis for processing personal data.

  • Identify an additional condition for processing special category data.

  • Collect only the information that is necessary.

  • Restrict access to staff and volunteers who need it for their role.

  • Apply appropriate security measures to protect the information.

  • Keep the information accurate and up to date.

  • Retain it only for as long as necessary.

  • Ensure staff understand their confidentiality and data protection responsibilities.



Where special category data is recorded in OASIS, organisations should consider using role-based access controls, follow their retention policies, and ensure appropriate governance and accountability arrangements are in place.


Using OASIS can support secure information management, but responsibility for compliance remains with the charity or CIO as the data controller.


Special category data often arises in charity settings through case notes, support plans, safeguarding records, disability information, occupational health records, equality monitoring, and other information needed to provide services or manage employment relationships.


Because this information is particularly sensitive, organisations should take extra care before collecting, sharing or disclosing it.



18. Is OASIS automatically UK GDPR compliant?


Using OASIS supports good information management, but responsibility for compliance always remains with the charity or CIO using the system. The ICO's accountability principle requires organisations to demonstrate compliance through appropriate governance, policies, procedures, staff training, security measures and record keeping.



19. What are the biggest data protection risks for charities?


Examples of risks highlighted by ICO guidance include:


  • Collecting more information than is necessary

  • Keeping information for longer than required

  • Inadequate staff training

  • Unauthorised access to beneficiary or employee records

  • Failure to identify and document a lawful basis

  • Weak security arrangements

  • Improper handling of special category data relating to service users or staff

  • Poor governance and accountability processes


Charities should regularly review their information governance arrangements for both service-user and employee data and ensure appropriate technical and organisational measures are in place to protect personal information.


OASIS users are not only managing beneficiary and casework data, but may also be responsible for employee records, which are subject to the same UK GDPR principles around lawfulness, transparency, minimisation, security, retention and individual rights.



20. Where can charities and CIOs get official data protection guidance?


The ICO provides free guidance and resources covering:


  • UK GDPR compliance

  • Lawful bases for processing

  • Special category data

  • Subject Access Requests

  • Individual rights

  • Data sharing

  • Information security

  • Accountability and governance

  • Privacy notices

  • Safeguarding-related information sharing



Further information for smaller organisations is available at: Advice for small and medium organisations | ICO



OASIS is a case management and information recording system. Whether your charity or CIO complies with UK GDPR depends on how your organisation collects, uses, shares, secures and manages personal data - together with its policies, procedures and governance arrangements.

Accountability for compliance always rests with the charity or organisation acting as the data controller.



 
 
bottom of page