GDPR Guidance for Charities and CIOs
- OASIS Blogger
- Aug 14
- 7 min read

Everyone responsible for using personal data has to follow strict rules called ‘data protection principles’ unless an exemption applies.
Data protection legislation controls how personal information is used by organisations, including businesses, government departments, charities and other organisations.
In the UK, data protection is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
In this guidance, we address frequently asked questions about GDPR for charities and CIO's using OASIS for case management.
Disclaimer
The answers below are intended as general guidance only and should not be relied upon as legal advice. IT Works (Scotland) Ltd cannot provide legal advice. Charities and CIOs should seek independent professional advice where necessary.
This guidance is based on Information Commissioner's Office (ICO) guidance and Gov.UK resources relating to UK GDPR, data protection, accountability, information sharing and individual rights.
1. Does UK GDPR apply to charities and CIOs?
Yes. UK GDPR applies to organisations that process personal data about living individuals, regardless of their size. This includes charities, CIOs, voluntary organisations and community groups that hold information about beneficiaries, supporters, volunteers, employees or other individuals.
Organisations must comply with the data protection principles and be able to demonstrate accountability.
2. What is personal data?
Personal data is information relating to an identified or identifiable living individual. In a charity setting this may include information about:
beneficiaries
volunteers
trustees
supporters
contractors
employees
Examples include:
names
addresses
telephone numbers
email addresses
beneficiary records
volunteer details
employment records
payroll information
case notes - where an individual can be identified directly or indirectly.
3. Is information stored in OASIS covered by UK GDPR?
Where information held in OASIS relates to identifiable living individuals, it is personal data and UK GDPR applies. Depending on the services provided by the charity, OASIS may also contain special category data that requires additional protection and safeguards.
4. Do charities always need consent to collect or share information?
No. The ICO makes clear that consent is only one of six lawful bases for processing personal data. Many charities rely on other lawful bases depending on the purpose of processing.
Organisations should identify the most appropriate lawful basis before processing personal data and document their decision.
5. Can a charity share information without consent?
Yes, in some circumstances. The ICO explains that information can be shared where there is an appropriate lawful basis for processing. Depending on the circumstances, this may include contract, legal obligation or legitimate interests.
Information sharing should be:
necessary
proportionate
transparent
appropriately documented
6. What is a lawful basis?
A lawful basis is the reason recognised under UK GDPR for processing personal data. ICO guidance includes lawful bases such as:
Consent
Contract
Legal obligation
Legitimate interests
Vital interests
Public task
Charities should identify and record the lawful basis that applies before collecting or using personal data.
7. What are legitimate interests?
Legitimate interests may be appropriate where processing is necessary for the organisation's legitimate purposes and those interests are not overridden by the rights and freedoms of the individual.
The ICO describes this as a balancing exercise that takes account of the impact on the individual and what they would reasonably expect.
Organisations relying on legitimate interests should document their assessment.
8. What is special category data?
Special category data is personal data that requires extra protection because it is particularly sensitive. ICO guidance includes information such as:
Health information
Ethnic origin
Religious or philosophical beliefs
Political opinions
Trade union membership
Genetic data
Biometric data used for identification
Sexual orientation
Charities and CIOs may process special category data relating to both service users and employees. For example, HR records may contain information about health conditions, occupational health support, equality monitoring, or trade union membership.
Additional conditions and safeguards are required when processing this information.
9. Can safeguarding information be recorded in OASIS?
Yes. Where safeguarding information is necessary for providing support, protecting individuals or meeting safeguarding responsibilities, charities may need to process and record such information.
Organisations should ensure they identify the appropriate lawful basis, apply suitable access controls, and follow their information governance procedures. The ICO also provides guidance on data sharing for safeguarding purposes.
10. How much information should we collect?
The data minimisation principle requires organisations to collect only the personal data that is necessary for their specified purpose.
Charities should ensure information collected through OASIS is relevant, adequate and limited to what is needed for service delivery, safeguarding, reporting or other identified purposes.
11. How long should we keep records in OASIS?
The ICO does not prescribe a single retention period for all records. Retention periods should reflect the purpose for which information was collected and any legal, regulatory, operational or safeguarding requirements that apply.
Charities should maintain documented retention and disposal procedures.
12. Can we keep information indefinitely?
Generally, no. The storage limitation principle requires organisations to keep personal data only for as long as necessary for the purpose for which it was collected.
When information is no longer needed, it should be securely deleted or anonymised in accordance with organisational policies.
13. What should staff be able to see?
Access to information should be restricted according to business need and role responsibilities. This is particularly important where OASIS contains sensitive, safeguarding or special category data.
Appropriate security measures and governance controls should help ensure that only authorised individuals have access to relevant information.
14. What happens if someone asks to see their information?
Individuals have rights under UK GDPR, including the right to access their personal data through a Subject Access Request (SAR).
Charities should have procedures in place to recognise, manage and respond to requests within the applicable legal timescales.
15. Do we need a privacy notice?
Yes. The ICO advises organisations to be transparent about how they use personal data. Privacy information should explain what information is collected, why it is used, the lawful basis relied upon, who it may be shared with, how long it is retained and the rights available to individuals.
Many charities and CIOs choose to provide separate privacy notices for different groups, such as beneficiaries, volunteers, donors, trustees and employees, reflecting the different purposes for which information is processed.
16. What employee information can charities and CIOs keep?
Charities and CIOs acting as employers will usually need to process personal data about their staff to meet employment, payroll, health and safety, pension and legal obligations.
Examples of employee information that organisations commonly hold include:
Name and contact details
Date of birth
National Insurance number
Tax and payroll information
Qualifications and employment history
Employment contract detail
Pay, benefits and working hours
Holiday and absence records
Training records
Health and safety incident records
Disciplinary and performance records
Emergency contact details
Some employment records may contain special category data, such as health information, ethnicity, religion, trade union membership or biometric information used for identification purposes. Where this applies, charities should ensure they have an appropriate lawful basis and condition for processing and apply suitable security measures.
Organisations should only collect information that is necessary, keep it accurate, restrict access to those who need it, and retain it only for as long as it is required.
Employees also have data protection rights, including the right to request access to their personal data held by the organisation. Charities and organisations should have processes in place to recognise and respond to these Subject Access Requests (SARs)
17. How should we handle special category data?
Special category data is personal data that is particularly sensitive and requires additional protection. This includes information about:
Health or medical conditions
Mental health and wellbeing
Racial or ethnic origin
Religious or philosophical beliefs
Political opinions
Trade union membership
Genetic data
Biometric data used for identification
Sexual orientation
Many charities process special category data as part of supporting beneficiaries, delivering services, safeguarding individuals, managing employees, or meeting equality and inclusion obligations.
When handling special category data, charities and CIOs should:
Be clear about why the information is needed.
Identify a lawful basis for processing personal data.
Identify an additional condition for processing special category data.
Collect only the information that is necessary.
Restrict access to staff and volunteers who need it for their role.
Apply appropriate security measures to protect the information.
Keep the information accurate and up to date.
Retain it only for as long as necessary.
Ensure staff understand their confidentiality and data protection responsibilities.
Where special category data is recorded in OASIS, organisations should consider using role-based access controls, follow their retention policies, and ensure appropriate governance and accountability arrangements are in place.
Using OASIS can support secure information management, but responsibility for compliance remains with the charity or CIO as the data controller.
Special category data often arises in charity settings through case notes, support plans, safeguarding records, disability information, occupational health records, equality monitoring, and other information needed to provide services or manage employment relationships.
Because this information is particularly sensitive, organisations should take extra care before collecting, sharing or disclosing it.
18. Is OASIS automatically UK GDPR compliant?
Using OASIS supports good information management, but responsibility for compliance always remains with the charity or CIO using the system. The ICO's accountability principle requires organisations to demonstrate compliance through appropriate governance, policies, procedures, staff training, security measures and record keeping.
19. What are the biggest data protection risks for charities?
Examples of risks highlighted by ICO guidance include:
Collecting more information than is necessary
Keeping information for longer than required
Inadequate staff training
Unauthorised access to beneficiary or employee records
Failure to identify and document a lawful basis
Weak security arrangements
Improper handling of special category data relating to service users or staff
Poor governance and accountability processes
Charities should regularly review their information governance arrangements for both service-user and employee data and ensure appropriate technical and organisational measures are in place to protect personal information.
OASIS users are not only managing beneficiary and casework data, but may also be responsible for employee records, which are subject to the same UK GDPR principles around lawfulness, transparency, minimisation, security, retention and individual rights.
20. Where can charities and CIOs get official data protection guidance?
The ICO provides free guidance and resources covering:
UK GDPR compliance
Lawful bases for processing
Special category data
Subject Access Requests
Individual rights
Data sharing
Information security
Accountability and governance
Privacy notices
Safeguarding-related information sharing
Further information for smaller organisations is available at: Advice for small and medium organisations | ICO
OASIS is a case management and information recording system. Whether your charity or CIO complies with UK GDPR depends on how your organisation collects, uses, shares, secures and manages personal data - together with its policies, procedures and governance arrangements.
Accountability for compliance always rests with the charity or organisation acting as the data controller.



