• Charity & Philanthropy Focus
  • Sep 7, 2026

Personal data breaches: what charities need to know

Cyber attacks and data theft are an increasingly common feature of the risk landscape for charities. Whether the incident arises from a phishing attack, ransomware event, supplier compromise or human error, a personal data breach can have significant regulatory, operational and reputational consequences.

Share this page: LinkedIn X

The recent cyber-security incident affecting Beacon Apps Ltd, a CRM provider used by many charities and not-for-profit organisations, is a reminder that organisations can be affected even where the root cause lies with a third-party supplier.

While every incident turns on its own facts, the Beacon incident highlights the importance of understanding what a personal data breach is, how to recognise one, when an organisation must notify the Information Commissioner’s Office (“ICO”) and what practical steps should be taken following a breach.

What is a personal data breach?

Under the UK GDPR, a personal data breach is a breach of security leading to accidental or unlawful destruction, loss or alteration of personal data or unauthorised disclosure of, or access to, personal data. Breaches can affect the confidentiality, integrity or availability of personal data.

Examples of personal data breaches go beyond cyber-security attacks and include sending personal data to the wrong recipient, losing a laptop or files containing personal data and accidental deletion of personal data.

How can we recognise a breach?

Many organisations first learn of a breach through:

    • a report from a supplier;
    • unusual activity detected by IT systems;
    • a member of staff identifying an error;
    • a complaint from an individual; or
    • law enforcement or cyber-security specialists.

If a breach has been identified, the organisation should investigate it promptly and begin assessing risk.

When do we need to notify the ICO?

Not every breach needs to be reported.

Under the UK GDPR, an organisation must notify the ICO unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Examples of a risk to individuals’ rights and freedoms include identity theft or fraud, financial loss, loss of confidentiality, reputational damage, discrimination or other economic or social disadvantage.

Where notification is required, it must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The ICO recognises that investigations may still be ongoing and allows organisations to provide additional information later as it becomes available.

What information goes into an ICO notification?

The ICO expects organisations to provide as much information as possible at the time of reporting. This typically includes:

    • a description of the nature of the breach;
    • the categories and approximate number of individuals affected;
    • the categories and approximate volume of personal data affected;
    • the likely consequences of the breach;
    • measures already taken to address the incident;
    • proposed mitigation measures;
    • a contact point for further enquiries; and
    • details of any notifications to affected individuals.

What if we decide not to notify?

You must maintain records of all personal data breaches, whether or not they are reported. If you conclude that a breach is not reportable, you should document the facts of the incident, the likely effects on individuals and the reasons why notification was not considered necessary.

When do we need to notify affected individuals?

The threshold for notifying individuals is higher than the threshold for notifying the ICO.

Affected individuals must be informed where the breach is likely to result in a “high” risk to their rights and freedoms. Relevant factors may include:

    • the volume of data involved;
    • the sensitivity of the information;
    • whether special category data (such as health information) has been compromised;
    • whether children or vulnerable people are affected;
    • whether the data is likely to be intelligible to an unauthorised person; and
    • the likelihood of misuse.

Individuals should be informed without undue delay and in clear, plain language. The communication should explain what happened, what information may be affected, the likely consequences, what steps the organisation is taking and what the individuals can do to protect themselves.

What other steps should we take following a breach?

The ICO encourages organisations to reflect on lessons learned and whether existing controls remain effective. Charities should review their internal procedures and incidence response plans, staff training on identifying and actioning personal data breaches, cyber-security measures and, if applicable, also review supplier due diligence processes.

A data breach notification to individuals may also prompt subject access requests and data erasure requests, which charities will need to prepare for. 

Finally, charities may also need to file a serious incident report with the Charity Commission.

What happens if we don’t notify the ICO of all notifiable breaches?

Failure to report a notifiable personal data breach can expose an organisation to significant regulatory consequences, including substantial financial penalties and the exercise of the ICO’s wider enforcement powers. Charities should therefore ensure they have robust incident response and reporting procedures in place so that potential breaches are identified, assessed and, where required, reported promptly.

Final thoughts

A personal data breach can create significant compliance, operational and reputational challenges for charities. Organisations should ensure they have clear internal processes for identifying incidents, escalating concerns, assessing risk and making timely reporting decisions.

This article is for general information purposes only and does not constitute legal advice or a comprehensive statement of the law. Specific legal advice should always be sought in relation to individual circumstances.

Meet the team:

View more