Charity & Philanthropy Focus – September 2026
Charities continue to operate against a backdrop of financial pressure, increasing regulation and evolving risks. Following International Day of Charity on 5 September, it is a timely opportunity to reflect on the vital contribution that charities, funders and philanthropic organisations make to society and their role in building resilience within communities.
In this edition, we explore a number of practical issues arising from that landscape, including how philanthropy can support long-term resilience, the effective use of restricted funds, governance policies and managing personal data breaches. We also consider the role of litigation in the charity sector and the wider considerations for trustees seeking to ensure their organisations remain effective, adaptable and well governed.
We hope you enjoy this edition and, if a topic raises a question, please do get in touch with your usual Wedlake Bell adviser or any member of our Charities team.
In this issue:
- Philanthropy: from crisis response to crisis readiness – as crises become more frequent and complex, we consider philanthropy’s role not only in responding to emergencies but also in strengthening preparedness. We explore the importance of community networks, organisational resilience and flexible funding, alongside the challenges charities face in maintaining the capacity needed to support future crisis response.
- Restricted funds: unlocking value for more effective use – charities can accumulate restricted funds that become difficult to manage or no longer reflect current needs. We explore how trustees can identify different types of restrictions, use statutory powers to modernise purposes where appropriate, and approach fund rationalisation in a way that supports effective use of charitable resources.
- Is it time for a policy health check? – policies can play an important role in governance, risk management and decision-making, but are often only reviewed when an issue arises. We consider the key areas trustees should assess, recent developments in guidance, and practical steps for ensuring policies remain current, proportionate and aligned with how the charity operates.
- Personal data breaches: what charities need to know – cyber incidents, supplier failures and human error can all lead to personal data breaches. We explain how to recognise a breach, assess whether it must be reported to the ICO, when affected individuals need to be informed, and the importance of maintaining records, reviewing procedures and learning lessons from incidents.
- When can a charity litigate? Key points for trustees – recent litigation involving the charity Sentebale has brought trustee decision-making around legal proceedings into focus. We explore when litigation may be justified, the duties trustees must consider, the circumstances in which Charity Commission or court consent may be required, and the importance of assessing costs, risks and potential impact on the charity.
When can a charity litigate? Key points for trustees
While every case will turn on its facts, UK charity law and best practice provides a clear framework to help trustees decide whether they can, and if so, if they should proceed to the courts.
Litigation and trustees’ duties
Charities can bring or defend legal proceedings, but trustees must approach litigation with particular care. Their overriding fiduciary duties (i.e. the legal obligation to act solely in the charity’s interests) must be met in doing so, including to:
-
- Act only in the charity’s best interests;
- Use charitable funds prudently and proportionately; and
- Protect the charity’s assets, reputation and ability to deliver its purposes.
Litigation is never risk‑free and will usually be appropriate only where trustees can show a clear overriding benefit to the charity.
When litigation may be justified
Litigation may be in a charity’s best interests where, for example:
-
- Significant charitable assets need protection or recovery;
- The charity must defend itself against serious claims;
- Reputational harm is materially affecting service delivery or funding; and/or
- Other options (such as arbitration or mediation) have been exhausted or are unsuitable.
Trustees should carefully consider and record:
-
- The merits of their case, having taken and considered legal advice;
- The likely cost to the charity and how much of that is irrecoverable (even if the charity wins);
- The potential impact on beneficiaries and charitable activities; and
- The balance of reputational pros and cons of litigating.
Charity proceedings and authorisation requirement
Not all disputes involving charities are treated the same way in law. Some will be classed as “charity proceedings” under the Charities Act 2011, which carry specific restrictions and requirements.
Charity proceedings may only be brought by:
-
- The charity itself;
- Any of its trustees;
- Any person “interested in the charity” (they must have a material interest and could include, for example, former trustees, members of a membership charity, beneficiaries or donors); or
- Any two or more inhabitants of the area of the charity, if it is a local charity.
Charity proceedings involve claims relating to (whether brought by or against the charity):
-
- The charity’s internal governance or administration;
- The exercise of trustees’ powers;
- The interpretation or application of the charity’s governing document; and
- Allegations relating to breach of trust or duty by the trustees.
Where proceedings are classed as charity proceedings, Charity Commission or court consent must be secured before a claim can be issued. Early legal advice is essential to determine whether consent is needed.
Funding litigation
The Sentebale case is notable because the charity has confirmed that the costs of proceedings will be met entirely by a third-party donor. For most charities, that will not be an option, and charitable funds may be used only where trustees reasonably believe litigation is in the charity’s best interests and the cost is proportionate.
Where third party funding is available, there will remain a question of whether it is appropriate and necessary to proceed with litigation. There will be risks beyond the purely financial that may still impact on the charity, including in terms of reputation management and engagement with stakeholders. Trustees must also take care to retain control of the proceedings, ensure that the funder does not influence trustee decisions, and manage conflicts of interest properly.
In each case, careful documentation by the trustees of the decision‑making process is essential.
Final thought
Litigation can be a legitimate course of action for charities, but it is often high risk. Trustees should only proceed where they can clearly demonstrate that it advances the charity’s interests, complies with the law, and represents a responsible use of its resources.
Personal data breaches: what charities need to know
The recent cyber-security incident affecting Beacon Apps Ltd, a CRM provider used by many charities and not-for-profit organisations, is a reminder that organisations can be affected even where the root cause lies with a third-party supplier.
While every incident turns on its own facts, the Beacon incident highlights the importance of understanding what a personal data breach is, how to recognise one, when an organisation must notify the Information Commissioner’s Office (“ICO”) and what practical steps should be taken following a breach.
What is a personal data breach?
Under the UK GDPR, a personal data breach is a breach of security leading to accidental or unlawful destruction, loss or alteration of personal data or unauthorised disclosure of, or access to, personal data. Breaches can affect the confidentiality, integrity or availability of personal data.
Examples of personal data breaches go beyond cyber-security attacks and include sending personal data to the wrong recipient, losing a laptop or files containing personal data and accidental deletion of personal data.
How can we recognise a breach?
Many organisations first learn of a breach through:
-
- a report from a supplier;
- unusual activity detected by IT systems;
- a member of staff identifying an error;
- a complaint from an individual; or
- law enforcement or cyber-security specialists.
If a breach has been identified, the organisation should investigate it promptly and begin assessing risk.
When do we need to notify the ICO?
Not every breach needs to be reported.
Under the UK GDPR, an organisation must notify the ICO unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Examples of a risk to individuals’ rights and freedoms include identity theft or fraud, financial loss, loss of confidentiality, reputational damage, discrimination or other economic or social disadvantage.
Where notification is required, it must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The ICO recognises that investigations may still be ongoing and allows organisations to provide additional information later as it becomes available.
What information goes into an ICO notification?
The ICO expects organisations to provide as much information as possible at the time of reporting. This typically includes:
-
- a description of the nature of the breach;
- the categories and approximate number of individuals affected;
- the categories and approximate volume of personal data affected;
- the likely consequences of the breach;
- measures already taken to address the incident;
- proposed mitigation measures;
- a contact point for further enquiries; and
- details of any notifications to affected individuals.
What if we decide not to notify?
You must maintain records of all personal data breaches, whether or not they are reported. If you conclude that a breach is not reportable, you should document the facts of the incident, the likely effects on individuals and the reasons why notification was not considered necessary.
When do we need to notify affected individuals?
The threshold for notifying individuals is higher than the threshold for notifying the ICO.
Affected individuals must be informed where the breach is likely to result in a “high” risk to their rights and freedoms. Relevant factors may include:
-
- the volume of data involved;
- the sensitivity of the information;
- whether special category data (such as health information) has been compromised;
- whether children or vulnerable people are affected;
- whether the data is likely to be intelligible to an unauthorised person; and
- the likelihood of misuse.
Individuals should be informed without undue delay and in clear, plain language. The communication should explain what happened, what information may be affected, the likely consequences, what steps the organisation is taking and what the individuals can do to protect themselves.
What other steps should we take following a breach?
The ICO encourages organisations to reflect on lessons learned and whether existing controls remain effective. Charities should review their internal procedures and incidence response plans, staff training on identifying and actioning personal data breaches, cyber-security measures and, if applicable, also review supplier due diligence processes.
A data breach notification to individuals may also prompt subject access requests and data erasure requests, which charities will need to prepare for.
Finally, charities may also need to file a serious incident report with the Charity Commission.
What happens if we don’t notify the ICO of all notifiable breaches?
Failure to report a notifiable personal data breach can expose an organisation to significant regulatory consequences, including substantial financial penalties and the exercise of the ICO’s wider enforcement powers. Charities should therefore ensure they have robust incident response and reporting procedures in place so that potential breaches are identified, assessed and, where required, reported promptly.
Final thoughts
A personal data breach can create significant compliance, operational and reputational challenges for charities. Organisations should ensure they have clear internal processes for identifying incidents, escalating concerns, assessing risk and making timely reporting decisions.
Is it time for a policy health check?
The Charity Commission annual return is often one such trigger. Registered charities in England and Wales must submit an annual return, or report income and spending, each year. The return can require trustees to confirm key information about how the charity is run, which often leads charities to ask a more practical question: do we have the right policies in place and are they up-to-date?
It is a question worth asking regularly. Policies are not simply administrative documents. Used properly, they help trustees demonstrate oversight, manage risk, delegate authority clearly, and ensure that decisions are taken consistently and in accordance with the charity’s purposes. They can also be useful evidence of good governance if the charity is dealing with a regulator, funder, auditor, bank or other stakeholder.
Policies are also a form of governance insurance. They may not prevent difficult situations from arising but they can help trustees make better decisions when the charity is under pressure. If trustees need to consider a serious incident report, respond to a whistleblowing concern, deal with a controversial donation, or approve urgent expenditure, a clear policy framework can help them act quickly and consistently. It is much easier to follow an agreed process than to create one from scratch in the middle of a live issue.
There is no single policy checklist that will be right for every charity. What is appropriate will depend on the charity’s size, legal form, activities, funding model and risk profile. A small grant making charity with no staff will not need the same suite of operational policies as a large service-delivery charity working directly with children or adults at risk. Similarly, a charity involved in public fundraising, overseas grant-making, campaigning, trading activity or significant digital work is likely to need more tailored policies and procedures than a charity with a simpler operating model.
That said, there are some common areas that most charities should consider. These include conflicts of interest, trustee conduct, delegation of authority, financial controls, risk management, reserves, data protection, complaints and serious incident reporting. Depending on the charity’s activities, policies on safeguarding, grant-making, donation acceptance and refusal, fundraising, investment, anti-bribery, anti-money laundering and whistleblowing may also be relevant. These are often the areas that become most important when issues arise, for example, where a donation raises reputational concerns or a safeguarding or data incident needs to be managed. The key point is not simply to collect policies, but to ensure they accurately reflect how the charity operates in practice.
Recent developments in sector guidance also make this a good time for trustees to take stock. The refreshed Charity Governance Code encourages charities to think about how good governance principles apply in their particular circumstances, rather than adopting generic policies or processes. Similarly, the revised Charity Commission guidance on grant making and conflicts of interest include some high level points that trustees may want to add in to their policies.
A good policy review should be proportionate. Trustees could start by mapping the policies the charity already has, noting when they were last reviewed, identifying who is responsible for them and considering whether they still reflect the charity’s current activities and governance structure. It is also worth checking policies against the charity’s governing document, committee terms of reference, delegation framework and financial controls. If these documents do not align, it can create uncertainty about who has authority to make decisions and how those decisions should be made.
The strongest policy frameworks are living documents. They are reviewed regularly, understood by those who need to use them, and updated when the charity’s activities, risks or regulatory expectations change. A policy that is current, practical and embedded in decision-making can be an important tool for trustees.
If you would like further advice on reviewing your governance policies, please contact the Charities Team at Wedlake Bell.
Restricted funds: unlocking value for more effective use
Over time, those funds can become administratively burdensome and may leave charitable resources underused where their purposes are no longer practical or sufficiently flexible. Fund rationalisation is rarely at the top of the agenda, but it may be worth revisiting. Updated statutory powers available to charities can make the exercise more straightforward than it once was and, where approached carefully, rationalisation can reduce administration and unlock value for more effective use.
Identify what is really restricted
The starting point is to determine the true nature of each fund. Trustees should carry out a proportionate review of the available documents, which may include wills, trust deeds, appeal wording, donor correspondence and historic board minutes.
The aim is to identify the fund’s purpose and whether the restriction is legally binding. A fund labelled in the accounts as “restricted” may, on closer inspection, reflect a non-binding donor “wish”, “preference” or an internal designation. Equally, a fund with limited records may still be subject to legally binding trusts.
The key is to avoid creating restrictions by assumption, while recognising and respecting those that are properly evidenced.
Separate the quick wins from the difficult cases
Following that initial review, the funds can usually be grouped into categories. Some may be unrestricted funds that have simply been designated internally – these can usually be redesignated or released by trustee decision. Others may be restricted income funds, where the whole fund can be spent but only for a particular purpose. If that purpose remains workable, the fund may be capable of being transferred into a broader fund with a compatible purpose.
The more difficult cases are those where the fund’s purpose itself needs to change. This is where the statutory powers under the Charities Act 2011 become important.
Use the statutory regime to modernise purposes and powers
For unincorporated charities, including funds held on charitable trusts, s.280A of the Charities Act 2011 enables trustees to amend trusts by resolution where they are satisfied that the amendment is expedient in the interests of the charity.
This can be particularly useful in a rationalisation exercise. If the change is administrative only, the trustees may be able to use s.280A without Charity Commission consent. This might include adding a clear power to transfer assets to another fund, where the existing documents do not already provide an adequate mechanism to support the intended consolidation.
If the consolidation requires an amendment to the fund’s purposes, Commission consent must be obtained before the amendment can take effect. In practice, the application should explain why the existing purpose is no longer workable, how the proposed broader purpose remains close to the donor’s intention (where possible) and how the change would enable the charity to achieve greater impact.
For charities dealing with a significant number of funds, a staged approach may help. Starting with the clearest cases, such as funds with plainly outdated purposes or closely aligned proposed purposes, can help trustees build a clear evidence base and make any Commission engagement more manageable.
Treat permanent endowment separately
Permanent endowment can be difficult to identify. Broadly, it is property that the charity must keep rather than spend, such as money given for investment where only the income may be spent. In some cases, funds may have been treated as permanent endowment historically even though the documents do not show a binding requirement to retain the capital. Where the evidence supports that conclusion, trustees may be able to reclassify the fund by resolution as part of the rationalisation exercise without using the statutory permanent endowment regime.
Where a fund is permanent endowment and trustees want to spend the capital, the process depends on value. For funds with a market value of £25,000 or less, trustees may usually do so without Commission authority if they are satisfied that spending capital would better achieve the fund’s purposes. For larger funds where market value exceeds £25,000, Commission consent is required before the capital spending restriction can be released. The application for consent should set out the financial position, any known donor wishes, current beneficiary needs and any change in circumstances since the fund was established.
The practical point is to identify permanent endowment early and to sequence any reclassification, purpose changes and/ or capital release resolutions carefully.
Watch out for fundraising appeals
These appeals can create separate issues. Donations raised for a specific purpose must be used for that purpose unless the appeal wording allows otherwise.
If an appeal raises more than needed, trustees should check whether the wording includes a secondary purpose. If it does not, they must agree new charitable purposes for the surplus, having regard to the similarity to the original purpose and the suitability in current circumstances. Where the surplus exceeds £1,000, Commission authority is required before the resolution can take effect – this should be factored into the rationalisation timetable.
The practical lesson for future appeals is simple: include a clear secondary purpose from the outset.
Key takeaway for trustees
A fund rationalisation exercise should not be presented simply as administrative spring cleaning. Reducing the administrative burden of managing multiple small or historic funds is valuable, but the stronger case is that rationalisation can bring charitable resources back into active and effective use.
Trustees should be clear about why the existing restrictions inhibit impact, what alternatives have been considered, how the proposed combined fund will operate and how the change supports current beneficiaries.
Done well, fund rationalisation respects the original wishes of the donor by ensuring that funds remain workable, effective and relevant for today’s beneficiaries.
Philanthropy: from crisis response to crisis readiness
A succession of days above 30°C has had a ripple effect across public health, transport and agriculture, leading to disruption as well as school closures. We are seeing time and again that crises do not occur in splendid isolation. In recent years, the pandemic, geopolitical conflict, inflationary pressures, disruption to international supply chains and climate-related events have overlapped in ways that have amplified their consequences and reduced the capacity of communities, institutions and civil society to absorb them.
The conventional model of crisis management has typically assumed an identifiable event, followed by response and then recovery. The question for philanthropy now is not simply how effectively it can respond when a crisis occurs, but what role it can play in improving readiness before it does. This approach is reflected in the Government’s own Resilience Action Plan, which seeks to adopt a “whole of society” approach, recognising that national resilience cannot be delivered by government alone. Individuals, businesses and civil society all have a role to play. The Government’s approach is moving towards “all hazards” preparedness: developing capabilities that can be adapted to different forms of disruption rather than attempting to construct a separate response to every conceivable crisis.
In a charity context, this translates into having systems, processes and networks in place to address the practical consequences of a crisis more effectively. For example, the ability to identify vulnerable people, communicate effectively, distribute assistance and mobilise volunteers frequently depends on organisations and relationships already embedded within communities. Those relationships cannot readily be constructed after an emergency has occurred. This was a recurring theme in a discussion on philanthropy and crisis response that we recently had the pleasure of hosting: resilience begins at household and community level, and effective preparedness depends as much on trusted relationships and local capability as on formal emergency planning.
There is, however, an important tension. The voluntary sector is routinely expected to provide additional capacity during periods of disruption. During the pandemic and subsequent humanitarian emergencies, charities demonstrated their ability to mobilise volunteers and resources at considerable scale and to reach communities that statutory agencies can find difficult to engage. Government resilience policy now expressly recognises the importance of that role.
At the same time, the Charity Commission’s 2025 Charity Sector Risk Assessment identifies financial resilience as one of the principal risks facing the sector. The pressures identified during the panel discussion extended beyond finance to the availability of volunteers and the capacity of smaller community organisations in particular. There is an evident tension between increasing reliance on civil society as part of the country’s resilience infrastructure and the resources available to sustain that capacity.
For philanthropy, this raises a question about the balance between response and preparedness. Emergency appeals have obvious advantages. The need is immediate, beneficiaries can be identified, and the application of funds can generally be demonstrated relatively quickly. Preparedness is more difficult. Its benefits may arise several years later and successful intervention may principally be evidenced by harm avoided rather than a readily identifiable output. Unlike crisis response, its success is often measured not by what happens, but by what does not happen.
There is nevertheless a clear economic case for earlier intervention. The Government’s Resilience Framework notes, for example, that every £1 spent by the Environment Agency advising on flood risk in the planning system has been estimated to save £12 in future flood damage. The precise return will necessarily vary between interventions but, at the risk of stating the obvious, investment before an event occurs can be substantially more efficient than meeting its consequences afterwards.
Philanthropy has a potentially distinctive role here. It is not to substitute for public expenditure or assume responsibilities properly belonging to government. Its value lies partly in its ability to operate differently. Philanthropic capital can be patient and flexible. It can support organisational capacity and local networks, finance collaboration and preventative interventions, and accept longer time horizons where the eventual benefit may be difficult to measure through conventional outputs.
The structure of funding also matters. Recent emergencies have demonstrated the value of established mechanisms through which resources can be deployed rapidly as circumstances change. Flexible funding, longer-term relationships and trusted intermediaries can enable organisations to adapt without having to construct new arrangements in the middle of a crisis. In that sense, the capacity to respond quickly is itself partly a product of investment made before the response is required.
There is a governance dimension to this as well. The Charity Commission’s risk management guidance asks trustees to consider risks arising from the wider environment, including economic, social, political, technological and environmental change, and whether their charity will remain able to meet beneficiaries’ needs in the future. In an environment characterised by overlapping and persistent disruption, organisational resilience is therefore not separate from the effective delivery of charitable purposes.
Emergency response will remain essential and will always trigger a philanthropic response. However, the changing risk environment suggests that greater attention should be given to the conditions that determine the severity and consequences of an emergency before it occurs.
The shift from crisis response to crisis readiness is therefore less about predicting the next crisis than about developing the capacity to deal with whatever form it takes. For philanthropy, that means considering not only where resources are required today but also what investment in organisations, communities and systems will leave them better placed to respond tomorrow.
Charity & Philanthropy Focus – May 2026
We are pleased to launch Charity and Philanthropy Focus, a new newsletter, sharing practical insights on the issues we see affecting charities, trustees and philanthropic organisations.
We hope you enjoy this first edition and, if a topic raises a question, please do get in touch with your usual Wedlake Bell adviser or any member of our Charities team.
In this issue:
- Aligning capital with purpose: a practical guide for trustees – trustees face growing pressure to align investments with purpose but are often held back by perceived complexity. We set out a practical approach: moving beyond exclusions, managing trade-offs between returns and purpose, and using the investment policy as a central tool, alongside more engaged use of advisers.
- Fundraising governance: a compliance journey – in light of the updated CC20 guidance, trustees have always been responsible for fundraising, but there is now a clearer expectation of active board oversight. We highlight what this means in practice for understanding, monitoring and challenging fundraising to meet legal, ethical and reputational standards.
- New data protection requirement – are you ready? – from 19 June 2026, organisations must have a clear process for handling complaints about personal data. We explain the key steps: accessible procedures, timely acknowledgement and response, and maintaining audit trails and staff training to demonstrate compliance.
- Grant making disclosures under SORP 2026: transparency without risk – with SORP 2026 now in force, we outline how charities can approach grant disclosures clearly and proportionately, including flexible presentation, the role of materiality in naming recipients and use of the “serious prejudice” exemption, supported by trustee judgement and proper documentation.
- ICO publishes “soft opt in” guidance – so what should charities do now? – following the introduction of the “charitable purposes soft opt‑in”, we explain the ICO’s guidance on when it can be used, including what counts as genuine support, limits on third-party data, and the need for clear opt-outs, with practical steps for compliant use.
ICO publishes “soft opt in” guidance – so what should charities do now?
What has changed and why it matters?
The “charitable purposes soft opt‑in” came into force on 5 February 2026 as part of the Data (Use and Access) Act 2025, which amended the rules under the Privacy and Electronic Communications Regulations 2003 (PECR) for direct marketing by electronic mail. In broad terms, the change allows charities (where specific conditions are met) to send direct marketing by electronic mail without prior consent to individuals who have expressed an interest in, or offered to support, the charity’s purposes. The ICO’s guidance is designed to explain how to apply those conditions in practice, and where charities should not rely on the new route. The final guidance was published after a consultation that received more than 140 responses, and includes anonymised examples and additional clarification on areas that charities raised as difficult in practice, particularly direct collections and the role of third parties.
Key messages:
1.Not every interaction with a charity equals “support”
If someone buys something from a charity, that might indicate they’re backing the charitable cause – but sometimes it’s purely a straightforward transaction, with no reasonable basis for assuming that person wants to hear from the charity about fundraising or its wider work. In those cases, the ICO’s steer is that charities should not rely on the charitable soft opt‑in. For charities with trading activity (think shops or ticketed events) the practical takeaway is to draw sensible lines about which types of interactions count as genuine engagement with the charitable purpose, and to be ready to explain, at least internally, why a particular group is eligible to receive messages under the new provision. Strong signals for “support” may include donations, volunteering, signing up for updates about the cause, and requesting information about the charity’s work.
2. Charities remain on the hook for third‑party lists and instigators
The ICO has warned that there is “no such thing” as a soft opt‑in compliant third‑party marketing list for this purpose. So charities cannot assume they can rely on the charitable soft opt‑in if someone else collected the details for them – even where the third-party is another organisation within its wider group.
It is worth remembering that, under the ICO’s broader PECR guidance, responsibility does not just sit with whoever presses send. PECR can catch the organisation that instigates the marketing (for example, where an agency or partner is asked to send messages on the charity’s behalf). In those cases, both parties may bear responsibility and the ICO expects the charity to do some basic due diligence and have a written contract that clearly sets out who is doing what, especially where personal data is involved.
3. Make opt-out easy, and repeat it
Even where a charity can rely on the soft opt‑in, the ICO’s message is familiar: recipients must be given a clear opportunity to opt-out, and that opportunity should be provided in every subsequent communication. In reality, the challenge will typically be operational rather than legal – CRM and campaign tools should record which legal basis is being relied on for each contact, opt-outs should be actioned quickly across channels, and messaging templates should consistently include unsubscribe/STOP options to enable easy opt-out.
So what should charities do now?
- Identify which engagements show genuine “support” (vs purely transactional) before relying on charitable soft opt‑in.
- Separate contacts being messaged under charitable soft opt‑in vs other routes (such as consent), and make sure the CRM can evidence that split.
- Bake in opt‑outs everywhere, including a clear refusal at collection and an easy opt‑out in every subsequent message.
- Avoid third‑party lists and don’t assume group-sourced lists are soft opt-in compliant for this purpose.
- If anyone else sends on the charity’s behalf, remember PECR can treat the charity as an instigator too – so use written contracts and compliance checks.
In the ICO’s announcement of the guidance, it also reminded charities (separately from marketing rules) that by 19 June 2026 organisations must have a process in place for handling data protection complaints. This is not limited to marketing, but it is relevant to supporter communications and trust. See further details in our article here.
Grant making disclosures under SORP 2026: transparency without risk
The good news? The SORP continues to allow flexibility and recognises that full public disclosure isn’t always the right answer.
Telling the story
SORP 2026 expects trustees to explain grant making clearly in the trustees’ annual report and in the notes to the accounts, and in a way that helps readers understand what the charity funds, why those grants are made, and how charitable resources are being used. There’s no single correct format. Grants can be presented by theme, programme, geography or activity, so long as the picture is clear. For many charities, especially those working internationally or across multiple programmes, this approach can be far more meaningful than a long list of recipients.
Naming grant recipients
Charities do not necessarily need to name every grant recipient. Where grants are made to organisations, trustees must consider materiality. If the total funding given to a particular organisation is material in the context of overall charitable expenditure, the default position is that it would usually be identified in the accounts. Where grants are not material at that level, the SORP allows a more aggregated approach provided the disclosure still explains the nature and purpose of the activity.
The “serious prejudice” exemption
SORP 2026 also recognises that disclosure can create real risks. Where naming a grant recipient could reasonably be expected to cause serious prejudice to the charity, the recipient organisation, or individuals connected with it, trustees may withhold identifying information. This is particularly relevant for grants to individuals and grants made in high‑risk or politically sensitive contexts, where public identification could expose people to harm or intimidation.
Importantly, this isn’t a blanket non‑disclosure. Even where identities are withheld, charities must still disclose, in aggregate, the number, total value and general purpose of the grants, and explain that the serious prejudice exemption has been applied.
Trustees approach to disclosure in the annual report
Trustees are expected to exercise judgement and to do so carefully. In practice, this means:
- Making a clear trustee decision about the disclosure approach.
- Assessing both materiality and risk (not convenience).
- Documenting the rationale.
- Retaining full grant information internally for audit and regulatory purposes.
SORP 2026 places clear weight on the exercise of trustee judgement. Decisions to reduce or aggregate disclosure should be taken consciously and for proper reasons. Where trustees rely on the serious prejudice exemption, they should be able to explain by reference to objective factors why public disclosure would not be appropriate in the circumstances.
The key takeaway
SORP 2026 does not force charities to choose between transparency and safety. It allows trustees to be open about how funds are used, while also protecting beneficiaries, partners and the charity itself where there are genuine risks.
For grant making charities, reviewing disclosure practices now, and ensuring trustee decisions are well reasoned and well recorded, is an important part of getting ready for the year ahead.
Fundraising governance: a compliance journey
At one level, nothing has changed. Trustees have always been responsible for their charity’s fundraising. But in another sense, this update reflects a continued shift towards clearer expectations of active board oversight.
To understand why this matters, it helps to look back.
The fundraising controversies of around 2015 marked a defining moment for charity governance. The tragic case of Olive Cooke prompted widespread public concern and political scrutiny. The issue was debated in Parliament and addressed directly by Prime Minister David Cameron. Subsequent investigations revealed extensive use of donor lists, wealth screening and data matching, often without donors fully understanding how their personal information was being used.
The Information Commissioner’s Office imposed fines on several household name charities including the British Heart Foundation, Cancer Research UK and the RSPCA for breaches of data protection law. For many organisations, this served as a clear reminder that fundraising activity, however operational in nature, sits firmly within the trustees’ governance remit.
The regulatory response was significant. The Etherington Review led to the creation of the Fundraising Regulator and a strengthened Code of Fundraising Practice. The Charity Commission reinforced its guidance to trustees and made clear that fundraising is not simply a management function. It is a core governance responsibility.
It is sometimes asked why both the Charity Commission and the Fundraising Regulator have roles in this area. Their functions are complementary. The Fundraising Regulator oversees how fundraising is carried out and sets the standards expected of fundraisers. The Charity Commission regulates trustees. It expects boards to understand how fundraising is conducted, oversee the risks, and ensure that activity carried out in the charity’s name meets legal and ethical standards. One regulates the activity. The other regulates those ultimately accountable for it.
Subsequent governance failures at major charities such as Oxfam and Kids Company reinforced the importance of board visibility over risk culture and operational practice. At the same time, fundraising has become more complex, involving digital campaigns data driven targeting and commercial partnerships, increasing both opportunity and risk.
The updated CC20 guidance reflects this evolution. It does not change the underlying legal duties of trustees. Instead, it clarifies the practical expectations. Trustees should understand how fundraising is conducted, ensure appropriate reporting and oversight, consider fundraising within the charity’s risk framework and satisfy themselves that fundraising practices align with the charity’s values and reputation. This aligns closely with the Charity Governance Code, particularly its emphasis on integrity decision making and effective risk and control as core board responsibilities.
For many charities, this will already reflect established practice. But the direction of travel is clear. The guidance provides a clearer framework against which trustee stewardship will be assessed by regulators stakeholders and ultimately the public.
The sector has travelled a considerable distance over the past decade. The result is greater clarity stronger governance expectations and a more explicit recognition that fundraising is not simply about income generation but about maintaining trust in the charity itself.