Why Ongoing Data Protection Training is Essential for Non-Profits

10th February 2026

Not-for-profit organisations (NfPs) like charities and other similar organisations frequently handle large amounts of personal data, some of it being sensitive or special category data. Recent ICO enforcement actions remind us that accountability, especially regarding data protection in the not-for-profit sector, is essential. Ongoing training can help NfPs remain compliant with UK laws, retain trust with service users and stakeholders, and maintain a good reputation.

Recent ICO Enforcement Action

In July 2025, the ICO fined Scottish charity Birthlink £18,000 for destroying 4,800 personal records, of which up to 10% may be irreplaceable. Birthlink is a charity that maintains the adoption contact register in Scotland, helping adopted people, birth families and relatives to connect with and potentially be reunited with family members. An ICO investigation found that Birthlink destroyed case files on service users who had found their birth families due to storage constraints. They intended to only destroy replaceable data, but following an inspection by the Care Inspectorate in August 2023, it was found that irreplaceable items, including handwritten letters and photographs from birth parents, had in fact been destroyed. 

A subsequent ICO investigation found that the charity had a limited understanding of data protection laws and had not implemented suitable training or relevant policies and procedures. The investigation also revealed that staff members had raised concerns about shredding personal items like photos and cards, but were told to continue.Birthlink’s interim chief executive, Abbi Jackson, admitted that “a lack of knowledge about data protection legal requirements existed at Birthlink at the time of the breach” and that there were “inadequate systems in place to keep vitally important information safe”. Source: Civil Society

The ICO investigation found that Birthlink infringed the following provisions of the UK GDPR:

  • Article 5(1)(f), (integrity and accountability principle), 
  • Article 5(2), (accountability principle),
  • Article 32(1)-(2) (security of processing), 
  • Article 33 (notification of a personal data breach to the Commissioner)

Source: The ICO 

The destroyed records may have been the only link that adopted people have to their birth families, highlighting the very real impact that mismanagement of personal data can have, especially for NfPs and charities. 

Data Protection Accountability for Not-for-profit Organisations

This case is a good example of how a lack of adequate training, data retention or data destruction policies, and failure to embed data protection accountability at an operational level can lead to a serious data breach with a very human cost. The charity has since implemented digital storage of all physical records, appointed a Data Protection Officer and initiated data protection training for staff members. The ICO has also published a campaign, Ripple Effect, which details the human impact that data breaches can have, and provides information and resources for organisations and individuals affected by data breaches.

Considerations for Not-for-profit Organisations

If you are a charity or other NfP, you should consider the following regarding data protection.

Data retention and data destruction policies

Every organisation that collects personal data should have a data retention policy AND a data destruction policy in place. The data protection principle of storage limitation requires that personal data should only be kept for as long as is necessary for the purpose it was collected. Organisations must set clear, justifiable, and documented retention periods, which may vary based on legal requirements – specific data retention periods will vary according to the purpose the data was collected for and other factors – in the case of Birthlink, it would be appropriate to retain the personal data involved in the case, and to have a policy or procedure in place detailing this. 

Data protection by design & by default

Data protection by design and by default are concepts introduced by Article 25 of the GDPR. This means that organisations should integrate data protection into every aspect of their data processing activities, from the point of collection through to data storage and the eventual destruction of collected data. Data protection by design means that data protection should be ‘baked into’ all data collection and processing activities and business practices, including during the development of new IT systems, services, policies, products and processes. Data protection by default means that strict privacy settings should automatically be applied to all data collection and processing, requiring no additional action from the individual. This ties in with the principles of data minimisation, purpose limitation, storage limitation and transparency.

Organisations can implement data protection by design and by default by conducting data mapping to find out how data comes into the organisation, how and where it is stored, who has access to it, and how it flows out of the organisation, including data sharing with third-party providers such as CRM systems and fundraising platforms. 

Using a DPIA (data protection impact assessment) is recommended for any new project or data processing activity. An activity that involves ‘high risk’ processing needs a DPIA as per Article 35(3) of the GDPR. This tool can help you to identify the potential risks of your planned data processing activity, weigh those up against the benefits, and make plans to mitigate or reduce these risks. The methods and results of a DPIA should be documented to provide evidence of compliance with the GDPR.

Data protection training

Charities and not-for-profit organisations should engage in data protection training, not just as part of an induction for new employees, but as an ongoing process for everyone involved. During the investigation into Birthlink, the ICO discovered that some staff members were unaware of basic data protection principles, policies were not understood or followed in practice, and the organisation could not provide evidence of data protection training taking place.  

Data protection training for charities and other non-profits should be:

  • Clearly mapped and evidenced for all employees, trustees and volunteers
  • Tailored for the organisation and its specific data collection and processing activities
  • Role-specific, with enhanced training for staff members who handle high-risk or sensitive data
  • Ongoing, with refresher courses that reinforce good practice and are updated following any changes in legislation 
  • Practical and hands-on, making it relevant and relatable for team members
  • Effective, as evidenced by post-training tests, scenario-based questions, simulations, follow-up testing and other methods.

We can provide practical and effective data protection training for your organisation that meets all requirements of the ICO and data protection legislation. Our bespoke training sessions explain data protection concepts in clear, easy-to-understand language, include real-life scenarios that are relevant to your organisation’s activities, and will empower your team members to make informed decisions regarding data protection. Between them, our trainers have over 50 years of experience in data protection training and can offer a fun, interactive and hands-on learning experience – find out more about our courses here or get in touch to discuss your specific needs using the form below.

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founding directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting, and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details