{"id":3115,"date":"2026-01-27T14:59:13","date_gmt":"2026-01-27T14:59:13","guid":{"rendered":"https:\/\/actuallydata.net\/craft\/?post_type=resource&#038;p=3115"},"modified":"2026-02-17T10:21:58","modified_gmt":"2026-02-17T10:21:58","slug":"data-policy-starter-template","status":"publish","type":"resource","link":"https:\/\/actuallydata.net\/craft\/resource\/data-policy-starter-template\/","title":{"rendered":"Data Policy Starter Template"},"content":{"rendered":"\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--30);padding-bottom:var(--wp--preset--spacing--30)\">\n<h3 class=\"wp-block-heading\"><strong><em>A One\u2011Page Guide for Charity Teams<\/em><\/strong><\/h3>\n\n\n\n<p>Good data helps us raise more, reach the right people, stay compliant, and make better decisions. This guide explains what our Data Policy means in day\u2011to\u2011day charity work \u2014 without the jargon.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The basics (what everyone should know)<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data is an asset<\/strong> \u2013 like our people, money, and reputation. How we look after it affects trust.<\/li>\n\n\n\n<li><strong>If you can see data, you\u2019re responsible for it<\/strong> \u2013 even if you didn\u2019t collect it.<\/li>\n\n\n\n<li><strong>Just because we <em>can<\/em> collect data doesn\u2019t mean we <em>should<\/em>.<\/strong> Purpose first.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What data are we talking about?<\/strong><\/h2>\n\n\n\n<p>In charities, data often includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Supporter and donor details<\/li>\n\n\n\n<li>Beneficiary and service\u2011user information<\/li>\n\n\n\n<li>Campaign, fundraising, and volunteering data<\/li>\n\n\n\n<li>Staff and trustee data<\/li>\n\n\n\n<li>Monitoring, evaluation, and impact data<\/li>\n<\/ul>\n\n\n\n<p>Some of this can be sensitive \u2014 especially beneficiary and safeguarding\u2011related data.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Common charity\u2011specific nuances (the bits that catch people out)<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Fundraising vs engagement<\/strong><\/h3>\n\n\n\n<p>Just because someone donated doesn\u2019t always mean we can contact them freely. Consent, opt\u2011in, and expectations matter \u2014 especially across channels.<\/p>\n\n\n\n<p><em><strong>Tip:<\/strong> When in doubt, check the Privacy Notice or ask before using data for a new purpose.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Beneficiary data needs extra care<\/strong><\/h3>\n\n\n\n<p>Beneficiary data often feels informal (\u201cit\u2019s just notes\u201d), but it can be highly sensitive.<\/p>\n\n\n\n<p><em><strong>Tip:<\/strong> Write notes as if the person could read them one day.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Spreadsheets are still systems<\/strong><\/h3>\n\n\n\n<p>Excel files, Google Sheets, and downloads from CRMs are still data systems.<\/p>\n\n\n\n<p><em><strong>Tip:<\/strong> If you wouldn\u2019t leave it on a train, don\u2019t leave it unsecured on your laptop.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. Sharing data with partners<\/strong><\/h3>\n\n\n\n<p>Working with agencies, consultants, or delivery partners is common.<\/p>\n\n\n\n<p><em><strong>Tip:<\/strong> If you\u2019re sending data outside the organisation, pause and check there\u2019s a clear reason and agreement in place.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>5. \u201cWe might need it later\u201d isn\u2019t a reason<\/strong><\/h3>\n\n\n\n<p>Holding on to data \u201cjust in case\u201d increases risk and workload.<\/p>\n\n\n\n<p><em><strong>Tip:<\/strong> If you don\u2019t know why you\u2019re keeping it, that\u2019s a sign it may be time to let it go.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Good everyday habits<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Only access data you need for your role<\/li>\n\n\n\n<li>Keep records accurate and up to date<\/li>\n\n\n\n<li>Lock screens and protect passwords<\/li>\n\n\n\n<li>Use approved systems, not personal accounts<\/li>\n\n\n\n<li>Report mistakes or near\u2011misses early \u2014 it\u2019s about learning, not blame<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>If something goes wrong<\/strong><\/h2>\n\n\n\n<p>Mistakes happen. What matters is acting quickly.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Tell your manager or the data lead straight away<\/li>\n\n\n\n<li>Don\u2019t try to fix or hide it yourself<\/li>\n\n\n\n<li>Early reporting helps protect people and the organisation<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The takeaway<\/strong><\/h2>\n\n\n\n<p>Good data practice isn\u2019t about fear or red tape. It\u2019s about:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Respecting the people behind the data<\/li>\n\n\n\n<li>Making better decisions<\/li>\n\n\n\n<li>Protecting trust in our charity<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">If you\u2019re unsure&#8230;<\/h2>\n\n\n\n<p>Ask. That\u2019s always the right first step.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h1 class=\"wp-block-heading has-text-align-center\"><strong>Data Policy \u2013 Starter Template<\/strong><\/h1>\n\n\n\n<p class=\"has-text-align-center\"><strong>Copy and use this starter template as a foundation \u2013 adapt it to fit your charity\u2019s needs and context<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\">Want a downloadable version?<\/p>\n\n\n\n<div class=\"wp-block-uagb-buttons uagb-buttons__outer-wrap uagb-btn__default-btn uagb-btn-tablet__default-btn uagb-btn-mobile__default-btn uagb-block-291ab33e\"><div class=\"uagb-buttons__wrap uagb-buttons-layout-wrap \">\n<div class=\"wp-block-uagb-buttons-child uagb-buttons__outer-wrap uagb-block-05b87a4c wp-block-button\"><div class=\"uagb-button__wrapper\"><a class=\"uagb-buttons-repeater wp-block-button__link\" aria-label=\"\" href=\"https:\/\/actuallydata.net\/craft\/wp-content\/uploads\/2026\/01\/Data-Policy-Starter-Template.docx\" rel=\"follow noopener\" target=\"_blank\" role=\"button\"><div class=\"uagb-button__link\">Download .docx Version<\/div><\/a><\/div><\/div>\n\n\n\n<div class=\"wp-block-uagb-buttons-child uagb-buttons__outer-wrap uagb-block-0909e8d8 wp-block-button\"><div class=\"uagb-button__wrapper\"><a class=\"uagb-buttons-repeater wp-block-button__link\" aria-label=\"\" href=\"https:\/\/actuallydata.net\/craft\/wp-content\/uploads\/2026\/02\/Data-Policy-Starter-Template.pdf\" rel=\"follow noopener\" target=\"_blank\" role=\"button\"><div class=\"uagb-button__link\">Download .pdf Version<\/div><\/a><\/div><\/div>\n<\/div><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"padding-top:0;padding-bottom:0\">\n<div class=\"wp-block-group has-ast-global-color-5-background-color has-background is-layout-constrained wp-container-core-group-is-layout-a0135418 wp-block-group-is-layout-constrained\" style=\"border-top-left-radius:10px;border-top-right-radius:10px;border-bottom-left-radius:10px;border-bottom-right-radius:10px;padding-top:var(--wp--preset--spacing--50);padding-right:var(--wp--preset--spacing--50);padding-bottom:var(--wp--preset--spacing--50);padding-left:var(--wp--preset--spacing--50)\">\n<p><strong>Data Use and Access Policy<\/strong><\/p>\n\n\n\n<p><strong>Organisation Name:<\/strong> [Insert Charity Name]<br><strong>Version:<\/strong> 1.0<br><strong>Approved by:<\/strong> [Board \/ SMT]<br><strong>Date Approved:<\/strong> [DD\/MM\/YYYY]<br><strong>Next Review Date:<\/strong> [DD\/MM\/YYYY]<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>1. Purpose<\/strong><\/p>\n\n\n\n<p>This Data Policy sets out how [Organisation Name] collects, uses, manages, shares, and protects data. Its purpose is to ensure that data is treated as a valuable organisational asset, used responsibly, lawfully, and effectively to support our mission and improve outcomes for the people and causes we serve.<\/p>\n\n\n\n<p>This policy provides a clear framework for decision\u2011making, accountability, and good practice across the organisation.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>2. Scope<\/strong><\/p>\n\n\n\n<p>This policy applies to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>All staff, trustees, contractors, consultants, and volunteers<\/li>\n\n\n\n<li>All data created, collected, processed, or stored by the organisation<\/li>\n\n\n\n<li>All systems, tools, platforms, and formats (including paper records, spreadsheets, databases, and cloud systems)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>3. Principles<\/strong><\/p>\n\n\n\n<p>[Organisation Name] manages data in line with the following principles:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Lawful and Fair Use<\/strong> \u2013 Data is collected and processed in line with relevant legislation and regulatory guidance.<\/li>\n\n\n\n<li><strong>Purpose\u2011Driven<\/strong> \u2013 Data is collected for clear, defined purposes that support organisational objectives.<\/li>\n\n\n\n<li><strong>Proportionate<\/strong> \u2013 We only collect data that we genuinely need.<\/li>\n\n\n\n<li><strong>Accurate and Reliable<\/strong> \u2013 Reasonable steps are taken to ensure data is accurate and kept up to date.<\/li>\n\n\n\n<li><strong>Secure<\/strong> \u2013 Data is protected against unauthorised access, loss, or misuse.<\/li>\n\n\n\n<li><strong>Accessible and Useful<\/strong> \u2013 Data is made available to those who need it to do their role effectively.<\/li>\n\n\n\n<li><strong>Accountable<\/strong> \u2013 Clear ownership and responsibility for data is defined.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>4. Data Types Covered<\/strong><\/p>\n\n\n\n<p>This policy covers, but is not limited to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Personal data<\/li>\n\n\n\n<li>Special category data<\/li>\n\n\n\n<li>Supporter and beneficiary data<\/li>\n\n\n\n<li>Staff and volunteer data<\/li>\n\n\n\n<li>Financial and transactional data<\/li>\n\n\n\n<li>Monitoring, evaluation, and impact data<\/li>\n\n\n\n<li>Operational and performance data<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>5. Legal and Regulatory Framework<\/strong><\/p>\n\n\n\n<p>[Organisation Name] complies with all relevant data protection and information governance legislation, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>UK General Data Protection Regulation (UK GDPR)<\/li>\n\n\n\n<li>Data Protection Act 2018<\/li>\n\n\n\n<li>Privacy and Electronic Communications Regulations (PECR)<\/li>\n<\/ul>\n\n\n\n<p>Related policies include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Privacy Notice<\/li>\n\n\n\n<li>Data Retention Policy<\/li>\n\n\n\n<li>Information Security Policy<\/li>\n\n\n\n<li>Acceptable Use Policy<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>6. Roles and Responsibilities<\/strong><\/p>\n\n\n\n<p><strong>Board of Trustees<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide oversight and assurance that data is managed responsibly.<\/li>\n\n\n\n<li>Approve this policy and any material changes.<\/li>\n<\/ul>\n\n\n\n<p><strong>Senior Management Team<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensure this policy is implemented and resourced appropriately.<\/li>\n\n\n\n<li>Promote a positive data culture across the organisation.<\/li>\n<\/ul>\n\n\n\n<p><strong>Data Owner(s)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Accountable for specific datasets or systems.<\/li>\n\n\n\n<li>Ensure data quality, appropriate access, and compliance.<\/li>\n<\/ul>\n\n\n\n<p><strong>All Staff and Volunteers<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Follow this policy and related procedures.<\/li>\n\n\n\n<li>Complete relevant training.<\/li>\n\n\n\n<li>Report data breaches or concerns promptly.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>7. Data Collection<\/strong><\/p>\n\n\n\n<p>Data is collected:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>For clear, legitimate purposes<\/li>\n\n\n\n<li>Using fair and transparent methods<\/li>\n\n\n\n<li>With appropriate consent or lawful basis<\/li>\n<\/ul>\n\n\n\n<p>We aim to collect data at the right level of detail and avoid unnecessary duplication.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>8. Data Quality<\/strong><\/p>\n\n\n\n<p>[Organisation Name] is committed to maintaining good data quality. This includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Clear definitions and standards<\/li>\n\n\n\n<li>Routine checks for accuracy and completeness<\/li>\n\n\n\n<li>Processes for correcting errors<\/li>\n<\/ul>\n\n\n\n<p>Data quality issues should be reported to the relevant Data Owner.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>9. Data Storage and Security<\/strong><\/p>\n\n\n\n<p>Data is stored securely using approved systems and tools. Controls include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Role\u2011based access<\/li>\n\n\n\n<li>Strong passwords and multi\u2011factor authentication where available<\/li>\n\n\n\n<li>Regular backups<\/li>\n\n\n\n<li>Secure disposal of data when no longer required<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>10. Data Sharing<\/strong><\/p>\n\n\n\n<p>Data is only shared:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where there is a lawful basis<\/li>\n\n\n\n<li>With appropriate safeguards in place<\/li>\n\n\n\n<li>In line with data sharing agreements where required<\/li>\n<\/ul>\n\n\n\n<p>Third\u2011party processors are assessed for compliance and security.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>11. Data Retention and Disposal<\/strong><\/p>\n\n\n\n<p>Data is retained only for as long as necessary and in line with the organisation\u2019s Data Retention Policy. When data is no longer required, it is securely deleted or destroyed.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>12. Data Breaches and Incidents<\/strong><\/p>\n\n\n\n<p>All suspected or actual data breaches must be reported immediately in line with the organisation\u2019s Data Breach Procedure. Appropriate action will be taken to assess, mitigate, and report incidents where required.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>13. Training and Awareness<\/strong><\/p>\n\n\n\n<p>[Organisation Name] ensures that staff and volunteers receive appropriate training to understand their data responsibilities and maintain good data practices.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>14. Review and Maintenance<\/strong><\/p>\n\n\n\n<p>This policy will be reviewed at least annually, or sooner if there are significant changes to legislation, systems, or organisational activities.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>Approval<\/strong><\/p>\n\n\n\n<p>This Data Policy was approved by:<\/p>\n\n\n\n<p>Name: ________________________<br>Role: ________________________<br>Date: ________________________<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A One\u2011Page Guide for Charity Teams Good data helps us raise more, reach the right people, stay compliant, and make [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"template":"","meta":{"_acf_changed":false,"content-type":"","pmpro_default_level":"","_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"stream":[12],"crm":[13],"class_list":["post-3115","resource","type-resource","status-publish","hentry","stream-forge","crm-salesforce","pmpro-has-access"],"acf":[],"aioseo_notices":[],"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"Carl Phillips","author_link":"https:\/\/actuallydata.net\/craft\/author\/carl\/"},"uagb_comment_info":0,"uagb_excerpt":"A One\u2011Page Guide for Charity Teams Good data helps us raise more, reach the right people, stay compliant, and make [&hellip;]","_links":{"self":[{"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/resource\/3115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/types\/resource"}],"author":[{"embeddable":true,"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/users\/6"}],"version-history":[{"count":0,"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/resource\/3115\/revisions"}],"wp:attachment":[{"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/media?parent=3115"}],"wp:term":[{"taxonomy":"stream","embeddable":true,"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/stream?post=3115"},{"taxonomy":"crm","embeddable":true,"href":"https:\/\/actuallydata.net\/craft\/wp-json\/wp\/v2\/crm?post=3115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}