Five checks when a charity supplier reports a data incident

A message from a software or service supplier can start a fast-moving response. These five checks help charity trustees establish the facts, protect people and make sound reporting decisions.

The Charity Commission published guidance on 7 August 2026 for charities affected by the Beacon cyber security incident. It encouraged affected charities to consider their duties to the Commission and the Information Commissioner's Office, and to communicate openly with the people affected.1 The same first-response discipline is useful whenever a supplier reports a data incident.

1. Record when your charity became aware

Start a timed incident log. Record when the message arrived, who received it, what the supplier said and which trustee or senior colleague is leading the response.

Ask the supplier for the incident date, discovery date, affected systems, data fields, people, containment steps and next update time. Ask whether anyone accessed or downloaded the data. Mark each point as confirmed, estimated or still unknown. The Information Commissioner's Office says a processor must tell the organisation responsible for the data without undue delay after becoming aware of a breach.2

2. Map the data and contain the risk

Identify which donors, beneficiaries, volunteers, staff or partners may be affected. Note whether the data includes contact details, financial information, health information, safeguarding records or login credentials. Consider the harm that misuse, loss or exposure could cause.

Take proportionate containment steps with the supplier. These may include resetting credentials, ending old sessions, restricting access and preserving evidence. If your charity downloads donation or Gift Aid data from Wonderful.org, the donation data export guide explains what can be exported. Record where your charity keeps those files and who can access them.

3. Make each reporting decision promptly

The ICO says a personal data breach must be reported within 72 hours of awareness when it is likely to create a risk to people's rights and freedoms. A high risk also requires affected people to be told without undue delay. Every personal data breach must be documented, including the facts, effects and remedial action.2

Charity Commission reporting uses a separate test. Trustees should consider a serious incident report when an event causes or risks significant harm to people, the charity's money or assets, its work or its reputation. Trustees remain responsible for deciding whether to report, including when the incident involves a partner or supplier.3 Report suspected cyber crime through Report Fraud in England, Wales and Northern Ireland, or Police Scotland on 101 in Scotland.

4. Give people useful facts

Prepare a short update that says what happened, what information may be involved, what your charity is doing and when people will hear more. Give practical advice when there is a clear action, such as changing a reused password or watching for messages that impersonate the charity.

Direct supporters to an official charity page for updates. Our guide to checking a social media appeal before donating shows the details donors may verify. Check that public contact and campaign information is current using the 30-minute autumn appeal clarity check.

5. Keep the record open until actions are complete

Track decisions, owners and deadlines in the incident log. Record the reasons for each ICO and Charity Commission reporting decision. Add later information from the supplier and keep copies of notices sent to affected people.

Once the immediate risk is controlled, review supplier access, data retention, contracts, backups and the charity's response plan. The Charity Commission recommends a response plan that identifies roles, reporting routes and recovery steps.4 Give trustees a final summary and record the agreed improvements.

Immediate action: open a timestamped incident log now. Add the time your charity first became aware, the response lead, the supplier contact and the next update deadline.

This article provides general information, not legal or data protection advice. Use the current regulator guidance and seek specialist advice for your charity's circumstances.

Further reading

Footnotes

  1. Charity Commission, Guidance for charities affected by the Beacon cyber security incident, published 7 August 2026. Read the guidance.
  2. Information Commissioner's Office, Personal data breaches: a guide. Read the guidance.
  3. Charity Commission, How to report a serious incident in your charity, updated 16 January 2026. Read the guidance.
  4. Charity Commission, Protect your charity from cyber crime, published 27 November 2024. Read the guidance.