“Those who guard their mouths and their tongues keep themselves from calamity” Proverbs 21:23 (NIVUK)
The amount of data entrusted to us and others, the enabling technology and risk arising from this no doubt go far beyond what the human writer of Proverbs could have envisaged when inspired to write these words. Data is valuable to those rightfully holding it and seeking to use it for God’s glory. It is also valuable to others, seeking to steal and destroy for their own wrongful purposes. The need to be diligent stewards of the data entrusted to us to protect ourselves and others has never been more important.
Recent events have provided a timely warning and reminder of what to do when calamity occurs.
Beacon CRM is a widely used customer relationship management platform in the charity sector. As part of their diligent stewardship, charities trusted Beacon CRM to guard their data and keep them safe. There could be no valid criticism of them doing so.
Unfortunately, as many will have seen, there has been a recent cybersecurity incident affecting Beacon CRM. According to them, copies of customer database backups were made and are likely to have been downloaded by an unauthorised third party, potentially affecting data held on behalf of over 1,500 charities. Although Beacon CRM is understood to store data in an encrypted state, they believe that the party responsible for this incident were able to decrypt it before copying it from Beacon CRM’s systems.
An organisation using Beacon CRM is likely to be the controller of any personal data that it stores on the platform. Therefore it is likely that your organisation has legal and regulatory obligations too.
Therefore, there are several areas that charity leaders and trustees should be reviewing.
Assess the impact to your organisation
- Establish whether a personal data breach has occurred.
- What personal data was held on the affected system?
- How many individuals could be affected?
- What categories of data was stored?
- Is any of the data particularly sensitive? Some of the personal data you process can be more sensitive in nature and therefore requires a higher level of protection. The UK GDPR refers to the processing of these data as ‘special categories of personal data’. This includes personal data about an individual’s:
- race;
- ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- and more. See a full list of special categories here: What is personal data? | ICO
- Whether that data is likely to have been accessed or copied;
- The potential negative consequences for the individuals affected.
- The potential financial impact, reputational risk or operational disruption to the charity itself.
Beacon CRM has provided information to customers (and has noted in particular that customers may want to assume that all of the data on Beacon CRM has been downloaded). Irrespective of Beacon CRM’s actions, it is still for your charity to assess how the incident may affect the individuals whose data you hold.
Do you need contact affected individuals?
Many charities who use Beacon CRM’s systems have already communicated the incident to those individuals affected, but it may not be legally necessary to do so. Before deciding what to say, charities should look carefully at who may be affected and what kind of information has been exposed. For example, the position may be different for donors, beneficiaries, service users or supporters. If your assessment shows that people are likely to face a serious risk as a result of the breach, they should be informed promptly. Any communication should explain the position clearly, include the information required under data protection law, and avoid saying more or less than is appropriate.
A charity may conclude that while informing individuals is not a legal requirement, that they should nonetheless do so out of an abundance of caution, not least to alert their supporters to potential risks and the steps that they can take to mitigate these risks. A balance is required, reflecting the personal information that has been affected by a breach, the uncertainty and potential anxiety which personal reporting may cause, and the expectations of a charity’s supporter base in such an incident.
See ICO’s guide on personal data breaches for further information.
Do you need to report the incident to the ICO?
When you’ve had a personal data breach, you must assess the likely risk to people’s rights and freedoms. If a risk is likely, you must notify the Information Commissioners Office (ICO), as soon as possible, and where feasible within 72 hours. Being open and transparent with the ICO at an early stage allows them to deal with breaches efficiently and ensures that they can then help you protect personal information. If any of the affected data is ‘sensitive’ data, then it is more likely that it will need to be reported. It is also more likely that a report will need to be made where individuals’ contact details have been compromised for potentially criminal purposes, such as using them for cyber-fraud.
Although the ICO has reportedly been notified of the Beacon CRM incident by some affected organisations, this does not remove the need for each charity to make its own assessment and report if they decide it’s necessary.
Maintaining a written record of the assessment process and the reason behind any decision is an important part of demonstrating accountability, even where the conclusion is that notification is not required. The assessment process should include considering whether any of the compromised data could be special category data, for example where it might reveal the religious beliefs of the individual.
Should you submit a Serious Incident Report?
Trustees should consider whether the incident constitutes a serious incident that should be reported to the Charity Commission. Serious data breaches, such as those that are reportable to the ICO, should generally also be reported to the Charity Commission as a Serious Incident Report; where a cyber-security incident is reportable to the ICO it is (in our view) highly likely to meet the threshold for reporting as a serious incident to the Charity Commission.
A number of charities affected by the Beacon CRM breach have already submitted serious incident reports to the Commission. As such the Commission have shared this: Guidance for charities affected by the Beacon cyber security incident – GOV.UK
Charities should ensure that the issue is escalated appropriately within the charity and that decisions are reasoned and properly recorded and include an assessment of all the relevant risks to the charity.
Review your own cybersecurity
Following an incident like this, it is important that all those who process personal information on behalf of your charity are vigilant to avoid internet scams and phishing. Are your data protection and cyber security policies and practices up to date, effectively implemented, and regularly reviewed? Have staff been adequately trained and do they need a refresher?
Supporting charities through cyber and data protection challenges
Responding to a data security incident requires more than a technical investigation. Charities must often balance legal obligations, regulatory expectations, governance requirements and reputational considerations, while continuing to deliver services and support beneficiaries.
At Edward Connor Solicitors, we work with charities to navigate these challenges, providing practical advice on regulatory reporting, stakeholder communications, trustee responsibilities and data protection compliance. Whether you are assessing a potential breach or managing the consequences of an incident, obtaining specialist advice at an early stage can help reduce risk and support effective decision-making.
If your charity uses Beacon CRM and would like support in assessing its legal and regulatory obligations, please contact us for urgent advice.
Stay updated: Sign up to our newsletter to receive updates on the latest legal news, resources and guidance for your gospel ministry.
This information has been provided by solicitors working for Edward Connor Solicitors. It is designed for the purpose of knowledge sharing only and does not constitute legal advice.

