“Those who guard their mouths and their tongues keep themselves from calamity.” Proverbs 21:23 (NIVUK)

The amount of data entrusted to us and others, the enabling technology and risk arising from this no doubt go far beyond what the human writer of Proverbs could have envisaged when inspired to write these words. Data is valuable to those rightfully holding it and seeking to use it for God’s glory. It is also valuable to others, seeking to steal and destroy for their own wrongful purposes. The need to be diligent stewards of the data entrusted to us to protect ourselves and others has never been more important.

Recent events have provided a timely warning and reminder of what to do when calamity occurs.

Many will have seen reports of a cybersecurity incident affecting Beacon CRM. Beacon CRM is a widely used customer relationship management platform in the charity sector. According to Beacon CRM, unauthorised access to its systems resulted in copies of customer database backups being obtained by a third party, potentially affecting data held on behalf of over 1,000 charities.

An organisation using Beacon CRM is likely to be the controller of any personal data that it stores on the platform. The key question is not therefore simply whether Beacon CRM or any other supplier has suffered a breach, but whether your organisation consequently has its own legal and regulatory obligations arising from the incident.

What should charities be doing now?

1. Assess whether a personal data breach has occurred that impacts your organisation

Charities that use Beacon CRM should urgently establish:

  • What personal data was stored within Beacon CRM;
  • Whether that data is likely to have been accessed or copied;
  • The categories of data and individuals affected, and the number affected in those categories; and
  • The potential impact on those individuals.

Although Beacon CRM has provided information to customers (and has noted in particular that customers may want to assume that all of the data on Beacon CRM has been downloaded), your charity remains responsible for assessing the risks to the individuals whose data you hold.

2. Consider whether notification to the ICO is required by you

Under the UK GDPR, organisations must notify the Information Commissioner’s Office (ICO) of data breaches, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The notification must generally be made within 72 hours of the organisation becoming aware of the breach. If any of the affected data is special category (‘sensitive’) data, then it is more likely that it will need to be reported. It is also more likely that a report will need to be made where individuals’ contact details have been compromised for potentially criminal purposes, such as using them for cyber-fraud. The ICO has confirmed it is aware of the Beacon CRM incident and is receiving reports from affected organisations.

Charities should document their decision-making process, even where they conclude that notification is not required. This should include considering whether any of the compromised data could be special category data, for example where it might reveal the religious beliefs of the individual.

3. Consider whether affected individuals need to be informed by you

Where a breach is likely to result in a high risk to individuals’ rights and freedoms, organisations may be required to notify affected individuals without undue delay.

The appropriate communication strategy will depend on the nature of the compromised data and the people that have been affected e.g. customers, servicer users or supporters. Careful drafting is important to ensure communications are clear, accurate and appropriate.

See ICO’s guide on personal data breaches for further information.

4. Review whether a Serious Incident Report should be submitted by you

Trustees should consider whether the incident constitutes a serious incident that should be reported to the Charity Commission. Serious data breaches, such as those that are reportable to the ICO would generally also be reported to the Charity Commission as a Serious Incident Report.

Charities should ensure that the issue is escalated appropriately within the charity and that decisions are reasoned and properly recorded.

For further details, see the Charity Commission’s guidance: How to report a serious incident in your charity.

5. How should trustees manage cyber risk?

Trustees should ensure that cyber incidents are treated as governance matters, not simply operational or IT issues. Trustees are responsible for managing the charity’s resources responsibly, including being aware of cyber-crime risks, taking reasonable steps to protect the charity, and responding properly if an attack occurs. Cyber security may be delegated to staff or an IT service provider, but trustees remain responsible for ensuring that appropriate protections are in place.

Are your policies and practices up to date, robust and being followed? Have staff been adequately trained and do they need a refresher?

For further details, see the Charity Commission’s guidance on protecting your charity from cyber crime.

How we can help

Our Data & Privacy team is currently supporting charities affected by this incident. We can assist with:

  • Rapid breach assessments and risk analysis;
  • ICO breach notifications and follow-up correspondence with the ICO;
  • Supporter, donor, volunteer and beneficiary communications;
  • Charity Commission Serious Incident Reports;
  • Advice to trustees on governance and regulatory obligations; and
  • Managing communications with regulators and other stakeholders.

If your charity uses Beacon CRM and would like support in assessing its legal and regulatory obligations, please contact us for urgent advice.

Please do contact us too for all other data protection enquiries too.

Stay updated: Sign up to our newsletter to receive updates on the latest legal news, resources and guidance for your gospel ministry.

This information has been provided by solicitors working for Edward Connor Solicitors. It is designed for the purpose of knowledge sharing only and does not constitute legal advice.

Please give us a call if you want to talk through your requirements and find out how we might be able to help you.

call us email us