Affected charities will be working at pace on the data protection issues raised and will be considering reporting to the ICO and to data subjects if they have not already done so. This guidance is an important reminder to also consider reporting to the Charity Commission.
Charity trustees are responsible for reporting to the Charity Commission adverse events which result in or risk significant harm, loss or damage to their charity, its beneficiaries, assets, services, or reputation. The Commission asks trustees to follow its existing guidance.
The Commission stops short of saying that charities must report to them if affected. It expects trustees to apply its guidance. Trustees will be well placed to evaluate the risk of significant harm, loss or damage and they should record their considerations and decision making. These records will be particularly important for charities that decide not to report in case they are asked why.
When applying the guidance, it is useful to bear in mind:
- If the threshold for reporting to both the ICO and the Commission is met, it is important that you ensure you report to both. The ICO can share information with the Commission and the Commission has said it is in contact with the ICO, but each has a separate reporting process, with its own thresholds and with its own content needs.
- In an easily missed examples table separate from the main guidance, reporting a data breach to the ICO is given as a positive example of something to report to the Charity Commission. According to the examples table, if you report to the ICO, you should also report to the Charity Commission.
- The Commission says it expects the volume of reports to affect how long it takes to respond. The circumstances of each affected charity will be different, but if the Commission is thinking in these terms, it is clearly anticipating a great many charities will decide that they need to report.
Please do not hesitate to get in contact with us for assistance with charity regulation and data protection.