Financial Controls, Data Protection and Electronic Marketing
Use this section for three areas of compliance that the Charity Commission and the Information Commissioner's Office (ICO) expect every charity to have under control: how money is handled, how personal data is used and how the charity contacts people by email, text and similar means.
What financial controls does a charity need?
The Charity Commission expects trustees to have financial controls that are appropriate to the charity's size and activities. Weak controls are one of the most common causes of loss and regulatory concern. There is an Internal Financial Controls Policy for a Charitable Company Limited by Guarantee, an Internal Financial Controls Policy for a Charitable Incorporated Organisation and an Internal Financial Controls Policy for a Small (Unincorporated) Charity, so choose the one that matches your structure and size. The policy on reporting concerns about fundraising is in the Appeals, Collections and Volunteer Fundraising section.
What does a charity need for data protection?
Charities hold personal data about donors, beneficiaries, volunteers and staff and must comply with UK data protection law in the same way as any other organisation. The Privacy Notice for a Charity (GDPR Compliant) is a template for telling people how the charity uses their personal data.
What are the rules on electronic marketing?
Sending fundraising or campaigning messages by email, text or automated call is subject to specific rules on consent and opt-outs as well as data protection law. The Guidance Note: Charity Electronic Marketing explains what a charity can and cannot do when contacting supporters electronically.
- Guidance Note: Charity Electronic Marketing
- Privacy Notice for a Charity (GDPR Compliant)
- Internal Financial Controls Policy for a Charitable Company Limited by Guarantee
- Internal Financial Controls Policy for a Charitable Incorporated Organisation
- Internal Financial Controls Policy for a Small (Unincorporated) Charity
Financial Controls, Data Protection and Electronic Marketing is part of Charity. Just £38.50 + VAT provides unlimited downloads from Charity for 1 year.
Frequently Asked Questions
Start with the four the Charity Commission most expects: safeguarding if you work with children or adults at risk, internal financial controls, trustee conflicts of interest and an expenses policy. Add complaints and fundraising whistleblowing as you grow. Adopt each by a trustee resolution, minute it and review annually. The templates in this section are drafted for small and medium charities, so adoption is an afternoon's work rather than a project.
Yes, in two ways. The annual return asks registered charities to confirm which key policies and procedures they have, so the absence is formally recorded each year. And when something goes wrong, a complaint, a serious incident or an inquiry, the Commission's first questions are usually what policies existed and whether they were followed. A policy adopted but ignored can be worse than none, so pair each template with a minuted review date and ensure you adopt and actually follow procedures implementing that policy.
Proportionate separation and oversight: two signatories or dual authorisation on payments, someone other than the recorder reconciling the bank, clear cash handling rules, expenses approved by someone other than the claimant and the board seeing regular financial reports. The Commission's guidance stresses controls must operate in reality, not just on paper. The internal financial controls policy templates here implement that guidance at SME charity scale.