Where charities are most vulnerable: Exploring common Data Breaches

Have you ever sent an email to the wrong person? Forgot to BCC a bulk email? Small mistakes like these can happen in seconds, but their consequences could be serious, and sometimes lead to personal data breaches.

Data processing, by nature, carries a degree of risk. Although organisations handling personal data are required by law to manage this risk by implementing data protection measures, unauthorised data incidents or ‘breaches’ can still occur despite best efforts.

In this blog we’ve outlined some of the most common types of breaches experienced by charities (based on sector data and our experience) and provided some measures you can take to prevent or mitigate them:


1) Mis-sent emails or post
One of the most frequent breaches, usually due to simple human error. Recovery is difficult once sent.

Mitigation: Double check recipients, schedule or delay emails so they can be double-checked before they’re sent, and train staff on checking addresses. Remember – email recalls/unsends do not work with external recipients. Have a clear incident response plan.

2) Failure to use BCC
Sending group emails without BCC can expose personal data.
Mitigation: Default to BCC for bulk emails, avoid manually sending where possible and use mailing tools (e.g. CRM platforms), and provide staff guidance on correct email field use.

3) Lost or stolen devices/paperwork
Can expose large volumes of data, especially if unprotected.
Mitigation: Encrypt devices, enforce strong passwords, enable remote wiping of devices, limit stored data on devices and apply clear desk and secure disposal policies. Staff should report immediately.

4) Insecure data storage
Poorly secured physical or digital storage increases breach risk.
Mitigation: Restrict access on a need to know basis, use secure cloud/storage systems, regularly audit permissions and lock physical files.

5) Failure to redact data (e.g. DSARs)
Incomplete redaction can expose third party data and breach the law.
Mitigation: Use redaction tools (not manual deletion alone), apply a second person review and train staff on DSAR handling procedures.

How Hope & May can assist
Hope and May can provide comprehensive advice and support with implementing a data breach policy and procedure, tailored to your organisation. As part of our external DPO service, we can manage your breach reporting requirements from initial report to case conclusion. Please reach out if you would like support with breach management, mitigation or policy drafting.

Website Asset

Get in touch

Login / Register
If you would like to manage your Organisations access to our courses and invite members via group code.

If you want to take courses as an individual.