During 2015/16, the ICO carried out an investigation into practices in charity fundraising and some charities’ compliance with the laws that protect privacy and prevent nuisance phone calls. This resulted in us fining two charities in December 2016 for breaking the law when handling donors’ personal information. Our investigation into other charities is nearing conclusion.
What have charities been doing?
1. Ranking you based on your wealth.
Some charities profile their donors based on their wealth. They hire companies to investigate income, property values, lifestyle, and even a person’s friendship circles in order to find the most wealthy and valuable donors. These companies also identify donors they believe charities should target because they are most likely to leave money in their wills – they call this legacy profiling.
What’s wrong with that?
Donors are oblivious to this practice. If you don’t know it’s happening, you can’t object.
2. Finding information about you, that you didn’t provide
Some charities hire companies to find missing information or update out of date information in their databases. These companies use information that has been provided by the donor to track down new data or fill in the gaps. For example, they may use your old telephone number to find your new one or they may use your email address to track down your postal address.
What’s wrong with that?
You have a right to choose what personal information you provide and you don’t have to update your details with a charity if you don’t want to. Charities could use the additional information they uncover, which you do not know they have, to contact you for more money.
3. Sharing your data with other charities, no matter what the cause and with no record.
It is common for some charities to exchange donor information, through an external organisation, with other charities to get details of prospective donors.
What’s wrong with that?
You can choose to let charities share your information with other organisations but charities must make it clear who these organisations are – for example an animal charity could ask you to let them share your details with other animal charities or it could name the specific other charities it wants to pass your details to. However some charities don’t know who they are sharing your details with.
So, for example, supporters of animal charities could have their information shared with homeless, humanitarian or religious charities even though the supporters only expected their information to be shared with other animal charities. This is not acceptable data sharing. Some charities don’t know if the information has been shared one or one hundred times. This can result in lots of unwanted charity marketing.
I think I may have been affected, what can I do?
If you’re worried charities have not been handling your personal information properly, you can report your concerns to the Fundraising Regulator at fundraisingregulator.org.uk. The Fundraising Regulator will pass relevant concerns to the ICO.
Can I do anything to protect myself?
You have rights when organisations handle your personal information. When organisations collect your information, they should usually be open about why they are collecting it, only use it in a reasonable way that you would expect, and shouldn't use it in way that is unfair to you.
When giving an organisation your personal details, ask yourself:
- who is collecting the information?
- is it necessary?
- what will be done with it?
- what are the consequences for me?
If the intentions are not clear, ask the company concerned before you give any personal information, especially if it is sensitive. Companies may want to use your personal information to send you marketing or pass your details to other companies for marketing. They should give you the chance to opt in or out of receiving such information.
If you have concerns about how an organisation has handled your information, you should raise your concern with them in the first instance. If the organisation has been unable, or unwilling, to resolve your information rights concern, you can raise the matter with us.
This has made me nervous about personal details I’ve given to other organisations, what should I do?
You have the right to get a copy of the information that is held about you. This is known as a subject access request.
This right of subject access means that you can make a request under the Data Protection Act to any organisation processing your personal data.
I’ve been getting a lot of marketing, not just from charities. How can I make it stop?
You have the right to stop organisations using your information to send you marketing mail, calls, emails and texts. You should get the opportunity to opt in or opt out of receiving such marketing at the point you give your personal details. You should also have the opportunity to change your preference later if you change your mind.