The G.P.S. Guide to Charity Safety: Navigating the 2026 GDPR & Online Safety Updates
Event Details
A 90-min online session including Q&A The 2026 GDPR Updates: Most charities are still following 2018 rules, but the Data (Use and Access) Act 2025 has changed the game. We’ll discuss relaxed
Event Details
A 90-min online session including Q&A
The 2026 GDPR Updates: Most charities are still following 2018 rules, but the Data (Use and Access) Act 2025 has changed the game. We’ll discuss relaxed cookie pop-up rules and the new “Charitable Soft Opt-in,” which finally allows you to email supporters who show interest in your mission without a complex prior “tick-box,” provided you have the correct 2026 legal basis and opt-outs in place.
G – Governance: Is about knowing exactly who has your data and why. We look at the risks of “Shadow IT”—the dangerous dependence on legacy spreadsheets, confidential notes on personal WhatsApps, or donor lists on unmanaged laptops. We will discuss the mandatory policies that must exist on your website, your lawful basis for processing PII, and how to maintain a complete list of your data controllers and internal processes.
P – Privacy: In 2026 includes a “Duty of Care” under the Online Safety Act. We discuss how to protect your youth and vulnerable members from modern threats like AI deepfakes and cyberflashing. Crucially, we’ll prepare you for the June 19, 2026 deadline, by which every charity must provide a digital “Complaints Front Door” to stay compliant with the new Information Commission standards.
S – Security: Is the heart of your technical defense. We move away from vague “IT talk” to a concrete Inventory of Assets. You will learn how to list every device and software tool (your “Assets”), indicate exactly how each is secured (AntiVirus, Encryption, MFA), and critically cross-reference them with Role-Based Access Control (RBAC) to ensure only the right people (e.g., Lead Mentors) touch the right data.
Speaker: Paul Johnson – Specialist Consultant Charity Sector
Paul is a pioneer and forthcoming author of the G.P.S. Model, a streamlined framework designed to help charitable organisations survive the 2026 regulatory shift. With the recent launch of the Data (Use and Access) Act 2025 and the Online Safety Act, he helps non-profits move away from self-certified GDPR compliance by deploying the GPS framework.