What a health charity needs to do to be compliant
The DSPT applies once you handle NHS patient data or hold NHS and ICB contracts, published by 30 June each year. UK GDPR brings the ICO fee, and a DPO once health data processing is core. Fundraising runs under the new Code and the soft opt-in, and trustees answer to the Charity Commission for cyber incidents.
Reviewed 5 July 2026 · Neil Chandarana, founder, Highguard
Every requirement for a health charity, in plain English.
The DSPT, once NHS data enters the picture
- Triggered by NHS data or contracts
- Publish annually by 30 June
- Scoped to health and care data
Not every charity completes the DSPT. The trigger is handling NHS patient or service-user data, usually through an NHS or ICB contract: at that point you complete the toolkit in the category for charities and NHS business partners, publishing by 30 June each year. The NHS Standard Contract's data-security condition is what makes it a practical requirement, and your publication status is visible to commissioners. The scope is your health and care data, not the whole organisation.
Sources: DSPT Toolkit · NHS Standard Contract
UK GDPR and the ICO fee
- ICO fee renews annually
- DPO required once health data is core
Almost every charity processing personal data pays the annual ICO fee; the narrow not-for-profit exemption rarely covers a charity running services. Records of processing, privacy notices and impact assessments for higher-risk work follow. A Data Protection Officer becomes required when large-scale processing of health data is a core activity, which is the point many health charities cross without noticing.
CQC, if you deliver regulated activities
- Applies to regulated activities only
- Regulation 17 and well-led cover data and cyber
A charity providing treatment, nursing or personal care registers with CQC like any other provider, and carries Regulation 17 duties: accurate, secure records and effective governance, with data and cyber assessed under the well-led question. Advice lines, peer support and research typically fall outside; hands-on care does not.
Fundraising and the soft opt-in
- New Code of Fundraising Practice from Nov 2025
- Charity soft opt-in live since Feb 2026
- Every message needs an opt-out
The new Code of Fundraising Practice, in force from November 2025, embeds data protection into fundraising standards. Separately, the Data (Use and Access) Act extended the soft opt-in to charities from February 2026: you can email or text people who previously supported you without fresh consent, provided every message offers an opt-out. Useful, but only with clean supporter data.
Sources: Fundraising Regulator
Charity Commission and trustee duties
- Serious incident reporting for breaches
- Cyber risk is a trustee duty
Significant data breaches and cyber attacks are reportable to the Charity Commission as serious incidents, and failing to report can itself be a breach of trustee duties. Managing cyber risk is part of trustees' duty to protect the charity, which means trustees need honest reporting on where the organisation stands, not reassurance.
Sources: Charity Commission
Cyber Essentials, when contracts ask
- Driven by procurement, not regulation
- NCSC has funded it for small charities
Cyber Essentials is not universal for charities, but NHS and public-sector procurement increasingly requests it, and the NCSC has run a funded Cyber Essentials programme for small charities in higher-risk sectors. If you bid for commissioned services, expect it to appear in the paperwork and budget time for the technical controls it checks.
Sources: NCSC
Health charity compliance as you grow.
Volunteer-run
ICO fee, UK GDPR basics, clean supporter data and trustees who understand their cyber duty. Small scope, same laws.
Clinical staff
Delivering care brings CQC registration, a DPO as health data processing scales, and a first DSPT publication.
NHS-commissioned
An annual DSPT visible to commissioners, NHS Standard Contract data clauses, and Cyber Essentials on request. Compliance becomes a condition of income.
Health charity compliance, asked and answered.
Do charities need to complete the DSPT?
Charities handling health and care data under NHS or ICB contracts do, in the category for charities and NHS business partners, publishing by 30 June each year. The NHS Standard Contract's data-security condition is what makes it a practical requirement.
Does our charity need a Data Protection Officer?
Once large-scale processing of health data is a core activity, yes. Many health charities cross that line as services grow. The role can be outsourced, but it must be named.
Can we email past donors without consent now?
Since February 2026, yes, under the charitable soft opt-in introduced by the Data (Use and Access) Act. It covers people who previously supported you or expressed interest, and every email or text must offer a clear opt-out.
Is a cyber attack reportable to the Charity Commission?
Significant incidents are. Data breaches and cyber attacks that cause serious harm to the charity, its funds or the people it serves should be reported as serious incidents, and trustees are responsible for making that call.
When is the charity DSPT due?
30 June each year, the same deadline as the rest of the health and care system. The 2025-26 deadline was 30 June 2026; the next is 30 June 2027.
Why this list keeps getting longer.
Somewhere along the way, compliance stopped being about security and became about admin. Portals, spreadsheets, evidence uploaded again and again, policy templates nobody reads.
The result is organisations that are certified but not secure. Teams that are busy but not protected.
It should not work like this. Compliance should be a side effect of good practice. Evidence of the work you already do, not a second job on top of it.
That is why Highguard exists. We are your compliance department. Specialists and AI agents do the work on this page, and you approve every word before anything is submitted.
Every engagement starts with an audit. In your first week you get a report of where you are compliant and where you are exposed, specific to your organisation.
Talk to us →Talk to us.
Book a 15-minute call. We'll show you where you stand and how fast we can get you certified.