Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
SECTOR 1 JUN 2026 · 3 MIN

Charities, funders and the security section of a grant form

Funders increasingly ask how you protect data. Answer the questions once, keep the evidence to hand, and no volunteer is guessing at midnight before a deadline.

RHODRI EMRYS · ASSURANCE
SHARE LinkedIn X Email
SECTOR cover image

Grant application forms have grown a data-protection and security section, and for a small charity that section arrives at the worst possible time: the night before the deadline, being filled in by a trustee or volunteer who does not know whether the answer is yes. The questions are not unreasonable - funders want to know their money is not about to fund a data breach - but they reward preparation, and they punish the last-minute guess.

The questions repeat between funders more than you would expect. Do you have a privacy notice. Where is personal data stored and who can access it. Do you have a data-protection or safeguarding policy. Are you registered with the ICO if you need to be. What would you do if data were lost. Because they repeat, the sensible move is to answer each one properly once, keep the answer in a shared file, and reuse it - rather than reinventing a plausible sentence under pressure every round.

Each answer should point at evidence, because a strong bid says not just “yes, we have a policy” but “here it is, last reviewed in March, owned by our treasurer”. Keep the privacy notice, the data-handling policy, the list of systems that hold personal information, and your ICO registration reference together in one place. When a volunteer opens that folder, the form becomes a copying exercise, not a research project.

The honest gap for most small charities is not policy, it is access. Personal data on beneficiaries and donors tends to accumulate in personal email accounts, spreadsheets and one long-serving volunteer's laptop, with no clear record of who can see it. Tightening that - shared accounts closed, access limited to who needs it, a second sign-in step on the systems holding the data - is the change that makes the form answers true, not just written.

Do the work outside deadline season and it compounds. The same evidence folder that answers a grant form also answers a funder audit, a data-subject request, and the ICO if the worst happens. It is a few hours of one person's time now against a scramble, or a lost bid, later.

WHAT TO DO
  • ✓Draft answers to the common funder security questions once and store them shared.
  • ✓Keep the privacy notice, data policy, systems list and ICO reference in one folder.
  • ✓Limit who can access personal data and add a second sign-in step to those systems.
  • ✓Note when each policy was last reviewed and who owns it, so answers cite evidence.