Charities routinely process personal data relating to donors prospective supporters, beneficiaries, employees, trustees, volunteers, suppliers and other contracts. For obvious reasons, the information that charities hold is of critical importance to them, particularly in respect of fundraising and marketing, service delivery and administration. With modern legislation now affecting how such data is stored and disseminated this collection of data is subject to data protection and electronic marketing law. Charities must have an eye on their legal responsibilities in this regard. The concept of data protection is extremely wide but charities should be familiar with: • the Data Protection Act 2018 (DPA 2018) • the General Data Protection Regulation (EU) (Retained Regulation (EU) 2016/679 (UK GDPR)) • Privacy and Electronic Communications (EC Directive) Regulations 2003, SI 2003/2426 (PECR) • the Data (Use and Access) Act 2025 (DUAA 2025), which amended the UK GDPR, DPA 2018 and PECR The UK GDPR regime is the replacement to the preceding regime under the General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), following Brexit. The DPA 2018 was originally