aithStar
← Knowledge Hub

Protecting your data: lessons from the Beacon CRM incident — and whether you need to register with the ICO

11 August 2026

  • data-protection
  • compliance
  • governance
  • cyber-security

A recent cyber incident has put charity data firmly back in the spotlight. In late July 2026, Beacon — one of the largest CRM (customer/supporter database) providers used by UK charities — suffered a security incident in which data held on its platform was likely copied, and affected charities were told to act as if their supporters' data may have been taken. It is a stark reminder that faith-based organisations hold a great deal of personal data — on members, donors, volunteers and beneficiaries — and that protecting it, knowing what to do if it's breached, and understanding your legal duties (including whether you must register with the ICO) all matter. This is a practical guide. It is general information, not advice — if you are dealing with an actual breach, take professional and legal advice quickly.

What happened — briefly, and factually

According to reporting and to Beacon's own notifications, in late July 2026 an unauthorised third party used a compromised access key to gain access to Beacon's systems and copy data held there. At the time of reporting there was no evidence that the data had been shared, but it was possible that all of the data on the platform had been downloaded — so affected charities were advised to act as if supporter data had been taken. A large number of charities across many causes were affected, and the Information Commissioner's Office (ICO) confirmed it was aware and assessing reports.

The important point is not about any one provider. Any organisation — or the suppliers it relies on — can suffer a security incident. What separates a manageable event from a crisis is whether you were prepared, and whether you understood your responsibilities. And a crucial principle sits underneath it: if a third party holds personal data on your behalf, you are still responsible for it.

Why this matters for faith-based organisations

Faith communities hold some of the most sensitive personal data there is: congregation and membership lists, donor records (including the names and addresses tied to Gift Aid), volunteers, and beneficiaries — some of whom may be vulnerable, or known to you through pastoral care, safeguarding or financial hardship. This is exactly the kind of data that causes real harm if it leaks. Protecting it is both a legal duty and a matter of the trust your community places in you.

Do you need to register with the ICO?

This is where many faith organisations are unsure — so let's be clear. Charities that process personal data must comply with data protection law, and there is no blanket exemption for charities.

  • If your organisation is a controller of personal data — meaning you decide how and why personal data (about members, donors, volunteers, staff or beneficiaries) is used, which most organisations do — you generally must register with the ICO and pay the data protection fee.
  • The fee is tiered by size — currently from around £52 a year for the smallest organisations, rising for larger ones. The exact amount depends on your size and turnover.
  • There is a narrow not-for-profit exemption from the fee — but it is limited and does not apply to many charities, and even if you are exempt from the fee you are still fully bound by data protection law.
  • The ICO provides a free self-assessment tool to check whether you need to register and pay. Use it — failing to register when you should is itself unlawful.

If you're not sure whether you're registered, check — it takes minutes, and it's the kind of basic compliance that regulators (and a breach investigation) will look at first.

How to protect the personal data you hold

Good data protection is mostly good habits:

  • Know what you hold. Keep a simple record of what personal data you have, where it lives (including on any third-party systems), who can access it, and how long you keep it.
  • Collect and keep only what you need, and securely delete what you don't.
  • Control access and secure it well. Strong, unique passwords, two-factor authentication, access limited to those who need it — and, as the Beacon incident shows, take particular care of access keys and API credentials, rotating them and storing them securely.
  • Check your suppliers. Before trusting a CRM, mailing tool or cloud service with your data, do some due diligence on its security, and put a written data processing agreement in place. Their breach can become your problem.
  • Keep software updated, and back up your data.
  • Train your people — most breaches involve human error or phishing, not just hacking.
  • Have a privacy notice and a lawful basis for what you do with people's data.

If a breach happens — what to do

Have a simple plan ready before you need it:

  1. Contain and assess — what data, whose, and what is the risk to those people?
  2. Notify the ICO within 72 hours of becoming aware, unless the breach is unlikely to pose a risk to people's rights and freedoms. (Don't wait until you have every detail — report on time and update.)
  3. Tell the affected individuals if there is a high risk to them.
  4. Record the breach — even if it isn't reportable, keep a log.
  5. If it's your supplier that's been breached (as with Beacon), remember that you, as controller, still have your own duties — assess the risk to your people, report and inform as needed, and act on the supplier's guidance rather than assuming they've handled everything for you.
  6. Consider a serious-incident report to the Charity Commission where the thresholds are met (our serious-incident reporting template can help), and take professional advice.

📄 Download a data breach response plan template — an editable plan to adapt and keep ready, covering roles, the first hour, risk assessment, the 72-hour ICO notification, telling those affected, supplier breaches, and your breach log.

The bottom line

The Beacon incident is a wake-up call, not a reason to panic: faith organisations hold precious, sensitive personal data, and looking after it is both a legal duty and a matter of trust. Know what you hold, secure it, check your suppliers, register with the ICO if you need to, and have a breach plan ready. Get those basics right, take advice on the rest, and you protect not just your data but the confidence of the people who share it with you.


This article is general information, not advice. Data protection law is detailed and fact-specific, and a live breach needs prompt, specialist handling — always check the current ICO guidance and take professional and legal advice on your own situation. For help getting your data-protection basics and governance in order, get in touch.

Sources verified (August 2026):

  • Civil Society Media — Charities' data likely copied in cybersecurity incident, Beacon CRM warns — https://www.civilsociety.co.uk/news/charities-data-likely-copied-cybersecurity-incident-crm-warns.html
  • Third Sector — Charities' data 'likely' to have been downloaded in security breach, CRM company warns — https://www.thirdsector.co.uk/charities-data-likely-downloaded-security-breach-crm-company-warns/digital/article/1966538
  • Bates Wells — Beacon CRM cybersecurity incident: what charities should do now — https://bateswells.co.uk/updates/beacon-crm-cybersecurity-incident-what-charities-should-do-now/
  • ICO — Data protection fee: registration FAQs and self-assessment — https://ico.org.uk/for-organisations/data-protection-fee/
  • ICO — Personal data breaches: a guide (including the 72-hour reporting duty) — https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/