Regulator issues guidance to charities impacted by Beacon CRM data breach

The Charity Commission has issued guidance to charities affected by a cyber security incident involving online donations and supporter management firm Beacon CRM.

Earlier this week the company said that charities’ data may have been downloaded by a third party as part of a cybersecurity breach.

The regulator is urging trustees at affected charities to follow its guidance on serious incident reporting, which requires them to “report incidents which results in or risks significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation”.

It is also asking charities to consider their obligations to report the incident to the Information Commissioner's Office (ICO), as well as to individuals whose data is stored by Beacon.

Trustees are also being signposted to the Commission’s dealing with cyber crime guidance and the ICO’s guidance.

The advice has been issued after affected a number of charities submitted serious incident reports to the Commission.

“Due to the volume of such reports expected on this matter alongside other incoming reports, it is likely to take longer than usual for the Commission to respond,” said the regulator.

“We appreciate your patience and understanding as we prioritise instances of the greatest risk.”

It added: “We know many Beacon customers have moved promptly to inform their supporters about this incident.

“Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work.

“We appreciate the additional resources charities will need to devote to addressing this issue and the Commission will seek to ensure its own regulatory engagement with affected charities is proportionate, while seeking to ensure trustees are fulfilling their responsibilities.”

Among charities impacted is the British Deaf Association (BDA), which has advised its supporters that information stored by Beacon may have been involved but said that “there is currently no evidence that the information has been published or misused”.

Details involved could have included records of payments and donations, communication preferences, event attendance and notes or attachments, warned the BDA, which has confirmed the incident has been reported to the ICO.



Share Story:

Recent Stories


Beyond the funding squeeze: Using equities to secure your charity’s future
With charities facing increasing financial pressure and traditional income streams under strain, making investments work harder has never been more important. M&G’s Richard Macey and Michael Stiasny join Charity Times to discuss why equities remain a vital long-term asset class for charities, how organisations can balance income generation and growth, and the opportunities the current market environment may offer to help strengthen financial resilience.

Charity Times Awards 2023

Charity Times video Q&A: In conversation with Hilda Hayo, CEO of Dementia UK
Charity Times editor, Lauren Weymouth, is joined by Dementia UK CEO, Hilda Hayo to discuss why the charity receives such high workplace satisfaction results, what a positive working culture looks like and the importance of lived experience among staff. The pair talk about challenges facing the charity, the impact felt by the pandemic and how it's striving to overcome obstacles and continue to be a highly impactful organisation for anybody affected by dementia.