Share this article
The charity sector may not be one that people often think about when it comes to information security risk. Yet it is just as important that a charity protects its data, donations, staff and supply chain relationships as any other organisation.
SRM began working with one of the UK’s leading and most recognised medical care charities in 2020, initially to support the IT Security Team. A requirement then arose to provide temporary cover for the role of Head of Information Governance and Security. This was undertaken against the backdrop of the Covid-19 Pandemic at a time when the charity was consolidating its transition to remote working.
Later reporting into charity’s Head of Compliance, SRM Consultant, Andrew Linn, provided ongoing consultancy support in Information Security as the organisation looked to fill newly identified roles and maintain the Data Security and Protection Toolkit (DSPT) and remote gaming technical standard compliance.
More broadly, SRM’s team of QSAs provided support and assessment around the charity’s ongoing PCI DSS compliance requirements. With a retail estate of more than 130 shops and regular events at which people can donate, card payments make up a sizeable portion of all money raised by the charity – which totalled £170 million in 2021. As a result, careful management of contactless devices and PDQ machines is essential to the charity, with regular training and reviews conducted throughout the year.
In addition, charities like our client raise millions of pounds each year via third-party providers such as JustGiving and GoFundMe for events such as the London Marathon. Working with a fundraising supply chain not only requires careful monitoring and management of suppliers’ information security infrastructure but also demands that sharing of data is handled appropriately.
Andrew Linn explains,
“Part of our role is to not only ensure that correct procedures are followed in the initial collection and processing of donor data but also that onward contact permissions are handled correctly, in line with GDPR best practice.”
As a fundraising charity working in the healthcare space, our client is also required to adhere to a number of other regulations and compliance criteria. These include the NHS Digital Data Security and Protection Toolkit (DSPT), and the Remote Gambling and Software Technical Standards (RTS). The latter is required for the running of the charity’s weekly lottery.