Donor records, beneficiary case files and volunteer rosters are all personal data. Charitable purpose does not exempt you from the Act.
In short
An NGO that decides why and how it collects donor, beneficiary or volunteer data is a Data Fiduciary under the DPDP Act, with the same core duties as any company: lawful consent, data minimization, security and breach reporting. There is no blanket exemption for charities. Where you serve children or vulnerable groups, or receive foreign grants, extra duties apply.
The obligations that most often bite for non-profits.
Fundraising lists, donation receipts and beneficiary intake all need a clear purpose and consent. A donor consenting to a receipt has not consented to years of appeal mail.
Field teams often gather far more than required. Tie every field on an intake form to a stated purpose, and drop identity documents you do not truly need to keep.
Programmes for children under 18 trigger verifiable parental consent and a ban on tracking or targeting. Case data on at-risk adults is high-risk and needs tighter access.
Sharing beneficiary or donor data with an overseas funder, HQ or platform is a cross-border transfer. It is allowed by default, but grant agreements and any sectoral rules still bind you.
The same five moves, sized for a non-profit.
List donor, beneficiary, volunteer and staff data, and where each lives.
Rework donation and intake forms so each purpose is clear and separable.
Stop collecting documents you do not need; set retention for what you keep.
Limit who can open case files; encrypt exports and backups.
Be ready to honour access and erasure requests and to report a breach.
Run the free readiness check for a gap report sized to your organisation.
Take the readiness check →