You’re onboarding three new volunteers next week. One will help answer enquiries via email, another will file documents in SharePoint, and a third will coordinate a campaign in Teams.
You want to add them immediately so they can start contributing, but you are questioning: will they automatically see the trustee meeting notes? Financial records? Beneficiary names? What should and shouldn’t they access?
These are reasonable questions. Volunteers are fundamental to the work of charities, but giving someone access to the wrong email account, folder or Microsoft Teams channel can expose far more information than intended.
In many systems, adding a person to a shared workspace gives them access to everything previously stored there. This can include previous conversations, uploaded files and documents that were never meant for volunteer use.
Safeguarding charity data does not mean distrusting volunteers or making their roles needlessly difficult. It means protecting beneficiaries, donors, employees, trustees and volunteers by ensuring that each person can access the information they genuinely need and nothing more.
This article explains which types of charity data need protecting, how to make consistent access decisions, and when access should be controlled. By the end, you will have a practical framework you can use whenever you onboard or offboard a volunteer.
Why GDPR Matters When Volunteers Handle Data
Many charities assume the General Data Protection Regulation, or GDPR, applies mainly to marketing databases, mailing lists or formal data collection. When, it applies whenever your organisation processes personal data.
Personal data is any information that identifies, or could be used to identify, a living person. This includes clear details such as names, email addresses, telephone numbers and home addresses.
It can also include identification numbers, photographs, location information, online identifiers and information about somebody’s personal circumstances.
If a volunteer can see a beneficiary’s telephone number, an employee’s email address, a donor’s contact details or another volunteer’s emergency contact information, they are handling personal data.
Your charity continues to be responsible for protecting that information, even when the volunteer did not collect it personally. Volunteers are not exempt purely because they are unpaid, and smaller charities are not excluded because they have limited staff, funding or technical resources.
In most cases, the charity is the data controller. This means it determines why personal data is collected, how it is used, how long it is retained and who can access it.
Being responsible does not mean every volunteer coordinator must become a data protection specialist. It does mean that access decisions should be deliberate, documented and proportionate.
Before allowing volunteers to process personal information, your charity should recognise its lawful basis for doing so. The appropriate lawful basis will depend on the purpose and circumstances.
Your privacy information should also explain how relevant personal data is used.
The Information Commissioner’s Office explains that organisations must follow principles including lawfulness, fairness, transparency, data minimisation and appropriate security. The accountability principle also expects organisations to take responsibility for compliance and demonstrate the measures they have put in place.
A useful founding point is Qlic’s charity-focused guide to GDPR, which explains core data protection responsibilities in practical terms.
Charities reviewing their wider compliance arrangements can also work through the right GDPR steps rather than treating volunteer access as an isolated IT issue.
The fundamental principle is simple: do not default to “let them see everything”. Begin with the volunteer’s role, identify the information needed to fulfil it, and grant access accordingly.
What Data Should Volunteers Not Typically Access?
Many charities assume the General Data Protection Regulation, or GDPR, applies mainly to marketing databases, mailing lists or formal data collection. When, it applies whenever your organisation processes personal data.
Personal data is any information that identifies, or could be used to identify, a living person. This includes clear details such as names, email addresses, telephone numbers and home addresses.
It can also include identification numbers, photographs, location information, online identifiers and information about somebody’s personal circumstances.
If a volunteer can see a beneficiary’s telephone number, an employee’s email address, a donor’s contact details or another volunteer’s emergency contact information, they are handling personal data.
Your charity continues to be responsible for protecting that information, even when the volunteer did not collect it personally. Volunteers are not exempt purely because they are unpaid, and smaller charities are not excluded because they have limited staff, funding or technical resources.
In most cases, the charity is the data controller. This means it determines why personal data is collected, how it is used, how long it is retained and who can access it.
Being responsible does not mean every volunteer coordinator must become a data protection specialist. It does mean that access decisions should be deliberate, documented and proportionate.
Before allowing volunteers to process personal information, your charity should recognise its lawful basis for doing so. The appropriate lawful basis will depend on the purpose and circumstances.
Your privacy information should also explain how relevant personal data is used.
The Information Commissioner’s Office explains that organisations must follow principles including lawfulness, fairness, transparency, data minimisation and appropriate security. The accountability principle also expects organisations to take responsibility for compliance and demonstrate the measures they have put in place.
A useful founding point is Qlic’s charity-focused guide to GDPR, which explains core data protection responsibilities in practical terms.
Charities reviewing their wider compliance arrangements can also work through the right GDPR steps rather than treating volunteer access as an isolated IT issue.
The fundamental principle is simple: do not default to “let them see everything”. Begin with the volunteer’s role, identify the information needed to fulfil it, and grant access accordingly.
What Data Should Volunteers Not Typically Access?
The simplest way to protect sensitive information is not to set a separate restriction on every individual file. A more sustainable approach is to identify categories of data that should not be consistently available to volunteers and store them in separate, controlled locations.
Most volunteers will never need to access certain information. Where a specific volunteer does need it for a legitimate purpose, the charity can grant targeted access with suitable safeguards.
Beneficiary data
Beneficiary records could contain names, addresses, contact details, health information, case notes, needs assessments or details of a person’s family circumstances.
An event volunteer almost never needs the charity’s full beneficiary list. A befriending volunteer may need the name and contact details of the person they have been assigned to support, but they do not need access to information about every additional beneficiary.
Access should be limited to the smallest amount of information required for the role. Where possible, volunteers should receive assigned records rather than access to the full beneficiary database.
Financial records
Bank statements, payment information, payroll records, salary details, expense claims and financial forecasts should normally remain within restricted finance or leadership areas.
A volunteer helping to send donor thank-you letters might need a list of names, addresses and donation dates. That does not necessarily mean they need to see bank statements, major donor records, full giving histories or the charity’s wider financial position.
Trustee minutes and board discussions
Trustee minutes, board papers and leadership discussions may include confidential information about strategy, staffing, financial risk, complaints, partnerships or safeguarding matters.
These are leadership conversations. Volunteers should not typically have access to trustee spaces merely because the documents are held in the same SharePoint site or Microsoft Team as general charity information.
Safeguarding records
Safeguarding files should be available only to designated safeguarding leads, senior management and others with a specific, authorised need.
A safeguarding record may contain highly sensitive information about children, vulnerable adults, alleged perpetrators, witnesses or family members. Storing these records in a general volunteer folder creates an preventable and serious risk.
HR and staff information
A volunteer providing administrative support does not commonly need access to staff performance reviews, sickness records, disciplinary information, employment contracts or confidential HR correspondence.
Even apparently routine information such as staff rotas may reveal details about absence, working patterns or personal circumstances. HR information should therefore be stored distinctly from general operational documents.
Donor information
Fundraising volunteers may require donor contact information for a campaign or event, but that does not mean they need unrestricted access to the full donor database.
Major donor records can contain giving history, wealth indicators, relationship notes, personal interests and future fundraising strategy. Present only the fields and records necessary for the task.
Legal documents and insurance policies
Contracts, legal advice, dispute records, insurance claims and policy documentation should usually remain in leadership-only or authorised operational spaces.
A volunteer may sometimes need a specific policy or approved document, but that can be shared directly without providing access to the full legal archive.
Funding applications and grant reports
Draft funding applications may disclose strategic priorities, budget pressures, service weaknesses, beneficiary information or plans that have not yet been approved.
A volunteer working on a particular grant may need access to that application, but they should not automatically be able to browse every historic or draft funding document.
When explaining restrictions, frame them positively. You might say: “We protect beneficiary privacy and sensitive donor relationships, which is why some information is kept in staff-only areas.”
This helps volunteers recognise that access controls are part of good governance rather than a reflection of personal mistrust.
Some charities also process special category data, which receives additional protection under UK GDPR. This includes information revealing a person’s race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric identification data, health information, sex life or sexual orientation.
Criminal offence data is subject to separate rules rather than being included within the UK GDPR definition of special category data.
Charities processing special category data must identify both an Article 6 lawful basis and an appropriate Article 9 condition. Those decisions must be documented before processing begins.
This is particularly relevant for charities providing health services, counselling, befriending, domestic abuse support, homelessness services, rehabilitation or support to faith or ethnic communities.
Before creating an account or adding someone to a shared workspace, coordinators must understand what volunteers can access.
Microsoft 365 permissions often operate at workspace level. Adding a volunteer to a Team, SharePoint site or shared mailbox may give them access to previous files, messages and emails stored there.
In Qlic’s Defending the Mission: A Guide to Charity Cyber Security video, Mikey Pruitt explains why charity information must be treated as a core organisational asset:
“The value and importance of the sensitive data that you accrue is your most valuable asset: donor, supporter, and beneficiary information like names, contact details, giving history, and payment methods are your crown jewels. It’s not just data; it’s the foundation of your fundraising efforts, the lifeline that keeps your mission going. Your research ideas and strategies are your intellectual property. It’s the secret sauce that makes your charity unique. Losing control of this data can have serious consequences.”
Separating sensitive information from routine volunteer resources safeguards those “crown jewels” without preventing volunteers from doing meaningful work.
How to Decide What Data a Volunteer Needs
Before granting access, ask one central question:
What data does this volunteer genuinely need to fulfil their role?
Using the same decision-making framework every time saves time, creates consistency and makes your access decisions simpler to explain.
- Question 1: Does this volunteer need this data?
- Yes -> Move to question 2.
- No -> Don’t grant access.
- Unsure -> ask the volunteer’s supervisor or the relevant information owner to confirm the requirement in writing.
The word “need” is vital. Information should not be shared simply because it might be useful one day or because separating it requires additional setup.
For example, a volunteer responding to general enquiries may need access to a dedicated shared mailbox. They do not need access to a chief executive’s inbox or a mailbox containing safeguarding and complaint correspondence.
- Question 2: Is there a safer alternative?
Before providing access to a complete system, Team or SharePoint site, consider alternatives such as:
- Share a specific file via OneDrive (read-only)
- Send weekly email update instead of folder access
- Invite to read-only private Teams channel
In other cases, you could create a dedicated volunteer resource library, export only the records required for a specific activity, remove unnecessary fields from a contact list, or provide an approved template rather than access to the source files.
- Question 3: Can we make it safer?
Where broader access is necessary, further safeguards can reduce the risk These can include:
- Read-only permissions (view, not edit)
- Time-limited access (end date when role ends)
- Extra approval required before sensitive actions
Multi-factor authentication and an organisation-managed account rather than a personal email address can also improve safety.
You can also restrict downloads to unmanaged devices, require extra approval for exports or deletion, and give clear instructions about where information may be stored.
Different volunteer roles require different access. Thinking in terms of roles rather than making every decision from scratch is faster, more consistent and more defensible.
A simple volunteer role access map might look like this:
Volunteer role | What they need access to | What they typically shouldn’t see |
|---|---|---|
Event volunteers | Event planning folder with read-only access and the event calendar | Financial records, beneficiary data, staff discussions and trustee notes |
Fundraising volunteers | Fundraising campaign Teams channel and a read-only donor contact list for relevant events | Major donor strategy, financial records, beneficiary data and internal strategy |
Volunteer coordinator | Volunteer database, email distribution lists and volunteer Teams channels | HR records, finance data, beneficiary case details and trustee notes |
Befriending volunteers | Contact information for their assigned beneficiary only | Other beneficiaries’ data, financial records, organisational strategy and staff discussions |
The access map does not need to be complex. A spreadsheet listing volunteer roles, systems, permitted access, prohibited access, approving manager and review date should be enough.
The map can then support a consistent request process. Before creating an account, record the volunteer’s role, supervisor and requested access.
You should also note whether that access is read-only or editable, why it is needed, who approved it and when it should end or be reviewed.
Qlic’s volunteer access onboarding checklist provides a practical template for collecting this information and documenting volunteer access decisions.
Practical Governance Principles to Protect Volunteer Data
Once you have decided what a volunteer should access, a small number of governance principles can help you safeguard information without overcomplicating onboarding.
Data minimisation
Grant access only to the information needed for the role. Do not provide access to an entire database when a restricted list will do, or to a whole SharePoint site when one folder is enough.
Data minimisation also relates to the information shown within a record. A volunteer arranging transport may need a beneficiary’s name, collection address and telephone number, but not their complete case history.
Separate storage for sensitive information
Store beneficiary information, safeguarding files, financial records, HR documents and trustee papers in spaces that volunteers do not routinely access.
Evident separation is generally easier to maintain than complex file-by-file restrictions. A charity might have one general volunteer resources site, one restricted staff operations site, and separate areas for trustees, finance and safeguarding.
This structure also decreases the risk that somebody accidentally moves a confidential document into a general folder.
Appropriate permission levels
Decide whether the volunteer needs to view, edit, upload, download, delete or share information.
Many volunteers need reference materials but do not need to change them. Read-only access can protect the original version and reduce accidental deletion or editing.
Where editing is necessary, consider limiting it to a working folder rather than the entire document library.
A clear escalation path
Volunteers should know who to contact if they can see information they were not expecting, receive a suspicious email or share something with the wrong person.
They should also know what to do if they lose a device, believe an account has been compromised or are unsure whether information can be downloaded or forwarded.
Provide the name and contact details of a real person or team. A vague instruction to “contact IT” is less useful than a documented process explaining who to call and what details to provide.
Time-limited access
Decide when access should end at the point it is granted.
Some volunteer roles have an evident completion date, such as a six-week campaign or one-day event. Others may need a scheduled review every three, six or twelve months.
Time-limited access avoids temporary permissions from becoming permanent simply because nobody remembered to remove them.
Transparent onboarding
Tell volunteers what they can access, what they cannot access and why. Clarify how to handle personal data, where documents must be stored and whether personal devices may be used.
Give practical examples. Volunteers should know not to forward charity email to a personal account, download beneficiary lists without permission or discuss cases through personal messaging applications.
They must also be encouraged to report unexpected access rather than exploring files to see what they contain.
Clarity helps volunteers make good decisions and reassures them that they are not expected to interpret complicated data protection rules alone.
Planned offboarding
Removing access is part of the volunteer lifecycle, not an administrative afterthought. The onboarding record should make it clear who is accountable for telling IT when the volunteer leaves or changes roles.
These principles can be incorporated into wider data protection guidelines so volunteer access, staff access and trustee responsibilities are managed consistently.
The experience of Silver Salisbury Group demonstrates the value of this structured approach.
The charity had been relying on personal email accounts and manually managed file sharing across its volunteer network. This created problems around consistency, security, accessibility and GDPR compliance.
A Microsoft 365-based approach using SharePoint, organisation-managed email and Teams created a clearer framework for onboarding, access management and document control.
Volunteers gained easier access to current resources, while the organisation improved accountability and reduced the risks associated with personal email attachments and informal sharing.
Good governance does not have to create obstacles. Done properly, it makes volunteering easier because people know where to find information, which version is correct and what they are authorised to do.
Offboarding: The Step Many Charities Miss
A secure onboarding process can be undermined if the charity does not remove access when a volunteer leaves.
A volunteer who has finished their role but can still access email, Teams, SharePoint, OneDrive folders or financial systems presents an ongoing data risk.
They may have no damaging intentions, but their account could be compromised, their device could be lost, or they could continue receiving information they are no longer authorised to see.
A good offboarding process should begin whenever a volunteer’s agreed role ends, they resign, become inactive or move into a different role.
It may also be necessary when the relationship ends suddenly or a safeguarding or conduct concern requires immediate suspension.
The charity should disable or remove the volunteer’s email and system access. They should also be removed from Microsoft Teams, SharePoint sites, shared mailboxes, calendars, OneDrive folders, databases and third-party services.
Relevant documents should be moved to an appropriate owner, and any files stored locally should be reviewed.
Where personal devices have been used, the charity should confirm that charity data has been deleted. Charity-owned equipment should also be returned.
If shared credentials have been used, passwords should be changed. However, shared accounts are best avoided because they make it difficult to identify who accessed or changed information.
Organisation-managed accounts are generally safer because access can be disabled centrally. They also give the charity greater control than personal email accounts that remain outside the organisation’s systems.
The charity should keep a record of what was removed, who completed the task and when it was done.
Offboarding is also an opportunity to check whether the volunteer exported records, created local copies or used a personal device. The aim is not to interrogate the person; it is to close the access loop politely and consistently.
For example:
“Thank you for supporting the campaign. As your role has now ended, we will close your charity account on Friday. Please save any relevant work to the campaign folder and delete any charity information held on personal devices.”
Former volunteers can unintentionally become insider threats when access remains active after their legitimate need has ended.
A documented checklist helps charities treat every departure consistently rather than relying on someone to remember each account manually.
What If Something Goes Wrong?
A data breach is a security incident that results in personal data being accidentally or unlawfully destroyed, lost, altered, disclosed or accessed without authorisation.
It can result from an intentional attack or an honest mistake.
A volunteer may email a beneficiary list to the wrong recipient, lose a laptop containing personal data or have their email account hacked.
A spreadsheet could be shared through a public link, paper records might be left in a public place, or a volunteer could see safeguarding information they were not authorised to access.
Personal data may also be deleted without a backup or uploaded to an unauthorised service.
Not every unexpected event is necessarily a reportable breach. However, suspected incidents should always be escalated promptly so the charity can establish what happened, contain the issue and assess the risk.
The good news is that GDPR does not assume organisations can prevent every incident. It requires them to implement appropriate safeguards and respond correctly when a breach occurs.
Volunteers should know who to contact if they suspect a breach. This should be a named person or clearly identified team rather than an unattended generic inbox.
The charity should then follow a simple response process:
- Contain the incident. This may mean recalling an email, removing a public link, disabling an account, remotely securing a device or asking an unintended recipient to delete information.
- Establish what happened. Identify the information involved, the people affected, who may have accessed it and whether the issue is ongoing.
- Assess the risk to individuals. Consider the sensitivity of the information, the likely consequences and the likelihood that harm will occur.
- Record the incident and decisions. Charities should document personal data breaches, including those that do not require notification.
- Contact the ICO where required. A notifiable breach must be reported without undue delay and, where feasible, within 72 hours of the charity becoming aware of it.
- Notify affected people where necessary. If the breach is likely to create a high risk to individuals’ rights and freedoms, those people must also be informed without undue delay.
This can sound formal, but the immediate response often begins with a few practical phone calls.
Contact your IT support provider, detect the information involved, secure the affected account and decide who else needs to know.
Technical controls can also reduce the likelihood or impact of an incident. Microsoft 365 tools such as access restrictions, retention controls, sensitivity labels and data loss prevention policies can help stop sensitive information being shared inappropriately.
Qlic’s guide explains how to prevent data loss using these protections.
In the video Cyber Security Tips for Charities: Protecting Your Organisation in the Age of AI, Oliver Bradshaw explains how immediate support can help a charity contain an attack:
“If an attack does happen, we recommend you call in to our support team immediately, and then we will work with you to see how far that’s gone, lock down the accounts, and you’d have that dedicated engineer the whole way through until completion, where we would then say, this is what happened. You need to report this to the ICO. We’ve done the steps to make sure it doesn’t happen again.”
Breaches happen to organisations of all sizes. The objective is not to pretend every possibility can be eliminated.
It is to reduce the risk, detect incidents quickly and respond calmly, honestly and transparently.
Having a plan for that conversation, rather than panicking when something goes wrong, is what makes the difference.
Getting Help When You Need It
Volunteer coordinators should not have to make complex access and data governance decisions without support.
The ICO (Information Commissioner’s Office) guidance provides official information about UK GDPR, data protection principles, lawful bases, individual rights, information security and breach reporting.
Trustees and senior leaders can also consult charity commission guidance covering governance, trustee responsibilities, staff, volunteers, finances and charity administration.
Trustees have overall responsibility for the management and administration of their charity. Information governance should therefore be treated as an organisational responsibility rather than left solely to a volunteer coordinator or IT contact.
Where your charity needs practical help, an experienced IT partner can review existing volunteer permissions and identify folders, Teams and systems containing sensitive information.
Ongoing cybersecurity monitoring can add another level of protection by helping the charity identify suspicious activity and respond quickly when something goes wrong.
If you’re reviewing your volunteer onboarding process or planning a move to Microsoft 365, Qlic IT can help you design secure permission structures, configure Teams and SharePoint, review your data governance, and ensure volunteers only have access to the resources they genuinely need.
Qlic IT can also create a documented onboarding process so every volunteer receives the same secure access setup. This eliminates gaps and guesswork while making the experience simpler for coordinators and volunteers alike.
Conclusion
Keeping volunteer data safe does not have to be complicated. The most important step is to make deliberate access decisions from the outset.
Begin by asking what information the volunteer genuinely needs. Check whether a safer alternative is available.
Where access is necessary, use read-only permissions, separate storage, organisation-managed accounts and time limits to reduce risk.
A role-based access map and repeatable onboarding checklist make these decisions faster and more consistent. Planned offboarding then ensures access is removed when the volunteer’s role ends.
You can begin by auditing your current access structure independently, or work with Qlic to design and configure permissions from scratch.
Either way, governance support is available, and you do not have to manage these decisions alone.
Want to get your volunteer access right but not sure where to start?
Qlic specialises in data governance for charities, helping you design secure access frameworks and confidently onboard volunteers. Contact us for expert guidance.


