ChecklistSocial Sector

AI and beneficiary data: a safeguards checklist for nonprofits

Before an AI tool reads case notes, eligibility records or feedback from the people your organization serves, work through four groups of checks: purpose and lawful basis, the impact assessment, vendor and model terms, and how decisions stay with people. Beneficiary data is often special category data about people who cannot easily say no, so the bar sits higher than for donor or staff data. The checklist below is written for that context.

Reviewed 8 min read

On this page
  1. Why beneficiary records need a stricter test than donor records
  2. Purpose, lawful basis and impact assessment checks
  3. Data handling and vendor terms to confirm in writing
  4. Fairness, human decisions and accountability to communities
  5. What to do when a safeguard check fails
  6. Safeguards that slip when a deadline looms
  7. A hypothetical refugee support charity screens a feedback tool
  8. Questions and answers
  9. Sources

Why beneficiary records need a stricter test than donor records

Beneficiary records describe people at their most exposed: health conditions, immigration status, ethnicity, religion, experiences of violence and sometimes biometrics captured at registration. Under the General Data Protection Regulation (EU) 2016/679, data about health, racial or ethnic origin, religious beliefs and biometrics used to identify a person is special category data, which may only be processed under one of the conditions in Article 91.

The relationship matters as much as the data. Someone registering for food aid, shelter or legal help is rarely in a position to refuse a form. The UK Information Commissioner's Office says freely given consent is harder to obtain where there is an imbalance of power2, and the ICRC's Handbook on Data Protection in Humanitarian Action discusses why humanitarian organizations often rely on other legal bases, such as vital interest or public interest, rather than consent5.

AI adds three things to that picture: new copies of the data (prompts, embeddings, logs, fine-tuning sets), new parties (model providers and their subprocessors) and new ways to be wrong at scale. ColdAI designs beneficiary systems with privacy and security practices suited to vulnerable populations7, and this is the list we would work through first. It assumes the GDPR or UK GDPR applies; organizations elsewhere should map each item to their own law, but the questions rarely change.

Purpose, lawful basis and impact assessment checks

Settle these before anyone books a vendor demo.

0 of 7 checked

Data handling and vendor terms to confirm in writing

Most exposure comes from what happens to records after they leave your own systems.

0 of 7 checked

Fairness, human decisions and accountability to communities

0 of 6 checked

What to do when a safeguard check fails

  • If

    The only lawful basis you can find is consent, and people rely on the service.

    Then

    Pause, or redesign the workflow so that declining has no effect on assistance.

    Consent given under pressure is unlikely to be valid, and the loss of trust outlasts the project.

  • If

    The vendor will not commit in the contract to no training on your data.

    Then

    Choose another provider or a deployment you control, such as a model hosted in your own cloud tenancy.

    Policy pages can change without notice; signed terms cannot.

  • If

    Group testing shows one community gets worse results.

    Then

    Limit the tool to tasks where staff check every output for that group, or stop until the gap closes.

    A tool that works for the majority can still deepen exclusion for the people most in need.

  • If

    The DPIA finds high residual risk you cannot reduce.

    Then

    Consult the supervisory authority before processing begins, as Article 36 requires1.

    Going ahead without that consultation is itself a compliance failure.

Safeguards that slip when a deadline looms

The DPIA is written after the pilot

Early signalThe assessment describes a system already in use and recommends no changes.

MitigationMake an approved assessment a gate in procurement and in grant budgets.

Free text leaks identities

Early signalA pseudonymized export still contains names and addresses inside case notes.

MitigationRun automated redaction and have a person spot-check samples before any transfer.

Feedback analysis drifts into profiling

Early signalSentiment scores begin appearing beside individual case files.

MitigationKeep feedback analytics aggregated and separate from case management.

Funder reports draw on personal stories

Early signalCase narratives reach reports without fresh, specific permission.

MitigationKeep a story-consent register and check it at every report; see grant reporting automation.

A hypothetical refugee support charity screens a feedback tool

Questions and answers

Can staff paste case notes into free AI tools?

Generally not. Consumer AI tools sit outside your processor agreements, may retain prompts and may use them to improve models unless a contract says otherwise. Case notes usually contain special category data about identifiable people. Give staff an approved tool covered by a processor contract with no-training terms, and write a short rule with examples of what may and may not be entered.

Do we need consent to analyze beneficiary feedback with AI?

Not necessarily, and consent is hard to rely on when people depend on you. Feedback analysis can often run under legitimate interests or, for public bodies and their delivery partners, a public task basis, supported by a clear notice. Remove identifiers before analysis where possible, keep results aggregated and make sure the impact assessment covers the AI provider.

Do the same data protection rules cover donor data?

The same law applies, but the risk is different. Donor data is rarely special category data and donors do not depend on you, so consent and legitimate interests are workable bases. Electronic marketing rules, such as PECR in the UK, also govern donor email and phone outreach. Beneficiary data needs the stricter controls on this page.

What if our organization works outside the EU and UK?

Map each item to the laws where you operate and where your data is processed. Many countries now have data protection laws built on similar ideas: purpose limits, sensitive data categories, impact assessments and processor contracts. Where local law is weaker, humanitarian and do-no-harm standards such as the ICRC handbook are a sensible floor.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  2. What is valid consent? — Information Commissioner's Office · checked 10 October 2026
  3. Data protection impact assessments (DPIAs) — Information Commissioner's Office · checked 10 October 2026
  4. Data (Use and Access) Act 2025, section 80: Automated decision-making — legislation.gov.uk · checked 10 October 2026
  5. Handbook on Data Protection in Humanitarian Action, third edition — International Committee of the Red Cross · checked 10 October 2026
  6. Handbook on Data Protection in Humanitarian Action, third edition (open access, table of contents) — Cambridge University Press · checked 10 October 2026
  7. Social sector: use cases, delivery process and approach — ColdAI

More in Social Sector

Back to Social Sector

Next step

Get a second view on your AI data protection impact assessment

Send the draft DPIA, the vendor terms and a description of the beneficiary data involved. We will mark the gaps against this checklist and suggest design changes that lower the risk.

Share your DPIA draft