Skip to main content
This website uses essential cookies required for its operation. Course content and all third-party embedded materials are accessible only to registered users. To manage your consent preferences, please register and log in.
x

Section outline

  • What you'll learn:  How to collect and manage personal data responsibly — both as a legal requirement under GDPR and as an ethical obligation to the communities you serve. 

    Why data protection matters for social enterprises 

    Social enterprises interact with personal data at every stage of their work: participant registration forms, interview recordings, testimonials, photos from community events, email lists, funding applications containing beneficiary information. All of this is personal data — and all of it carries legal and ethical responsibilities. 

    In the European Union, personal data is regulated by the General Data Protection Regulation (GDPR) — one of the strongest privacy laws in the world. GDPR applies to any organisation operating in the EU or handling the data of EU residents. For a social enterprise working with communities — especially vulnerable or marginalised communities — compliance with GDPR is not just a legal necessity. It is an expression of the respect and care that your mission demands. 

     

    • Privacy is about people, not paperwork 

      Many organisations think of GDPR as a collection of forms, consent boxes, and legal obligations. In reality, data protection begins with a simple principle: every piece of personal data belongs to a real person. 

      Behind every registration form, email address, photograph, or interview recording is someone who has trusted your organisation. Respecting that trust means collecting only what you need, explaining why you need it, and protecting it with the same care you would expect for your own personal information. 

      Good data protection is therefore not simply about avoiding fines. It is about demonstrating respect, professionalism, and responsibility towards the communities you serve. 

      privacy

      Key takeaway: Protect people's data as carefully as you protect their dignity.

    • Think before you collect 

      One of the simplest ways to comply with GDPR is to ask fewer questions.

      Many organisations collect information because it might become useful one day. In reality, unnecessary data creates unnecessary risk. Every additional piece of information must be stored, protected, updated, and eventually deleted.

      Before adding a question to a registration form, ask yourself:

      • Why do we need this information?
      • Will it help us deliver the project?
      • Could we achieve the same objective without collecting it?
       
      Collecting less data often makes projects safer, simpler, and easier to manage.
    • GDPR — the seven principles in plain language 

      1.     Lawfulness, fairness, and transparency: you must have a legal basis for collecting data (consent, contract, legal obligation, legitimate interest), collect it fairly, and tell people clearly what you're collecting and why.

      2.     Purpose limitation: collect data only for a specific, stated purpose. If you collect an email address to send someone a newsletter, you cannot use it for a different purpose without asking again.

      3.     Data minimisation: collect only the data you genuinely need. Do not ask for information 'just in case' it might be useful.

      4.     Accuracy: keep data up to date. Remove or correct inaccurate data.

      5.     Storage limitation: do not keep data longer than necessary. Define in advance how long you will retain different types of data, and delete it when that period ends.

      6.     Integrity and confidentiality: protect data against unauthorised access, loss, or damage. Use strong passwords, encrypted storage, and limited access controls

      7.     Accountability: be able to demonstrate that you comply with all six principles above. Keep records of what data you hold, why, and how it is protected.

    • Protecting data is not the responsibility of one person—it is part of everyday organisational practice. Simple habits make a significant difference:

      • locking computers when leaving your desk;
      • using strong passwords and two-factor authentication;
      • limiting access to participant information;
      • deleting outdated files regularly;
      • avoiding sharing personal data through unsecured messaging apps.

      Small routines prevent big problems.

    • Consent — the foundation of ethical data collection 

      The most commonly used legal basis for data collection in social enterprises is consent. But not all consent is valid. Under GDPR, consent must meet four conditions:

      •       Freely given: the person must be able to refuse without negative consequence. If participation in your programme is conditional on agreeing to data collection, the consent is not truly free.

      •       Specific: consent for one purpose does not cover another. A signature on a workshop registration form is not consent to be photographed, to have your story published, or to be contacted for future campaigns.

      •       Informed: the person must understand, in plain language, what data is collected, why, how it will be used, who will see it, and how long it will be kept.

      •       Unambiguous: consent must be expressed through a clear, positive action — a signature, a checkbox that the person actively ticks. A pre-ticked box, silence, or inaction does not constitute consent.

       Working with young people under 16: in most EU countries, you must obtain parental or guardian consent before collecting data from anyone under 16. Check the specific rules in your country — the age threshold varies.

    • Consent is an ongoing conversation 

      Obtaining consent is not the end of your responsibility. People should remain free to change their minds. They should know who to contact if they have questions, how they can withdraw consent, and what will happen to their data if they do. 

      This is especially important in long-term community projects, where trust develops over months or years. Consent should therefore be viewed as an ongoing relationship rather than a single signature collected at the beginning of a project. 

    • Artificial intelligence and personal data 

      Many social enterprises now use AI tools to draft reports, summarise interviews, analyse survey results, or create communication materials. Before uploading any personal information into an AI platform, check:

      • Does the platform process your data securely?
      • Is personal information anonymised?
      • Have participants agreed to this use?
      • Could sensitive information be exposed?

      AI can save time, but it should never replace responsible judgement. Remember that if you upload personal data to an online AI service, you remain responsible for protecting that information.

    • Data in digital contexts — specific challenges 

      Digital tools — social media, online forms, email platforms, cloud storage — introduce specific data protection challenges that social enterprises frequently underestimate:

      •       Third-party platforms: when you use Google Forms, Mailchimp, or a social media platform to collect or store data, that platform may also process the data. Check their privacy policies and choose GDPR-compliant providers.

      •       Photos and videos: any image in which a person is identifiable is personal data. You need specific consent for each use: website, social media, printed materials, NFTs.

      •       Blockchain permanence: data written to a blockchain cannot be deleted. This creates a direct tension with GDPR's 'right to erasure'. Never put personal data — names, faces, stories — directly into NFT metadata. Store personal content off-chain, where it can be modified or removed.

       

    • Data breaches happen — be prepared 

      Even well-managed organisations sometimes experience mistakes. A laptop may be lost. An email may be sent to the wrong person. A cloud folder may accidentally become public.

      The important question is not whether mistakes are possible—but whether your organisation knows how to respond. Good practice includes:

      • reporting incidents quickly;
      • informing affected people when necessary;
      • correcting the problem immediately;
      • reviewing procedures to prevent it happening again.

      Transparency during mistakes often strengthens trust.

    • 💡  NFT connection 

      Every element of an NFT project that involves a real person — a portrait, a name, a personal story, a testimonial — is personal data. This means: you need specific written consent for each use, clearly explaining that the content will be minted as an NFT and sold.

      You cannot rely on a general consent form. And because blockchain records are permanent, you must be especially careful about what goes on-chain.

      If a participant later asks you to delete their data — and they have the legal right to do so — you must be able to honour that request for the off-chain content, and explain honestly why the on-chain record cannot be changed. 

    • ✏️  Activity — Lesson 3

      Scenario: You are running a youth programme and want to document participant stories and photos for your annual report, social media, and a potential NFT collection. Work through these decisions:

      1. What specific consent do you need from each participant? Draft a 3-sentence consent statement.

      2. What data will you store on-chain vs off-chain in your NFT project, and why?

      3. A participant asks you to remove all their data after one of their photos has been minted as an NFT and sold. What do you do?

      4. Complete the GDPR Self-Assessment Checklist on the platform and post your score and one action you will take.

Credits …
NFT ❯
ⓘ Lab Description