Social enterprises interact with personal data at every stage of their work: participant registration forms, interview recordings, testimonials, photos from community events, email lists, funding applications containing beneficiary information. All of this is personal data — and all of it carries legal and ethical responsibilities.
In the European Union, personal data is regulated by the General Data Protection Regulation (GDPR) — one of the strongest privacy laws in the world. GDPR applies to any organisation operating in the EU or handling the data of EU residents. For a social enterprise working with communities — especially vulnerable or marginalised communities — compliance with GDPR is not just a legal necessity. It is an expression of the respect and care that your mission demands.
Many organisations think of GDPR as a collection of forms, consent boxes, and legal obligations. In reality, data protection begins with a simple principle: every piece of personal data belongs to a real person.
Behind every registration form, email address, photograph, or interview recording is someone who has trusted your organisation. Respecting that trust means collecting only what you need, explaining why you need it, and protecting it with the same care you would expect for your own personal information.
Good data protection is therefore not simply about avoiding fines. It is about demonstrating respect, professionalism, and responsibility towards the communities you serve.

Key takeaway: Protect people's data as carefully as you protect their dignity.
1. Lawfulness, fairness, and transparency: you must have a legal basis for collecting data (consent, contract, legal obligation, legitimate interest), collect it fairly, and tell people clearly what you're collecting and why.
2. Purpose limitation: collect data only for a specific, stated purpose. If you collect an email address to send someone a newsletter, you cannot use it for a different purpose without asking again.
3. Data minimisation: collect only the data you genuinely need. Do not ask for information 'just in case' it might be useful.
4. Accuracy: keep data up to date. Remove or correct inaccurate data.
5. Storage limitation: do not keep data longer than necessary. Define in advance how long you will retain different types of data, and delete it when that period ends.
6. Integrity and confidentiality: protect data against unauthorised access, loss, or damage. Use strong passwords, encrypted storage, and limited access controls
7. Accountability: be able to demonstrate that you comply with all six principles above. Keep records of what data you hold, why, and how it is protected.
The most commonly used legal basis for data collection in social enterprises is consent. But not all consent is valid. Under GDPR, consent must meet four conditions:
• Freely given: the person must be able to refuse without negative consequence. If participation in your programme is conditional on agreeing to data collection, the consent is not truly free.
• Specific: consent for one purpose does not cover another. A signature on a workshop registration form is not consent to be photographed, to have your story published, or to be contacted for future campaigns.
• Informed: the person must understand, in plain language, what data is collected, why, how it will be used, who will see it, and how long it will be kept.
• Unambiguous: consent must be expressed through a clear, positive action — a signature, a checkbox that the person actively ticks. A pre-ticked box, silence, or inaction does not constitute consent.
Working with young people under 16: in most EU countries, you must obtain parental or guardian consent before collecting data from anyone under 16. Check the specific rules in your country — the age threshold varies.
Many social enterprises now use AI tools to draft reports, summarise interviews, analyse survey results, or create communication materials. Before uploading any personal information into an AI platform, check:
AI can save time, but it should never replace responsible judgement. Remember that if you upload personal data to an online AI service, you remain responsible for protecting that information.
Data in digital contexts — specific challenges
Digital tools — social media, online forms, email platforms, cloud storage — introduce specific data protection challenges that social enterprises frequently underestimate:
• Third-party platforms: when you use Google Forms, Mailchimp, or a social media platform to collect or store data, that platform may also process the data. Check their privacy policies and choose GDPR-compliant providers.
• Photos and videos: any image in which a person is identifiable is personal data. You need specific consent for each use: website, social media, printed materials, NFTs.
• Blockchain permanence: data written to a blockchain cannot be deleted. This creates a direct tension with GDPR's 'right to erasure'. Never put personal data — names, faces, stories — directly into NFT metadata. Store personal content off-chain, where it can be modified or removed.
Even well-managed organisations sometimes experience mistakes. A laptop may be lost. An email may be sent to the wrong person. A cloud folder may accidentally become public.
The important question is not whether mistakes are possible—but whether your organisation knows how to respond. Good practice includes:
Transparency during mistakes often strengthens trust.
💡 NFT connection
Every element of an NFT project that involves a real person — a portrait, a name, a personal story, a testimonial — is personal data. This means: you need specific written consent for each use, clearly explaining that the content will be minted as an NFT and sold.
You cannot rely on a general consent form. And because blockchain records are permanent, you must be especially careful about what goes on-chain.
If a participant later asks you to delete their data — and they have the legal right to do so — you must be able to honour that request for the off-chain content, and explain honestly why the on-chain record cannot be changed.