Choosing a CRM is usually a decision led by functionality: does it manage referrals well, does it produce the reports funders want, will staff actually use it day to day. Security tends to sit further down the list, treated as a technical detail to sort out later rather than a factor in the decision itself.

What should you be asking?

10 questions every charity should ask...

For most charities, the CRM holds the most sensitive information the organisation has: service user records, case notes, safeguarding concerns, and contact details for people who may be vulnerable.

And yet security is often the last thing anyone asks about when choosing a system, if it comes up at all. Cyber incidents affecting the charity sector are a reminder that a charity's data is only as safe as the systems it sits in, and the suppliers behind them.

The good news: you don't need to be a security expert to do proper due diligence. You just need to ask the right questions, and expect clear answers.

Here are ten worth asking, whether you're choosing a new system or taking a fresh look at your current one.

1. Where is our data stored?

Start simple. Which country hosts your data? Who provides the infrastructure? Is anything ever transferred outside the UK, and are backups kept in the same place?

The answer should be clear and immediate. If a provider can't tell you plainly where your data lives and who can touch the systems it sits on, that tells you something in itself.

2. How is access controlled?

Ask about individual user accounts, role-based permissions, and the ability to restrict access to sensitive records. Multi-factor authentication matters here: stolen or compromised login credentials are one of the most common ways attackers get in, and MFA is exactly the kind of control that blunts it.

It's also worth asking how access is removed when someone leaves. If the answer involves a shared login or a manual workaround, that's a gap.

3. Is our data encrypted?

Ask how data is protected in transit, at rest, and, crucially, within backups. Your provider should be able to explain this in plain terms, and provide technical documentation if your trustees or funders want to see it.

4. How are backups managed?

Backups are the part of CRM security most charities never think about. They shouldn't be: a backup is a complete copy of everything you hold, and it's only useful if it's protected as carefully as the live system.

Ask how often backups are taken, where they're stored, whether they're encrypted, who can access them, and how quickly your data could be restored after an incident. And ask whether restoration is actually tested. A backup that's never been restored is a hope, not a plan.

5. What happens if there's a security incident?

Every charity using a cloud CRM should know the answer to one question: how quickly would we find out?

Under GDPR, charities have 72 hours to report a breach to the ICO once they're aware of it, so a supplier who's slow to notify puts your compliance clock under pressure through no fault of your own.

Ask for the documented incident response process, notification timescales, and how the supplier will support your own data protection obligations. This should all be clear in the contract, not worked out mid-crisis.

6. Who else can access our data?

Most providers use third parties for hosting, support, or other services. These are known as sub-processors, and they're part of your supply chain whether you've heard of them or not.

Ask which third parties can access your data, where they're located, what contractual safeguards are in place, and how you'd be told if the list changes.

7. What security testing is carried out?

Security isn't a firewall and a padlock icon. Ask whether the provider runs penetration testing, vulnerability assessments, security monitoring and regular patching, and whether they hold recognised certifications.

One caveat: treat certifications as part of the picture, not the whole assessment. A certificate on the wall tells you a process was audited; it doesn't tell you how your service is run day to day.

8. How are administrator accounts protected?

Admin accounts are the keys to the kingdom, so they deserve extra scrutiny. Ask whether MFA is enforced for them, whether admin activity is logged, and how privileged access is monitored and reviewed.

Then apply the same logic internally. Every user should have the minimum access needed to do their job: the principle of least privilege. It's one of the cheapest security improvements a charity can make.

9. What happens to our data if we leave?

Security doesn't end when the contract does. Ask whether you can export your data, in what format, whether there's a charge, and, importantly, when the supplier will delete it, including from backups. Can they confirm deletion in writing?

A good supplier makes leaving easy. You should never feel your own data is being held hostage.

10. Who's responsible for GDPR compliance?

Short answer: you both are, in different ways. Your charity is the data controller; the supplier is the data processor, and using their technology doesn't transfer your responsibilities to them.

Ask for the data processing agreement and check it covers roles, retention, deletion, sub-processors, international transfers, breach notification and support with data subject requests. And make sure your own use of the system matches your privacy notices and policies; that part's on you.

Don't ask "is it secure?", ask how

The most useful lesson from any supplier due diligence: "secure" is not a question, it's a marketing word. Specific questions get useful answers.

Instead of "Is our data secure?" ask "Where is it hosted, how is it encrypted, who can access it, and how are backups protected?"

Instead of "Are you GDPR compliant?" ask "Can you share your data processing agreement and explain how you handle data subject requests, sub-processors and incidents?"

Instead of "Do you have backups?" ask "How often, where, encrypted how, retained how long, and when did you last test a restore?"

A provider with good answers won't mind the questions. A provider who bristles at them has just answered a different one.

Security belongs in the buying decision, not after it

Functionality, usability and price will always matter when choosing a charity CRM. But your CRM is part of your data infrastructure: it holds information about the people you support, your staff and your volunteers. That makes security and supplier due diligence a core part of the selection process, not a box to tick after the ink is dry.

If you're reviewing your current system or comparing new ones, put the same ten questions to every supplier. The answers, and how readily they come, will tell you a lot.

Charitylog is a web-based CRM built specifically for UK charities delivering services and support. If you're comparing systems, we'd encourage you to ask us these questions too.

Find out more about Charitylog →

Older lady and younger female carer

Need more time to make a difference?

Get in touch

Latest blog posts

Charitylog slogan logo

CRM benefits

CRM Migration: The 12 Questions Every Charity Should Ask Before Switching Systems

Person using a calculator and looking at documents

CRM benefits

30% of Small UK Charities Have No CRM - and That's a Problem Worth Solving

Young woman in dark blazer and lanyard staring thoughtfully at tablet

Best practice CRMs

Best alternatives to Charitylog in 2026

Back to all blog posts