At least two Bailiwick-based charities have been caught up in a data ‘breach incident’ linked with a national software platform provider.
Beacon CRM is a cloud-based ‘customer relationship management’ (CRM) software platform, which serves charities, non-profit organisations and voluntary organisations.
It can help charities with fundraising, donations, memberships, and volunteer tracking and is known to be used by large organisations including Breast Cancer UK, Girlguiding, and NHS Charities Together.

The platform was the victim of a security incident recently, with hackers gaining access to database backups, holding information on more than 1,000 charities and other organisations.
While we don’t know which local charities have been affected, Guernsey’s Data Protection Commissioner Brent Homan has confirmed two have been impacted.
“We are aware of the Beacon CRM breach and have been in contact with our Crown Dependency data protection counterparts as we continue to monitor developments,” he said.

“At this point we have received two breach incident reports from Bailiwick-based charities relating to the Beacon breach.
“In terms of data compromised, we understand it to include contact information and financial data but we continue to assess the situation.”
Mr Homan said staff at the Office for the Data Protection Authority (ODPA) can advise any affected charities, or others who are worried about data protection.
Duty to report
He also confirmed that a data breach must be reported.
“Should a Guernsey charity or organisation become aware that they have been compromised by the breach we would remind them of their obligations to report such incidents to our Office,” he said.
“In addition to assessing the impact of such incidents, our Office will often provide actionable advice on notification obligations and how to mitigate risks stemming from a breach.”
The ODPA advice for individuals and organisations affected by data breaches mirrors advice issued by the UK government following the Beacon breach.
The ODPA recommends:
- Changing passwords for affected accounts.
- Updating passwords on other accounts if the same password has been reused.
- Being alert to phishing emails, texts, or telephone scams that may use information exposed in the breach.
- Monitoring financial accounts and other important services for suspicious activity.
- Following any specific protective measures recommended by the organisation that suffered the breach.
The UK government’s Charity Commission has said that it is taking longer to respond to affected organisations due to the “volume” of reports being received.
“In the meantime, we would encourage trustees to consult the Commission’s guidance for charities on dealing with cyber crime and the ICO’s guidance for organisations,” it said.
The Association of Guernsey Charities said it had not yet received any confirmation of local organisations being affected.
