Aid Donor Data Requests: Protect Beneficiary Names
A donor asks for the names, telephone numbers and identity details of everyone who received assistance. The request may be presented as routine verification: the donor wants evidence that the programme reached real people. For an NGO, however, the question is not simply whether the data exist. It is whether identifiable information must be disclosed, whether disclosure is lawful, and whether the same assurance can be provided with less risk to beneficiaries. In humanitarian and sensitive development settings, a list of names can reveal far more than attendance. It may expose health status, displacement, disability, protection concerns, political vulnerability or location.
Verification
Is Legitimate; Unlimited Disclosure Is Not
Donors are entitled to verify that funded activities occurred and
that money was used for the agreed purpose. Audit and monitoring rights are
normal features of grant agreements. But verification does not automatically
create a right to receive every underlying personal record. The current UK
Model Grant Funding Agreement is instructive because it combines audit and
information rights with detailed data-protection obligations. It requires
personal data shared between grant parties to be limited to what is required
for the funded activities and, in one staffing context, specifically
contemplates information being provided in a suitably anonymised format. That
shows that evidence and identification are not the same thing.
Begin
With the Purpose, Not the Spreadsheet
When a donor asks for names, the NGO should first identify the exact
purpose. Is the donor testing whether beneficiaries exist, checking for
duplication, investigating fraud, meeting a sanctions obligation, evaluating
outcomes, or preparing a public report? Each purpose may justify a different
evidential response. A request that says only “send the beneficiary list” is
too imprecise for responsible disclosure. The NGO should ask what decision the
donor needs to make and why identifiable data, rather than aggregated or coded
information, are necessary for that decision.
Humanitarian
Data Guidance Favors Necessity and Risk Reduction
The ICRC’s third edition Handbook on Data Protection in Humanitarian
Action, published in 2024, treats protection of personal data as part of
protecting life, integrity and dignity. OCHA’s revised Data Responsibility
Guidelines, issued in 2025, similarly frame humanitarian data management around
safe, ethical and effective use. These frameworks do not deny accountability.
They require organisations to consider the risks created by collection and
sharing, especially where affected people have limited power to refuse. The
practical implication is that an NGO should not enlarge a donor’s request
merely because disclosure is administratively convenient.
Local
Data Law Can Make the Question Legal, Not Merely Ethical
National law may also impose direct limits. Kenya’s Data Protection
Act requires personal data to be collected for explicit, specified and
legitimate purposes and limited to what is necessary. Its General Regulations
go further by identifying data minimisation measures such as avoiding
personal-data processing where possible, limiting the amount collected and
pseudonymising data once direct identification is no longer necessary. Uganda’s
Data Protection and Privacy Act similarly requires a lawful and specific
purpose, protection of privacy, information to data subjects about recipients
and retention, and a lawful basis for processing. A donor instruction therefore
needs to be tested against the law that governs the NGO’s processing and any
cross-border transfer.
Aggregate
Reporting Is Often Enough
If the donor needs to know how many people were assisted, names
usually add little. A programme can report totals by location, age band,
gender, vulnerability category or service type where those breakdowns are
genuinely needed and sufficiently safe. Supporting records can remain with the
NGO for audit. Aggregation is particularly useful when the donor’s purpose is
performance reporting rather than case-level investigation. The central
discipline is to separate the evidence needed to show that an outcome occurred
from the identity of the person who experienced it.
Pseudonymisation
Can Support Case-Level Checks
Where case-level verification is required, pseudonymisation may be a
better option. The NGO can replace names with unique codes and keep the key
separately under stronger access controls. The donor can then test dates,
assistance amounts, locations or service records without receiving direct
identifiers. Pseudonymisation is not the same as anonymisation, because
re-identification remains possible through the separate key. It therefore still
requires safeguards. But it reduces the amount of identity information moving
outside the programme team and can make verification more proportionate.
Sampling
Can Prove a System Without Exporting the Database
A donor may also be able to verify performance through sampling.
Rather than transferring a complete beneficiary database, an agreed sample can
be selected and checked against underlying records. For higher-risk programmes,
the review can be performed by an auditor or trusted reviewer under
confidentiality rules. The European Commission’s humanitarian audit methodology
already recognises sample testing as part of financial verification. A
controlled sample can therefore provide credible assurance while avoiding the
creation of a second full copy of a sensitive beneficiary database.
Controlled
Review Is Different From Data Transfer
Sometimes the donor genuinely needs to inspect identifiable records.
Even then, the NGO can ask whether review can occur without transferring the
data. A donor representative or auditor may inspect records in a secure
environment, with copying restricted and particularly sensitive fields masked
unless needed. The organisation can document what was reviewed and the outcome.
This is often preferable where the data concern survivors of violence,
refugees, children, health conditions or people in insecure areas. The donor
receives assurance, but the NGO does not lose control of an entire dataset.
When
Identifiable Disclosure May Be Necessary
There are situations in which identifiable disclosure can be
justified. A credible fraud investigation may require checking whether named
recipients exist. A legal obligation may require information to be supplied to
a competent authority. A carefully defined sanctions or counter-terrorism
requirement may concern a particular person or counterparty. A donor may also
have an agreed lawful basis for specified case-level monitoring. The important
point is that necessity should be demonstrated rather than assumed. The NGO
should record the purpose, legal basis, minimum fields, recipient, security
measures, retention period and any cross-border-transfer mechanism before
disclosure.
Consent
Is Not Always the Easy Answer
NGOs sometimes try to solve the problem by obtaining beneficiary
consent for donor disclosure. In many aid settings, that can be weak
protection. A person who needs food, shelter, health care or legal assistance
may not feel genuinely free to refuse a condition attached to assistance. Even
where consent is legally available, it should not be used to make an
unnecessary disclosure appear acceptable. The stronger approach is first to
minimise the data and identify another lawful basis where appropriate, then use
consent only where it is informed, meaningful and compatible with the programme
context.
Respond
in Writing and Offer an Alternative
A practical response to an overbroad request should not simply say
no. It should explain that the NGO supports verification, identify the privacy
or protection concern, and offer an alternative that meets the donor’s purpose.
Aggregate reporting, coded case records, a representative sample, secure
on-site review or narrowly limited disclosure may all be more defensible.
OCHA’s guidance on responsible data sharing with donors encourages precisely
this kind of clarification of purpose, formalisation of sensitive-data requests
and shared responsibility for risk.
Keep
a Disclosure Decision Record
The final protection is documentation. The NGO should keep the
donor’s request, the legal and protection assessment, internal approvals, the
alternative proposed, any agreed data-sharing conditions and a record of what
was actually disclosed. If the donor later asks why names were withheld, the
answer is then grounded in a reasoned process rather than an improvised
refusal. If names were disclosed, the same file demonstrates why that step was
necessary and limited.
Accountability
Does Not Require Maximum Identifiability
The most useful principle is simple: donor accountability should
increase confidence in the programme without increasing avoidable danger for
the people the programme exists to serve. A beneficiary list may sometimes be
necessary. It should never be the automatic starting point. Good verification
asks for the least identifying information capable of answering the legitimate
question.
Source note. Principal materials considered include
the ICRC Handbook on Data Protection in Humanitarian Action, third edition,
2024; the OCHA Data Responsibility Guidelines revised in 2025; the IASC
Operational Guidance on Data Responsibility in Humanitarian Action, second
edition; OCHA guidance on Responsible Data Sharing with Donors; the Kenya Data
Protection Act 2019 and Data Protection (General) Regulations; the Uganda Data
Protection and Privacy Act 2019; the UK Cabinet Office Model Grant Funding Agreement
published in December 2025; and the European Commission’s current humanitarian
audit framework. The applicable national data-protection law and the specific
grant agreement must be checked for each disclosure.
Suggested citation:
Ronald Serwanga, “Aid Donor Data
Requests: Protect Beneficiary Names” East Africa Legal Insight (4 September
2026).