Aid Donor Data Requests: Protect Beneficiary Names

A donor asks for the names, telephone numbers and identity details of everyone who received assistance. The request may be presented as routine verification: the donor wants evidence that the programme reached real people. For an NGO, however, the question is not simply whether the data exist. It is whether identifiable information must be disclosed, whether disclosure is lawful, and whether the same assurance can be provided with less risk to beneficiaries. In humanitarian and sensitive development settings, a list of names can reveal far more than attendance. It may expose health status, displacement, disability, protection concerns, political vulnerability or location.

Verification Is Legitimate; Unlimited Disclosure Is Not

Donors are entitled to verify that funded activities occurred and that money was used for the agreed purpose. Audit and monitoring rights are normal features of grant agreements. But verification does not automatically create a right to receive every underlying personal record. The current UK Model Grant Funding Agreement is instructive because it combines audit and information rights with detailed data-protection obligations. It requires personal data shared between grant parties to be limited to what is required for the funded activities and, in one staffing context, specifically contemplates information being provided in a suitably anonymised format. That shows that evidence and identification are not the same thing.

Begin With the Purpose, Not the Spreadsheet

When a donor asks for names, the NGO should first identify the exact purpose. Is the donor testing whether beneficiaries exist, checking for duplication, investigating fraud, meeting a sanctions obligation, evaluating outcomes, or preparing a public report? Each purpose may justify a different evidential response. A request that says only “send the beneficiary list” is too imprecise for responsible disclosure. The NGO should ask what decision the donor needs to make and why identifiable data, rather than aggregated or coded information, are necessary for that decision.

Humanitarian Data Guidance Favors Necessity and Risk Reduction

The ICRC’s third edition Handbook on Data Protection in Humanitarian Action, published in 2024, treats protection of personal data as part of protecting life, integrity and dignity. OCHA’s revised Data Responsibility Guidelines, issued in 2025, similarly frame humanitarian data management around safe, ethical and effective use. These frameworks do not deny accountability. They require organisations to consider the risks created by collection and sharing, especially where affected people have limited power to refuse. The practical implication is that an NGO should not enlarge a donor’s request merely because disclosure is administratively convenient.

Local Data Law Can Make the Question Legal, Not Merely Ethical

National law may also impose direct limits. Kenya’s Data Protection Act requires personal data to be collected for explicit, specified and legitimate purposes and limited to what is necessary. Its General Regulations go further by identifying data minimisation measures such as avoiding personal-data processing where possible, limiting the amount collected and pseudonymising data once direct identification is no longer necessary. Uganda’s Data Protection and Privacy Act similarly requires a lawful and specific purpose, protection of privacy, information to data subjects about recipients and retention, and a lawful basis for processing. A donor instruction therefore needs to be tested against the law that governs the NGO’s processing and any cross-border transfer.

Aggregate Reporting Is Often Enough

If the donor needs to know how many people were assisted, names usually add little. A programme can report totals by location, age band, gender, vulnerability category or service type where those breakdowns are genuinely needed and sufficiently safe. Supporting records can remain with the NGO for audit. Aggregation is particularly useful when the donor’s purpose is performance reporting rather than case-level investigation. The central discipline is to separate the evidence needed to show that an outcome occurred from the identity of the person who experienced it.

Pseudonymisation Can Support Case-Level Checks

Where case-level verification is required, pseudonymisation may be a better option. The NGO can replace names with unique codes and keep the key separately under stronger access controls. The donor can then test dates, assistance amounts, locations or service records without receiving direct identifiers. Pseudonymisation is not the same as anonymisation, because re-identification remains possible through the separate key. It therefore still requires safeguards. But it reduces the amount of identity information moving outside the programme team and can make verification more proportionate.

Sampling Can Prove a System Without Exporting the Database

A donor may also be able to verify performance through sampling. Rather than transferring a complete beneficiary database, an agreed sample can be selected and checked against underlying records. For higher-risk programmes, the review can be performed by an auditor or trusted reviewer under confidentiality rules. The European Commission’s humanitarian audit methodology already recognises sample testing as part of financial verification. A controlled sample can therefore provide credible assurance while avoiding the creation of a second full copy of a sensitive beneficiary database.

Controlled Review Is Different From Data Transfer

Sometimes the donor genuinely needs to inspect identifiable records. Even then, the NGO can ask whether review can occur without transferring the data. A donor representative or auditor may inspect records in a secure environment, with copying restricted and particularly sensitive fields masked unless needed. The organisation can document what was reviewed and the outcome. This is often preferable where the data concern survivors of violence, refugees, children, health conditions or people in insecure areas. The donor receives assurance, but the NGO does not lose control of an entire dataset.

When Identifiable Disclosure May Be Necessary

There are situations in which identifiable disclosure can be justified. A credible fraud investigation may require checking whether named recipients exist. A legal obligation may require information to be supplied to a competent authority. A carefully defined sanctions or counter-terrorism requirement may concern a particular person or counterparty. A donor may also have an agreed lawful basis for specified case-level monitoring. The important point is that necessity should be demonstrated rather than assumed. The NGO should record the purpose, legal basis, minimum fields, recipient, security measures, retention period and any cross-border-transfer mechanism before disclosure.

Consent Is Not Always the Easy Answer

NGOs sometimes try to solve the problem by obtaining beneficiary consent for donor disclosure. In many aid settings, that can be weak protection. A person who needs food, shelter, health care or legal assistance may not feel genuinely free to refuse a condition attached to assistance. Even where consent is legally available, it should not be used to make an unnecessary disclosure appear acceptable. The stronger approach is first to minimise the data and identify another lawful basis where appropriate, then use consent only where it is informed, meaningful and compatible with the programme context.

Respond in Writing and Offer an Alternative

A practical response to an overbroad request should not simply say no. It should explain that the NGO supports verification, identify the privacy or protection concern, and offer an alternative that meets the donor’s purpose. Aggregate reporting, coded case records, a representative sample, secure on-site review or narrowly limited disclosure may all be more defensible. OCHA’s guidance on responsible data sharing with donors encourages precisely this kind of clarification of purpose, formalisation of sensitive-data requests and shared responsibility for risk.

Keep a Disclosure Decision Record

The final protection is documentation. The NGO should keep the donor’s request, the legal and protection assessment, internal approvals, the alternative proposed, any agreed data-sharing conditions and a record of what was actually disclosed. If the donor later asks why names were withheld, the answer is then grounded in a reasoned process rather than an improvised refusal. If names were disclosed, the same file demonstrates why that step was necessary and limited.

Accountability Does Not Require Maximum Identifiability

The most useful principle is simple: donor accountability should increase confidence in the programme without increasing avoidable danger for the people the programme exists to serve. A beneficiary list may sometimes be necessary. It should never be the automatic starting point. Good verification asks for the least identifying information capable of answering the legitimate question.

Source note. Principal materials considered include the ICRC Handbook on Data Protection in Humanitarian Action, third edition, 2024; the OCHA Data Responsibility Guidelines revised in 2025; the IASC Operational Guidance on Data Responsibility in Humanitarian Action, second edition; OCHA guidance on Responsible Data Sharing with Donors; the Kenya Data Protection Act 2019 and Data Protection (General) Regulations; the Uganda Data Protection and Privacy Act 2019; the UK Cabinet Office Model Grant Funding Agreement published in December 2025; and the European Commission’s current humanitarian audit framework. The applicable national data-protection law and the specific grant agreement must be checked for each disclosure.

Suggested citation: 

Ronald Serwanga, “Aid Donor Data Requests: Protect Beneficiary Names” East Africa Legal Insight (4 September 2026).