---
title: "Monthly check-in 6: Infosec & GDPR"
slug: "monthly-check-in-6-infosec-gdpr"
updated: 2025-07-23T11:42:57Z
published: 2025-07-23T11:42:57Z
canonical: "resourceportal.antientropy.org/monthly-check-in-6-infosec-gdpr"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://resourceportal.antientropy.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Monthly check-in 6: Infosec & GDPR

### Who is this for?

          

This content is designed for participants in Anti Entropy's [SparkWell](https://www.antientropy.org/sparkwell) fiscal sponsorship program. While some context will be specific to SparkWell and may need more context, we've made these resources public because they may, nevertheless, be useful to others who may be founding or building an organization.

          All check-ins

          

1. [Introduction & onboarding](/v1/docs/monthly-check-in-1-onboarding)
2. [Mission, theory of change & impact evaluation](/v1/docs/monthly-check-in-2-mission-theory-of-change-impact-evaluation)
3. [Fundraising strategy & donor management](/v1/docs/monthly-check-in)
4. [Financial management & budgeting](/v1/docs/monthly-check-in-1)
5. [Legal compliance & risk management](/v1/docs/monthly-check-in-5-legal-compliance-risk-management)
6. **Infosec & GDPR (*current stage*)**
7. [Brand development & marketing](/v1/docs/monthly-check-in-7-brand-development-marketing)
8. ["Bus-proofing" & sustainability strategy](/v1/docs/monthly-check-in-8-bus-proofing-sustainability-strategy)
9. [HR systems & hiring strategy](/v1/docs/monthly-check-in-9-hr-systems-hiring-strategy)
10. [Board development & governance](/v1/docs/monthly-check-in-10-board-development-governance)
11. [Revisited: Mission, theory of change & impact evaluation](/v1/docs/monthly-check-in-11-revisited-mission-theory-of-change-impact-evaluation)
12. [Graduation](/v1/docs/monthly-check-in-12-graduation)

## Infosec & GDPR

### Why is this important?

When setting up a nonprofit, considering information security and GDPR is vital to protect sensitive data, maintain trust, and comply with legal requirements. Nonprofits often handle personal information from donors, beneficiaries, staff, and partners; strong infosec practices prevent data breaches, cyberattacks, and misuse of information. GDPR compliance ensures that data is collected, stored, and used responsibly, respecting individuals’ privacy rights and avoiding legal penalties. Together, they help safeguard the nonprofit’s reputation, build stakeholder confidence, and ensure ethical and lawful data management.

          

### Suggested reading

          

**Nonprofit Operations Playbook:**

- [Establish strong cybersecurity (Astera Institute)](https://astera-institute.notion.site/Establish-strong-cybersecurity-1bbaa1d01f24817aa3b4c6df5a78ae76)

**Other Related Readings**

- [GDPR Compliance Guide](/v1/docs/gdpr-compliance-guide)
- [Secure Google Workspace Settings](https://impact-shield.org/resources/secure-google-workspace-settings/) (Impact Shield)

### Milestones

Aim to complete these before your next monthly check-in:

✔️ Data map drafted

#### (Optional) Further outcomes

Consider completing these throughout the program:

✔️ Cybersecurity discussed ✔️ GDPR compliance understood

### Next up: Brand development & marketing

When setting up a nonprofit, brand development and marketing are crucial for building visibility, credibility, and support.

See the [Brand development & marketing](/v1/docs/monthly-check-in-7-brand-development-marketing) worksheet for more information.
