"Why do charities need access to medical data?"
They're probably charities such as http://www.cruk.manchester.ac.uk/
I think it's reasonable that they may require medical data.
But as for data processing firms who can't be bothered to comply with the T&Cs under which they have access, it should be end of contract for good. Once one or two discover the hard way that the T&Cs aren't just collections of black marks on paper or screens the rest will get the message.