By business type

Cookie Policy Generator for nonprofits

Written for donors, beneficiaries, volunteers and the fundraising rules charities are held to.

Generate your cookie policy Read the cookie policy guide

Charity cookie policies have a specific failure mode: donation-tracking and retargeting pixels running on pages where someone has just disclosed a cause they care about. That association is more sensitive than a typical commercial visit, and regulators have treated it that way.

Charities process some of the most sensitive data any organisation handles, and they do it with the least resource. Donor records, beneficiary case files, volunteer details and safeguarding notes sit in the same systems, and the beneficiary data is frequently special category - health, religious belief, ethnicity, immigration status.

Fundraising has its own rulebook on top of data protection. Wealth screening, donor profiling and list sharing between charities have all been the subject of enforcement action, and the UK Fundraising Regulator’s code adds standards that go beyond the statutory minimum.

Consent is the operational problem. Charities often hold donor lists assembled over decades under conditions nobody documented, and the temptation is to keep using them. The correct answer - suppress what you cannot evidence - is expensive but far cheaper than the alternative.

What a cookie policy for a nonprofit or charity has to cover

How a nonprofit or charity actually moves personal data

Donor records and giving history

Name, contact, amount, frequency and campaign attribution, often held for decades and used for future appeals.

Beneficiary case files

Frequently special category data, sometimes about children or vulnerable adults, needing an Article 9 condition and tight access control.

Volunteer records and DBS checks

Criminal-records data has its own strict conditions under the Data Protection Act 2018 schedules.

Wealth screening and donor research

Combining internal data with public sources to estimate capacity to give. Lawful only with care, and enforcement history exists.

Fundraising platforms and events

JustGiving, Enthuse and event registrations create records held by third parties with their own controller roles.

Gift Aid declarations

Linking a donation to a taxpayer identity, retained for statutory periods.

Third parties the draft will ask you about

Salesforce Nonprofit Cloud or Beacon · JustGiving or Enthuse · Stripe or GoCardless · Mailchimp or Dotdigital · Microsoft 365 · Eventbrite

The rules that apply

Special category data for beneficiaries

Health, religion, ethnicity and similar require an Article 9 condition, commonly the not-for-profit bodies condition or substantial public interest.

Fundraising regulation

Codes of practice covering consent, vulnerability, wealth screening and the frequency of approaches.

Direct marketing rules

PECR and equivalents apply to charities. The soft opt-in historically did not apply to donations in the UK, so consent has been the practical route.

Safeguarding records

Held under a distinct basis with strict access control and its own retention schedule.

Gift Aid and statutory retention

Tax records must be retained, which is a lawful reason to keep some donor data beyond the marketing relationship.

What the generated cookie policy contains

The charity document set

  1. Write separate notices for donors, beneficiaries and volunteers

    One document cannot serve three audiences with three different bases.

  2. Identify the Article 9 condition for beneficiary data

    And record it before the processing, not afterwards.

  3. Audit consent on legacy donor lists

    Suppress what cannot be evidenced.

  4. Set retention schedules per record type

    Gift Aid, safeguarding, donor marketing and volunteer records all differ.

  5. Document wealth screening if you do it

    With the balancing test and an opt-out route.

  6. Restrict access to safeguarding records

    Technically, not by policy alone.

Where this usually goes wrong

Using legacy donor lists with no consent record

The correct response is suppression, not optimism.

Beneficiary data in the same system as marketing data

Different bases, different access, different retention. Merging them is how safeguarding data ends up in an appeal mailing.

Wealth screening without a documented basis

It has attracted regulatory action, and the balancing test has to engage with donor expectations.

Sharing supporter lists with other charities

Previously common, now firmly a consent question and a disclosure that must be specific.

No Article 9 condition identified for beneficiary data

Article 6 alone is not enough for health, religion or ethnicity.

Volunteers treated as neither staff nor public

They need their own privacy notice covering references, DBS checks and expenses.

Frequently asked questions

Do charities have to comply with GDPR?

Yes, in full. There is no charitable exemption, and beneficiary data is frequently special category, which raises rather than lowers the standard.

Can we email past donors about a new appeal?

Only with a valid basis for electronic marketing. Where consent records are missing, the defensible position is suppression until consent is re-obtained.

Is wealth screening allowed?

It can be, with a documented legitimate interests assessment engaging with donor expectations, a clear disclosure and an opt-out. Doing it silently has attracted enforcement.

Do volunteers need their own privacy notice?

Yes. Their processing covers references, DBS checks, expenses and emergency contacts - none of which fits a donor notice.

Do I need a cookie policy as well as a privacy policy?

In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.

Do analytics cookies need consent?

In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.

Does a cookie policy need updating when I add a tool?

Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.

What about cookies set by embedded video and maps?

They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.

Cookie Policy Generator for nonprofits

Answer a short questionnaire and get a draft written for a nonprofit or charity. Free to start, no card required.

Generate your cookie policy

Other documents a nonprofit or charity needs

Each one is written for the same context, not a generic template.

The same document, by business type

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.