Cookie Policy Generator for nonprofits
Written for donors, beneficiaries, volunteers and the fundraising rules charities are held to.
Charity cookie policies have a specific failure mode: donation-tracking and retargeting pixels running on pages where someone has just disclosed a cause they care about. That association is more sensitive than a typical commercial visit, and regulators have treated it that way.
Charities process some of the most sensitive data any organisation handles, and they do it with the least resource. Donor records, beneficiary case files, volunteer details and safeguarding notes sit in the same systems, and the beneficiary data is frequently special category - health, religious belief, ethnicity, immigration status.
Fundraising has its own rulebook on top of data protection. Wealth screening, donor profiling and list sharing between charities have all been the subject of enforcement action, and the UK Fundraising Regulator’s code adds standards that go beyond the statutory minimum.
Consent is the operational problem. Charities often hold donor lists assembled over decades under conditions nobody documented, and the temptation is to keep using them. The correct answer - suppress what you cannot evidence - is expensive but far cheaper than the alternative.
What a cookie policy for a nonprofit or charity has to cover
Donation-tracking and conversion pixels on giving pages
Retargeting based on which appeal or cause a visitor viewed
Fundraising platform cookies set by JustGiving, Enthuse or equivalent
Analytics distinguishing supporter behaviour from beneficiary-facing pages
How a supporter refuses tracking without losing the ability to donate
How a nonprofit or charity actually moves personal data
Donor records and giving history
Name, contact, amount, frequency and campaign attribution, often held for decades and used for future appeals.
Beneficiary case files
Frequently special category data, sometimes about children or vulnerable adults, needing an Article 9 condition and tight access control.
Volunteer records and DBS checks
Criminal-records data has its own strict conditions under the Data Protection Act 2018 schedules.
Wealth screening and donor research
Combining internal data with public sources to estimate capacity to give. Lawful only with care, and enforcement history exists.
Fundraising platforms and events
JustGiving, Enthuse and event registrations create records held by third parties with their own controller roles.
Gift Aid declarations
Linking a donation to a taxpayer identity, retained for statutory periods.
Third parties the draft will ask you about
Salesforce Nonprofit Cloud or Beacon · JustGiving or Enthuse · Stripe or GoCardless · Mailchimp or Dotdigital · Microsoft 365 · Eventbrite
The rules that apply
Special category data for beneficiaries
Health, religion, ethnicity and similar require an Article 9 condition, commonly the not-for-profit bodies condition or substantial public interest.
Fundraising regulation
Codes of practice covering consent, vulnerability, wealth screening and the frequency of approaches.
Direct marketing rules
PECR and equivalents apply to charities. The soft opt-in historically did not apply to donations in the UK, so consent has been the practical route.
Safeguarding records
Held under a distinct basis with strict access control and its own retention schedule.
Gift Aid and statutory retention
Tax records must be retained, which is a lawful reason to keep some donor data beyond the marketing relationship.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
The charity document set
Write separate notices for donors, beneficiaries and volunteers
One document cannot serve three audiences with three different bases.
Identify the Article 9 condition for beneficiary data
And record it before the processing, not afterwards.
Audit consent on legacy donor lists
Suppress what cannot be evidenced.
Set retention schedules per record type
Gift Aid, safeguarding, donor marketing and volunteer records all differ.
Document wealth screening if you do it
With the balancing test and an opt-out route.
Restrict access to safeguarding records
Technically, not by policy alone.
Where this usually goes wrong
Using legacy donor lists with no consent record
The correct response is suppression, not optimism.
Beneficiary data in the same system as marketing data
Different bases, different access, different retention. Merging them is how safeguarding data ends up in an appeal mailing.
Wealth screening without a documented basis
It has attracted regulatory action, and the balancing test has to engage with donor expectations.
Sharing supporter lists with other charities
Previously common, now firmly a consent question and a disclosure that must be specific.
No Article 9 condition identified for beneficiary data
Article 6 alone is not enough for health, religion or ethnicity.
Volunteers treated as neither staff nor public
They need their own privacy notice covering references, DBS checks and expenses.
Frequently asked questions
Do charities have to comply with GDPR?
Yes, in full. There is no charitable exemption, and beneficiary data is frequently special category, which raises rather than lowers the standard.
Can we email past donors about a new appeal?
Only with a valid basis for electronic marketing. Where consent records are missing, the defensible position is suppression until consent is re-obtained.
Is wealth screening allowed?
It can be, with a documented legitimate interests assessment engaging with donor expectations, a clear disclosure and an opt-out. Doing it silently has attracted enforcement.
Do volunteers need their own privacy notice?
Yes. Their processing covers references, DBS checks, expenses and emergency contacts - none of which fits a donor notice.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator for nonprofits
Answer a short questionnaire and get a draft written for a nonprofit or charity. Free to start, no card required.
Generate your cookie policyOther documents a nonprofit or charity needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.