GDPR Policy Generator for nonprofits
Written for donors, beneficiaries, volunteers and the fundraising rules charities are held to.
Charity GDPR work is unusual because the highest-risk processing is the least commercial: beneficiary case files, safeguarding records and volunteer checks. Those need an Article 9 condition and access control, not just a policy.
Charities process some of the most sensitive data any organisation handles, and they do it with the least resource. Donor records, beneficiary case files, volunteer details and safeguarding notes sit in the same systems, and the beneficiary data is frequently special category - health, religious belief, ethnicity, immigration status.
Fundraising has its own rulebook on top of data protection. Wealth screening, donor profiling and list sharing between charities have all been the subject of enforcement action, and the UK Fundraising Regulator’s code adds standards that go beyond the statutory minimum.
Consent is the operational problem. Charities often hold donor lists assembled over decades under conditions nobody documented, and the temptation is to keep using them. The correct answer - suppress what you cannot evidence - is expensive but far cheaper than the alternative.
What a GDPR policy for a nonprofit or charity has to cover
Separate processing records for donors, beneficiaries, volunteers and staff
The Article 9 condition for beneficiary and safeguarding data, with the UK Schedule 1 condition
A DPIA for wealth screening, donor profiling or any large-scale beneficiary processing
Consent evidence for fundraising communications, with legacy lists suppressed where it is missing
Retention schedules per record type, including statutory Gift Aid and safeguarding periods
How a nonprofit or charity actually moves personal data
Donor records and giving history
Name, contact, amount, frequency and campaign attribution, often held for decades and used for future appeals.
Beneficiary case files
Frequently special category data, sometimes about children or vulnerable adults, needing an Article 9 condition and tight access control.
Volunteer records and DBS checks
Criminal-records data has its own strict conditions under the Data Protection Act 2018 schedules.
Wealth screening and donor research
Combining internal data with public sources to estimate capacity to give. Lawful only with care, and enforcement history exists.
Fundraising platforms and events
JustGiving, Enthuse and event registrations create records held by third parties with their own controller roles.
Gift Aid declarations
Linking a donation to a taxpayer identity, retained for statutory periods.
Third parties the draft will ask you about
Salesforce Nonprofit Cloud or Beacon · JustGiving or Enthuse · Stripe or GoCardless · Mailchimp or Dotdigital · Microsoft 365 · Eventbrite
The rules that apply
Special category data for beneficiaries
Health, religion, ethnicity and similar require an Article 9 condition, commonly the not-for-profit bodies condition or substantial public interest.
Fundraising regulation
Codes of practice covering consent, vulnerability, wealth screening and the frequency of approaches.
Direct marketing rules
PECR and equivalents apply to charities. The soft opt-in historically did not apply to donations in the UK, so consent has been the practical route.
Safeguarding records
Held under a distinct basis with strict access control and its own retention schedule.
Gift Aid and statutory retention
Tax records must be retained, which is a lawful reason to keep some donor data beyond the marketing relationship.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
The charity document set
Write separate notices for donors, beneficiaries and volunteers
One document cannot serve three audiences with three different bases.
Identify the Article 9 condition for beneficiary data
And record it before the processing, not afterwards.
Audit consent on legacy donor lists
Suppress what cannot be evidenced.
Set retention schedules per record type
Gift Aid, safeguarding, donor marketing and volunteer records all differ.
Document wealth screening if you do it
With the balancing test and an opt-out route.
Restrict access to safeguarding records
Technically, not by policy alone.
Where this usually goes wrong
Using legacy donor lists with no consent record
The correct response is suppression, not optimism.
Beneficiary data in the same system as marketing data
Different bases, different access, different retention. Merging them is how safeguarding data ends up in an appeal mailing.
Wealth screening without a documented basis
It has attracted regulatory action, and the balancing test has to engage with donor expectations.
Sharing supporter lists with other charities
Previously common, now firmly a consent question and a disclosure that must be specific.
No Article 9 condition identified for beneficiary data
Article 6 alone is not enough for health, religion or ethnicity.
Volunteers treated as neither staff nor public
They need their own privacy notice covering references, DBS checks and expenses.
Frequently asked questions
Do charities have to comply with GDPR?
Yes, in full. There is no charitable exemption, and beneficiary data is frequently special category, which raises rather than lowers the standard.
Can we email past donors about a new appeal?
Only with a valid basis for electronic marketing. Where consent records are missing, the defensible position is suppression until consent is re-obtained.
Is wealth screening allowed?
It can be, with a documented legitimate interests assessment engaging with donor expectations, a clear disclosure and an opt-out. Doing it silently has attracted enforcement.
Do volunteers need their own privacy notice?
Yes. Their processing covers references, DBS checks, expenses and emergency contacts - none of which fits a donor notice.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator for nonprofits
Answer a short questionnaire and get a draft written for a nonprofit or charity. Free to start, no card required.
Generate your GDPR policyOther documents a nonprofit or charity needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.