By business type

Privacy Policy Generator for nonprofits

Written for donors, beneficiaries, volunteers and the fundraising rules charities are held to.

Generate your privacy policy Read the privacy policy guide

A charity privacy policy has to serve three audiences with genuinely different processing: donors, beneficiaries and volunteers. Trying to cover all three in one set of paragraphs produces a document that is vague where it most needs to be precise.

Charities process some of the most sensitive data any organisation handles, and they do it with the least resource. Donor records, beneficiary case files, volunteer details and safeguarding notes sit in the same systems, and the beneficiary data is frequently special category - health, religious belief, ethnicity, immigration status.

Fundraising has its own rulebook on top of data protection. Wealth screening, donor profiling and list sharing between charities have all been the subject of enforcement action, and the UK Fundraising Regulator’s code adds standards that go beyond the statutory minimum.

Consent is the operational problem. Charities often hold donor lists assembled over decades under conditions nobody documented, and the temptation is to keep using them. The correct answer - suppress what you cannot evidence - is expensive but far cheaper than the alternative.

What a privacy policy for a nonprofit or charity has to cover

How a nonprofit or charity actually moves personal data

Donor records and giving history

Name, contact, amount, frequency and campaign attribution, often held for decades and used for future appeals.

Beneficiary case files

Frequently special category data, sometimes about children or vulnerable adults, needing an Article 9 condition and tight access control.

Volunteer records and DBS checks

Criminal-records data has its own strict conditions under the Data Protection Act 2018 schedules.

Wealth screening and donor research

Combining internal data with public sources to estimate capacity to give. Lawful only with care, and enforcement history exists.

Fundraising platforms and events

JustGiving, Enthuse and event registrations create records held by third parties with their own controller roles.

Gift Aid declarations

Linking a donation to a taxpayer identity, retained for statutory periods.

Third parties the draft will ask you about

Salesforce Nonprofit Cloud or Beacon · JustGiving or Enthuse · Stripe or GoCardless · Mailchimp or Dotdigital · Microsoft 365 · Eventbrite

The rules that apply

Special category data for beneficiaries

Health, religion, ethnicity and similar require an Article 9 condition, commonly the not-for-profit bodies condition or substantial public interest.

Fundraising regulation

Codes of practice covering consent, vulnerability, wealth screening and the frequency of approaches.

Direct marketing rules

PECR and equivalents apply to charities. The soft opt-in historically did not apply to donations in the UK, so consent has been the practical route.

Safeguarding records

Held under a distinct basis with strict access control and its own retention schedule.

Gift Aid and statutory retention

Tax records must be retained, which is a lawful reason to keep some donor data beyond the marketing relationship.

What the generated privacy policy contains

The charity document set

  1. Write separate notices for donors, beneficiaries and volunteers

    One document cannot serve three audiences with three different bases.

  2. Identify the Article 9 condition for beneficiary data

    And record it before the processing, not afterwards.

  3. Audit consent on legacy donor lists

    Suppress what cannot be evidenced.

  4. Set retention schedules per record type

    Gift Aid, safeguarding, donor marketing and volunteer records all differ.

  5. Document wealth screening if you do it

    With the balancing test and an opt-out route.

  6. Restrict access to safeguarding records

    Technically, not by policy alone.

Where this usually goes wrong

Using legacy donor lists with no consent record

The correct response is suppression, not optimism.

Beneficiary data in the same system as marketing data

Different bases, different access, different retention. Merging them is how safeguarding data ends up in an appeal mailing.

Wealth screening without a documented basis

It has attracted regulatory action, and the balancing test has to engage with donor expectations.

Sharing supporter lists with other charities

Previously common, now firmly a consent question and a disclosure that must be specific.

No Article 9 condition identified for beneficiary data

Article 6 alone is not enough for health, religion or ethnicity.

Volunteers treated as neither staff nor public

They need their own privacy notice covering references, DBS checks and expenses.

Frequently asked questions

Do charities have to comply with GDPR?

Yes, in full. There is no charitable exemption, and beneficiary data is frequently special category, which raises rather than lowers the standard.

Can we email past donors about a new appeal?

Only with a valid basis for electronic marketing. Where consent records are missing, the defensible position is suppression until consent is re-obtained.

Is wealth screening allowed?

It can be, with a documented legitimate interests assessment engaging with donor expectations, a clear disclosure and an opt-out. Doing it silently has attracted enforcement.

Do volunteers need their own privacy notice?

Yes. Their processing covers references, DBS checks, expenses and emergency contacts - none of which fits a donor notice.

Is a privacy policy legally required?

If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.

Can I copy another company’s privacy policy?

It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.

How often does a privacy policy need updating?

Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.

Does PolicifyAI give legal advice?

No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.

Privacy Policy Generator for nonprofits

Answer a short questionnaire and get a draft written for a nonprofit or charity. Free to start, no card required.

Generate your privacy policy

Other documents a nonprofit or charity needs

Each one is written for the same context, not a generic template.

The same document, by business type

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.