Privacy Policy Generator for nonprofits
Written for donors, beneficiaries, volunteers and the fundraising rules charities are held to.
A charity privacy policy has to serve three audiences with genuinely different processing: donors, beneficiaries and volunteers. Trying to cover all three in one set of paragraphs produces a document that is vague where it most needs to be precise.
Charities process some of the most sensitive data any organisation handles, and they do it with the least resource. Donor records, beneficiary case files, volunteer details and safeguarding notes sit in the same systems, and the beneficiary data is frequently special category - health, religious belief, ethnicity, immigration status.
Fundraising has its own rulebook on top of data protection. Wealth screening, donor profiling and list sharing between charities have all been the subject of enforcement action, and the UK Fundraising Regulator’s code adds standards that go beyond the statutory minimum.
Consent is the operational problem. Charities often hold donor lists assembled over decades under conditions nobody documented, and the temptation is to keep using them. The correct answer - suppress what you cannot evidence - is expensive but far cheaper than the alternative.
What a privacy policy for a nonprofit or charity has to cover
Donor processing: giving history, Gift Aid, appeals, and the marketing basis
Beneficiary processing with the Article 9 condition identified, and access restrictions
Volunteer processing including references and criminal-records checks
Fundraising platforms and their own controller roles
Retention per record type, including statutory Gift Aid and safeguarding periods
How a nonprofit or charity actually moves personal data
Donor records and giving history
Name, contact, amount, frequency and campaign attribution, often held for decades and used for future appeals.
Beneficiary case files
Frequently special category data, sometimes about children or vulnerable adults, needing an Article 9 condition and tight access control.
Volunteer records and DBS checks
Criminal-records data has its own strict conditions under the Data Protection Act 2018 schedules.
Wealth screening and donor research
Combining internal data with public sources to estimate capacity to give. Lawful only with care, and enforcement history exists.
Fundraising platforms and events
JustGiving, Enthuse and event registrations create records held by third parties with their own controller roles.
Gift Aid declarations
Linking a donation to a taxpayer identity, retained for statutory periods.
Third parties the draft will ask you about
Salesforce Nonprofit Cloud or Beacon · JustGiving or Enthuse · Stripe or GoCardless · Mailchimp or Dotdigital · Microsoft 365 · Eventbrite
The rules that apply
Special category data for beneficiaries
Health, religion, ethnicity and similar require an Article 9 condition, commonly the not-for-profit bodies condition or substantial public interest.
Fundraising regulation
Codes of practice covering consent, vulnerability, wealth screening and the frequency of approaches.
Direct marketing rules
PECR and equivalents apply to charities. The soft opt-in historically did not apply to donations in the UK, so consent has been the practical route.
Safeguarding records
Held under a distinct basis with strict access control and its own retention schedule.
Gift Aid and statutory retention
Tax records must be retained, which is a lawful reason to keep some donor data beyond the marketing relationship.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
The charity document set
Write separate notices for donors, beneficiaries and volunteers
One document cannot serve three audiences with three different bases.
Identify the Article 9 condition for beneficiary data
And record it before the processing, not afterwards.
Audit consent on legacy donor lists
Suppress what cannot be evidenced.
Set retention schedules per record type
Gift Aid, safeguarding, donor marketing and volunteer records all differ.
Document wealth screening if you do it
With the balancing test and an opt-out route.
Restrict access to safeguarding records
Technically, not by policy alone.
Where this usually goes wrong
Using legacy donor lists with no consent record
The correct response is suppression, not optimism.
Beneficiary data in the same system as marketing data
Different bases, different access, different retention. Merging them is how safeguarding data ends up in an appeal mailing.
Wealth screening without a documented basis
It has attracted regulatory action, and the balancing test has to engage with donor expectations.
Sharing supporter lists with other charities
Previously common, now firmly a consent question and a disclosure that must be specific.
No Article 9 condition identified for beneficiary data
Article 6 alone is not enough for health, religion or ethnicity.
Volunteers treated as neither staff nor public
They need their own privacy notice covering references, DBS checks and expenses.
Frequently asked questions
Do charities have to comply with GDPR?
Yes, in full. There is no charitable exemption, and beneficiary data is frequently special category, which raises rather than lowers the standard.
Can we email past donors about a new appeal?
Only with a valid basis for electronic marketing. Where consent records are missing, the defensible position is suppression until consent is re-obtained.
Is wealth screening allowed?
It can be, with a documented legitimate interests assessment engaging with donor expectations, a clear disclosure and an opt-out. Doing it silently has attracted enforcement.
Do volunteers need their own privacy notice?
Yes. Their processing covers references, DBS checks, expenses and emergency contacts - none of which fits a donor notice.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for nonprofits
Answer a short questionnaire and get a draft written for a nonprofit or charity. Free to start, no card required.
Generate your privacy policyOther documents a nonprofit or charity needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.