Privacy notice for a charity

A privacy notice for a charity, community interest company or not-for-profit, drafted for the trustees with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.

Share

Privacy notice for a charity

Buy now, £595

A charity processes data about four groups who need different things from the notice: donors, whose data is used for fundraising and must be used within the rules the regulator has enforced against charities; supporters and campaigners; beneficiaries, whose data is often special category; and volunteers, who are treated like staff. The notice has to explain the fundraising basis, the marketing rules including the soft opt-in now extended to charities, the handling of beneficiaries' data, the limits on wealth screening and profiling, and the sharing that gift aid and events involve. The business receives the privacy notice, the cookie notice and consent guidance within five working days for a fixed £595.

Who this is for

Registered charities, community interest companies, charitable incorporated organisations and not-for-profit organisations in England and Wales that fundraise, deliver services or both.

What matters in a charity privacy notice

Donors, supporters, beneficiaries and volunteers as four different groups

The business, as controller, owes a duty under Article 13 of the UK GDPR to tell each person whose data it holds what it does with it, and a charity's notice should address donors (contact, giving history, gift aid declarations, communication preferences), supporters and campaigners (sign-ups, petitions, event attendance), beneficiaries (the data the charity's services involve, often special category), volunteers (recruitment, checks, rotas, expenses), and staff separately, because the purposes, bases and retention differ for each; a single paragraph that treats a beneficiary like a donor has not told either what they need to know.

Fundraising, legitimate interests and the code of fundraising practice

Fundraising by post and telephone, the analysis of giving patterns and the retention of donor records can rest on legitimate interests under Article 6(1)(f) of the UK GDPR, with the interest stated, the balance recorded, the donor's right to object honoured and the Fundraising Regulator's Code of Fundraising Practice followed, while the Charities Act 2011 and the charity's governing document set what the trustees may do; the notice should state the basis for each fundraising activity, explain how a donor stops contact (the Fundraising Preference Service as well as the charity's own process), and should not claim consent for activities the charity carries out without asking, because consent that was never obtained is the regulator's first question.

Marketing, the soft opt-in and the change the 2025 Act made

Marketing to individuals by electronic means needs consent under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, or the soft opt-in where it applies, and the Data (Use and Access) Act 2025 extended the soft opt-in to charities, so that a charity may email or text a person whose details it obtained when they expressed an interest in or support for its charitable purposes, with a clear chance to refuse at the time and in every message, on commencement of that provision; the notice should say whether the charity relies on consent or on the soft opt-in for its email and text fundraising, and the sign-up forms should implement the one chosen, with the accountants and the fundraising team told that postal and telephone fundraising follow different rules (legitimate interests, with the Telephone Preference Service screened).

Beneficiaries and the special category data a charity's work involves

A charity delivering services to people in need processes health, disability, immigration status, criminal records, religion, sexual orientation and financial hardship data about beneficiaries, which is special category data under Article 9 of the UK GDPR or criminal records data under Article 10, processed under the conditions in Schedule 1 to the Data Protection Act 2018 (support for individuals with a particular disability or medical condition, safeguarding, health or social care, substantial public interest) with the appropriate policy document, or under explicit consent where the beneficiary gives it freely; the notice should state the condition for each service, who sees the data, how it is kept secure, and the sharing with other agencies (safeguarding, referrals, funders' reporting in anonymised form), in language the beneficiaries can read.

Wealth screening, profiling and the practices the regulator has fined

The Information Commissioner has fined charities for wealth screening (using external data to estimate donors' wealth), data matching and tele-matching (finding details donors had not given), and sharing donor data with other charities without telling them, and the notice should say whether the charity does any of those and on what basis, with the Fundraising Regulator's code requiring transparency; profiling of donors for targeted asks is lawful under legitimate interests only where it is explained in the notice, proportionate, and the donor can object, and the notice should describe it in terms a donor would recognise, because a donor who learns of the screening from the press is a complaint.

Gift aid, events and the data shared with others

Gift aid declarations are shared with HMRC and retained for the period HMRC requires, event registrations are shared with venues and event platforms as processors, fundraising platforms and payment processors hold donor and payment data as controllers or processors, volunteers' checks go to the Disclosure and Barring Service, and funders may receive anonymised or aggregated reporting; the notice should explain each, the international transfers to platforms outside the United Kingdom under Article 46, the retention periods for each group, what the individual may ask for (access, correction, erasure, restriction, portability, objection), how and within the month allowed, and the Information Commissioner's Office as the place to complain, and the notice should give the registration number the business holds with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Under the soft opt-in, which the 2025 Act extended to charities, where the details came from someone who expressed interest in or support for the charity's purposes and they could refuse at the time and in every message, once the provision is in force. The notice says which basis the charity relies on.

Is wealth screening allowed?

Only where the notice explains it, it is proportionate and donors can object; the regulator has fined charities for doing it silently. The notice describes any screening in terms a donor would recognise.

Do our beneficiaries need a separate notice?

A section written for them, in language they can read, stating the condition for the special category data the service involves and who sees it. The donor-facing notice does not do that work.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.