UK GDPR for Charities: What Non-profits Need to Do

Alex Solo
byAlex Solo12 min read

Charities often collect more personal data than they realise. Donor records, volunteer applications, beneficiary case notes, event sign ups, Gift Aid forms, mailing lists and safeguarding information can all fall within UK GDPR. The problem is that many charities treat data protection as an admin task rather than an operational risk. Common mistakes include sending marketing emails without a clear lawful basis, keeping personal data indefinitely “just in case”, and copying privacy wording from another organisation that does not match what the charity actually does.

That creates real pressure for trustees, founders and managers. You may be trying to grow fundraising, recruit volunteers, deliver services and meet safeguarding duties at the same time. This guide explains what GDPR for charities means in practice, when the issue usually arises, and what a charity needs to put in place before it collects more data, shares information with suppliers or launches a new campaign.

Overview

UK GDPR applies to charities in much the same way it applies to commercial organisations. If your charity collects or uses personal data, you need a lawful basis, clear privacy information, sensible retention rules, appropriate security and a process for handling people’s rights.

  • Work out what personal data you collect, where it comes from and why you use it.
  • Match each use of data to a lawful basis, including separate thinking for fundraising, service delivery, employment and volunteer management.
  • Publish a privacy notice that reflects your real activities, not a generic template.
  • Review consent and direct marketing practices, especially for email and text fundraising.
  • Set retention periods so donor, volunteer and beneficiary records are not kept longer than needed.
  • Check contracts with third party processors such as CRM providers, payroll providers, cloud storage and email platforms.
  • Put extra safeguards around special category data, criminal offence data and safeguarding records.
  • Have an internal process for data breaches, subject access requests and complaints.

What GDPR for Charities Means For UK Businesses

For charities, UK GDPR is not optional paperwork. It shapes how you collect, use, store, share and delete personal information across fundraising, service delivery and internal operations.

A charity is not exempt simply because it has a good purpose. If you process personal data, you are likely acting as a controller for at least some of that information. That means the charity decides why and how personal data is used, and must comply with the core data protection principles.

Those principles include lawfulness, fairness and transparency, collecting data for specific purposes, using only what is needed, keeping information accurate, not retaining it for longer than necessary, and protecting it with appropriate security.

What counts as personal data in a charity?

Personal data is any information relating to an identifiable person. In a charity setting, that can be wider than many teams expect.

  • Donor names, addresses, email addresses and giving history
  • Volunteer applications, references and rota details
  • Employee files, payroll records and sickness information
  • Beneficiary intake forms, support plans and case notes
  • Event registrations, attendance lists and accessibility requests
  • Website enquiry forms, newsletter sign ups and online donation records
  • CCTV footage if used at premises or events

Some data needs extra care. Health information, ethnicity, religion, sexual orientation and details about a person’s vulnerabilities are usually special category data. Many charities process this kind of data as part of their services or safeguarding work. Criminal offence data can also appear in DBS checks, incident records or safeguarding files.

What lawful basis can a charity rely on?

Your charity needs a lawful basis for each use of personal data. You cannot just say “consent” for everything because that often does not reflect how charities actually operate.

Consent may be right for some direct marketing activities, especially where privacy and electronic marketing rules point that way. But charities often rely on other lawful bases for day to day work, such as contract, legal obligation, legitimate interests, vital interests or public task, depending on the organisation’s function.

For example, a charity may use contract to administer paid event bookings or staff employment. It may rely on legal obligation for employment records or safeguarding reporting duties. It may use legitimate interests for some supporter administration where the impact on individuals is limited and expectations are clear. If the charity is carrying out public functions, public task may be relevant in some settings.

Where special category data is involved, you also need a separate condition for processing that type of data. This is where charities often get caught. A lawful basis under UK GDPR is only part of the answer. You may also need a condition linked to employment, social protection, substantial public interest, explicit consent, vital interests, not for profit bodies or health and social care, depending on the circumstances.

Do charities need a privacy notice?

Yes. If your charity collects personal data, people need to understand what you do with it. A privacy notice should explain, in plain English, key points such as:

  • Who the charity is and how to contact it
  • What personal data is collected
  • Why the data is used and the lawful bases relied on
  • Who the data is shared with
  • Whether data is sent overseas
  • How long records are kept
  • What rights individuals have
  • How to complain

This wording needs to match reality. If you collect emergency contact information for volunteers, profile donors, use third party fundraising platforms or keep case management records, your notice should say so clearly.

What about fundraising and marketing?

Fundraising is one of the biggest pressure points for GDPR for charities. Many organisations focus on UK GDPR but forget the separate rules that affect electronic marketing, especially email and text messages.

If your charity sends fundraising communications, review whether you need consent for certain channels and whether any exemptions genuinely apply. Do not assume that a previous donation means you can market freely. Keep a suppression list so people who opt out are not contacted again, and make sure donation platforms feed preferences back into your main CRM.

Trustees should also be careful with wealth screening, profiling and legacy marketing. These activities can be lawful, but they need transparency, a proper legal basis and thought about fairness and expectations.

When This Issue Comes Up

Data protection problems usually appear at moments of growth, change or urgency. The risk goes up when a charity starts collecting more information before it has worked out who can access it, why it is needed or how long it should be kept.

When you launch or formalise a charity

New charities often focus on registration, governance, funding and service design first. Privacy gets pushed to the side. But even at an early stage, you may be collecting trustee details, volunteer applications, supporter contacts and beneficiary referrals. Before you spend money on setup, decide where that information will sit and who is responsible for it.

When you introduce a donor database or CRM

A new CRM can make fundraising far easier, but it also centralises large volumes of personal data. Before you sign a contract with a platform provider, check what data will be uploaded, where it will be hosted, what security is offered, and whether the supplier acts as a processor under a written data processing agreement.

This is also the point to clean existing records. Importing years of outdated supporter data into a new system is a common mistake.

When you start online fundraising or events

Online donation pages, ticketing systems, webinar sign ups and newsletter forms all create new collection points. Each one needs clear wording about what the person is signing up for. Pre-ticked boxes, vague consent language and bundled permissions are common problems.

If children or vulnerable people may register, collect information with extra care. Make sure the form only asks for what is genuinely needed.

When you work with vulnerable beneficiaries

Charities delivering health, social care, housing, domestic abuse, refugee, disability or youth services often process highly sensitive information. This calls for a tighter approach to access controls, confidentiality, retention and information sharing.

Teams sometimes share too much data internally because they are all “part of the same charity”. Access should still be limited to people who need the information for their role.

When you recruit staff and volunteers

Application forms, references, DBS checks, equal opportunities monitoring and emergency contact records all raise privacy issues. You need to explain what information is used for recruitment, what is optional, how long unsuccessful applications are retained and who sees them.

Volunteer management can be overlooked because volunteers are not employees, but their personal data still needs the same disciplined treatment.

When there is a data breach or complaint

The hardest time to fix your process is after something goes wrong. A misdirected email, a lost laptop, public sharing of case notes, or an accidental disclosure in a fundraising mailing can all require a quick response. If there is a likely risk to individuals, the charity may need to assess whether the incident should be reported to the Information Commissioner’s Office and whether affected people should be told.

Practical Steps And Common Mistakes

The most effective approach is to build a working data protection system that fits the charity’s actual activities. Good compliance is less about collecting policies and more about making sure real teams know what to do.

Map your data properly

Start with a data mapping exercise. List what personal data you collect, where it comes from, why you use it, who you share it with and how long you keep it. Include the obvious and the less obvious.

  • Fundraising and donor administration
  • Volunteer recruitment and management
  • Employee records and payroll
  • Beneficiary services and case management
  • Events, campaigns and newsletters
  • Website analytics, cookies and contact forms
  • CCTV and building access systems

This usually exposes gaps quickly. You may find teams collecting duplicate information, using old spreadsheets outside the main system, or retaining files with no clear purpose.

Choose the right lawful basis for each activity

Do this before you rewrite your privacy notice or update forms. If the legal basis is wrong, the paperwork built on top of it will also be wrong.

A frequent mistake is relying on consent when the person has little real choice, or where the charity would still need the data anyway. Another common error is using “legitimate interests” without doing any balancing exercise or documenting why that basis is appropriate.

For charities handling special category data, create a separate record of the condition relied on and any policy document you need to support that processing.

Fix privacy notices and collection wording

Your privacy notice should be layered and practical. A full notice can sit on your website or in longer documents, while short privacy wording can appear at the point of collection on forms, event pages and referral routes.

Common mistakes include:

  • Using legal jargon that supporters and beneficiaries cannot understand
  • Leaving out key sharing arrangements with software providers or partner organisations
  • Failing to explain retention periods
  • Describing consent where the charity actually relies on another lawful basis
  • Using one generic notice for donors, volunteers, staff and beneficiaries even though the processing is very different

Review direct marketing and fundraising permissions

This area deserves its own review because reputational harm can be immediate. Check how people are added to mailing lists, what channel permissions are captured, and how opt outs are respected across all systems.

Make sure forms separate different choices clearly where needed. A person donating to an appeal is not automatically agreeing to receive ongoing fundraising by every channel. If you use third party fundraising agencies or platforms, align their wording with your internal records.

Set a retention schedule

Charities often keep records forever because no one wants to delete something useful. The main risk is that old records become hard to justify, harder to secure and more likely to be wrong.

Your retention schedule should match the types of records you hold and the reason you keep them. Different periods may apply to donor records, Gift Aid information, recruitment files, safeguarding records, financial records and beneficiary case files. The exact period depends on the context, legal requirements and the charity’s reasons for keeping the information.

Avoid “retain indefinitely” unless you can clearly justify it.

Put processor contracts in place

If outside suppliers process personal data on your behalf, your charity usually needs specific contractual terms with them. This often applies to cloud platforms, payroll services, CRM providers, survey tools, outsourced IT support and marketing systems.

Before you sign, check:

  • What data the supplier will process
  • Whether they use sub-processors
  • Where data is stored and whether overseas transfers are involved
  • What security commitments they give
  • How they help with subject access requests and deletion
  • What happens to the data when the contract ends

Train staff and volunteers

Policies do not prevent breaches on their own. People do. Training should be role specific and repeated regularly, especially for frontline teams handling beneficiary information and fundraising teams using supporter data.

Staff and volunteers should know:

  • How to recognise personal and special category data
  • When information can be shared internally or externally
  • How to report a suspected breach quickly
  • How to spot phishing and social engineering
  • How to respond if someone asks for a copy of their data

Prepare for data rights requests and breaches

Charities should have a practical response plan before a request or incident arrives. Subject access requests can come from beneficiaries, ex staff, volunteers, donors or parents. Some requests are straightforward, while others involve third party information, safeguarding concerns or multiple systems.

Data breach planning should cover escalation, internal decision making, evidence gathering and notification steps. Keep the process simple enough that a small team can follow it under pressure.

Common mistakes charities make

The same patterns show up repeatedly:

  • Collecting more information than is needed because a form “might be useful later”
  • Using old mailing lists without checking permissions
  • Giving broad access to case files or beneficiary records
  • Copying another charity’s privacy notice without matching actual practice
  • Forgetting volunteers in training and compliance processes
  • Uploading historic spreadsheets into new systems without cleaning them first
  • Keeping sensitive records indefinitely with no review point
  • Assuming a charitable purpose removes the need for proper consent or lawful basis analysis

FAQs

Do small charities have to comply with UK GDPR?

Yes. Size may affect how formal your systems need to be, but even a small charity must follow UK GDPR if it processes personal data.

Can a charity rely on legitimate interests for fundraising?

Sometimes, but not automatically. The charity needs to consider the purpose, the individual’s expectations, the privacy impact and any separate electronic marketing rules that may require consent for certain messages.

Not always. Consent is only one lawful basis. A charity may rely on another lawful basis for supporter administration, but it still needs to be transparent and handle marketing permissions correctly.

What if a charity handles health or safeguarding information?

That usually means the charity is processing special category data, and sometimes criminal offence data as well. Extra conditions, tighter access controls and stronger internal processes are usually needed.

Does a charity need a contract with its CRM or payroll provider?

Usually yes, if that provider processes personal data on the charity’s behalf. The contract should include data processing terms that meet UK GDPR requirements.

Key Takeaways

  • UK GDPR applies to charities just as it applies to other organisations that process personal data.
  • Charities should identify what data they collect, why they use it, what lawful basis applies and whether special category conditions are also needed.
  • Fundraising, email marketing, beneficiary services, volunteer management and safeguarding work all raise different privacy issues and should not be treated as one generic activity.
  • Clear privacy notices, retention rules, processor contracts, staff training and breach response procedures are the practical foundations of compliance.
  • The biggest mistakes are over collecting data, using weak marketing permissions, keeping records indefinitely and relying on copied templates that do not reflect real practice.

If your business is dealing with GDPR for charities and wants help with privacy notices, fundraising data practices, processor contracts, and data breach procedures, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.

Build privacy controls around the real data flow

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Build privacy controls around the real data flow

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.