Most charities have a notice on the website, usually headed privacy policy, and most of those notices were written with donors in mind. The volunteers the charity depends on and the people it exists to help are often covered by a sentence. This guide sets out what the law requires, what each group needs to be told, a template outline to adapt, and the part of a charity's data that its notice rarely describes.
The rule: the right to be informed in Articles 12 to 14
A charity that decides why and how personal data is used is a data controller, and the UK GDPR, Article 13 requires it to give people a defined list of information about that use "at the time when personal data are obtained". The Information Commission's Office (ICO) calls this "privacy information" and the document that carries it a privacy notice, "sometimes known as a privacy policy". Charitable status, income and size make no difference: a parish lunch club with a list of members' dietary needs has the same duty as a national charity, in proportion to what it holds.
Three articles do the work. Article 13 applies when the charity collects data from the person themselves: the donation form, the volunteer application, the referral a beneficiary fills in. Article 14 applies when the data comes from someone else, such as a local authority referral, a GP's letter, a fundraising platform or the emergency contact a volunteer names. Article 12(1) sets the standard for both: the information must be given "in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child". The ICO's right to be informed guidance adds that "You must actively provide privacy information to individuals": a page on the website counts only if people are made aware of it and given an easy way to reach it.
The Data (Use and Access) Act 2025 has changed the list. Since 19 June 2026, Article 13(2)(ca) and Article 14(2)(da) require the notice to tell people of "the right to make a complaint to the controller", alongside the right to complain to the regulator, and the ICO's guidance on preparing to handle data protection complaints says "You must tell people they can complain to you, as well as to us", for example "by displaying this in your privacy notice". On 30 September 2026 section 118 of the Act abolished the office of Information Commissioner, and section 119 transferred its functions to the Information Commission. The ICO's right to be informed pages carry a banner saying the guidance "is under review and may be subject to change" because of the Act, so check the date on any ICO page or template before relying on it.
Who a charity's notice has to reach
Before drafting, list every group whose personal data the charity holds and how it arrives. The ICO's small-organisation guide on how to write a privacy notice asks for the same inputs: the types of personal data collected, where it came from if not from the person, why it is held, the lawful basis, who it is shared with and how long it is kept. In most charities the groups are:
- Donors and supporters: names, contact details, donation history, Gift Aid declarations, bank details for regular gifts, event registrations and marketing preferences.
- Volunteers: applications, references, emergency contacts, availability, training, expenses and, for some roles, criminal record check information, which is criminal offence data with its own conditions.
- Beneficiaries and service users: referral forms, case notes, needs assessments, attendance and, very often, health information or other special category data such as religious belief or ethnicity.
- Staff: recruitment, payroll, absence and performance records, usually in a separate workforce notice.
- Trustees: eligibility declarations, the register of interests and the details published or filed with the regulator.
- Third parties named by someone else: emergency contacts, referrers, family members mentioned in a case note, and people photographed at events.
One notice rarely reaches all of them in clear and plain language. A donor reading on the website, a volunteer in a welcome pack and a beneficiary at a drop-in counter need different words. The usual answer is a short notice for each group, at the point where that group's data is collected, each linking to one full notice that sets out everything. The ICO recognises this layered approach ("short notices containing key privacy information that have additional layers of more detailed information"), and calls it good practice "to use the same medium you use to collect personal data to deliver privacy information": a printed form gets a printed short notice, a phone referral gets it said aloud and followed up.
What the notice must contain
Articles 13 and 14 set the list, and the ICO's checklist puts it in plain terms. A charity's full notice should work through it, with a charity's usual answer to each:
- Who the controller is, with contact details that reach a person: the charity's full registered name and address, not a trading name or a branch.
- The data protection officer's contact details, if the charity has one. Most small charities are not required to appoint one; our guide to a charity's data protection policy sets out the test.
- The purposes and the lawful basis for each: processing donations and Gift Aid, sending updates, running the service, recruiting and supporting volunteers, safeguarding. Each purpose needs its own basis, and where it is legitimate interests, the notice must say what those interests are.
- The categories of personal data, where the data did not come from the person (Article 14(1)(d)).
- The recipients or categories of recipients: HMRC when Gift Aid is claimed, a fundraising platform, a referral partner or the local authority, a funder that receives case studies, and the data processors that handle data for the charity, such as the supporter database, the mailing platform and the payroll bureau.
- Transfers outside the UK and the safeguards relied on, where personal data is transferred outside the UK because a supplier stores or accesses it abroad.
- How long the data is kept, or the criteria used to decide, and that it is deleted or anonymised at the end. Some periods are set elsewhere: for Gift Aid, HMRC's guidance on Gift Aid declarations says "You must keep a record of declarations for 6 years after the most recent donation you claimed Gift Aid on."
- The person's rights: access, rectification, erasure, restriction, objection and portability where they apply, and how to make a request.
- The right to withdraw consent at any time, where consent is the basis.
- The right to complain to the charity, and how, and the right to complain to the regulator.
- Whether providing the data is a statutory or contractual requirement, and what happens if the person does not provide it (Article 13 only): for example, that Gift Aid cannot be claimed without a declaration.
- Where the data came from, if not from the person, and whether from a publicly accessible source (Article 14 only).
- Any automated decision-making, including profiling, with meaningful information about it, where it applies.
Timing differs between the two articles. Under Article 13 the information is due when the data is collected. Under Article 14(3) it is due "within a reasonable period after obtaining the personal data, but at the latest within one month", or at the first communication with the person, or when the data is first disclosed to someone else, whichever is earliest. Article 13(3) and Article 14(4) add the rule charities most often miss: before using data for a new purpose, tell people about that purpose first. Starting a newsletter for beneficiaries, sharing volunteer details with a new partner or adding an AI tool to the supporter database is that case.
Donors, volunteers and beneficiaries: what each notice adds
Donors and supporters. The notice is where a supporter learns how the charity will contact them, so it has to match the marketing rules as well as UK GDPR. Since 5 February 2026 charities can use the charitable purposes soft opt-in under the Privacy and Electronic Communications Regulations to send direct marketing by email and text that furthers their charitable purposes without consent, but the ICO's guidance on the electronic mail marketing rules says the charity "must obtain the contact details directly from the person", must have obtained them through the person "expressing an interest in, or offering or providing support for" its charitable purposes, must give "an opportunity to refuse or opt out" when it collects them and in every message, and may use it only for contact details obtained on or after that date. Details passed on by an online fundraising platform do not qualify. The notice should also describe any research into supporters, such as wealth screening or matching against public records: the ICO tells controllers to "be very clear with individuals about any unexpected or intrusive uses of personal data, such as combining information about them from a number of different sources".
Volunteers. A volunteer privacy notice explains what the charity does with a volunteer's own data: the application and references, any Disclosure and Barring Service (DBS) check the volunteering role requires, emergency contacts, training and supervision records, expenses, and photographs at events. It should say which checks are required for which roles, who sees the results and how long they are kept, because criminal offence data needs a condition under the Data Protection Act 2018 as well as a lawful basis. The ICO's generator has a version for staff and volunteer information, updated on 10 July 2026 to reflect the Data (Use and Access) Act. Give the notice with the application form, not at induction, and repeat it in the volunteer handbook; our guide to volunteer records covers what to keep.
Beneficiaries and service users. This is the notice that matters most and the one most often missing. It needs plain words, an accessible format where people need one (large print, easy read, a translated version, or explained aloud), and honesty about sharing: with referral partners, with the local authority, with the GP, and the circumstances in which the charity will share information without agreement to protect someone from harm. When a referral arrives from another organisation, Article 14 applies, and the one-month clock starts on arrival. A child using the service is owed a version written for them. Article 14(5) lets the charity withhold the information where giving it would be impossible, would involve disproportionate effort, or would "render impossible or seriously impair" the purpose of the processing, and a controller relying on any of those three must protect the person's interests in other ways, "including by making the information available publicly". A safeguarding referral can engage that exception; a routine service cannot.

A template outline, and keeping it true
The ICO's privacy notice generator is the best free starting point: its page says the tool "has been designed for sole traders and start-ups, as well as small and medium-sized businesses and charities", and it has charity and voluntary sector versions for customer and supplier information, updated on 7 July 2026. Whatever the source, a charity's full notice usually follows this outline. The headings and the example charity are fictional:
- About us: "Millbrook Community Pantry is a registered charity. We are the controller for the personal information described here. Contact our data protection lead at …"
- The information we hold: a short table by group – supporters, volunteers, people we help, staff, trustees – with the categories of data for each, and which of it is special category or criminal offence data.
- Why we use it, and our lawful basis: one line per purpose, with the basis and, for legitimate interests, the interest.
- Where it comes from: from you; from the organisation that referred you; from a fundraising platform you gave through.
- Who we share it with: named categories, and the named suppliers where that is more meaningful.
- Keeping in touch: what we send, how to opt out, and that opting out never affects the help you receive.
- How long we keep it, and how we keep it secure: the periods from the retention schedule, by record type, and the main security measures in a sentence or two.
- Your rights, how to complain to us, and how to complain to the regulator.
- Changes to this notice: the date of this version, and how we will tell you about a new use before it starts.
Then the short notices: three or four sentences on the donation form, the volunteer application and the referral form, each naming the charity, the purpose, who it is shared with and where the full notice is. The ICO's checklist says "We regularly review and, where necessary, update our privacy information". In practice that means checking the notice against the charity's retention schedule and supplier list at least once a year, and whenever a new service, partner or system starts. A notice whose date has been rolled forward without anyone reading the supplier list has not been reviewed.
The data the notice does not describe
Read a typical charity privacy notice and the personal data lives in four places: the supporter database, the case management system, the volunteer spreadsheet and a locked cupboard. Ask the volunteers where a beneficiary's details actually go and a fifth place appears. The coordinator posts Monday's delivery list, with names and addresses, in the volunteers' group chat. A driver replies that the woman at number 12 seemed confused and the house was cold. A volunteer photographs a referral form so the next shift has the access code. A family member messages the coordinator's personal number about a hospital discharge.
Each of those is personal data the charity is processing, some of it special category, and the notice says nothing about it. The recipients list does not include the messaging app or the forty phones the messages sit on; the retention statement cannot be true for messages the charity cannot delete; and a beneficiary who asks for everything the charity holds about them is entitled to the messages too, which the charity cannot search. An end-to-end encrypted consumer app gives the charity no copy of its own, by design.
There are two honest fixes, and both start with the trustees. One is to change the notice so that it describes what really happens, which most trustees will not want to sign. The other is to change the practice: keep operational messages about people the charity supports in a channel the charity controls, with everyone in it told that it is on the record. ComplyChat is built for that – a mobile number verified by SMS is the identity, so volunteers without a charity account can take part, messages are stored and processed in the UK, and on paid plans the lasting record files into the charity's own Microsoft 365 once its tenant is connected, under its own retention rules. It does not write the notice or choose the lawful basis.
A question for the next trustees' meeting: if a beneficiary read our privacy notice and then saw the volunteers' group chat, would they recognise the charity the notice describes?
Questions people ask
What should be included in a privacy notice?
A privacy notice must include who the controller is and how to contact it, the DPO's details if there is one, the purposes and lawful basis for each, any legitimate interests relied on, the recipients, any transfers outside the UK, how long the data is kept, the person's rights, the right to withdraw consent where relevant, and the rights to complain to the organisation and to the regulator. Articles 13 and 14 of the UK GDPR set the list, and Article 14 adds the categories of data and their source when the data came from someone else.
Can you provide an example of a privacy notice?
The ICO's free privacy notice generator produces one tailored to the organisation, with versions for the charity and voluntary sector and for staff and volunteer information. Section five of this guide gives a fictional outline a charity can adapt, with a short notice for each form that links to the full one.
Can I write my own privacy policy in the UK?
Yes. The ICO's small-organisation guidance notes that a privacy notice is "sometimes known as a privacy policy" and offers a generator built for "small and medium-sized businesses and charities". Whoever writes it must decide the lawful bases first and cover everything Articles 13 and 14 list, in clear and plain language.
Do charities need a GDPR policy?
A charity needs data protection policies where that is proportionate to its processing: Article 24 of the UK GDPR says a controller's measures shall then include "the implementation of appropriate data protection policies". The privacy notice is a separate, outward-facing document: the policy tells trustees, staff and volunteers how the charity handles data, and the notice tells the people whose data it is.
Does GDPR apply to volunteers?
Yes. UK GDPR protects any "information relating to an identified or identifiable natural person" under Article 4(1), so a charity's records about its volunteers are personal data and the volunteers are owed a privacy notice like anyone else. When volunteers handle the charity's data about other people, they do so for the charity, which remains the controller responsible for it.
Official guidance and your next step
The primary sources are Article 14 of the UK GDPR with Articles 12 and 13, the ICO's right to be informed guidance and its checklists, the ICO's privacy notice generator, its complaints guidance and its guidance on electronic mail marketing for the charitable purposes soft opt-in. Quotations are from those pages as read on 3 October 2026; several ICO pages carry a banner saying they are under review following the Data (Use and Access) Act 2025, so check the date on the page you use.
This guide is a practical summary for charities in the UK, not legal advice. Where a charity shares sensitive information with statutory services, works with children, or relies on an exemption to withhold privacy information, take professional advice.
Then do one thing: take the charity's three main forms – donation, volunteer application and referral – and check that each carries a short notice that names the charity, the purpose and who the data is shared with, and links to a full notice dated within the last year. Any form without one is where to start.
We build ComplyChat for the work conversations organisations need to keep. In many charities the personal data the privacy notice never mentions sits in volunteers' messages, and a notice can only be true about places the charity can see. The organisational record described here is on paid plans; Free is personal messaging with one private group, direct messages and three calendar months of recent history, and it is not a way to meet a retention duty.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- UK GDPR, Article 13 legislation.gov.uk
- Right to be informed guidance ico.org.uk
- Preparing to handle data protection complaints ico.org.uk
- How to write a privacy notice ico.org.uk
- Gift Aid declarations gov.uk
- The electronic mail marketing rules ico.org.uk
- Privacy notice generator ico.org.uk
- Article 24 of the UK GDPR legislation.gov.uk
- Article 14 of the UK GDPR legislation.gov.uk




