- Regulation (EU) 2016/679 — GDPR, Article 27
- Directive 2002/58/EC for fundraising communications
- Directive (EU) 2015/849 — AML for certain transfers
- Regulation (EU) 2022/2065 — DSA where the platform hosts campaigns
Who has to appoint one
Nonprofits and donation platforms established outside the Union that collect data about donors, members or beneficiaries in the EU. Nonprofit status does not create an exemption: the GDPR applies to any controller processing personal data, and fundraising communications are subject to the same marketing rules as commercial ones.
Thresholds and exemptions
No threshold, and the Article 27(2) exemption rarely applies because donor databases are neither occasional nor low-risk. Data revealing religious or political affiliation, common in this sector, is special-category data requiring an Article 9 condition.
What must appear on the label
Not physical. The representative's identity in the privacy notice, transparent information about how donations are used, and clear consent mechanics for fundraising communications.
Marketplace fields
Payment providers and card schemes apply their own due diligence to donation platforms, and cross-border fundraising attracts national rules on public collections in several member states.
Documentation you must hold
Article 30 records, the Article 27 designation, consent records for marketing, retention schedules for lapsed donors, the transfer mechanism, and where the organisation processes data revealing beliefs or political opinions, the Article 9 basis, which for member organisations is usually the not-for-profit body derogation.
Standards and testing
Not applicable, though wealth screening and donor profiling have been criticised by authorities and require a documented assessment.
Language requirements
Privacy and consent information in the language of the donors.
When it applies
The representative before processing begins. Consent before any non-essential tracking on the donation page, which is where many platforms fail.
How long records are kept
Lapsed donor data for a defined period rather than permanently. Indefinite retention of donor histories has been penalised.
What happens if you do not comply
Up to €20 million or 4% of turnover, and authorities have shown no reluctance to fine charities: several of the earliest UK and EU cases in this area concerned donor profiling and data sharing between organisations.
Who enforces it
Data protection authorities, national authorities regulating public collections, and financial intelligence units for AML aspects.
Where the boundary lies
Membership of an organisation can itself reveal religious or political beliefs, making the member list special-category data. The not-for-profit body derogation in Article 9(2)(d) covers members and regular contacts, but not general marketing to purchased lists.
Questions we are asked
- Are charities exempt from the GDPR?
- No. There is no nonprofit exemption. The only relief is the Article 9(2)(d) condition for processing members' data within the organisation.
- Can we share donor lists with partner organisations?
- Only with a lawful basis and transparency, and where beliefs are revealed, an Article 9 condition. Sharing donor lists without consent has produced enforcement in several member states.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom