Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should charities build consent processes that satisfy…
Governance, Ownership & Risk

How should charities build consent processes that satisfy GDPR when they collect supporter data for fundraising and events?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Governance, Ownership & Risk

Charities should treat consent as a controlled, documented process, not a one-time checkbox. The consent request must be clear, specific, freely given, and tied to a positive action. They should also make withdrawal easy, stop communications after opt-out, and embed privacy by design into systems that store and process donor and supporter data.

For charities, consent is only valid when supporters understand exactly what they are agreeing to and can choose without pressure. That means separating fundraising consent from event registration, membership updates, or general service messages, and avoiding bundled opt-ins that make the choice unclear. The consent flow should record what was shown, when it was shown, and which channel the supporter accepted.

Under GDPR, consent is a legal basis, not a convenience layer. That makes the design of the journey as important as the wording of the notice: the opt-in must be specific, granular, and presented before processing starts, so the charity can prove it had permission for the exact use case.

For supporter data used in fundraising and events, charities should also think in terms of purpose limitation. If the same data set will support donations, volunteer engagement, or event logistics, the consent capture should reflect those separate purposes rather than assuming one permission covers all future communications.

A defensible process is one that can survive review by a regulator, a trustee, or the charity’s own data protection lead. The practical test is whether the organisation can show a clean chain from notice to action to recordkeeping: the supporter saw a clear request, actively opted in, and the system stored evidence of that decision in a retrievable form.

Charities should build the process around minimum necessary collection. If an event only requires registration and follow-up logistics, do not ask for broad marketing permission at the same moment unless it is genuinely optional and clearly separated. The same principle applies to fundraising, where supporters may agree to one channel but not another, or to operational messages without agreeing to future appeals.

Consent management also needs a withdrawal path that is as easy as the original opt-in. A supporter who unsubscribes should not have to navigate a separate support process, and the operational systems behind email, SMS, event tools, and CRM records must honour that choice quickly and consistently.

Risk and Threat Considerations

Consent failures usually happen when charities treat privacy as a formality rather than a control. The risk is not only non-compliance, but also unnecessary collection, confused supporter expectations, and communications sent after a withdrawal request because the operational systems were not aligned.

Failure mechanism: The charity bundles unrelated purposes, fails to capture a clear affirmative action, or stores consent records in a way that cannot be matched to the actual notice and campaign, which weakens proof and increases the chance of invalid processing.

Impact: The organisation may lose the lawful basis for outreach, face complaints or enforcement risk, and damage trust with supporters who feel they were marketed to without a meaningful choice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST AI RMF and NIST SP 800-63 set the technical controls, while EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
EU AI ActGeneral Compliance and GovernanceGDPR consent design needs documented governance, accountability, and proof of lawful processing.
Recommendation — Document consent decisions and operational controls so each processing purpose can be evidenced and reviewed.
NIST CSF 2.0GV.OV — OversightCharity consent handling depends on governance oversight, accountability, and auditable privacy practice.
Recommendation — Assign oversight for consent governance and verify records support the organisation’s privacy obligations.
CIS Controls v85 — Account ManagementConsent withdrawal and supporter preference handling rely on accurate account and contact-state management.
Recommendation — Synchronise supporter preference changes across systems so opt-outs are enforced consistently.
NIST AI RMFGovernPrivacy-by-design consent workflows require accountable governance over data use and recordkeeping.
Recommendation — Establish governance for consent capture, storage, and withdrawal so processing stays within approved purposes.
NIST SP 800-636.1 — Identity proofing and enrollmentSupporter onboarding and permission capture benefit from clear enrollment-style confirmation of requested processing.
Recommendation — Treat consent capture as an explicit enrollment step and retain evidence of the exact choice made.

Practitioner Guidance

What to verify: Check that each consent path is purpose-specific, timestamped, and linked to the exact wording shown to the supporter. If your CRM cannot distinguish fundraising consent from event consent, the process is too blunt to rely on.

Decision rule: If the communication is essential to deliver the event or transaction, treat it as operational messaging rather than marketing consent; if it is optional, separate it clearly and do not make access dependent on agreement.

What good looks like: A supporter can opt in to one channel, decline another, and withdraw later without staff intervention, while the system stops future sends and preserves a usable audit trail for the decision.

Practitioner takeaway: The strongest charity consent process is not the longest notice, but the one that can be proved, enforced, and withdrawn cleanly across every system that touches supporter data.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org