How do I handle donor data under the GDPR?
Know why you hold data, record consent per channel, keep data no longer than needed and answer access or erasure requests within a month.
To handle donor data under the GDPR, know why you hold each piece of data, record how people agreed to be contacted, keep data only as long as you need it, and answer requests for access or erasure within one month. This article gives a practical overview for small non-profits. It is general information, not legal advice; for your own situation, ask a lawyer or your data protection authority.
Which rules apply to a non-profit?
The General Data Protection Regulation (GDPR) applies to every organisation that processes personal data of people in the EU, including associations and foundations. Donor names, emails, addresses and gift histories are personal data. The regulation is published on EUR-Lex, and the national supervisors, such as the Belgian Data Protection Authority and the French CNIL, publish guidance in their own language.
Do I need consent to contact donors?
Consent is one of the lawful bases in Article 6, not the only one. Processing a donation you received, or issuing a tax certificate, rests on other bases. Sending marketing, such as a fundraising newsletter, often relies on consent, though the rules can differ by country and by channel (email, post, phone), so check your national guidance. When you do rely on consent:
- You must be able to show it. Record who agreed, when and where.
- It must be specific. Agreeing to a newsletter is not agreeing to be called.
- People must be able to withdraw as easily as they gave it (Article 7(3)), and every person can object to direct marketing at any time (Article 21).
WeGlow CRM keeps consent per channel on each contact: newsletter and email, post, phone, and use of photos. For each channel it shows whether the person agreed, since when and from which source, or that nobody has asked yet.
How long may I keep donor data?
The GDPR does not give one number. Article 5(1)(e) says personal data may be kept no longer than necessary for the purpose, and the European Commission advises setting time limits to erase or review the data. Different purposes have different clocks:
- Active supporters: as long as the relationship lasts and they have not objected.
- Accounting and tax records: as long as the law requires. WeGlow CRM mentions a legal retention period of 7 years after the assessment year for tax certificates, and prevents erasure of a contact while that period runs.
- Inactive contacts: set a review rhythm, for example once a year, and decide who to remove. Write the rule down.
The retention periods you pick are your decision as the organisation; the legal minimums for accounting differ by country.
What do I do when someone asks for their data or wants to be forgotten?
Under Articles 12 to 17 you must answer within one month (in Dutch), which can be extended by up to two further months for complex cases, with notice. People may ask for a copy of their data (access) and, in many cases, for erasure. Erasure has exceptions (in Dutch), such as legal obligations to keep accounting records.
- Confirm who is asking, without collecting more data than needed.
- Find the person in your database.
- Export their data, or erase it, and note the date.
- Reply in writing within the deadline.
On a contact in WeGlow CRM you can export the person's data as a file, or choose to anonymise or delete. Both erasing options ask you to type the contact's email address to confirm. Personal data is erased, while donation amounts stay on record anonymously for accounting. The system blocks erasure when tax certificates are still within the legal period, when a recurring donation is active, or when a membership is collected by direct debit, and tells you why. There is also an export of all contacts, gifts and certificates, and an audit log of changes.
What else should be in order?
Four things: a register of processing activities, access rules, a breach plan and a privacy notice. Each has its own rules.
- A register of processing activities (Article 30). Smaller organisations are partly exempt, but the exemption is narrow (in Dutch), so many keep one anyway. WeGlow CRM has a field to note who else at your organisation has access.
- Access rules. Give team members the lowest role they need; WeGlow CRM roles are enforced in the database.
- A breach plan. A serious breach must usually be reported to the authority within 72 hours (Article 33).
- A privacy notice on your donation page and in your first email.
What does a tool cost, and where do I start?
Start with a half-day audit: where is donor data, who has access, what is the lawful basis. If you want everything in one place, WeGlow CRM starts from €29 per month (excl. VAT) for up to 1,000 contacts, €59 for up to 5,000, €89 for up to 10,000 and €149 for up to 25,000. Check the current prices in your dashboard.
Are small associations exempt from the GDPR?
No. Size does not exempt you from the main rules, although some obligations, such as the register, have partial exceptions.
Can I keep the gift if someone asks for erasure?
You can keep anonymous financial records. Personal data tied to legal retention duties may have to stay until the period ends.
Is a GDPR tool enough to be compliant?
No. A tool helps with records, exports and access, but compliance also depends on your policies and habits.
Read next
- The Complete Non-Profit CRM Guide
- How to manage volunteers and members in one database
- How to move your donors from Excel to a CRM
Sources
- EUR-Lex: Regulation (EU) 2016/679 (GDPR): Articles 5, 6, 7, 12 to 17, 21, 30 and 33 (checked on 2 October 2026).
- European Commission: legal grounds for processing data: consent must be freely given, informed, specific and as easy to withdraw as to give (checked on 3 October 2026).
- European Commission: principles of the GDPR: keep data for the shortest time possible and set time limits (checked on 3 October 2026).
- European Commission: obligations for organisations: notify a data breach within 72 hours (checked on 3 October 2026).
- Belgian Data Protection Authority: rights of citizens: answer within one month, with an extension for complex requests, in Dutch (checked on 3 October 2026).
- Belgian Data Protection Authority: the right to erasure: exceptions, including a legal obligation, in Dutch (checked on 3 October 2026).
- Belgian Data Protection Authority: register of processing activities, exceptions, in Dutch (checked on 3 October 2026).
- CNIL: Guide RGPD pour les associations: the French supervisor on associations and the GDPR, in French (checked on 3 October 2026).
- WeGlow CRM privacy features and dashboard prices (checked on 2 October 2026).
More from Glowie
- The Complete Non-Profit CRM Guide
- How to manage volunteers and members in one database
- How to move your donors from Excel to a CRM
- How do I segment and list my supporters?
- How do I track major donors and sponsors?