Is my charity newsletter GDPR compliant?
Consent, unsubscribing and legitimate interest explained, with sources from the Belgian DPA, CNIL and EUR-Lex. General information, not legal advice.
A charity newsletter is GDPR compliant when you have a valid reason to email each person (in practice usually their consent), you tell them clearly who you are and what they will receive, every mail has an easy unsubscribe, and you stop mailing people who object. This article is general information, not legal advice: for your own situation, ask the data protection authority or a lawyer.
Do I need consent to send a newsletter?
In most cases, yes, consent is the safest basis. The GDPR requires consent to be given by a clear affirmative act. Silence, pre-ticked boxes or inactivity do not count, and you must be able to show that the person consented. The European Data Protection Board has published guidelines on what valid consent means (Guidelines 05/2020).
Consent should also be separate from other matters, in clear and plain language, and not tied to something the person needs from you, such as a receipt.
The French authority CNIL says the same for email prospecting of individuals: consent must be free, specific, informed and unambiguous, with an unticked box. It notes an exception for existing customers and similar products, and it adds that merely creating an online account is not a sale.
What about legitimate interest for charities?
Recital 47 of the GDPR says processing for direct marketing may be regarded as carried out for a legitimate interest. CNIL's page on prospecting says that fundraising organisations may use legitimate interest instead of consent, provided they inform people that their data will be used for non-commercial prospecting and let them object easily and free of charge.
Because rules differ by country and by situation, and because national electronic-marketing rules may apply on top of the GDPR, do not assume this covers you. When in doubt, use consent.
Can people always stop me?
Yes. Under Article 21 GDPR people may object to direct marketing at any time. Once they do, you may no longer process their data for that purpose, and you must bring that right clearly to their attention at the latest at the first communication.
You reply to a request in principle within 1 month. Withdrawing consent must also be as easy as giving it (Article 7). That is why every mail needs a visible unsubscribe link, and why you must act on it.
What should the newsletter itself contain?
- Who you are: organisation name and address in the footer.
- Why they receive the mail and how to leave.
- A link to your privacy policy that explains what data you keep and why.
- Only the data you need. For a newsletter, an email address and a first name are usually enough.
What about my existing contact list?
Check where each contact came from and what they were told. People who gave you their address for a receipt did not necessarily agree to a newsletter. Keep a record of when and how consent was given. If you cannot show it, ask again or leave them out. For the practical side, see our article on growing an email list.
Where do the authorities explain this?
The Belgian Data Protection Authority has a themed page on marketing, noting that direct marketing messages may only process personal data in line with the GDPR and that it adopted a recommendation on direct marketing. CNIL publishes practical guidance for email campaigns. The legal texts are on EUR-Lex. Read them rather than relying on a summary, including ours.
How does WeGlow Mail help?
WeGlow Mail is built to make the basics visible. Every mail carries a compliance footer with your sender identity, address and an unsubscribe link, in the recipient's language. The Check step before sending explains that marketing mail must name the sender and location, and leaves out contacts who unsubscribed or whose address bounced.
When you import contacts, a consent tickbox is recorded as a GDPR record, and you can undo an import within 24 hours. Subscription statuses such as unsubscribed and bounced are kept per contact.
WeGlow Mail does not make you compliant by itself: you remain responsible for having consent and for what you write. Price: WeGlow Mail is included free up to 250 contacts (500 emails per month) in every plan. Start (up to 1,000 contacts) is €19 per month (excl. VAT), Growth (up to 2,500) is €29. With the Pro platform plan (€40 per month or €400 per year) mailing is included up to 2,500 contacts. Check the current prices in your dashboard.
Do I need double opt-in?
The sources we checked do not make a universal rule of it. It is, however, a way to prove consent, and you must be able to do that. Ask your data protection authority what it expects in your situation before you decide.
Can I email people who donated?
Not automatically. It depends on what they were told and agreed to when they gave. People who gave you their address for a receipt did not necessarily agree to a newsletter, so ask for it as a separate choice.
How long may I keep an address?
Only as long as you need it for the purpose it was collected for. Give every address a clear purpose, check regularly whether that purpose still exists, and remove people who unsubscribe from your sending list.
Can unsubscribing be harder than subscribing?
No. According to the European Commission, withdrawing consent must be as easy as giving it, and the Belgian Data Protection Authority says objecting and withdrawing must be possible at any time, easily and free of charge. A hidden or laborious unsubscribe does not fit that.
Read next
- How do I grow an email list for my charity?
- How do I keep my charity emails out of spam?
- How do I segment my donor emails?
Sources
- GDPR (EUR-Lex): consent, Article 7, Article 21, Recital 47 on direct marketing and legitimate interest (checked on 2 October 2026).
- EDPB, Guidelines 05/2020 on consent: the Board's guidelines on valid consent (checked on 2 October 2026).
- CNIL, la prospection par courrier électronique: consent for individuals, existing-customer exception, fundraising organisations and legitimate interest (checked on 2 October 2026).
- Belgian Data Protection Authority, marketing: direct marketing must comply with the GDPR; recommendation on direct marketing (checked on 2 October 2026).
- European Commission, legal grounds for processing data: consent must be freely given, informed, specific and unambiguous, and as easy to withdraw as to give; legitimate interest only if the person's rights do not override it (checked on 3 October 2026).
- European Commission: objection to direct marketing, duty to inform at the first communication and a reply in principle within 1 month (checked on 3 October 2026).
- Belgian Data Protection Authority, your rights regarding direct marketing (in Dutch): objecting and withdrawing consent at any time, easily and free of charge (checked on 3 October 2026).
- Belgian Data Protection Authority, consent and legitimate interests (in Dutch): no hierarchy between legal grounds (checked on 3 October 2026).
More from Glowie
- The Complete Non-Profit Newsletter Guide
- How do I grow an email list for my charity?
- How do I handle donor data under the GDPR?
- How do I keep my charity emails out of spam?
- How do I segment my donor emails?