Resources · 26 June 2026
AI policy for charities (UK): donor data, fundraising and trustee oversight
By the Operating Bench Team · Last reviewed 26 June 2026
Charities run on trust, on tight budgets, and on some genuinely sensitive data: donor records, and information about beneficiaries who are sometimes vulnerable. Your staff and volunteers are already using AI for grant bids, donor research and communications. A clear AI policy lets you keep those time savings without risking donor trust, beneficiary safety, or the attention of a regulator. Here is what it should cover and how to begin.
Why charities need this
- Donor data and fundraising rules. AI is tempting for donor research, wealth screening and profiling, all of which sit squarely under the Code of Fundraising Practice, the Fundraising Regulator and UK GDPR.
- Beneficiary data. Case notes and safeguarding information about beneficiaries are among the most sensitive data a charity holds, and the least suited to a consumer chatbot.
- Volunteers and tight resources. Much of the work is done by volunteers on personal accounts and devices, so a policy that only reaches employees misses half the risk.
What a charity AI policy should cover
- Donor and beneficiary data. State plainly what may and may not go into AI tools. Donor lists, giving histories and beneficiary case data do not belong in an unapproved tool, something we cover in detail in can charities use ChatGPT?. Ground it in UK GDPR, and in PECR for any marketing or fundraising messaging.
- Fundraising and profiling. Reflect the Code of Fundraising Practice: be transparent about how you use data, respect donors’ preferences and the Fundraising Preference Service, and treat AI-driven wealth screening and profiling with care, with a duty not to place donors under undue pressure.
- Beneficiary safeguarding. Make clear that information about vulnerable beneficiaries stays out of unapproved tools, and that AI is never the sole basis for a decision that affects someone’s support.
- Volunteers and personal devices. Bring volunteers explicitly into scope, and give them the same short, clear rules as staff.
- Approved tools and disclosure. Name the AI tools you allow and for what, and decide when to disclose AI use, in communications, in applications, and increasingly because a funder asks.
- Trustee oversight, DPIAs and records. Trustees’ duties of prudence and care extend to AI risk. Complete a data protection impact assessment before adopting a tool that processes personal data, name an owner, and keep records.
Where the regulators sit
Three bodies frame this: the Charity Commission (trustee duties and reputation), the Fundraising Regulator and its Code of Fundraising Practice (how you may raise money), and the ICO under UK GDPR and PECR (how you may use personal data). A charity policy that respects all three is a defensible one.
How to start
- Find out what is already in use, across staff and volunteers, without blame.
- Decide your approved tools and what data may go into each.
- Set a simple data rule: is this safe to put into this tool?
- Brief everyone, staff and volunteers, with a one-page guide.
- Complete a DPIA for any tool that processes donor or beneficiary data.
- Put it to your trustees, name an owner, and review.
That is a defensible baseline, and it is what our AI Safe-Use Pack for charities and non-profits is built to provide: seven core documents rewritten for charities, covering donor and beneficiary data, fundraising practice and trustee oversight, alongside the policy, risk register, approved-tools matrix and a DPIA starter. For the essentials first, the general AI Safe-Use Pack covers the core, and the free AI Starter Kit gives you the ground rules on one page.
This article is general information, not legal advice. How fundraising and data-protection rules apply to your charity should be considered with appropriate professional advice.