Does your site comply with GDPR regulations?
If you are asking yourself what legal requirements you need to comply with when building a new charity website then this post should help. At White Fuse we're not lawyers but we do build a lot of websites so we’ve done the hard work of gathering the information you need to know. Of course, the responsibility for all legal compliance is yours, so be sure to check with a legal advisor for anything you're unsure of.
Collecting data about people
The hardest legal requirements to get your head round relate to the collection of information about users of your website. The way you manage this data is governed primarily by the Data Protection Act 1998 (DPA). This will change from 25 May 2018 when the new EU Data Protection Directive (known as 'GDPR') will take effect in UK law. This new legislation will firm up the existing requirements and, most notably, require organizations to obtain and record active consent before processing data for marketing purposes. In order to comply with your current legal obligations and avoid costly mistakes, you must make sure the information you store is kept secure, accurate and up to date. This legislation covers all of your activities but in relation to the website, there are four specific things to consider:
1. Registration with the ICO
If your organization processes data as defined by the DPA then you need to maintain a registration with the Information Commissioner's Office (ICO). This applies to most organizations but you can comply very quickly on the ICO website.
3. Cookie compliance notification
Cookies are simple text files that are stored on your computer by almost all websites that you visit so they can track information about you. This can include which pages you click on or whether you visited the website in the previous few days.
Showing organizational information
You need to publish a certain amount of information about your organization on your website.
What information should be shown?
- Name of the company or charity
- Registered address
- The part of the U.K. in which the company or charity is registered
- Registered number
- VAT number, if registered for VAT
Where should this information be shown?
There are no specific rules about where this information should be displayed. We recommend showing it in the footer of your website so that it appears on every page but some organisations choose to show it only on the 'about us' or 'contact us' pages.
Websites for those in a regulated profession (such as solicitors or doctors) must also show the following information for each individual professional who is listed on the site:
- Details of any professional body or similar institution with which he or she is registered
- Professional title and the place where that title was awarded
- A reference (ideally through a hyperlink) to the professional rules applicable to the service provider
There are a number of additional requirements for the provision of information when concluding contracts online. To ensure these are all covered, e-commerce sites should display a page of 'terms and conditions' available to all users. These should be laid out clearly and written in plain English. To safeguard your interests, these should be reviewed by a lawyer.
Distance Selling Regulations
E-commerce providers, including trading charities, should make themselves aware of the Distance Selling Regulations. Among other things, these regulations require e-commerce websites to provide the following information:
- The main characteristics of the goods or services offered on the website
- The price of the goods or services, including all taxes
- The cost of delivery of the goods or services
- Payment and delivery information
- A notice that the consumer has the right to cancel the contract without cause during a seven-day cooling off period, other than in exceptional cases
- The minimum duration of any permanent or recurrent contract
Regulations on charity fundraising in the UK are voluntary, meaning the sector relies on a 'self-regulatory' framework to ensure best practice. The thinking behind this is that it is in charities’ best interests to maintain a good reputation for the whole sector. It also saves money and bureaucracy if the sector can effectively police itself.
The self-regulatory framework relies on a number of key actors and resources. Codes of Fundraising Practice have been produced to provide broad best practice guidance in various key areas. These are maintained by the Fundraising Regulator which also handles any complaints and works proactively with charities to improve the reputation of the sector and promote responsible fundraising practices.
Quick fundraising checklist for websites
If you have clear answers to the following there is a good chance you are at least on the right track:
- Are you confident of the privacy and security of data you hold on your supporters and stakeholders?
- Are donations processed securely?
- Do your marketing materials contain clear information about your organisation and activities that could not be seen as misleading?
- Could any of the imagery in your materials be shocking or offensive?
- Have you made it clear how supporters can donate in a tax efficient manner?
- Do you have a complaints procedure? How is this publicised?
If you have any doubts about legal requirements, speak to a lawyer.
*This article was updated on March 22, 2018.
For more from White Fuse, visit https://whitefusemedia.com.