GDPR
Does GDPR apply to non-profits?
Yes. The GDPR has applied since 25 May 2018, and charities, associations and other non-profits have no general exemption.
Under the GDPR’s rules on which organisations are covered, it generally applies when a non-profit:
Processes personal data in the context of its establishment in the EU.
Operates outside the EU but processes data in connection with offering goods or services to people in the EU, including free services, or monitoring their behaviour there.
Donor records, membership lists, volunteer details and employee information can all be covered. GDPR compliance requires a lawful basis, transparent notices, appropriate security and respect for individuals’ rights. Consent is one possible lawful basis, not a requirement for every activity.
Türkçe
English