About this tool
Generate an NGO privacy policy for donors, volunteers and grant reporting, with IRS receipt thresholds and record retention worked out.
A nonprofit privacy policy has to cover three populations that a generic website template treats as one: donors, whose records are shaped by tax law as much as by data protection law; volunteers, whose files often include criminal record checks; and the people the organisation helps, whose records commonly contain health, belief or political data. This generator writes those sections separately, names an Article 9(2) condition for the sensitive ones, and computes the US receipting thresholds — the 250 dollar written acknowledgment under 26 U.S.C. section 170(f)(8) and the 75 dollar quid pro quo disclosure under section 6115 — alongside the Schedule B contributor threshold and grant record retention under 2 CFR 200.334.
Open Nonprofit Privacy Policy Generator on AltFTool — it loads instantly in your browser.
Provide your input — an image, text, or data.
Let the tool analyze or generate the result.
Review, refine, and reuse the output wherever you need it.
Donors, volunteers and beneficiaries get separate sections instead of one paragraph that fits none of them.
Health, belief and political data are tied to a named Article 9(2) condition, including the not-for-profit exception.
Deductible amount, acknowledgment duty and Schedule B threshold are computed from the figures you enter.
A donor cannot deduct a contribution of 250 US dollars or more without a contemporaneous written acknowledgment from the charity under 26 U.S.C. section 170(f)(8), which must state the amount and whether anything was given in return. Separately, 26 U.S.C. section 6115 requires a written disclosure whenever a donor pays more than 75 US dollars and receives goods or services back, stating that only the excess over their value is deductible.
Not for most public charities. Schedule B to Form 990 lists contributors who gave the greater of 5,000 US dollars or 2% of total contributions, and that copy goes to the IRS. A section 501(c)(3) organisation that is not a private foundation redacts contributor names and addresses from the copy it makes available for public inspection, so the amounts are public but the names generally are not.
Only with a condition from Article 9(2) of the GDPR, because Article 9(1) prohibits it by default. The realistic routes are the person's explicit consent, a substantial public interest condition in domestic law, or the not-for-profit exception in Article 9(2)(d), which lets a body with a political, philosophical, religious or trade union aim process the data of members, former members and people in regular contact with it — provided it is never disclosed outside without consent.
For a US federal award, 2 CFR 200.334 requires financial records, supporting documents and statistical records to be kept for three years from the date the final financial report is submitted, and longer if litigation or an audit begins before that. Indian organisations receiving foreign contribution must preserve those accounts for six years under the Foreign Contribution (Regulation) Act 2010 and file Form FC-4 by 31 December each year. Set the period per record type and confirm it with your auditor.