Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Legal Issues To Check Before You Sign
- 1. What exactly are donors agreeing to?
- 2. Can you lawfully collect and use donor data the way you plan to?
- 3. Who owns and controls the donor database?
- 4. Where does liability sit if there is a payment error or data breach?
- 5. Are your fundraising claims specific enough, but not too specific?
- 6. Do state and territory fundraising rules apply?
FAQs
- Do Australian charities need donation terms on their website?
- Does the Privacy Act apply to every charity or not-for-profit?
- Can we keep donor details and contact people about future fundraising?
- Can donors ask for a refund?
- What should we review before accepting a fundraising platform's standard terms?
- Key Takeaways
Online fundraising can look simple on the surface. Add a donation button, connect a payment gateway and start sharing your campaign. But charities, social enterprises and community organisations often get caught by three avoidable mistakes: using vague donation terms, collecting donor data without a clear privacy position, and relying on a platform's standard terms without checking who carries the risk if something goes wrong.
Those issues matter before you accept your first donation. A donor complaint about recurring payments, a data breach involving supporter information, or a dispute with a fundraising platform can create real cost and reputational damage. This guide answers the practical legal questions Australian charities and online fundraisers should sort out first, including what your donation terms should cover, when the Privacy Act may apply, how to handle direct marketing consent, and what to review before you sign a platform or service provider agreement.
Overview
Donation terms and privacy settings are not just admin documents, they shape the legal relationship with your donors and the way your organisation handles personal information. Clear terms reduce disputes, and a properly drafted privacy position helps you collect, use, store and disclose donor data lawfully and transparently.
- Set out whether donations are one-off, recurring, refundable or non-refundable.
- Explain how payment processing, receipts, failed payments and chargebacks are handled.
- State who is collecting donor information, why it is collected and how it will be used.
- Check whether your organisation must comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- Address direct marketing, supporter communications and opt-out processes.
- Review fundraising platform terms, data ownership, liability caps and termination rights before you sign.
- Make sure your campaign wording does not mislead donors about where funds will go.
What Donation Terms and Privacy Legal Essentials for Charities and Online Fundraisers Means For Australian Businesses
At a practical level, this means your organisation needs two things working together: donation terms that tell donors the rules of giving, and privacy documentation, including a privacy policy or collection notice, that tells people what happens to their personal information.
For many Australian charities and not-for-profits, the legal work starts at the point money and personal information are collected online. That could be through your own website, a crowdfunding page, a peer-to-peer fundraising platform, an event registration system or a third party donation processor.
Why donation terms matter
Donation terms help manage expectations before a donor clicks pay. They are especially useful where your fundraising involves recurring contributions, workplace giving, major donor pledges, campaign-based appeals or fundraising events with ticket components.
A clear set of written terms can cover:
- whether donations are gifts or payments for goods or services
- whether donations can be cancelled or refunded, and in what limited circumstances
- how recurring donations are authorised, changed or stopped
- how failed payments, chargebacks and transaction errors are handled
- whether tax deductibility applies, where relevant
- what happens if a specific appeal reaches its target or cannot proceed
- how donations may be redirected if a project changes
This is where founders often get caught. They assume a short line near the payment button is enough, then face a complaint when a supporter says they did not agree to monthly deductions or believed their donation was restricted to a specific purpose.
Why privacy matters
Privacy becomes a legal issue as soon as you collect information that identifies someone, such as a donor's name, email address, phone number, billing details or donation history. If your organisation is covered by the Privacy Act, the Australian Privacy Principles set standards for collection, use, disclosure, storage and access.
Even where a smaller organisation may not be strictly required to comply with every APP obligation, a clear privacy policy is still good practice. It helps build donor trust, supports good data handling and reduces the chance of complaints when you send updates, marketing messages or share data with service providers.
Your privacy position usually needs to explain:
- what personal information you collect
- how you collect it, including through websites, forms and third party platforms
- why you collect it, such as processing donations, issuing receipts and sending updates
- whether you disclose it to payment providers, CRM systems, email tools or overseas service providers
- how donors can access or correct their information
- how complaints about privacy can be made
When Australian privacy law may apply
The Privacy Act does not only affect large corporations. Some charities and not-for-profits are covered because of their annual turnover, the types of information they handle, or the way they operate. Health information, government-related functions and certain commercial activities can change the position.
The coverage question is not always straightforward. Before you rely on an assumption that your charity is exempt, get advice on whether the Act applies to your structure, activities and data practices. Even if you are not strictly caught, donors, grant providers and corporate partners may still expect privacy compliance standards in contracts and due diligence processes.
Fundraising statements also need to be accurate
Donation terms and privacy documents do not fix misleading campaign wording. If your appeal says funds will be used for bushfire recovery, medical research or a named local program, your actual use of funds needs to align with that representation.
Australian Consumer Law can be relevant where statements are misleading or deceptive. Sector-specific fundraising rules can also apply depending on the state or territory you operate in and whether you are fundraising across multiple jurisdictions. This is particularly important before you print campaign materials, publish social posts or accept donations through a national online appeal.
Legal Issues To Check Before You Sign
The main legal risk sits in the gaps between your donor-facing documents and your supplier contracts. Before you sign a platform agreement or accept the provider's standard terms, make sure your terms, privacy wording and operational process match what the service actually does.
1. What exactly are donors agreeing to?
Your donation flow should make it clear what the donor is authorising. If there is a recurring payment, the donor should actively agree to that arrangement and be able to see the key terms before payment is processed.
Check whether your donation terms deal with:
- one-off versus recurring donations
- minimum commitment periods, if any
- how to cancel recurring payments
- whether administrative errors can be corrected
- whether fees are deducted before funds are remitted
- receipt timing and record keeping
If your campaign includes merchandise, event entry or membership benefits, the legal position may be more complicated because not every payment will be a pure donation. The wording should distinguish gifts from transactions involving goods, services or benefits.
2. Can you lawfully collect and use donor data the way you plan to?
Many organisations collect more information than they need. That creates privacy risk without much operational benefit. Before you launch online, decide what information is genuinely necessary and how long it should be kept.
Review:
- whether your forms ask only for relevant details
- whether optional marketing consent is clearly separated from payment authorisation
- whether you are transparent about analytics, cookies and tracking tools
- whether your privacy policy reflects your actual systems and workflow
- whether staff and volunteers can access donor data on a need-to-know basis
If you are using donor information for newsletters, event invitations or future appeals, make sure that use is properly disclosed and that people have a practical way to opt out.
3. Who owns and controls the donor database?
This point matters a lot with third party fundraising platforms. Some providers host the donation page, process payments and store donor details in their own systems. If the contract is silent or one-sided, you may have limited rights to export data, contact donors directly or retain access after termination.
Before you sign, check:
- whether your organisation owns donor data or only receives a limited licence to use it
- whether the platform can use donor data for its own marketing or analytics
- whether data can be exported in a usable format
- what happens to data when the contract ends
- whether data is stored overseas
4. Where does liability sit if there is a payment error or data breach?
Standard supplier terms often cap the provider's liability very low while pushing broad responsibility onto the charity or fundraiser. That can be a bad fit if the provider controls the technology, the payment flow and part of the donor experience.
Look closely at clauses dealing with:
- service outages and failed transactions
- security incidents and data breach notification
- chargebacks and fraudulent transactions
- indemnities in favour of the provider
- exclusions for indirect or consequential loss
- insurance requirements
Before you rely on a verbal promise that the provider will “handle compliance”, check the written contract. If privacy obligations, breach reporting and security standards are not documented properly, the risk may still sit with your organisation.
5. Are your fundraising claims specific enough, but not too specific?
Donors respond to specific appeals, but narrow wording can create legal and practical problems if circumstances change. For example, a campaign for “100 per cent of donations to school rebuilding in one named town” leaves little room if needs shift or administrative costs apply.
Your campaign wording, donation terms and internal approvals should line up on:
- whether donations are for general purposes or a restricted appeal
- whether excess funds can be redirected to a similar purpose
- whether administration or processing costs may be deducted
- how urgent changes to a project will be communicated
6. Do state and territory fundraising rules apply?
Online fundraising can trigger registration or fundraising compliance requirements depending on where your organisation is based and where donors are located. The rules differ across Australia, and some campaigns operate nationally without realising the state-based position is different.
This issue sits alongside, not instead of, donation terms and privacy. Before you spend money on setup or commit to a major appeal, confirm whether your charity or fundraiser needs registrations, authority, permits or other fundraising compliance steps in the relevant jurisdictions. If unsure, speak with a lawyer and your accountant or tax adviser on related structuring questions.
Common Mistakes With Donation Terms and Privacy Legal Essentials for Charities and Online Fundraisers
The most common mistake is assuming that a payment page solves the legal side automatically. It does not. Your organisation still needs accurate donor-facing terms, a privacy position that reflects reality, and contracts that protect you behind the scenes.
Using generic terms copied from overseas
UK or US template wording often misses Australian legal concepts, local fundraising rules and the way Australian Consumer Law can apply to representations made to donors. It may also refer to overseas regulators or refund practices that do not fit your process.
If your source wording came from a global platform, review it carefully before you publish it in Australia.
Burying recurring donation consent
Monthly giving needs clear, informed consent. Problems arise when recurring deductions are disclosed in small print, hidden in a pre-ticked box or mentioned only after payment.
A safer approach is to make recurring frequency, amount and cancellation steps obvious in the payment flow and mirrored in the donation terms.
Collecting donor information for one purpose, then using it for another
A supporter who donates to a disaster appeal may not expect to be added automatically to multiple marketing lists or shared with campaign partners. If your actual use goes beyond what was clearly disclosed, complaints can follow even where the legal position is arguable.
Your forms, collection notice and privacy documents should match the donor's real experience.
Not checking overseas data handling
Many fundraising tools, CRM systems and email providers store data outside Australia. Cross-border disclosure can raise extra privacy issues, particularly if your policy does not mention it or your provider contract is vague about location and security.
This is an easy point to miss when you accept standard online terms without review.
Overpromising how donations will be used
Specific campaign language can help fundraising performance, but overly rigid statements create legal and reputational exposure. If the organisation later needs to redirect funds because the project changes, donors may feel misled.
Clear appeal wording and carefully drafted donation terms can preserve reasonable flexibility without sounding evasive.
Treating privacy as a policy-only issue
A privacy policy on your website is not enough if staff, volunteers and contractors do not follow the process. Access controls, breach escalation, donor communications and record retention all need practical internal rules.
That matters most in founder moments such as:
- before you onboard volunteers to help with donor outreach
- before you import old mailing lists into a new CRM
- before you share supporter details with an event partner
- before you sign a new donation platform contract
FAQs
Do Australian charities need donation terms on their website?
Not every organisation is legally required to publish stand-alone donation terms, but clear terms are strongly recommended where you accept online donations, especially recurring donations or restricted campaign donations. They help reduce disputes and set expectations from the start.
Does the Privacy Act apply to every charity or not-for-profit?
No. Coverage depends on factors such as turnover, activities and the type of information handled. The position can be nuanced, so it is worth getting advice rather than assuming your organisation is exempt.
Can we keep donor details and contact people about future fundraising?
Often yes, but you need to be transparent about that use, follow applicable privacy and marketing rules, and give people a simple way to opt out. Your collection notice and privacy policy should reflect what you actually do.
Can donors ask for a refund?
That depends on your donation terms and the circumstances. Many organisations state that donations are generally non-refundable except for clear error, unauthorised transaction or where required by law. The key is to say this clearly before payment.
What should we review before accepting a fundraising platform's standard terms?
Focus on data ownership, privacy obligations, liability, chargebacks, security, fees, termination rights and whether donor information is stored overseas. Those clauses often matter more than the headline price.
Key Takeaways
- Donation terms should clearly address recurring payments, refunds, restricted appeals, receipts, failed payments and chargebacks.
- Privacy compliance starts when you collect donor information, whether through your own website or a third party platform.
- The Privacy Act may apply to some charities and online fundraisers, and the position should be checked rather than assumed.
- Campaign wording must align with how funds will actually be used, especially for specific or restricted appeals.
- Before you sign a platform or processor contract, review data ownership, overseas storage, security obligations, liability caps and termination rights.
- Internal processes matter as much as public documents, particularly for donor communications, access controls and data breach response.
- State and territory fundraising compliance can also apply to online appeals and should be checked early.
If you want help with donation terms, privacy policies, fundraising platform contracts, data handling clauses, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.






