Changes to the Data (Use and Access) Bill: Can charities use the soft opt-in?

April 8th, 2025 Posted in Data Protection

If you’re involved in a charity’s fundraising or direct marketing efforts, you might have heard of the proposed amendments to the Data (Use and Access) Bill, which could significantly impact how charities engage with potential supporters through email. The change aims to introduce a “soft opt-in” approach for charities, a more streamlined way to send marketing messages to individuals who have shown an interest in your charitable cause. The Bill is still making its way through parliament so you can’t amend your practices just yet but now is a good time to understand the change, its potential benefits, and its limitations.

This blog explores what “soft opt-in” is, how it could benefit charities, and what preparations are necessary to ensure compliance. With data protection laws evolving, it’s crucial for charities to stay informed and prepared for these potential changes to maintain trust and transparency with supporters.

What is ‘soft opt-in’ and how might it benefit a charity?

Since the introduction of PECR, charities and commercial organisations generally must obtain explicit consent from individuals to send them direct marketing material. It’s a journey you may be familiar with; during the donation, pledge, event sign-up, volunteering, or expression of interest journey, the individual is presented with a tick box asking whether they consent to receive information, via email, regarding the charity and its work. If they don’t tick the box, then consent hasn’t been obtained and direct marketing can’t be sent via email.

Many commercial organisations choose to take this approach as well, however, they can, instead, provide the recipient with the opportunity to opt-out of receiving marketing via email rather than opting in. Restrictions and limitations apply but, in most cases, this means that a statement is presented to an individual advising them to tick (or untick) a box if they DO NOT want to receive direct marketing via email. This is the ‘soft opt-in’ and the key requirements for commercial organisations are:

  • The recipient must have provided their contact details directly to the organisation (i.e their details were not obtained via a third party)
  • During a sale or negotiations for a sale (eg: a purchase or a request for a quote)
  • The marketing must be about that organisation’s OWN similar product or service to the one the recipient previously bought or enquired about
  • The recipient must have been provided with an opt-out when their details were collected
  • The recipient must be provided with an opt-out in all subsequent messages.

It is worth noting that the proposed amendment contained in the Bill does not match commercial organisation rules exactly. This is covered in more depth below.

Read our Guide to PECR here. 

Potential Benefits

The Direct Marketing Association (DMA) anticipate that the proposed change to the rules will greatly enhance opportunities for charities to raise funds. A data analytics company that works closely with charities and is a DMA member has advised the DMA that charities could see an increase of up to £290 million in donations if the soft opt-in is extended to charities.

Because of this, the DMA is very supportive of the change and in a letter to the government stated, “While not a silver bullet, including the soft opt-in for email marketing for charities will help facilitate greater fundraising and go some way to mitigating the additional burden while demonstrating that the government understands the important work they do for society.”

Whilst it remains to be seen if the use of soft opt-in really could increase donations as dramatically as suggested above, there seems to be little doubt that there is definitely potential.

How does the proposed amendment apply to charities?

The proposal is not to apply the existing soft opt-in rules to charities. Rather, it is to include a new paragraph in Regulation 22 of PECR, which enables charities to send direct marketing via email where (abridged):

  • The sole purpose is to further one or more of the charity’s charitable purposes;
  • The charity obtained the contact details during the course of the recipient:
    • Expressing an interest in one or more of the charity’s charitable purposes; or
    • Supporting one of those purposes; AND
    • The recipient has been given a simple means of refusing the use of their contact details for direct marketing purposes, at the time the details were initially collected, and at the time of each subsequent communication.

This final point is key to understanding what is required in practice. The recipient must have been given the choice to opt-out at the point their details were collected. Therefore, if you are a charity and your contacts have previously opted out, you can’t opt them back in as a direct response to this regulatory change.

If you want to rely on soft opt-in, you’ll need to present an opt-out statement during a future interaction. The most likely benefit, therefore, is that you may see an increase in the volume of contactable records obtained going forward.

The way in which the proposed amendment is worded differs quite significantly from the existing soft opt-in and will be a real positive for charities; the rules to which commercial organisations are subject require that the direct marketing be limited to just products or services that are similar to those which the individual previously purchased or showed an interest in.

This amendment states that charities can use the approach to send direct marketing as long as the sole approach is to further one or more of the charity’s charitable purposes. This will cover situations in which donors have demonstrated an interest in supporting the charitable purposes generally and it avoids subjective questions regarding the nature of ‘similarity’. i.e. if a supporter donates or expresses an interest in charitable campaign A, and doesn’t opt out of email marketing, you can subsequently send them an email about charitable campaign B.

What other considerations are there?

It’s important to understand that when processing an individual’s email address, you will be processing their personal data. Therefore, you will also need to consider the provisions within the UK GDPR as well as the PECR, which means, amongst other things, that you need to have a lawful basis for the processing.

If you are relying on soft opt-in, it is likely that you are relying on legitimate interests as your lawful basis, not consent. This is because the soft opt-in does not fulfil the requirements of consent, as defined under the UK GDPR.

As such, prior to using the soft opt-in approach, you should carry out a Legitimate Interests Assessment, balancing the proportionality and necessity against individuals’ rights.  The assessment, in this context, will likely provide other benefits as well, as it will help you understand what other controls and safeguards are in place, what messaging or notices require updates and whether your CRM / Donation Platforms / Mailing Systems include appropriate functionality. You may already use legitimate interests in relation to you marketing by mail and telephone, in which case, you will have already carried out LIAs for these activities.

Potential Actions

  1. Don’t amend your supporter journeys just yet but stay informed. At the time of writing, the Bill is currently at the Report stage in the House of Commons and may yet be amended further or may not pass at all. Your data protection officer (DPO) or data protection consultant (DP consultant) may be keeping abreast of developments so ask them for insight. Alternatively, the DMA, Civil Society and Chartered Institute of Fundraising will likely all produce more guidance as the situation develops.
  2. Prepare to change your supporter journeys. This should be relatively simple at the front end of your systems but may be more difficult at the back end, depending on the systems you use. At the front end, you’ll require opt-out boxes, rather than opt-in. As mentioned above, you may already have this in place for mail and telephone and, at the very least, some wording will need to be tweaked. At the back end, you’ll need to be able to record the new lawful basis upon which you rely. This won’t require changes to your existing contact lists, as you’ll not be able to retrospectively apply the soft opt-in, but as with all marketing contact lists, you’ll need to be able to evidence the statement provided to the supporter. You may need to clarify the approach donation platforms intend to take and obtain a copy of any amended privacy statement they provide.
  3. If the bill passes:

a) Conduct a Legitimate Interests Assessment – with the support of your DPO or DP consultant.

b) Update your Privacy Notices – to reflect the new lawful basis and approach.

c) Check your data subject rights request procedure is appropriate and fit for purpose. The Bill is likely to introduce other consequential changes in respect of rights requests and complaints procedures so this review may be broader than just the objections process. Get more insight into the Data (Use and Access) Bill.

d) Determine an appropriate retention period for opt-in records.

e) Update your Records of Processing Activities accordingly.

f) Update your marketing procedures, if you have them.

4. Obtain direct advice. Precisely how you implement any change will depend on your internal systems and existing approach. If you’re unsure how to manage the change then seek further advice from your DPO, DP consultant if you have one or, if not, an experienced data protection practitioner.

Need data protection support for your organisation?

As a charity, it’s essential to stay ahead of the regulatory changes that may affect your marketing strategies. If you’re unsure how to adapt your practices to the evolving data protection landscape, contact our expert data protection consultancy today for tailored advice and support in navigating the new rules.

 

Written by Richard Wood

Richard is a Data Protection Consultant. Before joining Evalian, Richard worked as a Data Protection Advisor in the Ministry of Defence and as a Data Protection Compliance Officer in the Office for National Statistics. Prior to data protection, Richard worked in Audit, Compliance and Assurance within the energy industry. Richard’s qualifications include the Practitioner’s Certificate in Data Protection (PC.dp) and Certified Internal Auditor (CIA (through IIA)).