Donors give most freely when they trust the organisation asking, and part of that trust is knowing that a gift will not turn into a stream of unwanted data collection. A donation should never feel like surveillance. It is worth understanding, then, how a contactless donation device handles personal information, and where the responsibility for protecting it sits.
The anonymous gift
Most contactless gifts are, by their nature, anonymous. When a donor taps a card or phone to give, the device processes a payment without the charity collecting their name, address or contact details. The person gives, the gift is recorded, and they walk on. For the everyday tap, there is simply very little personal data involved, which is the most privacy-friendly outcome there is.
Where card security sits
The security of the payment itself is handled to strict industry standards by the payment and giving software, not held loosely on the device by the charity. Card details are processed through the regulated payment layer, which on a DonorDynamics device is provided by Give A Little, and the hardware and firmware keep the device locked down and dependable beneath it. A charity does not store card numbers on the unit, and should not need to handle them at all.
Gift Aid and personal data
Gift Aid is the one common case where personal information is collected, because the declaration requires the donor's name and details and their confirmation that they are a UK taxpayer. That information is gathered for a specific, legitimate purpose, to reclaim the relief from HM Revenue and Customs, and it should be handled accordingly. Under the UK General Data Protection Regulation and the Data Protection Act 2018, the charity is responsible for processing that data lawfully, keeping it secure, using it only for the purpose given, and retaining it no longer than needed.
Who is responsible for what
It helps to be clear about the division of duties. DonorDynamics designs and builds the hardware and firmware, and keeps the device locked to its task and secure. The donation and payment experience, including how any Gift Aid information is captured and handled, is provided by the giving software. The charity, as the organisation collecting the gift, is the data controller for any personal data it gathers, such as Gift Aid declarations, and decides how that data is used. Knowing which party holds which responsibility makes it far easier to give donors a clear and honest answer.
That clarity is worth passing on to supporters. Being able to tell a donor that an ordinary tap is anonymous, that their card details are handled securely by the payment provider, and that any Gift Aid information is used only to claim the relief, is reassuring and true. For the specifics of how the giving software handles data, and to confirm the current arrangements for your own setup, the Give A Little page is the right place to look, and our frequently asked questions cover common queries.
Want to give donors a clear answer on privacy? Read about the giving platform on the Give A Little page, see our frequently asked questions, or compare the secure hardware on our comparison chart.