
Privacy Notice Checklist for Community Group Websites
Why it matters: A practical, low-jargon checklist to help community groups review website forms, reduce unnecessary personal information, explain what happens to submissions, and separate optio...
You'll explore:
- Introduction and quick answer: what your website privacy notice should explain
- 1. Website form inventory checklist: list every place your site collects information
- 2. Personal information minimisation checklist: only ask for what you need
- 3. Privacy notice content checklist: what the notice should cover
- 4. Consent and permission checklist: separate optional updates from service communications
- 5. Common website form checks: contact, volunteer, event, membership, donation, referral, and newsletter forms
- 6. Placement checklist: where to link the privacy notice and what to say near forms
- 7. Pre-publish review, common mistakes, and what to do next if unsure
- Website form inventory tracker
- Common form checks by form type
- Quick answer: what a community group privacy notice should explain
- Website form inventory checklist
- Personal information minimisation checklist
- No dated evidence packet supplied
- This is not legal advice
- Minimise first, write second
- Frequently asked questions
Introduction and quick answer: what your website privacy notice should explain
A community group website can collect personal information in ordinary ways: a contact form, volunteer enquiry, membership application, event booking, donation page, newsletter signup, or referral request. A privacy notice helps people understand what they are sharing, why you are asking for it, who may see it, and what happens next. This article is a practical checklist, not legal advice. Privacy, consent, safeguarding, charity, health, children’s information, marketing, and cross-border tool rules can vary by jurisdiction. If your group handles sensitive information, referrals, safeguarding concerns, health details, children’s details, or information shared with partner organisations, check current regulator guidance for your jurisdiction before relying on a template. Quick answer: a privacy notice for community group website forms should explain what each form collects, why the group needs it, who receives it, where it is stored or sent, how long it is likely to be kept, how people can ask questions or request changes, and where optional consent is requested separately.
- Start by listing every website form and tool that collects information.
- Remove fields you cannot clearly justify before writing the notice.
- Write the privacy notice in plain language that matches your actual forms and processes.
- Separate ordinary administration messages from optional newsletters or promotional updates.
- Make the privacy notice easy to find before someone submits a form.
- Use extra care for referral, safeguarding, health, children’s, or sensitive-information forms.
1. Website form inventory checklist: list every place your site collects information
Before updating a privacy notice, make an inventory of every place the website collects personal information. This matters because privacy wording is only useful if it reflects what the website actually does. Do not stop at the obvious contact page. Check embedded tools, booking widgets, payment pages, newsletter forms, file uploads, anti-spam tools, maps, analytics, referral forms, and old pages that may still be live. Also check where submissions go: a shared inbox, a spreadsheet, a volunteer coordinator’s email account, a membership system, a payment provider, or an event platform. For workflow and privacy reviews, do not share credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records. Use blank examples or manually written non-sensitive summaries instead.
- Open the website as a visitor and click through every menu, footer link, event page, membership page, donation page, and volunteer page.
- Search the website admin area for old forms, draft forms, embedded scripts, and archived pages that may still collect submissions.
- Record the fields on each form exactly as they appear to users.
- Mark required fields separately from optional fields.
- Record who receives submissions and whether a third-party system is involved.
- Check whether any form invites people to include sensitive information in a free-text box.
- Remove or unpublish forms that are no longer monitored.

2. Personal information minimisation checklist: only ask for what you need
Minimisation means asking for less information when less will do. It is often easier and safer to reduce a form than to write a long explanation for unnecessary fields. For each field, ask: do we need this information at this stage, for this purpose, from this person? If the answer is unclear, remove the field, make it optional, or delay the question until later. For example, a volunteer enquiry form may need a name, contact method, and broad area of interest, but detailed references, identity checks, or availability patterns may be better handled later in a more controlled process. Be especially careful with free-text boxes. They are useful, but people may include more personal information than you expected. If the form is only for general enquiries, say so near the box and tell people not to include sensitive details unless your group has a suitable process for receiving them.
- Remove fields that are collected out of habit rather than need.
- Delay detailed questions until someone reaches the right stage of the process.
- Use optional fields only where optional really means optional.
- Avoid asking for sensitive details through general contact forms.
- Use short prompts for free-text boxes, such as “Please do not include sensitive personal information in this form.”
- Limit access to submissions to people who need them for the stated purpose.
- Review old forms after events, recruitment drives, or campaigns end.
3. Privacy notice content checklist: what the notice should cover
A useful privacy notice answers practical questions in plain English. It should not simply copy legal phrases. It should tell people what happens when they use your website forms. For a community group, the notice can usually be written around form types and purposes. For example: “If you use our volunteer enquiry form, we use your details to respond to your enquiry and discuss suitable volunteering options.” That is clearer than a broad statement saying the group collects data for “administration”. Because no dated regulator evidence was supplied for this article, this checklist avoids stating jurisdiction-specific legal requirements. Use it as a drafting and review aid, then check current local guidance where needed.
- Who the group is and how to contact it about privacy questions.
- What personal information the website collects, grouped by form or activity.
- Which fields are required and which are optional, where this is not obvious on the form.
- Why the group asks for each type of information.
- Who inside the group may see the information, such as trustees, staff, coordinators, membership volunteers, or event organisers.
- Which outside organisations or tools may receive the information, such as booking platforms, payment providers, email tools, web hosts, or referral partners.
- Where information is likely to be stored, such as email inboxes, spreadsheets, membership systems, event tools, or cloud storage.
- How long the group expects to keep different types of submissions, or how retention decisions are made.
- How someone can ask a question, correct information, withdraw from optional communications, or request a change, using wording appropriate to the group’s jurisdiction.
- When information may need to be shared for safeguarding, legal, safety, or serious-risk reasons, if relevant to the group’s work.
- How optional consent or permission requests are handled separately from service administration.
- When the group last reviewed the notice, if the group chooses to include a review date.
4. Consent and permission checklist: separate optional updates from service communications
Consent can be confusing because not every website form needs a checkbox for every use of information. A person can submit a form so your group can respond to their enquiry, process an event booking, manage a membership request, or deal with a volunteer application. That is different from asking them to receive optional newsletters, fundraising appeals, marketing updates, partner communications, or other extra messages. Avoid bundled wording such as “By submitting this form, you agree to receive all future updates from us” if the form is mainly for an enquiry or booking. Instead, separate the immediate purpose from optional updates. A practical pattern is: explain the service or admin use beside the form, then use a separate unticked checkbox for optional communications where consent-style wording is appropriate in your jurisdiction. Some activities may require a different basis, permission wording, safeguarding process, or regulator check. This is especially important for sensitive information, children’s information, referrals, health details, photographs, or sharing with partner organisations.
- Do not use one checkbox to cover unrelated purposes.
- Keep newsletter, campaign, or marketing permission separate from contact, booking, membership, or volunteer administration.
- Use clear labels such as “I would like to receive the monthly email newsletter” rather than vague wording such as “I agree to communications.”
- Do not make optional updates a condition of submitting a necessary form unless you have checked that this is appropriate.
- Tell people how to unsubscribe or change optional communication preferences.
- If a form collects sensitive or referral information, check current regulator guidance before relying on simple consent wording.
- Review photo, video, children’s activity, safeguarding, and partner-sharing permissions separately from ordinary website form wording.
5. Common website form checks: contact, volunteer, event, membership, donation, referral, and newsletter forms
The same privacy notice checklist should be applied differently depending on the form. A contact form usually needs a short explanation. A referral form may need a higher-care review. A donation form may involve a payment provider. A newsletter form should explain that signup is optional and how people can leave the list. Use the table below to test each form before publishing or updating the privacy notice.
- Contact forms should not ask for phone numbers, addresses, or demographic details unless they are genuinely needed.
- Volunteer forms should separate early interest from later screening, eligibility, references, or safeguarding steps.
- Event forms should separate booking administration from optional future updates.
- Membership forms should explain membership administration, renewals, and who manages member records.
- Donation forms should identify payment-provider involvement where relevant, without asking donors to submit card details through an ordinary website form.
- Referral forms should be reviewed carefully before they collect sensitive information.
- Newsletter forms should use clear optional signup wording and a simple way to unsubscribe.
6. Placement checklist: where to link the privacy notice and what to say near forms
A privacy notice is more useful when people can find it before they submit information. Do not hide it only on a policy page that is difficult to reach. Link it from the website footer and place a short privacy note near forms that collect personal information. The short note does not need to repeat the full notice. It can say what the form is for and link to the full privacy notice. For higher-risk forms, such as referral, safeguarding, support request, health, or children’s activity forms, add more specific wording before the free-text area or upload field.
- Add a privacy notice link in the website footer or another consistent site-wide location.
- Add a short privacy note near the submit button or before the main personal-information fields.
- Use plain wording such as “We will use these details to respond to your enquiry. Read our privacy notice.”
- For optional newsletters, place the permission checkbox close to the email field and explain what people will receive.
- For event forms, explain whether details are used only for booking administration or also for future updates.
- For referral or support request forms, explain who will review the information and warn people not to submit emergency or highly sensitive details if the form is not designed for that purpose.
- Check mobile layouts so the privacy link is visible before submission.
- Check accessibility: link text should be meaningful, forms should have labels, and important privacy wording should not be shown only as an image.
7. Pre-publish review, common mistakes, and what to do next if unsure
Before publishing a privacy notice or new form, run a short review with someone who understands the group’s actual process. The goal is to make sure the form, the privacy notice, and the behind-the-scenes handling all match. Common mistakes include copying a generic privacy policy that does not mention the group’s forms, collecting information “just in case”, using one consent checkbox for several unrelated activities, keeping form submissions indefinitely, forgetting third-party tools, and allowing old forms to remain live after a project ends. If you are unsure, use self-serve next steps first: map your forms, remove unnecessary fields, write short form-specific privacy notes, and check current regulator guidance for your jurisdiction. If the issue involves referrals, safeguarding, children, health, legal risk, cross-border tools, or sensitive information, seek appropriate advice from a qualified source or regulator guidance rather than relying on a generic checklist. Capacity boundary: Chestnut Communities is not currently offering paid reviews, implementation, urgent support, or automatic AI replies. Do not send credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records when asking for general guidance or discussing examples.
- Check every form against the inventory tracker.
- Confirm each field has a clear purpose.
- Confirm optional permissions are separate from necessary administration.
- Confirm the privacy notice matches the actual inboxes, tools, and people involved.
- Confirm retention expectations are written down and practical.
- Confirm higher-risk forms have been reviewed before publication.
- Confirm privacy links work on desktop and mobile.
- Set a review reminder when forms, tools, staff, volunteers, or processes change.
Website form inventory tracker
| Website location or form | Information collected | Required or optional | Why the group needs it | Who can see it |
|---|---|---|---|---|
| Contact form | Name, email address, message, and possibly phone number | Name, contact method, and message are often required; phone should be questioned or made optional unless needed | To respond to the enquiry and route it to the right person | Website administrator, inbox monitor, relevant coordinator, or named response volunteer |
| Membership enquiry form | Name, contact details, membership interest, eligibility or local-area information where relevant | Separate essential membership details from information that can wait until someone joins | To answer membership questions, assess the enquiry, and manage next steps | Membership secretary, administrator, or committee member responsible for membership |
| Volunteer application or enquiry form | Name, contact details, interests, availability, skills, and possibly eligibility information | Early-stage interest fields should be limited; detailed screening can often wait | To discuss suitable roles and decide the next volunteer step | Volunteer coordinator, safeguarding lead where relevant, or role supervisor |
| Event booking form | Name, contact details, ticket or attendance details, access needs, dietary details where relevant | Booking details may be required; future updates should be optional | To administer the booking and support attendance at the event | Event organiser, administrator, venue contact where appropriate, or booking platform |
| Donation form | Donor name, contact details, donation reference, payment-provider record, and gift-related information where relevant | Do not collect payment card details through a general form; use suitable payment tools | To process the donation, issue acknowledgements, and keep required donation records where applicable | Treasurer, donation administrator, payment provider, or finance volunteer |
| Referral or support request form | Referrer details, person needing support, contact information, circumstances, support needs, and free-text details | Treat as higher risk; question every field and avoid collecting more than needed online | To assess whether the group can respond, signpost, or pass the request to the right internal process | Limited referral team, safeguarding lead, service coordinator, or authorised partner where appropriate |
Common form checks by form type
| Form type | Fields to question | Plain-English explanation to add | Permission or consent point to consider | Common minimisation check |
|---|---|---|---|---|
| Contact form | Phone number, postal address, demographic details, long free-text prompts | We use these details to respond to your enquiry and may pass it to the right person in the group. | Do not add newsletter permission unless it is separate and optional. | Can the group respond with just a name, email address, and short message? |
| Volunteer form | Date of birth, full address, references, identity details, background checks, detailed availability | We use your details to discuss volunteering options and manage the next step in the volunteer process. | Separate volunteering administration from optional mailing-list signup or campaign updates. | Can detailed screening wait until after an initial conversation? |
| Event booking form | Unnecessary demographic data, full addresses, dietary or access details collected without explanation | We use this information to manage your booking and support attendance at the event. | Separate event administration messages from future event marketing or newsletters. | Are access or dietary questions clearly relevant to this event and visible as optional where appropriate? |
| Membership form | Occupation, household details, date of birth, full address, interests unrelated to membership | We use this information to manage membership, renewals, member communications, and relevant group administration. | Explain member communications separately from optional public newsletters if they are different. | Can some details be collected after membership is approved or renewed? |
| Donation form | Payment card details in ordinary forms, excessive donor profiling, unnecessary public recognition preferences | We use donation details to process and acknowledge the donation, and a payment provider may process payment information. | Ask separately before adding donors to newsletters or public thank-you lists where permission is appropriate. | Is the payment handled by a suitable provider rather than a general website form? |
| Referral or support request form | Health details, safeguarding details, children’s information, third-party details, open-ended sensitive narratives | We use referral information to assess the request and decide the appropriate next step. Access is limited to authorised people. | Check current regulator or sector guidance before relying on simple consent wording for sensitive or third-party information. | Can the online form collect only the minimum needed to triage the request safely? |

Quick answer: what a community group privacy notice should explain
- What personal information the website collects
- Which forms or tools collect it
- Why the group asks for each type of information
- Who inside or outside the group may see it
- Where the information is sent or stored
- How long the group expects to keep it
- How someone can ask questions or request a change
- Where optional consent, such as newsletter permission, is requested separately
- When the group should check current regulator guidance for its jurisdiction
Website form inventory checklist
- List every visible form on the website
- Check membership, volunteer, event, donation, referral, and newsletter pages
- Check embedded forms, booking tools, payment tools, maps, analytics, spam protection, and file upload features
- Record every field on each form
- Mark which fields are required and which are optional
- Identify who receives each submission
- Identify any third-party system or email inbox that receives the data
- Check whether old or unused forms still collect information
Personal information minimisation checklist
- Remove fields the group does not have a clear reason to collect
- Delay detailed questions until they are genuinely needed
- Make optional fields clearly optional
- Avoid collecting sensitive or referral details through a general form unless the group has reviewed the risks
- Use free-text boxes carefully because people may include more information than expected
- Check whether a shorter version of the form would still let the group respond effectively
No dated evidence packet supplied
This is not legal advice
Minimise first, write second
Frequently asked questions
Does a small community group need a privacy notice if it only has a contact form?
If a contact form asks for a name, email address, phone number, message, or other identifiable information, it is good practice to explain what you collect and how you use it. Depending on your jurisdiction, privacy rules may also expect this type of information to be explained clearly. Keep the notice proportionate: say who receives the message, why you need the details, how long you normally keep enquiries, and how someone can contact the group about privacy questions.
Can one privacy notice cover all of our website forms?
Often, one clear privacy notice can cover multiple website forms if it is specific enough. Group the notice by activity, such as contact enquiries, volunteering, membership, events, donations, referrals, and newsletters. For forms that collect more sensitive information, add a short form-specific explanation next to the form as well as linking to the full notice.
Do we need a consent checkbox on every form?
Not necessarily. A checkbox is not a substitute for a clear privacy explanation, and consent rules vary by jurisdiction and purpose. Separate optional communications, such as newsletters or fundraising updates, from ordinary administration, such as responding to an enquiry or managing an event booking. If you collect sensitive information, children’s information, referral details, photos, or information to share with partners, check current regulator guidance before relying on simple checkbox wording.
Where should we put the privacy notice link on a form?
Put the link where people can see it before submitting the form. A common approach is to place a short sentence near the submit button, such as “We will use these details to respond to your enquiry. Read our privacy notice.” Also keep a privacy notice link in the website footer or another consistent site-wide location.
How long should a community group keep website form submissions?
Set a practical retention period based on the purpose of the form and any rules that apply to your group. Avoid keeping submissions indefinitely just because they arrived by email or were saved in a spreadsheet. For example, general enquiries may not need to be kept once resolved, while membership, donation, safeguarding, referral, or event records may need a different retention approach. Record the decision and check current guidance for your jurisdiction and sector.
What should we do if a referral form collects sensitive information?
Pause and review the form before publishing or continuing to use it. Referral forms can collect sensitive details about health, support needs, safeguarding, children, family circumstances, or risk. Limit what the form asks for, explain who will see the information, avoid unnecessary free-text prompts, secure the submission route, restrict access, and check current regulator or sector guidance. If the form is not suitable for urgent or emergency information, say that clearly and provide the appropriate contact route.
Interactive checklist
Assess readiness with the Community AI checklist
Work through each section, get a readiness score, and print the results to align your team before you launch any AI project.



