Running a small UK charity means picking up compliance knowledge as you go, usually right when a trustee asks "are we actually allowed to do this on the website?" Here's a straightforward rundown of what tends to matter, in plain English.
Say you're a registered charity, and show your number
If your charity is registered with the Charity Commission (or the equivalent regulator in Scotland or Northern Ireland) and your income is above the threshold that requires registration, charity law expects you to make that clear on documents used to raise funds — and a donations or "support us" page on your website counts. In practice this means: state that you're a registered charity, and show your charity number, somewhere a visitor would reasonably find it (a footer is the usual place). The exact income thresholds and wording requirements are worth double-checking on the Charity Commission's own guidance for your charity's specific size and nation, since the detail can shift — but the underlying expectation, being upfront about your registered status, is a stable one.
GDPR applies to you too
Any UK charity that collects supporter or member details — a mailing list, a donation form, a volunteer sign-up — is handling personal data under GDPR, the same as any other organisation. That means: only collect what you actually use, tell people plainly what you do with it (a short, honest privacy policy, not a legal wall of text), and have a real way to action a "please delete my details" request when someone asks. See our plain-English GDPR guide for clubs and charities for the full breakdown.
Cookie consent isn't optional if you're tracking visitors
If your website uses analytics or tracking cookies — including some donation-platform embeds and social share buttons — UK PECR rules require genuine opt-in consent before those cookies load, not a banner that quietly tracks in the background regardless of what someone clicks. This is one of the most commonly missed rules among small charities, mostly because the default cookie banner on many website builders doesn't actually block anything.
Accessibility is good practice, and sometimes a real requirement
The Public Sector Bodies Accessibility Regulations legally apply to public sector websites, not most small charities. That said, accessibility is still worth taking seriously: some funders and grant applications specifically ask about it, and a website that's hard to use with a screen reader or on a small screen quietly excludes some of the supporters and beneficiaries you're trying to reach. Clear text contrast, sensible heading structure, and alt text on images cost very little to get right from the start.
Transparency builds trust, even where it isn't mandatory
Publishing your latest annual accounts, a short trustee list, and a safeguarding policy (if your charity works with children or vulnerable adults) usually isn't a strict legal requirement for website content specifically — but it's exactly what a cautious donor, a funder, or a partner organisation looks for before trusting a small charity. It costs a page, and it answers the "can I trust this organisation" question before anyone has to ask.
Where Natterio fits
None of the above is legal advice for your specific charity — check the Charity Commission's own guidance for anything income- or registration-specific to you. What Natterio does handle at the platform level: GDPR-compliant cookie consent that actually blocks tracking until accepted, UK-hosted data with real export and deletion, and a site structure that makes it easy to add a footer charity number, a trustees page, or a safeguarding policy without fighting a template. Build your charity's website free.