Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
WordPress donation plugin that processes donor and payment data and connects to gateways such as Stripe and PayPal.
GiveWP is a popular WordPress plugin that lets nonprofits and causes collect donations directly on their own website. It builds donation forms, manages donor records and connects to payment gateways such as Stripe and PayPal to take the actual payment. The site operator running the WordPress installation is the data controller for the donor records held in the site database.
GiveWP processes donor personal data such as name, email, postal address and donation amount, along with payment data that flows through the chosen gateway. It sets functional cookies that keep the donation session and form state working during checkout. The connected gateways may set their own cookies and transfer data to the United States as part of processing the payment.
The functional donation cookies are strictly necessary to complete a transaction, so they fall under the ePrivacy exemption. The donation and payment data, however, is governed by the GDPR and needs a lawful basis. Because payment gateways act as separate processors or controllers and may operate from outside the European Union, you must address those relationships and transfers in your documentation.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
You do not need consent for the essential cookies that make the donation form work, but you do need consent for any non essential cookies and for sending marketing messages to donors. Processing the donation itself usually rests on contract or legitimate interest. Keep the marketing opt in separate from the donation step so consent stays freely given and unbundled.
Donor records live in your WordPress database on your own hosting, but payment processing introduces an international transfer because Stripe and PayPal are United States based. These providers rely on safeguards such as standard contractual clauses and the relevant data privacy framework. Review their data processing terms, record the transfer in your documentation and tell donors in your privacy notice.
Sign data processing agreements with your payment gateways and add them to your records of processing. Configure GiveWP to collect only the donor data you need, set a retention policy for old donation records and add a clear unbundled marketing opt in. Publish a privacy notice that names the gateways and the United States transfer, and keep WordPress and the plugin updated.
Websites using GiveWP must obtain user consent under GDPR regulations.
DPIA considerations
Assess the donor and payment data you collect, the lawful basis for processing donations and the role of each payment gateway as a separate processor or controller. Because gateways such as Stripe and PayPal are United States based, document the international transfer and the safeguards in place. A targeted assessment is sensible where you process large volumes of donations or sensitive cause related data.
Sample consent text
We use the details you enter to process your donation and issue your receipt, relying on the contract and our legitimate interest. Payments are handled securely by our gateway, which may process data outside the European Union under appropriate safeguards. Tick here only if you also want to receive news about our work.
Third-party domains contacted
js.stripe.comwww.paypal.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| give_session | Functional | Session | Maintains the donor donation session and form state during checkout. Strictly necessary to complete a donation. |
| wp_give_donation | Functional | Session | Stores temporary donation form data so the donation can be processed correctly. Strictly necessary. |
GiveWP collects user analytics data — you legally need a consent banner. Try FlowConsent free.
GiveWP sets functional cookies that keep the donation session and form state working during checkout, such as a session cookie. These are strictly necessary. Connected gateways like Stripe and PayPal may set additional cookies of their own.
You do not need consent for the essential cookies that make the donation form work, but you do need consent for any non essential cookies and for marketing emails. Keep any marketing opt in separate and unbundled from the donation itself.
Processing a donation is usually based on contract or your legitimate interest, since you need the data to take the payment and issue a receipt. Marketing communications to donors require separate consent.
GiveWP stores donor records on your own hosting, but the payment gateways do transfer data. Stripe and PayPal are United States based and process payment data there under safeguards such as standard contractual clauses.
A targeted assessment is advisable where you process large volumes of donations, sensitive cause related data or rely on United States payment processors. Document the data flows, the gateway relationships and the international transfers.
Sign data processing agreements with your gateways, collect only the donor data you need, set a retention policy and add an unbundled marketing opt in. Publish a privacy notice naming the gateways and the United States transfer, and keep everything updated.
Other WordPress donation tools include Charitable and Donation Forms by WPForms, while hosted platforms like Donorbox and HelloAsset offer alternatives. Choosing a European payment processor can reduce transfer concerns.
List the GiveWP functional cookies as strictly necessary for processing donations, and describe the gateway cookies from Stripe or PayPal separately. Explain in your privacy notice how donor and payment data is handled and transferred.