Charitable soft opt-in: two rules that should impact your Salesforce setup
Blog
In our previous post, we spoke about the charitable purposes soft opt-in – the new provision in the Data (Use and Access) Act 2025 that allows UK charities to send fundraising emails to supporters without explicit consent, provided six specific requirements are met.
This follow-up post covers two practical questions I often get asked, both of which have direct implications for how your Salesforce instance should be configured:
- Can I collect soft opt-in from third-party fundraising platforms (hint: no)?
- Does it matter whether someone opted in actively or passively (hint: kind of)?
We’ll answer both questions here – keep reading.
Can I collect soft opt-in from third-party fundraising platforms?
No, you cannot.
One of the six requirements is that the charity must have collected the individual’s contact details directly. The ICO’s guidance makes clear what this means in practice, with an explicit example of what they would consider “bad practice” for capturing soft opt-ins:

This unfortunately rules out contacts originating from platforms such as JustGiving and Enthuse, which represent a significant proportion of online support for many UK charities. Those contacts can only be marketed to under explicit consent – the same rules that applied before February 2026.
The implication for your data import routines is straightforward but important: every record entering Salesforce needs to carry reliable information about where it originated. Not just “donation received” but “donation received via which channel.” Records from third-party platforms must be flagged as ineligible for the soft opt-in at the point of import, and kept clearly separate from records collected directly through your own website or forms.
If your current import process doesn’t capture and preserve that originating channel information, that’s a gap that needs closing before you can safely use the soft opt-in at all.
There is a caveat here; ICO has not yet issued guidance on the distinction between a ‘third-party fundraising platform’ and what might simply be a tool a charity uses (think FormAssembly, or a FinDock Giving Page).
ICO also hasn’t issued guidance on where agencies acting as a representative for the charity fall on that spectrum. More to come on this, I’m sure.
Does it matter whether someone opted in actively, or passively?
Before answering in full, let’s first define the terms ‘commercial’ and ‘charitable’ in context of soft opt-ins.
All charities, by definition, have a charitable mission. On that basis, charities can now choose to record charitable purpose soft opt-ins. And you can use those soft opt-ins to send messages to people encouraging them to donate, volunteer, or otherwise support your mission.
In addition to the charitable activities, some charities also have what can be described as commercial activities (comparable to an online shop selling physical products).
Those charities can choose to record commercial purpose soft opt-ins, as a supplement to active consent and charitable soft opt-in. And the commercial soft opt-in can then be used to promote those commercial activities. This might include selling merchandise, raffle tickets, or charity gifts such as a birthday card for your grandmother. The type of soft opt-in – charitable or commercial – depends on what kind of interaction generated the soft opt-in:
- Did they donate an amount of money, an item, or a service at their discretion? Then it was likely charitable.
- Did they receive something from you after paying an amount at a price set by the charity? Then it was likely commercial.
Now that we’ve defined those terms, let’s try to answer the question.
When a charity builds a send list for a fundraising appeal, does it need to distinguish between contacts held under explicit consent versus soft opt-in? Or is “contactable” simply “contactable”?
For a straightforward fundraising appeal with no commercial content (e.g. a charity shop promotion), the two groups are practically interchangeable at the point of selection. The email going to both groups is identical. In that narrow scenario, the distinction doesn’t affect who receives the send.
But you cannot treat everyone as a single group in your database. This is because the distinction between consent and soft opt-in becomes important when we are talking about something else than a straightforward fundraising appeal.
Here are 3 examples of such situations:
- Mixed-content emails. If a send contains both a fundraising appeal (“become a donor”) and a charity shop promotion (“buy a birthday card for your nan”), you can only include contacts who hold both the charitable purposes soft opt-in and the commercial soft opt-in, or explicit consent. To build that selection correctly, you must know what type of opt-in each potential recipient has.
- Audit and compliance. If the ICO investigates a complaint, you need to be able to demonstrate which legal basis applied to each person you contacted. If your data doesn’t record this, you cannot demonstrate compliance.
- Preference changes. People move between states over time – a soft opt-in contact may later give explicit consent, or they might opt out. The correct handling of those changes depends on knowing the starting position. Merge the buckets, and you’ve lost that history.
The conclusion is practical rather than theoretical: your Salesforce data model needs to maintain the distinction between explicit consent and different types of soft opt-in at all times. Your selection query for a simple fundraising appeal can pull from the different groups simultaneously – but the underlying data must keep them separate.
So, the answer to the question “does it matter?” is: the distinction between consent and soft opt-in (probably) doesn’t matter much to your marketing team, but it (should) matter to your data/compliance team.
What this means in practice
Both points come back to the same underlying requirement: your Salesforce instance needs a data model that is more granular than a simple “can contact / cannot contact” checkbox. It needs to record the lawful basis for each individual, the channel through which their details were collected, and the date of collection – every time they give it to you.
If that infrastructure isn’t in place, the risk isn’t just theoretical. It affects your ability to build accurate send lists, respond to a regulatory investigation, and adapt as guidance evolves.
If you’d like to review how your current Salesforce setup handles consent and contact data, get in touch today!
Disclaimer
This blog post is intended for general informational purposes only and reflects our understanding of the Data (Use and Access) Act 2025 and ICO guidance as of the date of publication. It does not constitute legal advice and should not be relied upon as such. Data protection law is evolving, and how it applies to your organisation will depend on your specific circumstances. We strongly recommend seeking independent legal or compliance advice before making decisions based on anything in this post.
About the author:
Aske Bong-Saxe is our Solutions Architect