Prompt

How do I ensure my supporter record enrichment with a data enrichment platform is compliant with GDPR and CCPA?

Nonprofits & NGOs · Advocacy / Advocacy1 observationLast seen Aug 13, 2026

Latest observation

Aug 13, 2026 · OpenAI APIWeb search: off

To keep supporter record enrichment compliant with GDPR and CCPA/CPRA, treat it as a regulated data-processing activity, not just a marketing task. The safest approach is to put lawful basis, transparency, minimization, vendor controls, opt-outs, and governance around the enrichment workflow.

1) Define exactly what data you’re enriching

Document:

  • What identifiers you send to the enrichment platform
  • What fields you receive back
  • Which fields are used for fundraising/marketing/segmentation
  • Whether the data includes personal data or sensitive personal information
  • Whether the enrichment provider acts as a processor/service provider or an independent controller/business

Only collect/enrich what you actually need.

2) Establish a lawful basis under GDPR

For EU/UK supporters, you need a valid lawful basis for enrichment and any downstream use. Common options:

  • Legitimate interests: often used for B2B/contact enrichment or supporter relationship management, but requires a documented balancing test
  • Consent: safer for certain marketing-related uses, especially if enrichment feeds targeted advertising or email campaigns
  • Contract: usually only if enrichment is strictly necessary to perform a contract
  • Legal obligation: rare for enrichment

Do a Legitimate Interests Assessment (LIA) if relying on legitimate interests.

3) Update your privacy notice

Tell supporters, clearly and before or at collection, that you:

  • Use third-party data enrichment tools
  • May combine information from public and commercial sources
  • Describe the categories of data collected
  • State the purposes: profiling, segmentation, personalization, suppression, fraud prevention, etc.
  • Name categories of sources and, where appropriate, the enrichment vendor
  • Explain retention and rights available to them

Under GDPR, this should be in your privacy notice. Under CCPA/CPRA, it should be in your notice at collection and privacy policy.

4) Minimize and avoid sensitive data unless strictly needed

Do not enrich with or infer:

  • Health data
  • Religion
  • Political opinions
  • Sexual orientation
  • Precise geolocation
  • Race/ethnicity
  • Other sensitive categories

Under CPRA, “sensitive personal information” has special handling and in some cases a right to limit use/disclosure. Under GDPR, special category data needs a separate lawful basis and Article 9 condition.

5) Put a contract in place with the enrichment vendor

Your agreement should include:

  • DPA / data processing terms
  • Instructions on processing
  • Confidentiality obligations
  • Security measures
  • Subprocessor disclosures
  • Data deletion/return at end of service
  • Assistance with data subject requests
  • Restrictions on vendor reuse, resale, or model training
  • Cross-border transfer provisions if data leaves the EU/UK

For CCPA/CPRA, ensure the vendor qualifies as a service provider or contractor, not a separate business using data for its own purposes.

6) Check international data transfers

If supporter data is sent outside the EU/UK:

  • Use appropriate transfer mechanisms: SCCs, UK IDTA/Addendum, etc.
  • Complete a transfer risk assessment where needed
  • Verify vendor sub-processors and hosting locations
  • Consider EU/UK data residency if risk is high

7) Respect data subject rights and opt-outs

You need a process to handle:

  • Access
  • Deletion
  • Correction
  • Objection to processing/profiling
  • Restriction where applicable
  • Portability in GDPR contexts

Under CCPA/CPRA, support:

  • Right to know
  • Right to delete
  • Right to correct
  • Right to opt out of sale/share
  • Limit use of sensitive personal information

Also honor global privacy controls where required, if your use falls under “sale/share” or targeted advertising.

8) Determine whether your enrichment is a “sale” or “sharing” under CCPA/CPRA

This is a common risk area. If you disclose data to an enrichment provider in exchange for value, it may be considered a:

  • Sale, or
  • Sharing for cross-context behavioral advertising

If so, you may need:

  • A “Do Not Sell or Share My Personal Information” link
  • Contractual terms limiting use
  • Opt-out mechanisms

Don’t assume enrichment is exempt just because it’s “service” activity.

9) Avoid automated decision-making pitfalls

If enriched data is used to make significant decisions about individuals, GDPR may require:

  • Additional transparency
  • Human review
  • Controls on solely automated decisions
  • DPIA assessment if the profiling is high risk

Even if you’re not making formal “significant decisions,” be careful with profiling that meaningfully affects people.

10) Conduct a DPIA / privacy impact assessment

Do a Data Protection Impact Assessment if enrichment is likely to:

  • Involve large-scale profiling
  • Combine datasets
  • Use sensitive data
  • Create high privacy risk
  • Affect vulnerable individuals

For many nonprofit supporter enrichment programs, a DPIA is a strong governance step even if not strictly mandatory.

11) Set retention and suppression rules

Define:

  • How long enriched data is kept
  • When it is refreshed
  • When stale data is deleted
  • How suppression lists are maintained
  • Whether you keep only derived scores or source attributes

Keep suppression/opt-out records as needed, but don’t retain unnecessary enrichment data indefinitely.

12) Validate data accuracy

Enrichment data can be wrong or outdated. GDPR expects reasonable steps to ensure accuracy. You should:

  • Review accuracy rates
  • Flag inferred vs. observed data
  • Allow correction requests
  • Avoid over-reliance on low-confidence attributes

13) Be careful with children’s data

If you support minors or youth-related programs:

  • Confirm age thresholds and applicable parental consent requirements
  • Avoid enrichment of children’s data unless you have a clearly lawful basis and strong safeguards
  • Under CPRA/COPPA interplay, additional restrictions may apply

14) Document everything

Keep records of:

  • Purposes of enrichment
  • Lawful basis
  • Vendor due diligence
  • Contracts and transfer safeguards
  • DPIA/LIA
  • Opt-out handling
  • Retention policy
  • Data mapping and access logs

This helps demonstrate accountability.

15) Practical compliance checklist

Before launch, confirm:

  • Data inventory completed
  • Lawful basis documented
  • Privacy notice updated
  • Vendor DPA/service provider terms signed
  • Sale/share assessment completed for CCPA/CPRA
  • Transfer mechanism in place for EU/UK data
  • DPIA/LIA completed
  • Opt-out and rights workflow tested
  • Sensitive data excluded or separately governed
  • Retention/deletion policy defined
  • Security review completed

A sensible default approach

If you want the lowest-risk setup:

  1. Use enrichment only for internal supporter management and suppression/householding
  2. Exclude sensitive data and high-risk inferences
  3. Use a vendor under strict processor/service provider terms
  4. Give clear notice
  5. Offer easy opt-outs
  6. Keep a documented LIA/DPIA

If you want, I can also provide:

  • a GDPR + CCPA compliance checklist specifically for nonprofit supporter enrichment, or
  • a sample privacy notice clause you can adapt.

Observation history

Unlock observation history

Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.