Nonprofit Data Privacy & Technology Compliance Guide

Founder and Managing Attorney
Nonprofits collect and rely on a wide range of data — donor records, client information, employee files, and payment details. This guide explains the data privacy, cybersecurity, and technology compliance issues a nonprofit may need to manage, from privacy notices and vendor agreements to incident response and AI use. It is educational information, not legal advice for your specific organization.
The exact issues that apply depend on the data the organization handles, its operations, its jurisdiction, and the vendors it uses — there is no universal checklist. Importantly, an organization's nonprofit status does not by itself determine whether a particular privacy law applies; what matters is the data and the activity. For help applying these concepts to your organization, see our compliance and risk guidance and our contracts and agreements services.
What Kinds of Data Nonprofits Handle
A practical first step is understanding what data the organization actually collects and where it lives. Common categories include:
- Donor data: Names, contact details, giving history, and payment information collected through donations and fundraising.
- Client or beneficiary data: Information about the people the organization serves, which may include sensitive details depending on the program.
- Volunteer data: Contact information, screening records, and assignment details collected during volunteer onboarding.
- Employee data: HR, payroll, and benefits records collected during hiring and employment.
- Board and member data: Contact and governance information for directors, officers, and members.
- Payment information: Card or bank details collected through donations, events, or earned revenue, which may implicate payment-card obligations.
- Website and contact-form submissions: Information submitted through the website, forms, and inquiries.
- CRM and platform records: Records stored in a CRM, email-marketing platform, fundraising tool, or other cloud service.
Holding sensitive data does not, by itself, mean a particular regulatory framework applies. Whether HIPAA, FERPA, payment-card obligations, or state privacy laws are implicated depends on the specific data and activities. Organizations should confirm which requirements apply to them rather than assuming a framework applies merely because sensitive data exists.
Privacy Notices and Privacy Policies
A privacy notice helps set expectations with donors, clients, volunteers, and website visitors. A useful notice generally addresses:
- What data is collected
- Why it is collected and how it is used
- Whether and how it is shared
- How long it is retained
- What rights individuals may have where applicable
- How to contact the organization with questions
One privacy-notice template does not fit every organization. Copying another organization's notice can create expectations the organization does not actually meet, or reference practices that do not apply. A notice should match the organization's actual data practices and be reviewed when those practices change. For the governance context around adopting and maintaining policies, see our governance and policies services.
Donor Data Privacy
Donors reasonably expect their information to be handled carefully. Issues to consider include how donor data is stored, who can access it, whether and how it is shared with vendors, and whether list rentals or exchanges are consistent with the organization's representations and any applicable fundraising or privacy requirements. Online donation platforms and fundraising vendors may have their own terms that affect how donor data is used. Before sharing donor data with a vendor or partner, organizations should review their privacy commitments and the vendor agreement. For fundraising-related registration requirements, see our charitable solicitation registration guide.
Employee and Volunteer Data
Nonprofits also hold HR-related data — onboarding records, background-check results, payroll and benefits information, and volunteer screening records. Access to this data should be limited to those who need it, and retention should follow a documented approach rather than indefinite keeping. Background checks in particular are regulated, and their use should be reviewed against applicable requirements before being adopted. For the broader employment-law context, see our nonprofit employment and HR compliance guide and our nonprofit volunteer policies guide.
Cybersecurity Governance
Cybersecurity is a governance issue, not just a technical one. Practical governance practices include:
- Access controls and role-based permissions that limit data to those who need it
- Multi-factor authentication for sensitive systems and accounts
- Regular backups and a tested restoration process
- An incident-response plan with clear internal escalation
- Vendor access that is reviewed and revoked when no longer needed
- Onboarding and offboarding controls that add and remove system access promptly
- Board or leadership visibility into serious incidents and high-risk systems
This guide is not a technical implementation manual. The goal is for leadership to understand what practices reduce risk and to confirm the organization has them in place. For ongoing oversight support, see our outside general counsel services.
Vendor and SaaS Risk
Many nonprofits depend on outside platforms — CRMs, cloud storage, email-marketing tools, payment processors, fundraising platforms, HR systems, and AI tools. Each vendor relationship can create data exposure. Legal considerations when reviewing a vendor or SaaS agreement include:
- Data ownership and whether the organization can retrieve its data
- Confidentiality obligations for the vendor and its subcontractors
- Security obligations and standards the vendor must meet
- Breach-notification requirements in the agreement
- Subcontractor use and whether it can be delegated
- Termination, data return, and data-deletion terms
- Indemnity and liability allocation where appropriate
Reviewing these terms before signing — not after an incident — is far less costly. For help reviewing and negotiating these agreements, see our contracts and agreements services.
Data Retention and Deletion
Keeping every record indefinitely is not a sound practice. A documented retention approach helps the organization keep what it needs for legal, operational, and governance reasons while deleting what it no longer needs. Retention periods can depend on the type of record, the organization's obligations, and its jurisdiction, so organizations should confirm applicable requirements rather than applying a single universal period. For the governance documentation that supports retention decisions, see our board meeting minutes guide.
Incident Response and Breach Readiness
Preparing before an incident helps an organization respond effectively. Practical steps include:
- Internal escalation to the right people promptly
- Preservation of facts, logs, and affected records
- Coordination with affected vendors and platforms
- Legal review before any notifications or public statements
- Notification analysis against applicable requirements
- Communications planning that avoids premature or inaccurate statements
Breach-notification requirements and timelines can depend on the data involved and the jurisdiction, and they can change. Organizations should confirm the current requirements that apply rather than assuming a fixed deadline, and should involve legal counsel early. Premature or inaccurate notifications can create their own risk.
Website Tracking, Cookies, and Third-Party Scripts
Analytics tools, pixels, cookies, and third-party scripts can collect visitor data. Whether notice or consent is required can depend on what is collected, how it is used, and the visitor's jurisdiction — one legal regime does not necessarily apply everywhere. Organizations should review their tracking tools against applicable requirements and their own privacy notice, rather than assuming no review is needed.
Email, SMS, and Outreach Compliance
Email and text-message outreach raise questions about consent, unsubscribe and opt-out mechanisms, the distinction between marketing and transactional messages, and platform or vendor requirements. The rules and their consequences can depend on the channel, the recipient, and the jurisdiction. Organizations should confirm the requirements that apply to their outreach rather than relying on assumed penalties or thresholds, and should ensure their practices match their platform agreements.
AI Use by Nonprofits
Artificial-intelligence tools are increasingly accessible, and their use raises governance questions even where specific legal obligations are still developing. Considerations include:
- What data may be entered and whether it includes confidential donor, client, or employee information
- The vendor's retention, training, and reuse terms
- Whether outputs receive meaningful human review before use
- Bias, accuracy, and risk considerations for the intended use
- Internal policy controls on who may use the tool and for what
Organizations should avoid overstating current AI-specific legal obligations and should confirm what applies to their situation. A simple internal policy on what data may be entered into AI tools and who may use them can reduce risk before adoption.
Board Oversight of Privacy and Technology
Boards commonly have visibility into matters that carry significant organizational risk — serious incidents, high-risk systems, sensitive-data programs, major vendor relationships, and significant policy changes. Day-to-day technology decisions are typically management-level. The right division depends on the organization's structure, and counsel can help clarify what warrants board review versus management action. For the governance framework, see our governance and policies services and the Board Governance Center.
Common Privacy and Technology Compliance Mistakes
- Assuming a law applies (or does not apply) based on nonprofit status rather than the data and activities involved.
- Copying another organization's privacy notice without matching it to actual data practices.
- Signing vendor or SaaS agreements without reviewing data ownership, security, breach, and termination terms.
- Keeping every record indefinitely without a documented retention approach.
- Granting broad system access and failing to remove it when staff or volunteers leave.
- Assuming website cookies and tracking tools require no notice or consent review.
- Treating AI tools as interchangeable without considering what data is entered and vendor retention terms.
- Lacking an incident-response plan before a suspected breach occurs.
- Overstating current AI-specific legal obligations or promising compliance the organization has not verified.
- Overlooking board oversight of serious incidents and high-risk data programs.
Nonprofit Data Privacy & Technology Compliance Checklist
The following is an educational framework for thinking through nonprofit data privacy and technology compliance. It is not a universal legal checklist — the issues that apply depend on the data the organization handles, its operations, jurisdiction, and vendors, and should be confirmed against current applicable law.
Privacy & Technology Compliance — Checklist
- Inventory the categories of data the organization collects.
- Identify where each category of data is stored.
- Identify which vendors and platforms have access to that data.
- Review privacy notices for accuracy against actual practices.
- Review vendor and SaaS agreements for data, security, and breach terms.
- Confirm access controls and role-based permissions.
- Require multi-factor authentication where appropriate.
- Maintain onboarding and offboarding controls for system access.
- Establish documented data retention and deletion practices.
- Maintain incident-response and escalation procedures.
- Review website tracking tools, cookies, and third-party scripts.
- Review email and SMS outreach practices for consent and opt-out.
- Establish written guidance for any use of AI tools.
- Periodically review privacy and technology risks and policies.
This checklist is educational and is not a substitute for legal advice. Privacy and technology requirements vary by data type, jurisdiction, and the nature of the activities, and may change over time.
When Should a Nonprofit Involve Legal Counsel?
Legal counsel can be valuable when an organization is adopting a new CRM or fundraising platform, signing a vendor or SaaS agreement, launching online donations or email marketing, drafting or updating a privacy notice, responding to a suspected data incident, or adopting AI tools. Preventative guidance is typically less costly and less disruptive than reacting after a problem escalates.
Our compliance and risk guidance and contracts and agreements services support organizations through these decisions, and our outside general counsel services provide ongoing access for organizations with recurring privacy and technology questions. For related governance and documentation, see our board meeting minutes guide and compliance training workshops. To scope the work, start with Get Clarity.
Educational information, not legal advice. This guide is provided for general educational purposes. Privacy, cybersecurity, and technology requirements — including breach-notification rules, state privacy laws, and sector-specific frameworks such as HIPAA, FERPA, and payment-card obligations — vary by data type, jurisdiction, and the nature of the activities, and may change over time. This guide does not state the specific requirements that apply to any particular organization and is not a substitute for legal advice tailored to your organization.