Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Training · Nonprofit

Privacy & Security Training for Charities & Foundations

Our training turns the people most likely to cause a charity's next incident, well-meaning fundraisers, volunteers and directors, into its first line of defence. Sessions are built around your CRM, your campaigns and your programs rather than generic office scenarios. Charities typically book training after a near-miss email, ahead of an insurer renewal that asks about awareness programs, or when a wave of seasonal volunteers is about to arrive.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

Who needs training in a charity, and on what

The audience here is unlike a company's workforce: most people touching sensitive records are unpaid, part-time or elected, and each group makes distinct mistakes.

Fundraisers and development staff

The team living in the CRM needs fluency in donor confidentiality, anonymity requests, screening ethics and what may be said about a gift publicly, especially around bequests and in-memoriam donations.

Volunteers with system or paper access

Gala committees, receipting helpers, drivers and tax-clinic volunteers handle addresses, payment slips and client details for a few weeks a year, which is precisely why their habits need shaping fast.

Board members carrying lists home

Directors review donor reports, prospect lists and financials on personal devices and personal email. Governance-level training covers their handling duties and the tone they set.

Program staff with beneficiary records

Intake workers and case managers hold the charity's most sensitive files and need scenarios about disclosure requests, photography consent and community confidentiality.

The finance and admin core

The people processing gifts, payroll and vendor payments are the prime targets for payment-fraud lures and need verification reflexes drilled, not described.

Regulatory map

Why regulators, insurers and accreditors expect charity training

Awareness programs are no longer optional niceties; several of the frameworks that already bind your organization treat them as evidence of taking obligations seriously.

The national baseline names training

The Cyber Centre's controls for small and medium organizations include employee awareness, and cyber-insurance questionnaires echo it directly, so a documented program materially helps at renewal.

Primary source →

Statutory safeguard duties imply competent people

Where BC PIPA, Alberta PIPA or Quebec's law reaches your charity, protection obligations extend to everyone acting for the organization, volunteers included, and untrained handlers undermine any claim of reasonable safeguards.

Read our guide →

Accreditation reviews look for practice, not paper

Imagine Canada's fundraising standards presume staff who understand donor-privacy commitments; training records are the natural evidence that policies left the shelf.

Primary source →

CASL knowledge prevents accidental violations

Staff who understand the fundraising exemption and the two-year implied-consent window send confidently and lawfully, instead of either spamming or self-censoring the annual appeal.

Primary source →

What goes wrong

The mistakes charity training is engineered to stop

We build modules backwards from the incidents that actually happen in this sector, most of which begin with a person rather than a system.

  • The CC field on a mass email

    Exposing a recipient list, as happened to a Medicine Hat YMCA program with about 200 guardians, takes one keystroke. Training installs the BCC habit and, better, moves list sends into platforms.

    Source →

  • Phishing aimed at gift processing

    A ransomware attachment opened at an Edmonton early-education society shows the entry point: urgent-looking messages during busy periods. Simulation and recognition drills cut the click rate where it matters.

  • Oversharing a donor's generosity

    Thanking a donor publicly who gave anonymously, or confirming a bequest to a caller, breaches Standard C3 commitments and can end a relationship. Scenarios rehearse the graceful refusal.

  • Casual exports and USB spreadsheets

    Volunteers and staff copying CRM segments to personal laptops for convenience create shadow databases no one protects or deletes. Training pairs the rule with the safer workflow.

Our training for charities & foundations

Training built from your charity's real workflows

Every engagement is custom: modules reflect your systems, your policies and the season you are heading into, delivered in formats volunteers can actually attend.

Two data analysts Working on data analysis dashboard for business strategy
  1. Role-based curriculum design

    Separate tracks for fundraisers, volunteers, program staff, finance and the board, each sized to their access and risk rather than one generic hour for all.

  2. Scenario libraries from your operations

    Exercises built on your CRM, your receipting run, your gala and your intake process, so learners recognize the situation the day it happens.

  3. Live, remote or on-demand delivery

    Lunchtime sessions for staff, evening or recorded options for volunteers and directors, with short refreshers scheduled before giving season.

  4. Human-risk assessment and phishing exercises

    Baseline measurement of susceptibility, followed by targeted reinforcement, giving your board and insurer a before-and-after picture.

  5. Records and attestations

    Completion tracking and sign-offs that slot straight into accreditation submissions, funder due diligence and renewal questionnaires.

How the engagement runs

How a charity training program comes together

Setup is light on your team; most of the effort is ours, and the calendar bends around campaigns.

  1. Step 1

    Audience and incident review

    We map who touches which records, review any near-misses, and read your policies so training teaches your actual rules.

  2. Step 2

    Module build and pilot

    Draft sessions are piloted with a small group, then tuned for tone and length, because volunteer attention is a scarce resource.

  3. Step 3

    Rollout by role and season

    Staff first, then board, then volunteer cohorts timed to onboarding waves, finishing before the November change freeze.

  4. Step 4

    Measurement and annual refresh

    Phishing results, completion rates and incident trends feed a yearly update so content stays current with platforms and law.

What it costs

Pricing drivers for charity training programs

Cost tracks the number of distinct audiences and modules, delivery format, whether phishing simulation and human-risk assessment are included, and how many sessions your volunteer schedule requires. Training a fifteen-person staff plus one board evening is a modest engagement; adding rolling volunteer cohorts across program sites grows it predictably.

Training seats are already bundled into our Minimum Viable Privacy and Virtual Privacy Office arrangements, so if you are considering one of those, the smarter move may be the package. Either way, a short call yields a fixed quote.

Charities & Foundations: Training questions, answered

With scenarios from their own pipeline: a reporter asking who funded the new wing, a board member requesting the major-gifts list for personal networking, a spouse asking about a memorial donation, a donor who wants recognition withdrawn. Each rehearses the commitment behind Standard C3, honouring anonymity and controlling giving information, and gives fundraisers wording that protects the relationship while declining the disclosure. Policy references come after the practice, not before.

A focused governance session covering three things: their personal handling duties for reports, prospect lists and financials they receive; the questions they should be asking management about incidents, vendors and insurance; and the example they set, since directors who forward board packages to personal email license everyone else to improvise. One well-run evening with follow-up materials usually accomplishes more than mandatory modules directors quietly skip.

Reduce the opportunity, then train the habit. Move bulk messages out of personal mailboxes into your email platform or CRM sends, restrict volunteer accounts to the lists their role needs, and turn on external-sender banners. Then run short, concrete sessions during onboarding, ten minutes on list hygiene, ten on spotting urgent-payment and credential lures, repeated each season because volunteer turnover erases institutional memory annually.

That constraint shapes the whole design. We deliver evenings, weekends, recorded modules and micro-sessions inside existing volunteer meetings, and we keep giving season clear so no one is pulled from campaign work. Onboarding-wave timing matters most: a cohort trained in October protects your busiest quarter, while a spring session mainly protects your summer barbecue.

Completion records by person and role, session outlines showing topics covered, dates of phishing exercises with aggregate results, and a schedule demonstrating recurrence rather than a one-off. We generate all of these as standard artifacts, formatted so a renewal questionnaire, a contribution-agreement due-diligence request or an accreditation submission can cite them directly.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.