Training · Nonprofit
Privacy & Security Training for Charities & Foundations
Our training turns the people most likely to cause a charity's next incident, well-meaning fundraisers, volunteers and directors, into its first line of defence. Sessions are built around your CRM, your campaigns and your programs rather than generic office scenarios. Charities typically book training after a near-miss email, ahead of an insurer renewal that asks about awareness programs, or when a wave of seasonal volunteers is about to arrive.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
Who needs training in a charity, and on what
The audience here is unlike a company's workforce: most people touching sensitive records are unpaid, part-time or elected, and each group makes distinct mistakes.
Fundraisers and development staff
The team living in the CRM needs fluency in donor confidentiality, anonymity requests, screening ethics and what may be said about a gift publicly, especially around bequests and in-memoriam donations.
Volunteers with system or paper access
Gala committees, receipting helpers, drivers and tax-clinic volunteers handle addresses, payment slips and client details for a few weeks a year, which is precisely why their habits need shaping fast.
Board members carrying lists home
Directors review donor reports, prospect lists and financials on personal devices and personal email. Governance-level training covers their handling duties and the tone they set.
Program staff with beneficiary records
Intake workers and case managers hold the charity's most sensitive files and need scenarios about disclosure requests, photography consent and community confidentiality.
The finance and admin core
The people processing gifts, payroll and vendor payments are the prime targets for payment-fraud lures and need verification reflexes drilled, not described.
Regulatory map
Why regulators, insurers and accreditors expect charity training
Awareness programs are no longer optional niceties; several of the frameworks that already bind your organization treat them as evidence of taking obligations seriously.
The national baseline names training
The Cyber Centre's controls for small and medium organizations include employee awareness, and cyber-insurance questionnaires echo it directly, so a documented program materially helps at renewal.
Statutory safeguard duties imply competent people
Where BC PIPA, Alberta PIPA or Quebec's law reaches your charity, protection obligations extend to everyone acting for the organization, volunteers included, and untrained handlers undermine any claim of reasonable safeguards.
Accreditation reviews look for practice, not paper
Imagine Canada's fundraising standards presume staff who understand donor-privacy commitments; training records are the natural evidence that policies left the shelf.
CASL knowledge prevents accidental violations
Staff who understand the fundraising exemption and the two-year implied-consent window send confidently and lawfully, instead of either spamming or self-censoring the annual appeal.
What goes wrong
The mistakes charity training is engineered to stop
We build modules backwards from the incidents that actually happen in this sector, most of which begin with a person rather than a system.
The CC field on a mass email
Exposing a recipient list, as happened to a Medicine Hat YMCA program with about 200 guardians, takes one keystroke. Training installs the BCC habit and, better, moves list sends into platforms.
Phishing aimed at gift processing
A ransomware attachment opened at an Edmonton early-education society shows the entry point: urgent-looking messages during busy periods. Simulation and recognition drills cut the click rate where it matters.
Oversharing a donor's generosity
Thanking a donor publicly who gave anonymously, or confirming a bequest to a caller, breaches Standard C3 commitments and can end a relationship. Scenarios rehearse the graceful refusal.
Casual exports and USB spreadsheets
Volunteers and staff copying CRM segments to personal laptops for convenience create shadow databases no one protects or deletes. Training pairs the rule with the safer workflow.
Our training for charities & foundations
Training built from your charity's real workflows
Every engagement is custom: modules reflect your systems, your policies and the season you are heading into, delivered in formats volunteers can actually attend.

Role-based curriculum design
Separate tracks for fundraisers, volunteers, program staff, finance and the board, each sized to their access and risk rather than one generic hour for all.
Scenario libraries from your operations
Exercises built on your CRM, your receipting run, your gala and your intake process, so learners recognize the situation the day it happens.
Live, remote or on-demand delivery
Lunchtime sessions for staff, evening or recorded options for volunteers and directors, with short refreshers scheduled before giving season.
Human-risk assessment and phishing exercises
Baseline measurement of susceptibility, followed by targeted reinforcement, giving your board and insurer a before-and-after picture.
Records and attestations
Completion tracking and sign-offs that slot straight into accreditation submissions, funder due diligence and renewal questionnaires.
How the engagement runs
How a charity training program comes together
Setup is light on your team; most of the effort is ours, and the calendar bends around campaigns.
Step 1
Audience and incident review
We map who touches which records, review any near-misses, and read your policies so training teaches your actual rules.
Step 2
Module build and pilot
Draft sessions are piloted with a small group, then tuned for tone and length, because volunteer attention is a scarce resource.
Step 3
Rollout by role and season
Staff first, then board, then volunteer cohorts timed to onboarding waves, finishing before the November change freeze.
Step 4
Measurement and annual refresh
Phishing results, completion rates and incident trends feed a yearly update so content stays current with platforms and law.
What it costs
Pricing drivers for charity training programs
Cost tracks the number of distinct audiences and modules, delivery format, whether phishing simulation and human-risk assessment are included, and how many sessions your volunteer schedule requires. Training a fifteen-person staff plus one board evening is a modest engagement; adding rolling volunteer cohorts across program sites grows it predictably.
Training seats are already bundled into our Minimum Viable Privacy and Virtual Privacy Office arrangements, so if you are considering one of those, the smarter move may be the package. Either way, a short call yields a fixed quote.
Charities & Foundations: Training questions, answered
With scenarios from their own pipeline: a reporter asking who funded the new wing, a board member requesting the major-gifts list for personal networking, a spouse asking about a memorial donation, a donor who wants recognition withdrawn. Each rehearses the commitment behind Standard C3, honouring anonymity and controlling giving information, and gives fundraisers wording that protects the relationship while declining the disclosure. Policy references come after the practice, not before.
A focused governance session covering three things: their personal handling duties for reports, prospect lists and financials they receive; the questions they should be asking management about incidents, vendors and insurance; and the example they set, since directors who forward board packages to personal email license everyone else to improvise. One well-run evening with follow-up materials usually accomplishes more than mandatory modules directors quietly skip.
Reduce the opportunity, then train the habit. Move bulk messages out of personal mailboxes into your email platform or CRM sends, restrict volunteer accounts to the lists their role needs, and turn on external-sender banners. Then run short, concrete sessions during onboarding, ten minutes on list hygiene, ten on spotting urgent-payment and credential lures, repeated each season because volunteer turnover erases institutional memory annually.
That constraint shapes the whole design. We deliver evenings, weekends, recorded modules and micro-sessions inside existing volunteer meetings, and we keep giving season clear so no one is pulled from campaign work. Onboarding-wave timing matters most: a cohort trained in October protects your busiest quarter, while a spring session mainly protects your summer barbecue.
Completion records by person and role, session outlines showing topics covered, dates of phishing exercises with aggregate results, and a schedule demonstrating recurrence rather than a one-off. We generate all of these as standard artifacts, formatted so a renewal questionnaire, a contribution-agreement due-diligence request or an accreditation submission can cite them directly.
More for charities & foundations
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.