Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Nonprofit

Privacy & Security for Charities & Foundations

Canadian charities and foundations hold records that would genuinely hurt people if exposed: giving histories, wealth-screening profiles, bequest files, beneficiary case notes and volunteer police checks. Most hold them with no privacy officer and with IT run by an MSP or a volunteer. Privacy Horizon builds right-sized privacy and security programs around your donor CRM, receipting workflow and grantmaking, timed to fit outside the giving-season freeze. Work usually starts with a vendor breach notice, a funder clause, a CRM migration or an Imagine Canada accreditation deadline.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

We serve registered charities in social services, faith communities, the arts, the environment and international development, along with community foundations and private or family foundations. The typical profile is five to 150 staff, a paid donor CRM such as Keela, CanadaHelps or a Raiser's Edge-class platform, and nobody whose job description mentions privacy.

Our contacts are usually the executive director, the director of finance and operations who inherited IT, the director of development, the CRM administrator, and a board treasurer or governance chair who has started asking pointed questions about cyber risk and insurance.

Hospital foundations and disease charities that touch patient communities sit in a different regulatory world and are served separately. Here the data at stake belongs to donors, volunteers, grantees and program participants, not patients.

Diverse adults packing donation boxes in charity food bank

Services

Privacy & security services for charities & foundations

Each service below is scoped for how charities & foundations actually operate — their systems, their regulators and the reviews they face.

What you hold

The records a charity or foundation must safeguard

Fundraising and program delivery generate several distinct files, each with its own sensitivity and its own storage location. Protection starts with knowing what you actually hold.

Donor constituent records

Contact details, giving history, pledges, payment tokens, spouse and employer fields sit in the CRM as the development office's core asset. Losing control of this file damages the stewardship relationships a charity spends years building.

Prospect research and wealth screening

Estimated-wealth and bequest-likelihood profiles were precisely the fields stolen in the Blackbaud incident, and they are the hardest records to explain to a major-gifts prospect after a leak.

Planned-giving and estate files

Bequest intentions, in-memoriam gifts and correspondence with executors involve grieving families and unsettled estates. These files deserve tighter access than the general constituent database.

Beneficiary intake forms and case notes

Service charities hold shelter, food-bank and program-participant records that are far more sensitive than anything in the donor file, often on shared drives and paper intake forms.

Volunteer files and vulnerable-sector checks

Police check results, emergency contacts and scheduling data for people who are not employees still need retention limits, locked storage and a clear owner.

Grantee and DAF-advisor data

Foundations hold applicant financials, grantee reports and donor-advised-fund advisor identities. A foundation with no program clients still runs real privacy risk through its grants pipeline.

Regulatory map

Which laws actually govern donor and beneficiary data

No single statute covers the Canadian charitable sector. The answer changes with your province, your incorporating statute and what you do with your lists, which is why so many organizations guess wrong.

PIPEDA's commercial-activity test

The OPC treats core charitable activity, including donations, newsletters and fundraising, as non-commercial, so many charities fall outside PIPEDA. Selling, bartering or leasing a donor, membership or fundraising list is commercial and brings the Act into play.

Read our guide →

BC PIPA reaches all your activity

British Columbia's Personal Information Protection Act expressly includes not-for-profit organizations and applies to everything they do, not merely commercial dealings.

Read our guide →

Alberta's Societies-Act carve-out has a trap

Organizations incorporated under Alberta's Societies Act and similar statutes are exempt except for commercial activity, and accepting donations is not commercial. A federally incorporated charity operating in Alberta enjoys no such carve-out and is fully covered.

Primary source →

Quebec Law 25's enterprise test

Quebec's private-sector Act applies to any organized economic activity whether or not it is commercial, catching most charities and foundations with Quebec donors. Duties include a published person in charge, an incident register and privacy assessments before data leaves the province.

Primary source →

CRA books-and-records requirements

Duplicates of official donation receipts must be kept two years past year-end, most other records six years, with originals at the charity's Canadian address. Inadequate records risk sanctions up to revocation.

Primary source →

CASL's fundraising exemption

Commercial electronic messages sent by or on behalf of a registered charity whose primary purpose is raising funds are exempt. Other messages need consent, and a donation or volunteer work gives two years of implied consent.

Primary source →

Imagine Canada Standards Program

Accreditation commitments cover fundraising and donor privacy, including honouring requests for anonymity under Standard C3 and pledging not to sell donor lists.

Primary source →

What goes wrong

How Canadian charities actually get breached

The public incident record for the sector is dominated by a few repeatable patterns, none of which required a sophisticated attacker.

  • A fundraising vendor gets compromised

    The 2020 Blackbaud ransomware incident saw backups stolen from Raiser's Edge and NetCommunity environments, touching at least 24 Canadian organizations. Each charity, not the vendor, owned the decision to notify its donors.

    Source →

  • Mailbox compromise and phishing

    Alberta OIPC breach decisions record a compromised account at a Calgary social-services agency and a ransomware attachment opened at an Edmonton early-education society, the everyday entry points for small teams.

    Source →

  • CC where BCC belonged

    A Medicine Hat YMCA program emailed roughly 200 guardians with every address visible, one of the most common self-inflicted incidents in organizations that run on distribution lists.

  • Break-ins that take paper

    Alberta parent societies and after-school programs reported emergency-contact forms stolen in physical break-ins, a reminder that intake binders and front-desk filing need the same care as servers.

  • List trading that changes your legal status

    Leasing or exchanging your donor file is commercial activity under PIPEDA and breaks the no-sale pledge accredited charities make, converting a marketing decision into a legal and reputational exposure.

When organisations call us

The moments charities and foundations call us

Almost nobody in this sector buys privacy work on a whim. A specific event puts it on the board agenda, and the work is then planned around November-December giving and January-February receipting, when systems freeze.

  • A vendor says your donors were exposed

    A breach notice from a CRM, donation platform or mail house lands, and someone must decide within days who is told what, on what legal or contractual basis.

  • A CRM or donation-platform migration

    Moving from spreadsheets to Keela, CanadaHelps or Raiser's Edge NXT is the one chance to design consent, retention and receipting in from the start rather than retrofit them.

  • Accreditation or re-accreditation

    The Imagine Canada Standards Program's fundraising standards carry donor-privacy commitments an applicant has to evidence, not merely assert.

  • A funder's due-diligence clause

    Contribution agreements commonly include confidentiality and security obligations, and a grants officer eventually asks how you meet them.

  • Cyber-insurance renewal

    Renewal questionnaires now probe MFA, backups, incident response and training, and a blank answer can price a small charity out of coverage.

  • Quebec exposure surfaces

    Donors, a chapter or a campaign in Quebec means Law 25 duties, starting with naming and publishing a person in charge of personal information.

Charities & Foundations: privacy & security questions, answered

It depends on province, incorporation and activity. An Ontario charity that never trades lists may have no privacy statute over its donor data at all, with duties flowing from contracts, accreditation standards and litigation risk instead. BC PIPA covers all nonprofit activity, Alberta exempts locally incorporated societies outside commercial activity while fully covering federally incorporated charities, and Quebec's Law 25 catches most organizations through its enterprise test. Getting this map right is the first task of any engagement.

Start with an inventory of the systems that hold donor, volunteer and beneficiary data, then apply a recognized small-organization baseline such as the Cyber Centre's controls: MFA, backups, patching, an incident plan and training. Assign one accountable owner, usually the director of finance and operations, and let your MSP execute against a documented plan rather than its own defaults.

Yes. CRA requires a registered charity's books and records, including duplicates of official donation receipts, to be kept at its Canadian address, with receipt duplicates retained two years past year-end and most other records six years. That requirement should shape which CRM, receipting and cloud services you choose, and it is a concrete reason Canadian-hosted platforms appeal to many charities.

Not ignore, but the law is friendlier than most boards fear. Commercial electronic messages sent by or on behalf of a registered charity whose primary purpose is raising funds are exempt under the regulations. Messages outside that exemption need consent, and a donation or volunteer work within the previous two years provides implied consent. Sound list hygiene still matters because the exemption does not cover everything you send.

It proved that a vendor's breach becomes each charity's problem. Backups containing donor and wealth-screening data were stolen, at least 24 Canadian organizations were affected, and the duty to notify donors sat with each charity rather than with Blackbaud. It also ended in a US$49.5 million multistate settlement over the vendor's security and communications. The lesson: vet fundraising vendors before signing and plan for their failures in your incident response.

Different risk, not lower. A community or private foundation holds grantee applications and financials, donor-advised-fund advisor identities, and often deep prospect research on a small number of wealthy families. A leak of any of these does immediate relationship damage, and Law 25 or funder agreements can attach formal duties to them. The absence of beneficiary case files simplifies the map without shrinking it.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.