New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Nonprofit
Privacy & Security for Charities & Foundations
Canadian charities and foundations hold records that would genuinely hurt people if exposed: giving histories, wealth-screening profiles, bequest files, beneficiary case notes and volunteer police checks. Most hold them with no privacy officer and with IT run by an MSP or a volunteer. Privacy Horizon builds right-sized privacy and security programs around your donor CRM, receipting workflow and grantmaking, timed to fit outside the giving-season freeze. Work usually starts with a vendor breach notice, a funder clause, a CRM migration or an Imagine Canada accreditation deadline.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We serve registered charities in social services, faith communities, the arts, the environment and international development, along with community foundations and private or family foundations. The typical profile is five to 150 staff, a paid donor CRM such as Keela, CanadaHelps or a Raiser's Edge-class platform, and nobody whose job description mentions privacy.
Our contacts are usually the executive director, the director of finance and operations who inherited IT, the director of development, the CRM administrator, and a board treasurer or governance chair who has started asking pointed questions about cyber risk and insurance.
Hospital foundations and disease charities that touch patient communities sit in a different regulatory world and are served separately. Here the data at stake belongs to donors, volunteers, grantees and program participants, not patients.

Services
Privacy & security services for charities & foundations
Each service below is scoped for how charities & foundations actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Charities & Foundations
vCISO for charities and foundations: fractional security leadership for donor CRMs, M365 nonprofit tenants, insurer renewals and board accountability.
Virtual Privacy Officer
Virtual Privacy Officer for Charities & Foundations
Virtual Privacy Officer for charities and foundations: a named privacy lead for donor data, Law 25 duties, CRA retention and CASL, without a full-time hire.
Penetration Testing
Penetration Testing for Charities & Foundations
Penetration testing for charities and foundations: scope tests around vendor-hosted donation pages, grant portals, WordPress sites and M365 tenants.
Incident Response Planning
Incident Response Planning for Charities & Foundations
Incident response plan for charities and foundations: who decides, who notifies and how fast when donor, beneficiary or grantee data is exposed.
Privacy & Security Policy Development
Privacy & Security Policy Development for Charities & Foundations
Privacy policy development for charities and foundations: donor privacy policy, beneficiary confidentiality, volunteer agreements and CRA-aware retention.
Privacy & Security Training
Privacy & Security Training for Charities & Foundations
Privacy and security training for charities and foundations: sessions built for fundraisers, volunteers and boards handling donor and beneficiary data.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Charities & Foundations
Vendor security review for charities and foundations: vet donor CRMs, payment platforms and mail agencies before your file leaves the building.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Charities & Foundations
Minimum Viable Privacy for charities and foundations: a $5,499 CAD/year baseline for your donor CRM, CRA retention and the which-law-applies question.
What you hold
The records a charity or foundation must safeguard
Fundraising and program delivery generate several distinct files, each with its own sensitivity and its own storage location. Protection starts with knowing what you actually hold.
Donor constituent records
Contact details, giving history, pledges, payment tokens, spouse and employer fields sit in the CRM as the development office's core asset. Losing control of this file damages the stewardship relationships a charity spends years building.
Prospect research and wealth screening
Estimated-wealth and bequest-likelihood profiles were precisely the fields stolen in the Blackbaud incident, and they are the hardest records to explain to a major-gifts prospect after a leak.
Planned-giving and estate files
Bequest intentions, in-memoriam gifts and correspondence with executors involve grieving families and unsettled estates. These files deserve tighter access than the general constituent database.
Beneficiary intake forms and case notes
Service charities hold shelter, food-bank and program-participant records that are far more sensitive than anything in the donor file, often on shared drives and paper intake forms.
Volunteer files and vulnerable-sector checks
Police check results, emergency contacts and scheduling data for people who are not employees still need retention limits, locked storage and a clear owner.
Grantee and DAF-advisor data
Foundations hold applicant financials, grantee reports and donor-advised-fund advisor identities. A foundation with no program clients still runs real privacy risk through its grants pipeline.
Regulatory map
Which laws actually govern donor and beneficiary data
No single statute covers the Canadian charitable sector. The answer changes with your province, your incorporating statute and what you do with your lists, which is why so many organizations guess wrong.
PIPEDA's commercial-activity test
The OPC treats core charitable activity, including donations, newsletters and fundraising, as non-commercial, so many charities fall outside PIPEDA. Selling, bartering or leasing a donor, membership or fundraising list is commercial and brings the Act into play.
BC PIPA reaches all your activity
British Columbia's Personal Information Protection Act expressly includes not-for-profit organizations and applies to everything they do, not merely commercial dealings.
Alberta's Societies-Act carve-out has a trap
Organizations incorporated under Alberta's Societies Act and similar statutes are exempt except for commercial activity, and accepting donations is not commercial. A federally incorporated charity operating in Alberta enjoys no such carve-out and is fully covered.
Quebec Law 25's enterprise test
Quebec's private-sector Act applies to any organized economic activity whether or not it is commercial, catching most charities and foundations with Quebec donors. Duties include a published person in charge, an incident register and privacy assessments before data leaves the province.
CRA books-and-records requirements
Duplicates of official donation receipts must be kept two years past year-end, most other records six years, with originals at the charity's Canadian address. Inadequate records risk sanctions up to revocation.
CASL's fundraising exemption
Commercial electronic messages sent by or on behalf of a registered charity whose primary purpose is raising funds are exempt. Other messages need consent, and a donation or volunteer work gives two years of implied consent.
Imagine Canada Standards Program
Accreditation commitments cover fundraising and donor privacy, including honouring requests for anonymity under Standard C3 and pledging not to sell donor lists.
What goes wrong
How Canadian charities actually get breached
The public incident record for the sector is dominated by a few repeatable patterns, none of which required a sophisticated attacker.
A fundraising vendor gets compromised
The 2020 Blackbaud ransomware incident saw backups stolen from Raiser's Edge and NetCommunity environments, touching at least 24 Canadian organizations. Each charity, not the vendor, owned the decision to notify its donors.
Mailbox compromise and phishing
Alberta OIPC breach decisions record a compromised account at a Calgary social-services agency and a ransomware attachment opened at an Edmonton early-education society, the everyday entry points for small teams.
CC where BCC belonged
A Medicine Hat YMCA program emailed roughly 200 guardians with every address visible, one of the most common self-inflicted incidents in organizations that run on distribution lists.
Break-ins that take paper
Alberta parent societies and after-school programs reported emergency-contact forms stolen in physical break-ins, a reminder that intake binders and front-desk filing need the same care as servers.
List trading that changes your legal status
Leasing or exchanging your donor file is commercial activity under PIPEDA and breaks the no-sale pledge accredited charities make, converting a marketing decision into a legal and reputational exposure.
When organisations call us
The moments charities and foundations call us
Almost nobody in this sector buys privacy work on a whim. A specific event puts it on the board agenda, and the work is then planned around November-December giving and January-February receipting, when systems freeze.
A vendor says your donors were exposed
A breach notice from a CRM, donation platform or mail house lands, and someone must decide within days who is told what, on what legal or contractual basis.
A CRM or donation-platform migration
Moving from spreadsheets to Keela, CanadaHelps or Raiser's Edge NXT is the one chance to design consent, retention and receipting in from the start rather than retrofit them.
Accreditation or re-accreditation
The Imagine Canada Standards Program's fundraising standards carry donor-privacy commitments an applicant has to evidence, not merely assert.
A funder's due-diligence clause
Contribution agreements commonly include confidentiality and security obligations, and a grants officer eventually asks how you meet them.
Cyber-insurance renewal
Renewal questionnaires now probe MFA, backups, incident response and training, and a blank answer can price a small charity out of coverage.
Quebec exposure surfaces
Donors, a chapter or a campaign in Quebec means Law 25 duties, starting with naming and publishing a person in charge of personal information.
Charities & Foundations: privacy & security questions, answered
It depends on province, incorporation and activity. An Ontario charity that never trades lists may have no privacy statute over its donor data at all, with duties flowing from contracts, accreditation standards and litigation risk instead. BC PIPA covers all nonprofit activity, Alberta exempts locally incorporated societies outside commercial activity while fully covering federally incorporated charities, and Quebec's Law 25 catches most organizations through its enterprise test. Getting this map right is the first task of any engagement.
Start with an inventory of the systems that hold donor, volunteer and beneficiary data, then apply a recognized small-organization baseline such as the Cyber Centre's controls: MFA, backups, patching, an incident plan and training. Assign one accountable owner, usually the director of finance and operations, and let your MSP execute against a documented plan rather than its own defaults.
Yes. CRA requires a registered charity's books and records, including duplicates of official donation receipts, to be kept at its Canadian address, with receipt duplicates retained two years past year-end and most other records six years. That requirement should shape which CRM, receipting and cloud services you choose, and it is a concrete reason Canadian-hosted platforms appeal to many charities.
Not ignore, but the law is friendlier than most boards fear. Commercial electronic messages sent by or on behalf of a registered charity whose primary purpose is raising funds are exempt under the regulations. Messages outside that exemption need consent, and a donation or volunteer work within the previous two years provides implied consent. Sound list hygiene still matters because the exemption does not cover everything you send.
It proved that a vendor's breach becomes each charity's problem. Backups containing donor and wealth-screening data were stolen, at least 24 Canadian organizations were affected, and the duty to notify donors sat with each charity rather than with Blackbaud. It also ended in a US$49.5 million multistate settlement over the vendor's security and communications. The lesson: vet fundraising vendors before signing and plan for their failures in your incident response.
Different risk, not lower. A community or private foundation holds grantee applications and financials, donor-advised-fund advisor identities, and often deep prospect research on a small number of wealthy families. A leak of any of these does immediate relationship damage, and Law 25 or funder agreements can attach formal duties to them. The absence of beneficiary case files simplifies the map without shrinking it.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What should I do after a data breach?
- What's the difference between data privacy and cybersecurity?
- How can I protect my personal and business information from cyberattacks?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.