Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

MVP program · Nonprofit

Minimum Viable Privacy Program for Charities & Foundations

Minimum Viable Privacy packages a working baseline into one program a small charity can afford: a gap review of your donor CRM and receipting flow, the policies a funder or Imagine Canada actually checks, training for ten people, and twelve hours of coaching, for $5,499 CAD a year. It suits the five-to-fifty-person organization that just received a contribution agreement with a privacy clause, is migrating off spreadsheets into Keela or CanadaHelps, or needs a defensible answer before an accreditation deadline, without hiring anyone.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The one system MVP concentrates on first

A charity this size cannot protect everything equally, so the baseline starts with the platform and the people who touch it most, then works outward.

The donor CRM as the highest-value target

Whether you run Keela, CanadaHelps or a Raiser's Edge-class platform, that one system holds constituent records, giving history and often payment tokens. Getting its access list, backups and settings right delivers most of the available protection.

A named owner instead of nobody

Most charities this size have no job title that includes privacy. MVP assigns the function, typically to the director of finance and operations, and equips them to hold it.

Consent language on the donation form

What your online giving page promises about use, sharing and anonymity has to match what the development office does afterward. The gap review checks that match before anyone else does.

Volunteer and board access to constituent data

Gala committees, receipting helpers and directors who see prospect lists or financials need access limits appropriate to unpaid, high-turnover roles, not the same login every staff member gets.

A retention clock that starts on day one

Receipt duplicates, screening notes and old spreadsheets accumulate for years with no disposal rule. The baseline sets a first retention schedule against CRA's own floors, giving cleanup a defensible starting point.

Regulatory map

The compliance floor a small charity needs cleared

Before any control gets built, MVP answers the question most charities have never actually resolved: which law, if any, governs the data you hold.

Whether PIPEDA even applies to you

The OPC treats core fundraising, newsletters and donations as non-commercial, so many charities owe no federal privacy duty on their donor file at all. MVP's gap review documents that answer instead of leaving it assumed.

Read our guide →

BC and Alberta PIPA where they reach you

BC's statute covers a not-for-profit's entire activity, while Alberta exempts locally incorporated societies outside commercial dealings but fully covers a federally incorporated charity. The baseline states which regime applies to your organization.

Read our guide →

A minimal Law 25 position for Quebec donors

If any donor, chapter or campaign touches Quebec, the enterprise test likely catches you, starting with naming and publishing a person in charge of personal information, one of MVP's first deliverables.

Primary source →

CRA's retention floor before anything is deleted

Receipt duplicates held two years past year-end and most other books six years, at your Canadian address, set the minimum any privacy-driven retention schedule has to respect.

Primary source →

Imagine Canada's baseline expectations

Where accreditation is the trigger, the Standards Program looks for evidence of donor-privacy practice, not a binder. MVP's policy set is written to match what an applicant actually needs to show.

Primary source →

What goes wrong

What stays exposed without any baseline at all

Organizations that skip a baseline entirely tend to discover the gap the same three ways, none of them pleasant.

  • A vendor notice with nobody ready to read it

    The 2020 Blackbaud incident showed that a fundraising platform's breach becomes the charity's decision to make. Without a baseline, that decision gets made for the first time under pressure.

    Source →

  • A CC mistake nobody had trained against

    Alberta OIPC decisions record guardians and clients exposed by a single mis-sent bulk email. A ten-minute rule about BCC and list sends, part of MVP's training, prevents the sector's most common self-inflicted incident.

    Source →

  • A funder question with no honest answer

    When a contribution agreement's confidentiality clause finally gets read closely, an organization with no policy or retention schedule has nothing to point to, and negotiating from that position weakens every subsequent grant conversation.

  • Wealth-screening data nobody governs

    Prospect research collected without a stated policy is the kind of file that shocks donors if it ever surfaces, whether through a leak or a routine access request.

Our mvp program for charities & foundations

What the MVP year delivers for a charity

The package is fixed and sequenced so the highest-value pieces land first, built around your CRM and your calendar rather than a generic checklist.

Inclusion, tolerance, humanitarian aid and support, multicultural society, discrimination and racism, volunteer team, human rights
  1. Baseline privacy gap review

    A structured look at your donor CRM, receipting workflow, consent language and volunteer access, benchmarked against the statutes and standards that actually apply to your organization, producing a short, ranked list rather than a lengthy audit.

  2. Prioritized control recommendations

    Directional guidance on what to fix first once the which-law question is answered: typically access limits, a retention schedule and a documented consent flow, chosen for impact against limited hours.

  3. Core policy development

    A starter donor privacy statement, a short volunteer confidentiality undertaking and a retention schedule reconciling CRA floors with your accreditation or funder commitments, drafted for your own systems.

  4. Readiness assessment workshops

    Working sessions with the executive director, finance lead and CRM administrator that rehearse the situation that prompted the purchase: a funder clause, a CRM migration or an accreditation review.

  5. Training with ten seats

    Role-appropriate privacy and security training and human-risk assessment for up to ten people, enough to cover most fundraising and finance staff plus a board representative at this size of organization.

  6. Twelve hours of coaching

    Expert time spent wherever the year takes you: a wealth-screening question, a vendor's contract clause, or a funder's due-diligence request as it lands.

How the engagement runs

How the baseline gets built over the term

Setup is deliberately light on your team, and nothing structural is scheduled during the November-to-February giving and receipting freeze.

  1. Step 1

    Intake and the which-law determination

    We confirm which statutes and standards actually apply to your provinces, incorporation and activities, so every later decision starts from a documented answer instead of a guess.

  2. Step 2

    Gap review and a ranked plan

    The CRM, receipting flow and consent language are reviewed against that determination, and the findings become a short list the executive director can approve in one meeting.

  3. Step 3

    Policy drafting and readiness workshops

    Core policies are drafted and refined live with your team, then rehearsed in a workshop built around the funder, CRM or accreditation situation that started the engagement.

  4. Step 4

    Training rollout and coaching close-out

    The ten training seats are delivered by role, and remaining coaching hours handle whatever surfaced mid-year, ending the term with a clear view of what a larger program would add.

What it costs

What MVP costs and what a charity gets for it

Minimum Viable Privacy is $5,499 CAD per year, billed annually on a twelve-month term, and covers the gap review, core policy development, readiness assessment workshops, twelve hours of coaching, and training with human-risk assessments for ten seats. The price is fixed and published, so a treasurer can approve it without a procurement process.

Organizations that outgrow it, typically by opening a Quebec chapter, adding beneficiary programs with case files, or facing recurring funder due diligence, usually move to the Virtual Privacy Office retainer once the MVP year ends, and everything built during MVP carries forward rather than being redone.

Charities & Foundations: MVP program questions, answered

Five things, sized to the organization: a named owner, usually the director of finance and operations; a documented answer to which privacy law applies to your donor and beneficiary data; a short policy set covering donor privacy, volunteer confidentiality and retention; basic CRM access controls; and trained staff and board members. That is what MVP delivers across its term, without a hire or a large consulting budget.

Read the clause first, then work backward: most contribution agreements ask for confidentiality commitments, reasonable safeguards and sometimes a named privacy contact, all of which the MVP baseline produces. The gap review checks your practice against the specific wording in hand, and the readiness workshop rehearses how you would answer the funder's due-diligence questions before the next renewal.

Usually yes for the pieces Imagine Canada actually reviews: a donor privacy policy addressing anonymity and list use, evidence of donor-privacy training, and a retention schedule. The gap review and core policy drafting are sequenced to land early in the term so an accreditation deadline can be met, and the remaining coaching keeps the program current afterward.

For most day-to-day questions, MVP is the whole answer: it names an owner, documents which law applies, and builds the policies and training that owner needs. Where a dispute, a regulator inquiry or a genuinely novel contract term arises, that owner will recognize when to bring in counsel, because the baseline includes understanding your obligations well enough to spot the exception.

Almost always. A statement written years ago typically predates your current CRM and whatever funder clause prompted this question, so it describes practices you no longer follow while missing ones you do. The gap review treats it as a starting draft rather than discarding it, which usually shortens the policy step.

Nothing is wasted. Charities that add a Quebec chapter, take on beneficiary case files or face recurring funder due diligence typically step up to the Virtual Privacy Office, where a designated privacy coach and monthly hours replace the fixed package. Every policy and schedule produced during MVP transfers directly into that retainer.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.