Incident response · Nonprofit
Incident Response Planning for Charities & Foundations
An incident response plan tells your charity exactly who does what in the hours after donor, beneficiary or grantee data goes astray, before panic and guesswork take over. The complication in this sector is that the duty to notify may be statutory in one province, contractual in another, and purely reputational in a third, so the plan has to encode those branches in advance. Most organizations commission one after a vendor notice, a misdirected email or an insurer question exposes that no plan exists.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
Incidents a charity's plan must be written for
Generic corporate playbooks assume employees, servers and a legal team. Your plan needs scenarios drawn from how charity incidents actually unfold.
A vendor breach notice arrives
Your CRM or donation platform reports that backups or records were taken, as Blackbaud did to hundreds of clients in 2020. The plan defines who reads the notice, what questions go back to the vendor, and how exposure is assessed from your own data map.
A misdirected email exposes a list
A newsletter sent with recipients in CC, or a beneficiary roster attached to the wrong message, is the sector's most frequent self-inflicted incident and needs a same-day containment and assessment routine.
A mailbox or tenant compromise
One phished credential can expose years of donor correspondence and receipts. The plan scripts credential resets, forwarding-rule checks, and scoping of what the intruder could read.
Ransomware during a campaign
Encryption of the CRM or file server in late November threatens receipting and program delivery at once. Recovery order, communications and decision authority must be settled before, not during.
Physical loss of program records
Break-ins at Alberta parent societies took paper emergency-contact forms; laptops vanish from event venues. The plan covers paper and devices, not just cloud accounts.
Regulatory map
Notification duties that branch by province and contract
Whether and whom you must notify is the least intuitive part of charity incident response, because the answer depends on jurisdiction, incorporation and even what activity the data served.
Alberta: notice without unreasonable delay
Where Alberta's PIPA applies, a real risk of significant harm requires reporting to the Information and Privacy Commissioner without unreasonable delay, and the commissioner can require individual notification. Federally incorporated charities in Alberta cannot rely on the societies carve-out.
Quebec: the CAI, individuals and a register
Law 25 requires notifying the Commission d'accès à l'information and affected individuals when an incident risks serious injury, and keeping a register of every incident regardless of severity. The plan builds that register into the workflow.
PIPEDA: only where activity was commercial
If the exposed data served commercial activity, list leasing being the classic charity example, federal breach reporting and record-keeping duties can attach. The plan's assessment step asks that question explicitly.
Contracts and standards fill the statutory gaps
For an Ontario charity outside any statute, contribution-agreement clauses, insurer conditions and Imagine Canada commitments often still compel notice to funders, carriers and donors. The plan inventories these obligations so nobody hunts through agreements mid-incident.
What goes wrong
What goes wrong when charities improvise a response
The damage from sector incidents usually comes less from the initial exposure than from the fumbled weeks that follow it.
Silence that curdles donor trust
The Blackbaud episode showed charities waiting on vendor updates while donors learned of the theft from the news, and the multistate settlement later faulted the vendor's own communications. A plan sets your notification decision points independent of vendor timing.
Recall attempts that make it worse
Frantic recall emails after a CC mistake often re-expose the list or confirm its sensitivity. The plan prescribes the correct sequence: contain, assess harm, then communicate once and clearly.
Evidence destroyed by cleanup
An MSP wiping a compromised mailbox before logs are preserved can erase the ability to say what was read, forcing worst-case notification. The plan makes preservation a first-hour task.
Missed insurer conditions
Cyber policies commonly require prompt notice and approved vendors; a well-meaning ED who hires their own forensics firm first can jeopardize coverage. The plan puts the policy's phone number on page one.
Our incident response for charities & foundations
What your charity's response plan will contain
The deliverable is a working document sized for an organization without in-house counsel or IT, plus the artifacts that make it usable under stress.

Roles mapped to real people
Incident lead, communications owner, board liaison and MSP contact assigned by name and backup, acknowledging that the same three people wear most hats in a small charity.
A jurisdiction and obligation matrix
One table answering who must be told, on what legal, contractual or standards basis, and how fast, for each province you operate in and each funder whose agreement carries clauses.
Scenario playbooks
Step-by-step runbooks for vendor breach, misdirected email, mailbox compromise, ransomware and lost records, each tuned to your systems and season.
Assessment and severity tools
A harm-assessment worksheet aligned to the real-risk-of-significant-harm and serious-injury thresholds, so decisions are documented and defensible afterwards.
Templates ready to adapt
Draft notices for donors, program participants, funders, the board and regulators, written in a charity's voice rather than legal boilerplate.
Register and log formats
Incident register meeting Law 25 expectations and evidence-log forms your MSP can follow, keeping the record straight from hour one.
How the engagement runs
Building and proving the plan with your team
Step 1
Obligation and asset discovery
We review where donors, beneficiaries and grantees are located, which statutes and contracts attach, what systems hold the data, and what your insurer requires.
Step 2
Drafting with the people who will use it
Working sessions with the ED, finance director and MSP produce a plan that matches your actual phone tree and tooling, not an org chart you do not have.
Step 3
A tabletop exercise to pressure-test it
We walk your team through a vendor-breach or CC-incident scenario, timing decisions and exposing gaps while they are free to fix.
Step 4
Finalization and annual refresh
The tested plan is issued with a maintenance schedule so contacts, vendors and legal branches stay current as platforms and provinces change.
What it costs
Cost drivers for a charity incident response plan
Effort scales with your obligation map more than your headcount: how many provinces your donors and programs span, whether Quebec duties apply, how many funder agreements carry notice clauses, how many core systems and vendors the playbooks must cover, and whether a tabletop exercise is included. A single-province foundation with two systems is a compact engagement; a national service charity with beneficiary records is not.
We scope it in one conversation and quote a fixed fee, and organizations already inside a Virtual Privacy Office retainer receive incident protocol work as part of that arrangement.
Charities & Foundations: Incident response questions, answered
Perhaps not by statute, but often yes in practice. If your charity operates where BC PIPA, Alberta PIPA or Law 25 reaches you, statutory duties may attach directly. Outside those, look to your contracts, insurer, and accreditation commitments, and weigh litigation and trust risk: donors who learn from journalists rather than from you rarely give again. The 2020 experience showed the charity, not the vendor, owns that decision, which is why your plan should score harm and decide notification on your own timeline.
Contain first: stop any follow-up sends and preserve the message. Assess who received it, how sensitive the exposed fields are, and whether recipients could identify or locate vulnerable clients, a serious consideration for shelter populations. Document the assessment, then decide notification against the statutes and agreements that apply to your program, involve the ED and, where harm is real, notify affected individuals quickly with concrete guidance. Ask recipients in writing to delete, but never resend the list while doing so.
Your designated incident lead, normally the ED or the person your plan names, reports to the commissioner where Alberta PIPA applies and the incident poses a real risk of significant harm. The statute's standard is without unreasonable delay, so the clock starts once your assessment supports the threshold, not when it is convenient. The report describes the incident, the data, the harm analysis and mitigation; the commissioner may then direct you to notify individuals if you have not already.
Check both before you need them. Cyber policies typically condition coverage on prompt notice and use of approved responders, so calling the carrier belongs in the first hours, not after cleanup. Funder agreements vary: many contribution agreements include confidentiality or security clauses that oblige disclosure of incidents touching program data, and staying silent can cost a relationship worth more than the breach itself. Your plan should list each funder clause so the decision is a lookup, not a debate.
Your charity leads; the MSP executes. Decision authority over notification, communications and spending cannot sit with a vendor, so the plan names an internal incident lead and gives the MSP defined technical tasks: isolate, preserve, reset, report. We also pre-agree escalation language in writing with the MSP so evidence preservation happens before remediation, the step most often botched when nobody has said it out loud in advance.
More for charities & foundations
Other services for this niche
About this service
Answers & guides
- Do you need an incident response plan, and what should it include?
- What should I do after a data breach?
- When should you hire a privacy breach response consultant?
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- Writing an Incident Response Plan Your Team Will Actually Use
- PIPEDA Breach Notification and Record-Keeping: What to Get Right
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.