Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Incident response · Nonprofit

Incident Response Planning for Charities & Foundations

An incident response plan tells your charity exactly who does what in the hours after donor, beneficiary or grantee data goes astray, before panic and guesswork take over. The complication in this sector is that the duty to notify may be statutory in one province, contractual in another, and purely reputational in a third, so the plan has to encode those branches in advance. Most organizations commission one after a vendor notice, a misdirected email or an insurer question exposes that no plan exists.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

Incidents a charity's plan must be written for

Generic corporate playbooks assume employees, servers and a legal team. Your plan needs scenarios drawn from how charity incidents actually unfold.

A vendor breach notice arrives

Your CRM or donation platform reports that backups or records were taken, as Blackbaud did to hundreds of clients in 2020. The plan defines who reads the notice, what questions go back to the vendor, and how exposure is assessed from your own data map.

A misdirected email exposes a list

A newsletter sent with recipients in CC, or a beneficiary roster attached to the wrong message, is the sector's most frequent self-inflicted incident and needs a same-day containment and assessment routine.

A mailbox or tenant compromise

One phished credential can expose years of donor correspondence and receipts. The plan scripts credential resets, forwarding-rule checks, and scoping of what the intruder could read.

Ransomware during a campaign

Encryption of the CRM or file server in late November threatens receipting and program delivery at once. Recovery order, communications and decision authority must be settled before, not during.

Physical loss of program records

Break-ins at Alberta parent societies took paper emergency-contact forms; laptops vanish from event venues. The plan covers paper and devices, not just cloud accounts.

Regulatory map

Notification duties that branch by province and contract

Whether and whom you must notify is the least intuitive part of charity incident response, because the answer depends on jurisdiction, incorporation and even what activity the data served.

Alberta: notice without unreasonable delay

Where Alberta's PIPA applies, a real risk of significant harm requires reporting to the Information and Privacy Commissioner without unreasonable delay, and the commissioner can require individual notification. Federally incorporated charities in Alberta cannot rely on the societies carve-out.

Primary source →

Quebec: the CAI, individuals and a register

Law 25 requires notifying the Commission d'accès à l'information and affected individuals when an incident risks serious injury, and keeping a register of every incident regardless of severity. The plan builds that register into the workflow.

Primary source →

PIPEDA: only where activity was commercial

If the exposed data served commercial activity, list leasing being the classic charity example, federal breach reporting and record-keeping duties can attach. The plan's assessment step asks that question explicitly.

Read our guide →

Contracts and standards fill the statutory gaps

For an Ontario charity outside any statute, contribution-agreement clauses, insurer conditions and Imagine Canada commitments often still compel notice to funders, carriers and donors. The plan inventories these obligations so nobody hunts through agreements mid-incident.

What goes wrong

What goes wrong when charities improvise a response

The damage from sector incidents usually comes less from the initial exposure than from the fumbled weeks that follow it.

  • Silence that curdles donor trust

    The Blackbaud episode showed charities waiting on vendor updates while donors learned of the theft from the news, and the multistate settlement later faulted the vendor's own communications. A plan sets your notification decision points independent of vendor timing.

    Source →

  • Recall attempts that make it worse

    Frantic recall emails after a CC mistake often re-expose the list or confirm its sensitivity. The plan prescribes the correct sequence: contain, assess harm, then communicate once and clearly.

  • Evidence destroyed by cleanup

    An MSP wiping a compromised mailbox before logs are preserved can erase the ability to say what was read, forcing worst-case notification. The plan makes preservation a first-hour task.

  • Missed insurer conditions

    Cyber policies commonly require prompt notice and approved vendors; a well-meaning ED who hires their own forensics firm first can jeopardize coverage. The plan puts the policy's phone number on page one.

Our incident response for charities & foundations

What your charity's response plan will contain

The deliverable is a working document sized for an organization without in-house counsel or IT, plus the artifacts that make it usable under stress.

Group of volunteers in community donation center, food bank and coronavirus concept
  1. Roles mapped to real people

    Incident lead, communications owner, board liaison and MSP contact assigned by name and backup, acknowledging that the same three people wear most hats in a small charity.

  2. A jurisdiction and obligation matrix

    One table answering who must be told, on what legal, contractual or standards basis, and how fast, for each province you operate in and each funder whose agreement carries clauses.

  3. Scenario playbooks

    Step-by-step runbooks for vendor breach, misdirected email, mailbox compromise, ransomware and lost records, each tuned to your systems and season.

  4. Assessment and severity tools

    A harm-assessment worksheet aligned to the real-risk-of-significant-harm and serious-injury thresholds, so decisions are documented and defensible afterwards.

  5. Templates ready to adapt

    Draft notices for donors, program participants, funders, the board and regulators, written in a charity's voice rather than legal boilerplate.

  6. Register and log formats

    Incident register meeting Law 25 expectations and evidence-log forms your MSP can follow, keeping the record straight from hour one.

How the engagement runs

Building and proving the plan with your team

  1. Step 1

    Obligation and asset discovery

    We review where donors, beneficiaries and grantees are located, which statutes and contracts attach, what systems hold the data, and what your insurer requires.

  2. Step 2

    Drafting with the people who will use it

    Working sessions with the ED, finance director and MSP produce a plan that matches your actual phone tree and tooling, not an org chart you do not have.

  3. Step 3

    A tabletop exercise to pressure-test it

    We walk your team through a vendor-breach or CC-incident scenario, timing decisions and exposing gaps while they are free to fix.

  4. Step 4

    Finalization and annual refresh

    The tested plan is issued with a maintenance schedule so contacts, vendors and legal branches stay current as platforms and provinces change.

What it costs

Cost drivers for a charity incident response plan

Effort scales with your obligation map more than your headcount: how many provinces your donors and programs span, whether Quebec duties apply, how many funder agreements carry notice clauses, how many core systems and vendors the playbooks must cover, and whether a tabletop exercise is included. A single-province foundation with two systems is a compact engagement; a national service charity with beneficiary records is not.

We scope it in one conversation and quote a fixed fee, and organizations already inside a Virtual Privacy Office retainer receive incident protocol work as part of that arrangement.

Charities & Foundations: Incident response questions, answered

Perhaps not by statute, but often yes in practice. If your charity operates where BC PIPA, Alberta PIPA or Law 25 reaches you, statutory duties may attach directly. Outside those, look to your contracts, insurer, and accreditation commitments, and weigh litigation and trust risk: donors who learn from journalists rather than from you rarely give again. The 2020 experience showed the charity, not the vendor, owns that decision, which is why your plan should score harm and decide notification on your own timeline.

Contain first: stop any follow-up sends and preserve the message. Assess who received it, how sensitive the exposed fields are, and whether recipients could identify or locate vulnerable clients, a serious consideration for shelter populations. Document the assessment, then decide notification against the statutes and agreements that apply to your program, involve the ED and, where harm is real, notify affected individuals quickly with concrete guidance. Ask recipients in writing to delete, but never resend the list while doing so.

Your designated incident lead, normally the ED or the person your plan names, reports to the commissioner where Alberta PIPA applies and the incident poses a real risk of significant harm. The statute's standard is without unreasonable delay, so the clock starts once your assessment supports the threshold, not when it is convenient. The report describes the incident, the data, the harm analysis and mitigation; the commissioner may then direct you to notify individuals if you have not already.

Check both before you need them. Cyber policies typically condition coverage on prompt notice and use of approved responders, so calling the carrier belongs in the first hours, not after cleanup. Funder agreements vary: many contribution agreements include confidentiality or security clauses that oblige disclosure of incidents touching program data, and staying silent can cost a relationship worth more than the breach itself. Your plan should list each funder clause so the decision is a lookup, not a debate.

Your charity leads; the MSP executes. Decision authority over notification, communications and spending cannot sit with a vendor, so the plan names an internal incident lead and gives the MSP defined technical tasks: isolate, preserve, reset, report. We also pre-agree escalation language in writing with the MSP so evidence preservation happens before remediation, the step most often botched when nobody has said it out loud in advance.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.