Policy development · Nonprofit
Privacy & Security Policy Development for Charities & Foundations
We draft the policy set a charity genuinely needs: a donor privacy policy that stands up to Imagine Canada scrutiny, a beneficiary confidentiality policy for program teams, volunteer agreements, and a retention schedule that respects CRA floors before anything is deleted. The trigger is usually an accreditation application, a funder asking to see your policies, a Law 25 obligation, or a new CRM that made the old two-paragraph statement obviously inadequate.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
Where written rules protect a charity in practice
Policies earn their keep at the moments staff, volunteers and vendors face a choice about someone's information. We write for those moments, not for a binder.
Promises made on the donation page
What your public privacy statement says about use, sharing and anonymity becomes a commitment the development office must be able to keep, including for in-memoriam gifts and monthly sustainers whose data flows through processors.
The gap between donor and beneficiary worlds
Fundraisers and program staff handle utterly different sensitivities. Written boundaries stop a compelling client story or photo from migrating into an appeal without proper consent.
Volunteers touching real records
Gala committees, drivers, tax-clinic helpers and board members see addresses, giving capacity and case details. A confidentiality agreement gives you something to point to on their first day and something to enforce if trust is broken.
Prospect research within stated limits
A wealth-screening policy defines which sources are acceptable, which fields may be stored and who may view them, so moves management proceeds without secret dossiers the organization cannot defend.
Records kept exactly as long as required
A retention schedule reconciles CRA minimums with privacy maximums across receipts, bequest files, screening profiles, intake forms and vulnerable-sector checks, then assigns disposal to a named role.
Regulatory map
The frameworks your charity's policies must answer to
A charity's policy suite is judged by regulators in some provinces, accreditors everywhere, and the CRA on records, so drafting starts from that overlapping map.
Imagine Canada fundraising standards
Accreditation requires demonstrable donor-privacy commitments, including honouring anonymity requests under Standard C3 and the pledge not to sell donor lists that accredited organizations make alongside the Donor Bill of Rights.
CRA books-and-records floors
Receipt duplicates held two years past year-end, most other records six years, originals at your Canadian address: the retention schedule must encode these before any privacy-driven destruction, because inadequate records risk sanctions up to revocation.
Law 25 governance requirements
A Quebec footprint brings a published person in charge and expectations of documented practices, assessments for new systems, and pre-transfer analysis when data leaves the province, all of which your policies must reflect.
PIPA obligations in BC and Alberta
BC's statute covers a not-for-profit's every activity, and federally incorporated charities in Alberta are covered too, so policies for organizations in those provinces must meet statutory standards on consent, access and safeguards.
CASL rules for what you send
An email policy captures the fundraising exemption's boundaries and the two-year implied-consent window a donation or volunteer role creates, keeping campaigns defensible without silencing them.
What goes wrong
Incidents that trace back to missing policies
Sector breach files read like a catalogue of moments where a written rule, known and followed, would have changed the outcome.
Lists exposed by habit
The Medicine Hat YMCA incident, where guardians' addresses went out in CC, is the canonical case for a bulk-communication rule requiring BCC or platform sends for any list of constituents.
Paper files without a custody rule
Emergency-contact forms stolen in break-ins at Alberta parent societies show what happens when no policy governs where intake paperwork lives overnight and who locks it away.
Departing staff taking the donor file
A development officer moving to another organization may see the prospect list as their rolodex. Confidentiality terms and offboarding rules make clear it is neither theirs nor transferable.
Data hoarded past all justification
Decades of lapsed-donor records and old screening profiles multiply the blast radius of any future compromise, the pattern Blackbaud's stolen backups exposed across the sector. A retention schedule is breach mitigation written in advance.
Our policy development for charities & foundations
The policy suite we draft for a charity or foundation
Deliverables are custom-written from your actual systems and programs, in plain language a volunteer can follow, with the compliance mapping documented for auditors and accreditors.

Donor privacy policy and public statement
Covers collection, use, sharing, anonymity, screening and preferences, versioned for the website and for internal fundraising practice.
Beneficiary confidentiality policy
Rules for intake forms, case notes and storytelling consent at service charities, written with program staff realities in mind.
Volunteer and board confidentiality agreements
Short, enforceable terms for the people your insurer and accreditor most worry about, paired with guidance on when checks and renewals apply.
Retention and destruction schedule
Record-by-record periods reconciling CRA, statutes and operational need, with disposal methods and ownership assigned.
Email and communications policy
CASL consent handling, unsubscribe processing and bulk-send rules embedded into how campaigns actually go out.
Update and approval cycle
A board-ready adoption package and a review calendar, so the suite stays current as laws, platforms and programs change.
How the engagement runs
How drafting works with a lean charity team
The engagement is built around interviews and iteration, not questionnaires left on your desk.
Step 1
Practice discovery
We interview development, programs, finance and key volunteers, and inspect the CRM, forms and current documents to learn what actually happens to information.
Step 2
Gap analysis against your obligations
Existing documents are mapped to the statutes, standards and contracts that bind you, producing a prioritized drafting list.
Step 3
Drafting and working-session review
Policies arrive in plain Canadian English, refined live with the people who must apply them until the rules fit the work.
Step 4
Adoption and rollout support
Board resolutions, website text, staff briefings and volunteer sign-off materials accompany the final suite.
What it costs
What shapes the price of a charity policy suite
The drivers are how many document types you need, whether beneficiary programs add a second sensitivity tier, how many provinces and statutes the mapping must cover, and how much legacy material can be salvaged versus written fresh. A foundation needing a donor policy and retention schedule sits at one end; a multi-program service charity with volunteers, vulnerable-sector checks and a Quebec chapter sits at the other.
After a discovery call we quote a fixed fee for a defined suite, and if a policy you asked for is genuinely unnecessary for your situation, we will say so and price without it.
Charities & Foundations: Policy development questions, answered
It should state plainly what donor information you collect and why, how giving histories and contact preferences are used, that anonymity requests are honoured, and that the organization does not sell donor lists, commitments accredited charities make explicitly. It also needs to be true: the Standards Program looks for evidence of practice, so the policy must match how your CRM, receipting and appeals actually operate, including how third parties like mail houses handle your file.
Usually yes, because the audiences, sensitivities and legal bases differ completely. Donor policy speaks to fundraising ethics, screening and CASL; beneficiary policy governs intake, case notes, storytelling consent and disclosure to authorities, often for people in vulnerable circumstances. One omnibus document tends to serve neither program staff nor fundraisers, though both policies should share definitions, breach procedure and a single retention schedule so the suite stays coherent.
A clear definition of confidential information covering donor, beneficiary and organizational records; a promise to access only what the role requires; rules on personal devices, photography and social media; return-of-materials and post-service survival clauses; and acknowledgment of consequences. Keep it to a page or two so people actually read and sign it, and pair it with a short orientation, since an unexplained signature protects nobody.
One built from different clocks. Receipt duplicates follow the CRA two-years-past-year-end rule and most financial books six years; bequest and planned-giving files typically persist until the gift is realized plus a limitation buffer; vulnerable-sector check results should be confirmed and then minimized quickly, retaining the verification rather than the document where feasible. The schedule assigns each record class a period, a legal basis, a storage location and a destruction owner.
It is your most public compliance artifact, and a stale one misleads donors and undercuts you with accreditors, funders and regulators alike. A decade-old statement predates Law 25, your current CRM and probably your online-giving stack, so it likely describes practices you no longer follow while missing ones you do. Refreshing it is quick once the underlying policy work is done, and it is often the visible proof point a funder or board asks for first.
More for charities & foundations
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.