How Nonprofits Collect Personal Data (and What That Means for Compliance)
Good news, nonprofits. Many privacy laws don’t apply to you! Unfortunately, that’s where many nonprofits tune out the rest of the story – a bad idea that could lead to hefty fines and lawsuits for your nonprofit.
The truth is, modern nonprofits almost certainly collect personal data, and there are several
privacy laws that require even nonprofits to take certain steps to ensure that data is handled with respect for the individuals it belongs to.
When nonprofit leaders think about personal data, donor information may be the first thing that comes to mind. But nonprofits often collect personal data from many other people, including volunteers, members, event attendees, newsletter subscribers, and website visitors.
Some of this information is collected more directly. Other data may be collected automatically by the nonprofit’s website and the third-party tools connected to it. We will get into examples of both later on.
Understanding where personal data comes from is an important first step toward protecting the data of your users and meeting all your compliance obligations.
What is personal data?
Personal data is information that identifies an individual or can be linked to an identifiable individual. Depending on the privacy law, it may also be called “personal information” or “personally identifiable information (PII).”
Many nonprofits think personal data is the same thing as sensitive data, but it is not. It is actually rare for a website to collect sensitive data like:
- Health information;
- Social Security Numbers;
- Information about children; and
- Financial information.
However, it is extremely common for websites to collect non-sensitive personal data, such as:
- Names;
- Email addresses;
- Physical addresses;
- Phone numbers;
- IP addresses; and
- Payment information.
Like sensitive data, personal data is also protected by several different laws. Simply collecting any of these could open up your nonprofit to having to comply with numerous privacy laws.
Common Ways Nonprofits Collect Personal Data
Nonprofit websites typically collect personal data directly and automatically. From a privacy compliance standpoint, it doesn’t really matter which method is used, but many nonprofits think if a user provides their data willingly (directly), then no privacy laws apply. This is not the case. Both may require you to comply with privacy laws.
With that said, here are some of the most common ways personal data gets collected through a nonprofit's website:
Direct methods:
Donation forms – Collecting payment information for one-time or recurring donations means handling payment information, names, email addresses, and phone numbers.- Contact forms – When someone fills out a "Contact Us" or inquiry form, they're typically submitting their name, phone number, and email address.
- Newsletter sign-ups – Capturing names and email addresses to keep supporters informed is a standard practice for most nonprofits.
- Volunteer or membership applications – These often collect detailed personal data, including names, addresses, and phone numbers.
- Event registrations – Online event sign-ups typically collect names, contact information, and sometimes payment details.
Automatic methods:
Analytics tools – Tools like Google Analytics collect IP addresses from every visitor to your site – often without visitors ever providing consent (i.e., no proper consent solution in place).- Security tools – reCAPTCHA and other security tools automatically collect IP addresses as well to help keep your site secure.
- Embedded videos – YouTube and Vimeo embeds can share users’ IP addresses with Google and Vimeo.
- Scheduling tools – Tools to schedule appointments, like Calendly, can automatically share people’s email addresses and names with the third-party scheduling tool you’re using.
- Donation tools – DonorBox, Fundraise Up, and Bloomerang will automatically share a donor’s information with those third parties upon being used.
Why This Matters for Nonprofits
A common misconception is that nonprofits are exempt from privacy laws. While some laws do carve out exceptions for certain types of nonprofits, many privacy laws apply to nonprofits just as they do to for-profit businesses.
This is especially important to understand because privacy laws are designed to protect people, not organizations. That means the
laws of a particular state or country can apply to your nonprofit even if you're not based there. Collecting even a single email address from a resident of a given state or country could require your organization to comply with that jurisdiction's privacy law.
So, What privacy laws apply to nonprofits?
Here are some of the privacy laws that can apply to nonprofits:
- GDPR (General Data Protection Regulation) – Applies if your nonprofit serves or monitors the behavior of European Union residents, regardless of where your organization is located.
- UK Data Protection Act (UK DPA) – Similar to GDPR, this applies to nonprofits that serve or monitor residents of the United Kingdom.
- Quebec Law 25 – Applies to any organization participating in an economic activity in Quebec (including nonprofits).
- CalOPPA (California Online Privacy Protection Act) – May apply to nonprofits whose websites include paid advertising, promote unrelated business activities, or solicit members who receive commercial benefits.
- Nevada Revised Statutes Chapter 603A – Applies to operators of websites that collect personal data from Nevada residents, and does not explicitly exempt nonprofits.
Some laws do provide partial exemptions for certain nonprofits. For example:
Delaware Personal Data Privacy Act (DPDPA) – exempts nonprofits that provide services to victims of child abuse, domestic violence, human trafficking, sexual assault, or stalking, but not other nonprofits.- Oregon Consumer Privacy Act – exempts nonprofits involved in detecting insurance fraud or providing radio/television programming –but again, not all nonprofits.
Failing to comply with these laws could result in fines or lawsuits. In fact, most fines start at $2,500 per violation (i.e., per website visitor). As you can imagine, this can add up quickly and result in a huge penalty for a nonprofit to overcome.
What Should Your Nonprofit Do About These Laws?
Understanding how your nonprofit collects personal data and that the data is protected by privacy laws are critical first steps. Once you have that picture, you can take the right steps to protect your organization and your website users.
Here's where to start:
Audit your data collection points. Walk through your website and identify every place where personal information is collected (i.e., forms, donation pages, sign-up forms, and even the analytics tools running in the background). If any of these are no longer being used, remove them from your site.
Understand which privacy laws apply to you. Based on where your supporters, donors, and volunteers are located, different laws may apply. Don't assume your location is the only factor. The best way to do this is through an attorney, but certain
Privacy Policy Generators can also help you identify which laws apply.
Get a Privacy Policy in place. A Privacy Policy isn't just a legal formality, but it's how you communicate to your community what data you collect, why you collect it, and how you protect it. It’s required by every privacy law that applies to nonprofits and each law requires different disclosures to be listed within that Privacy Policy.
Once more, finding a privacy attorney that specializes in this is your best option. Attorneys can give legal advice tailored toward your nonprofit.
For nonprofits looking for a more affordable option, a Privacy Policy generator is a great option. For this article, we partnered with Termageddon. Termageddon generates comprehensive, auto-updating policies for $12/month or $119/year, and automatically updates your policy as laws change.
Conclusion
There’s nothing wrong with collecting data. Most nonprofits rely on collecting at least a little personal data to operate smoothly.
Nonprofits do incredible work and protecting the personal data of the people who support that work (your website users) should be just a part of the process.
By reading this article, you’ve already taken the crucial first steps to doing just that.










