The "Nonprofit Exemption" Myth That'll Get You Sued: Which Privacy Laws Apply to Nonprofits?
"We're a nonprofit, so privacy laws don't apply to us."
It's one of the most common (and costly) misconceptions floating around the nonprofit world. And it's easy to see why the myth persists. Many privacy laws do exempt nonprofits. However, several major privacy laws apply to nonprofits just as they would to any for-profit business. Believing the exemption myth doesn't make your organization exempt. It just makes you exposed.
Why This Myth Still Exists in 2026
Privacy laws that apply to nonprofits have been around for over eight years now, so why do so many still think they don't exist? It comes down to three main reasons:
1. Thinking that because many laws exempt nonprofits, all of them do
It is true that many laws exempt nonprofits and that privacy laws pull inspiration from one another. So, it may be natural to see two or three laws all exempt nonprofits in the same way and assume others do as well.
Unfortunately, privacy laws are not interchangeable. Each law has its own:
Definitions;- Scope;
- Applicable thresholds;
- Compliance requirements;
- Consumer rights;
- Enforcement; and
- Exemptions.
This means that one law may broadly exempt nonprofit organizations. Another may exempt only certain categories of nonprofits. A third may not contain a nonprofit exemption at all.
2. Thinking the law's location is all that matters
Privacy laws are often named after the state and/or country in which they were created. This makes sense, but it causes confusion for nonprofit and business owners alike as to which laws apply to them.
For example, a nonprofit in Ohio may see "California" in a privacy law and immediately dismiss it as irrelevant. It happens all the time. Unfortunately, that's not how privacy laws work.
Privacy laws are designed to protect people who live in a particular state, province, or country. As a result, an organization located somewhere else may still need to comply with that law when it collects information from residents of that jurisdiction. This means that if someone from California can visit your site and send a donation, fill out your contact form, or subscribe to your email newsletters, you may need to comply with certain California privacy laws.
3. Thinking that sharing and selling data are the same thing
Many nonprofit leaders believe that because they don't "sell" donor or supporter data, they're automatically off the hook. Selling data is actually pretty rare for nonprofits, but most privacy laws focus on the collection, use, and sharing of personal data.
Examples of selling data might be:
Selling your donor email addresses to a data broker for money; or- Swapping your donor list for something else of value (i.e., another donor list).
Examples of sharing data might be:
Using Google Analytics on your website, which shares user IP addresses with Google;- Using an email service provider like MailChimp, which shares email addresses with MailChimp to send out your newsletter;
- Using an online payment system like Stripe, which shares names, phone numbers, emails, addresses, and payment information with a third-party provider (Stripe).
Why This Myth Is Dangerous
Here's what makes this myth so costly: ignorance doesn't excuse the penalties.
If a privacy law applies to your nonprofit and you're not compliant, it doesn't matter whether you believed you were exempt. You may still have to deal with:
Fines – Many privacy laws impose fines starting at $2,500 to $7,500 per violation. A "violation" is usually each website visitor whose rights are infringed upon. If just a handful of out-of-state donors submit a form on a non-compliant page, the penalties can quickly add up.- Loss of Donor Trust – Nonprofits survive on trust and credibility. Being named in a privacy lawsuit, receiving an enforcement letter from a state Attorney General, or suffering a donor data breach damages donor relationships that take decades to build.
Which Privacy Laws Actually Apply to Nonprofits?
A nonprofit's privacy and website practices do impact which privacy laws apply to it. One nonprofit may need to comply with different laws than another nonprofit. That's why it's so important to avoid generic templates and find a Privacy Policy Generator or an attorney who can create policies specifically for your nonprofit's needs.
That being said, there are several privacy laws that specifically say that nonprofits are not exempt simply because they are a nonprofit organization. Those laws include:
General Data Protection Regulation (GDPR)
You need to comply with GDPR if you:
Are located in the European Union;- Offer goods or services, regardless of payment, to European Union data subjects, regardless of where your nonprofit is actually located; or
- Monitor the behavior of European Union residents, regardless of where your nonprofit is actually located.
U.K. Data Protection Act (UK DPA)
You need to comply with the UK DPA if you:
- Are located in the United Kingdom;
- Offer goods or services, regardless of payment, to United Kingdom data subjects, regardless of where your nonprofit is actually located; or
- Monitor the behavior of United Kingdom residents, regardless of where your nonprofit is actually located.
Quebec Law 25
You need to comply with Quebec Law 25 (formerly Quebec Bill 64) if you:
Collect, hold, use, or share personal information in the course of carrying on an enterprise within the meaning of Article 1525 of the Civil Code.
California Online Privacy Protection Act of 2003 (CalOPPA)
You need to comply with CalOPPA if you:
Promote business activities unrelated to the nonprofit;- Include paid advertising; or
- Solicit new members who may receive a commercial benefit not related to your nonprofit's exempt purpose in return for their dues.
California Invasion of Privacy Act (CIPA)
You need to comply with CIPA if you:
Track California residents using tracking technology (Google Analytics, chatbots, advertising pixels, etc.).
Nevada Revised Statutes Chapter 603A
You need to comply with Nevada Revised Statutes Chapter 603A if you:
Own and operate a website or online service;- Collect and maintain the personal information of consumers who reside in Nevada and use or visit the website or online service; and
- Purposefully direct your activities toward Nevada, consummate a transaction with the state of Nevada or a resident of Nevada, purposefully avail yourself of the privilege of conducting activities in Nevada, or otherwise engage in any activity that constitutes sufficient nexus with Nevada to satisfy the requirements of the U.S. Constitution.
There are also a couple of laws that exempt some, but not all, nonprofits. These are:
Delaware Personal Data Privacy Act (DPDPA) – Exempts nonprofits that provide services to victims of or witnesses to child abuse, domestic violence, human trafficking, sexual assault, violent felonies, or stalking. Nonprofits working in other areas aren't exempt.
Oregon Consumer Privacy Act – Exempts nonprofits established to detect or prevent fraudulent acts related to insurance, and nonprofits that provide programming to radio or television networks. Nonprofits working in other areas aren’t exempt.
How Should Nonprofits Address These Laws?
The patchwork of global and state privacy laws changes constantly, and navigating them can be tricky.
To bring your nonprofit into compliance, you've got a few options.
Option 1: Audit your website and remove all personal data – Okay, this may not be entirely applicable, as collecting some user data is typically considered essential to operating most nonprofits. That being said, limiting how much data you collect is always a good practice. Audit your website, see what data you're collecting, sharing, and storing, and then get rid of any data you don't actively use (think an old Facebook Pixel from last year's ad campaign).
Option 2: Hire a specialized privacy attorney –
A reliable choice for custom, direct legal counsel and advice, but not always affordable for smaller or growing nonprofits.
Option 3: Use an auto-updating Privacy Policy Generator like Termageddon –
Termageddon asks targeted questions about your nonprofit's exact tools and data practices to build customized policies and a cookie consent tool. When privacy laws change, your website's policies update automatically, keeping your nonprofit protected without you having to worry.
The Bottom Line
The "nonprofit exemption" isn't a myth; it's an incomplete truth. Some privacy laws do exempt nonprofits. But plenty of others don't, and the ones that do are often narrower than you'd think. The safest assumption isn't "we're exempt" it's "we need to find out which laws apply to us."
Your nonprofit exists to make a difference. A privacy law violation shouldn't be what eats your budget or damages the trust you've worked to build. Take the time to understand what applies to your organization, and get a Privacy Policy that actually keeps up with the law.










