By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 26, 2026
Quick Answer
Nonprofits and NGOs that collect donor data that attackers value, beneficiary information, or personal records from supporters face privacy obligations that vary by jurisdiction and the nationality of the individuals whose data is held. PIPEDA applies to most Canadian charities. GDPR applies when donors or beneficiaries are in the EU or UK. Some US state privacy laws apply when fundraising from residents of the states that do not exempt nonprofits. Understanding which frameworks apply to your organization is the starting point for a nonprofit donor data privacy programme that satisfies them all.
Key Takeaways
- PIPEDA applies to commercial activities of nonprofits in Canada, which includes most donor relationships and many beneficiary services, and requires protection of personal information with appropriate safeguards.
- GDPR applies to any nonprofit that collects personal data from individuals in the EU or UK, regardless of where the organization is based, and carries significant penalty exposure for non-compliance.
- US state privacy laws treat nonprofits inconsistently: California’s CCPA/CPRA and most state laws exempt nonprofits, but a growing subset (Colorado, Delaware, Maryland, Minnesota, New Jersey, Oregon) can cover them, and state breach-notification laws apply regardless.
- Quebec Law 25 adds requirements for nonprofits with Quebec data, including a designated privacy officer, privacy impact assessments, a public privacy policy, and prompt reporting of confidentiality incidents to the regulator.
- A single privacy programme built around the strictest applicable standard satisfies the majority of overlapping jurisdictional requirements without maintaining separate compliance tracks.
Does Privacy Law Apply to Nonprofits?
A common misconception in the nonprofit sector is that privacy law applies primarily to commercial businesses and that charitable organizations operate in a different regulatory space. This is not accurate. Privacy law in Canada, the EU, the UK, and a number of US states applies based on the activities of the organization and the personal information it holds, not solely its tax status.
PIPEDA defines commercial activity broadly to include any transaction, act, or conduct of a commercial character. The Office of the Privacy Commissioner of Canada has confirmed that many nonprofit activities, including fundraising, membership programmes, and donor relationship management, constitute commercial activities subject to PIPEDA. Organizations that assumed their charitable status exempted them from privacy law obligations have been corrected by the OPC in the course of investigations.
The treatment differs by regime. GDPR has no nonprofit exemption at all: it applies based on whether the organization processes personal data of individuals in the covered jurisdiction, so a Canadian charity that fundraises from UK donors, or a US NGO that processes personal data of EU beneficiaries, is subject to GDPR regardless of its nonprofit status. US state privacy laws are more varied: most exempt nonprofits at the entity level, but a growing minority do not. The result is that a nonprofit usually has to check each framework against its own activities rather than assume any of them simply does not apply.
PIPEDA: Canadian Federal Privacy Requirements
The Personal Information Protection and Electronic Documents Act applies to private-sector organizations in Canada that collect, use, or disclose personal information in the course of commercial activities. For most nonprofits, this includes donor personal information collected for fundraising, gift processing, and donor relationship management.
PIPEDA requires organizations to: obtain meaningful consent for the collection, use, and disclosure of personal information; limit collection to what is necessary for the identified purpose; protect personal information with safeguards appropriate to its sensitivity; retain information only as long as necessary; and notify the Privacy Commissioner of Canada and affected individuals of material privacy breaches.
The notification obligation is particularly relevant for nonprofits. A breach of a donor database that exposes names, contact information, giving histories, and payment details is likely a material breach under PIPEDA’s real risk of significant harm standard. The notification must be made as soon as feasible, which requires having a breach response plan in place before an incident occurs. Many nonprofit organizations have not documented this plan, which creates both a compliance gap and a practical response problem when an incident happens.
Quebec Law 25: Additional Requirements for Quebec Operations
Quebec’s Act Respecting the Protection of Personal Information in the Private Sector, as modernized by Law 25, applies to nonprofits with Quebec donors, beneficiaries, staff, or operations. Law 25 imposes requirements beyond PIPEDA in several important respects.
Organizations subject to Law 25 must designate a person responsible for personal information protection, which by default is the person with the highest authority in the organization unless the role is formally delegated. They must conduct privacy impact assessments before implementing new technology projects that involve personal information. They must maintain a privacy policy that is publicly accessible. And where a confidentiality incident presents a risk of serious injury, they must report it to the Commission d’accès à l’information and to affected individuals promptly, and maintain a register of confidentiality incidents. Law 25 does not set a fixed number of hours for reporting; the standard is prompt notification once the risk is identified, similar in practice to PIPEDA’s as-soon-as-feasible standard.
Quebec-based nonprofits and organizations with significant Quebec donor or beneficiary populations have needed to assess their Law 25 obligations since the phased implementation began in 2022. Organizations that have not yet completed this assessment are operating with an unaddressed compliance gap.
GDPR: When It Applies to Nonprofits Outside the EU
The General Data Protection Regulation applies to any organization that offers goods or services to individuals in the EU, or that monitors the behaviour of individuals in the EU, regardless of where the organization is established. For nonprofits, this means GDPR applies when fundraising from EU donors, when maintaining contact with EU supporters, or when operating programmes that serve EU residents or collect data from them.
A Canadian charity with a significant number of UK or EU donors, or an international NGO with programme operations in European countries, is processing personal data subject to GDPR. The obligations include a lawful basis for processing each category of personal data, clear and accessible privacy notices, documented data subject rights including the right to erasure and the right to data portability, data transfer restrictions for personal data leaving the EU, and breach notification to the applicable supervisory authority within 72 hours of becoming aware of the breach.
The penalty structure of GDPR is designed to be significant relative to an organization’s size. Fines of up to 4% of annual global turnover or 20 million euros, whichever is greater, are the maximum for the most serious violations. While enforcement against small nonprofits for technical violations is less common than against large commercial organizations, an organization that experiences a breach and cannot demonstrate GDPR compliance faces enforcement exposure that can be existential for a small NGO.
Post-Brexit, the UK has its own data protection regime under the UK GDPR and the Data Protection Act 2018, which closely parallels EU GDPR in its requirements. Nonprofits with UK donors or operations face both regimes where applicable.
US State Privacy Laws: A Growing Patchwork
The United States has no federal comprehensive privacy law, but around 20 states have enacted their own, and they treat nonprofits inconsistently. Most exempt nonprofits at the entity level. California’s CCPA and CPRA apply only to for-profit “businesses,” so a standalone nonprofit generally falls outside them unless it shares branding or common control with a covered for-profit. Virginia, Connecticut, Texas, Utah, and several other states also exempt nonprofits, often keyed to federal tax-exempt status.
A growing subset of states does cover nonprofits. Colorado and New Jersey have no nonprofit exemption, so any entity meeting the processing thresholds is in scope. Delaware, Maryland, Minnesota, and Oregon exempt only narrow categories, such as certain insurance-fraud-prevention organizations, which means most nonprofits operating there are covered if they meet the thresholds. A nonprofit that fundraises nationally, maintains a large donor database, or runs programmes serving residents of several states needs to assess which of these state laws reach its specific processing, rather than assume a blanket exemption.
Separately from the comprehensive privacy laws, state breach-notification laws apply to nonprofits regardless of whether a comprehensive law covers them. Nearly every state requires notification to affected individuals, and in many cases to the state attorney general, when personal information is accessed without authorization. A nonprofit that is exempt from a state’s comprehensive privacy law can still have a mandatory breach-notification obligation in that same state.
What Does a Nonprofit Privacy Programme Look Like in Practice?
A privacy programme for a nonprofit begins with a data inventory that identifies what personal information is collected, from whom, for what purposes, where it is stored, who has access, and how long it is retained. This inventory is the foundation for assessing which privacy laws apply and what obligations they impose.
The programme then addresses the common requirements across applicable frameworks: privacy notices that accurately describe the organization’s data practices, consent mechanisms that meet the requirements of each applicable jurisdiction, access controls that limit personal data to staff with a genuine need, data retention schedules that do not keep donor or beneficiary records longer than necessary, breach detection and response procedures, and a process for handling data subject requests including access, correction, and deletion.
Armour Cybersecurity’s Privacy Risk Management service builds this programme for nonprofits as part of its nonprofit cybersecurity services, calibrated to the jurisdictions where the organization operates and fundraises. It addresses PIPEDA, Quebec Law 25, GDPR, and applicable US state requirements from a shared control framework, avoiding the duplication of building separate compliance tracks for each jurisdiction.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the nonprofits that handle donor privacy well never treat it as four separate legal problems. They inventory the donor, beneficiary, and volunteer data they actually hold, map it once to the strictest standard that touches it, usually GDPR for consent and data-subject rights and Law 25 for its documentation duties, and build a single set of controls, one privacy notice framework, one consent model, one retention schedule, one breach-response plan that knows the notification clock in every jurisdiction, so a UK donor, a Quebec beneficiary, and a Colorado supporter are all covered by the same programme rather than by paperwork nobody maintains.
Frequently Asked Questions
Does PIPEDA apply if our nonprofit does not charge for services?
The OPC’s interpretation of commercial activity under PIPEDA includes fundraising activities regardless of whether services are provided for a fee. Soliciting donations, managing donor relationships, and processing gift payments are treated as commercial activities. Nonprofits that collect personal information in connection with these activities are subject to PIPEDA for that information. Beneficiary service delivery that does not involve a commercial transaction may fall outside PIPEDA but may still be subject to provincial privacy legislation or GDPR depending on the population served.
How do we handle EU donor data under GDPR if we are a Canadian organization?
A Canadian organization subject to GDPR for its EU donor data must identify a lawful basis for processing each category of personal data, most commonly legitimate interests or explicit consent. It must provide a GDPR-compliant privacy notice to EU donors. It must address data transfer requirements when EU personal data is processed outside the EU, which for transfers to Canada can rely on Canada’s adequacy status. Armour’s privacy programme addresses these requirements as part of the cross-jurisdictional framework.
What is the breach notification timeline for nonprofits?
Under PIPEDA, notification to the Privacy Commissioner and affected individuals must be made as soon as feasible after the organization determines that a breach creates a real risk of significant harm, which in practice means days to weeks. Under Quebec Law 25, there is no fixed deadline: a confidentiality incident that presents a risk of serious injury must be reported to the Commission d’accès à l’information and affected individuals promptly, and the organization must keep a register of confidentiality incidents. Under GDPR, supervisory-authority notification is required within 72 hours of becoming aware of a breach. US state breach-notification laws vary but typically require notification within roughly 30 to 90 days. A breach response plan that identifies the notification obligations by jurisdiction, with contacts and template communications for each, is essential for meeting these timelines.
Do volunteers have the same privacy rights as staff under these laws?
Volunteer personal information is generally subject to the same privacy law protections as employee information. The scope depends on the specific law and how volunteer data is used, but organizations that hold volunteer records including contact information, skills, availability, criminal record check results, and service histories should include volunteer data in their privacy programme alongside donor and beneficiary records.
The Bottom Line
Donor data privacy is not one obligation but several that overlap, and the mistake that gets nonprofits into trouble is assuming charitable status is a general exemption. It is not. PIPEDA treats fundraising and donor management as commercial activity; Quebec Law 25 layers on a privacy officer, impact assessments, a public policy, and prompt confidentiality-incident reporting; GDPR reaches any organization with EU or UK donors and backs it with fines large enough to threaten a small NGO; and while most US state laws exempt nonprofits, a growing set does not, and breach-notification duties apply either way. The efficient answer is not four compliance programmes but one, built to the strictest standard that touches the data and mapped down from there. Armour Cybersecurity helps nonprofits and NGOs build nonprofit cybersecurity services and privacy programmes that satisfy PIPEDA, Quebec Law 25, GDPR, and applicable US state requirements from a single framework, so protecting supporter data is something the organization can actually maintain rather than a set of obligations it discovers only after a breach.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



