Skip to content
  • Home
  • Services
    • Audit & Attest
      • Financial Statement Audits
      • Employee Benefit Plans
      • Attestation Engagements
      • Compilations & Review
      • SOC
      • Agreed-Upon Procedures
    • Advisory
      • Transaction Advisory Services
      • Cybersecurity, Technology Risk, Privacy
      • High Net Worth Services
      • Forensic Services
      • Litigation Services
      • Management Consulting
      • Technology Services
      • Valuation Services
    • Business & Tax
      • Corporate Income Tax
      • Individual Income Tax
      • International Tax
      • State and Local Tax Compliance and Tax Minimization Services
      • Tax Planning
    • T&C Family Office Group
  • Industries
    • Construction & Real Estate
    • Healthcare
    • Manufacturing & Distribution
    • Nonprofit Organizations
    • Private Equity Firms
    • Privately-held Companies
    • Technology & Energy
  • Firm
    • Overview
    • Our People
    • Our Community
    • Templeton Group
      • PracticePro 365
      • T&C Family Office Group
      • Templeton Investigative Services
  • Careers
    • Experienced
    • Students
    • Benefits
  • News
  • Pay My Bill
  • Home
  • Services
    • Audit & Attest
      • Financial Statement Audits
      • Employee Benefit Plans
      • Attestation Engagements
      • Compilations & Review
      • SOC
      • Agreed-Upon Procedures
    • Advisory
      • Transaction Advisory Services
      • Cybersecurity, Technology Risk, Privacy
      • High Net Worth Services
      • Forensic Services
      • Litigation Services
      • Management Consulting
      • Technology Services
      • Valuation Services
    • Business & Tax
      • Corporate Income Tax
      • Individual Income Tax
      • International Tax
      • State and Local Tax Compliance and Tax Minimization Services
      • Tax Planning
    • T&C Family Office Group
  • Industries
    • Construction & Real Estate
    • Healthcare
    • Manufacturing & Distribution
    • Nonprofit Organizations
    • Private Equity Firms
    • Privately-held Companies
    • Technology & Energy
  • Firm
    • Overview
    • Our People
    • Our Community
    • Templeton Group
      • PracticePro 365
      • T&C Family Office Group
      • Templeton Investigative Services
  • Careers
    • Experienced
    • Students
    • Benefits
  • News
  • Pay My Bill
CONTACT US

“Privacy, please” when your nonprofit stores sensitive data

  • Audit & Attest, Blog, Nonprofit

How well does your nonprofit protect the privacy of donors, staffers, clients and volunteers? It’s an important question because failure to protect personal data can expose your organization to costly lawsuits, regulatory fines and reputational damage.

Initial assessment

There are two main types of risks associated with inadequately protected personal data. One is cybercriminals hacking your IT network and stealing data to perpetrate identity theft or other fraud. Another is dishonest employees or contractors having inappropriate access to data such as donors’ credit card numbers or colleagues’ HR records. At a minimum, you must protect against these threats. Depending on your mission, you may need to safeguard additional sensitive personal information.

Start by reviewing your current operating practices to understand how, where and why personal data is collected, used, disclosed and retained. A thorough review that includes HR and IT managers should highlight ways you may be putting information at risk. For example:

  • Are you retaining unnecessary or outdated personal data?
  • Are you adequately restricting access to confidential details, such as the financial information of supporters or medical records of patients (in the case of a health care charity)?
  • Do you store both physical and digital data in a secure location and properly dispose of them when you should?

Answers to such questions can help you identify areas for improvement.

Enhanced efforts

Your organization needs robust cybersecurity software that you update as soon as new versions become available. You also need to educate staffers about phishing scams and other techniques fraudsters might use to gain entry to your network. To further enhance your privacy efforts:

Always use encryption. When collecting, storing or transferring sensitive data, employ HTTPS and SSL/TLS encryption protocols to keep unauthorized eyes from viewing it.

Collect only what you need. Many nonprofits capture more data with their various apps than they actually require. If, for instance, your analytics software retains extensive tracking data from website visitors, review the data to ensure such collection is necessary. If not, turn off that feature or use aggregated or anonymized data tools. Be sure to disclose what data you collect and enable visitors to opt out.

Properly destroy it. Establish a policy that outlines how long you’ll store certain data. The Privacy Management Framework of the American Institute of CPAs suggests keeping data only “for the time necessary to fulfill the stated purposes” of any agreement. Paper records should be shredded and digital records should be “erased” or “wiped” using reliable software.

Develop a donor policy. Post a privacy policy prominently on your website and in solicitation materials that explicitly states you won’t sell or trade a donor’s personal information without their consent. Even in cases where it’s legal or acceptable to share donor lists, for the sake of trust and goodwill, offer supporters a simple method to opt out.

Take other steps. Your nonprofit may need to consult legal counsel to ensure compliance with state-specific and international data collection laws. And, depending on your nonprofit’s niche, you may be subject to other laws, as in the case of health care organizations and HIPAA.

Financial costs

The stakes couldn’t be higher. If your nonprofit is found to have irresponsibly handled private information, it could result in regulatory fines, litigation and withdrawal of donor support. Contact us for more information about reducing such risk.

© 2025

Categories
  • Agribusiness
  • Assurance, Advisory & Review
  • Audit & Attest
  • Blog
  • Business and Tax
  • Business Consulting & Corporate Compliance
  • Corporate Income Tax
  • Current Opportunities
  • Cybersecurity, Technology Risk, Privacy
  • Employee Benefit Plan
  • Employee Benefit Plans / 401(k)
  • Healthcare
  • High Net Worth Individuals
  • High Net Worth Services
  • Individual Income Tax
  • Industries
  • Manufacturing & Distribution
  • Newsletter Articles
  • Newsletters
  • Nonprofit
  • Press Releases
  • Privately Held Companies
  • Professional Services
  • Real Estate & Construction
  • Retail
  • Services
  • Specialty Tax Services
  • State and Local Tax Complianc
  • T&C Family Office Group
  • Tax Planning
  • Tax Planning & Compliance
  • Technology
  • Uncategorized
  • Valuation Services
  • Valuation Services

SHARE THIS ON:

RELATED POSTS

Employers must stay on top of 401(k) eligibility rules

Employers of all types and sizes continue to sponsor 401(k) plans to attract job candidates and help employees save for retirement. Sure, there are other

Read More »

From the simple to the complex: 6 strategies to protect your wealth from lawsuits and creditors

Asset protection is a strategic approach to safeguarding your wealth from potential lawsuits and creditor claims. Indeed, protecting your assets is critical in today’s litigious

Read More »

Your nonprofit has lost an executive. Now what?

A fictional nonprofit lost its executive director (ED) when she died unexpectedly. The charity had a basic contingency plan, but the document didn’t name an

Read More »

Contact Us

WEST PALM BEACH
Esperante Building
222 Lakeview Avenue
Suite 1200
West Palm Beach, FL 33401
(561) 798-9988
Fax: (561) 798-4053

FORT LAUDERDALE
The Main
201 East Las Olas Boulevard
Suite 1650
Fort Lauderdale, FL 33301
(954) 333-0001
Fax: (954) 765-0719

Twitter Facebook Instagram Youtube Linkedin
© 2025 Templeton & Company. All Rights Reserved. Website by Weber & Co.
Services
  • Audit & Attest
  • Advisory
  • Business & Tax
  • T&C Family Office Group
  • Pay My Bill
  • Audit & Attest
  • Advisory
  • Business & Tax
  • T&C Family Office Group
  • Pay My Bill
Industries
  • Construction & Real Estate
  • Healthcare
  • Manufacturing & Distribution
  • Nonprofit Organizations
  • Private Equity Firms
  • Privately-held Companies
  • Technology & Energy
  • Construction & Real Estate
  • Healthcare
  • Manufacturing & Distribution
  • Nonprofit Organizations
  • Private Equity Firms
  • Privately-held Companies
  • Technology & Energy
Firm
  • Overview
  • Our People
  • Our Community
  • Templeton Group
  • Terms & Conditions
  • Overview
  • Our People
  • Our Community
  • Templeton Group
  • Terms & Conditions
Careers
  • Experienced
  • Students
  • Benefits
  • Experienced
  • Students
  • Benefits