Nonprofit data privacy: complete guide
A practical guide to US data privacy laws for nonprofits: what applies, what data you collect, donor privacy, cookies, and a compliance checklist.
A practical guide to US data privacy laws for nonprofits: what applies, what data you collect, donor privacy, cookies, and a compliance checklist.
Many nonprofits collect far more personal information than they realize: donor records, volunteer applications, employee files, event registrations, and website analytics all add up quickly.
While several privacy laws exempt nonprofits, that exemption is far from universal. Depending on where your donors and supporters are located, what data you collect, and how your website operates, privacy obligations may still apply to your organization.
This guide explains what nonprofits should know about data privacy in 2026: which laws deserve your attention, what data you’re likely collecting, and the practical steps you can take to build a privacy program that fits an organization your size.
Nonprofit data privacy is the practice of controlling how your organization collects, uses, shares, and protects personal information, whether that information belongs to a donor, a volunteer, an employee, or someone your programs serve.
It matters because nonprofits hold real, sensitive data even though they aren’t selling anything. A donor’s payment details, a volunteer’s background check, a beneficiary’s health information, and years of email history all carry the same risk they would at a for-profit company.
Donors notice too. In Give.org's 2025 Donor Trust Special Report on privacy and security, 28% of donors said they would stop giving to a nonprofit after a data breach, and another 52% said they would pause donations until they were confident the issue had been resolved.
The practical starting point is a data inventory: a simple list of what personal information you collect, where it lives, and who has access to it. Everything else in this guide, from privacy policies to consumer rights to vendor reviews, builds on that inventory.
There is no comprehensive federal privacy law in the US, and no blanket nonprofit exemption either. Whether a specific law applies to your organization depends on the law itself, your state, and the volume of data you process.
State privacy laws. As of 2026, 20 states have comprehensive privacy laws, and they treat nonprofits inconsistently. States like Virginia, Connecticut, Utah, Nebraska, New Hampshire, Tennessee, Kentucky, and Iowa exempt most nonprofits, often based on federal tax-exempt status. Others provide little or no exemption.
CCPA. California’s law generally applies only to for-profit “businesses,” so most standalone nonprofits fall outside its scope. The exception: a nonprofit that shares common branding or data with a covered for-profit business can still be pulled into CCPA obligations. See our CCPA applicability guide for the full threshold breakdown.
Colorado and Oregon illustrate the other end of the spectrum. Colorado’s law has no nonprofit exemption at all, and Oregon’s exemption covers only narrow categories, such as insurance-fraud-prevention organizations. Our guide to Colorado Privacy Act requirements for nonprofits breaks down what that means in practice.
Instead of asking “are nonprofits exempt,” ask:
Where are our donors, members, and website visitors located?
What personal data do we collect, and how much of it?
Which state laws cover those locations?
Do we meet that law’s consumer or revenue thresholds?
If you’re part of a nonprofit organization, you may also qualify for Clym for Good, a program that provides eligible nonprofits with discounted access to Clym’s privacy, accessibility, and compliance solutions.
Unlike many businesses, nonprofits depend on trust to attract donors, volunteers, members, and beneficiaries. A privacy incident doesn’t just create legal risk, it can affect fundraising, public confidence, and long-term relationships with the communities you serve.
Strong privacy practices also make day-to-day operations easier. Understanding what personal information you collect, where it’s stored, and who has access helps improve transparency, reduce unnecessary risk, and respond more efficiently when questions arise.
Common nonprofit data includes:
Donor information: contact details, donation history, and payment information
Volunteer information: applications, background checks, and scheduling data
Employee data: HR and employment records
Event registrations and membership records
Website analytics: IP addresses, device data, and email engagement
Sensitive information in some cases: health, immigration, or financial hardship details tied to your mission
A few categories, health details from a beneficiary or financial hardship information used for aid eligibility, can qualify as sensitive information depending on context. Our glossary explains what counts as sensitive information in more detail.
There is no single “donor privacy law” in the US. Instead, donor privacy comes down to a few practical habits and applicable state privacy laws where they apply. Ask yourself:
Are we collecting only the donor information we actually need?
Who inside our organization can access donor records?
Which vendors, CRMs, donation processors, and fundraising platforms receive donor data?
Would our donors expect us to share their information this way?
That last question matters more than it sounds. The Give.org Donor Trust Report found 62% of donors are concerned about their information being shared with third parties, which makes list swapping and list rental worth revisiting even where no law strictly requires it.
The same discipline applies to fundraising emails and newsletters. Federal CAN-SPAM rules require honoring unsubscribe requests promptly, and where a state law grants an opt-out right over data sharing, make sure it extends to your marketing database, not just your website cookies.
Learn more: Understanding personally identifiable information (PII)
Most nonprofit websites run more tracking technology than staff can list from memory: analytics tools, advertising pixels, embedded donation forms, social integrations, and newsletter or event registration platforms. Each one can quietly collect and share personal information the moment a page loads.
Start by identifying every cookie, tracker, pixel, and third-party script your website actually runs. Once you know what’s running, you can decide whether consent, opt-out controls, or other privacy mechanisms are needed, which depends on where your visitors are located and the specific laws that cover them, not on your nonprofit status. A growing number of states also require honoring browser signals like Global Privacy Controls (GPC).
Clym’s consent management platform detects the tracking technologies on your website and adapts the consent experience to each visitor’s location automatically. You can also run a free website scan to see what your website is currently collecting before deciding what your setup needs to look like.
A nonprofit privacy policy should tell visitors, donors, and beneficiaries what you collect, why, and what choices they have, in language a non-lawyer can follow. At minimum, it should cover:
Categories of personal information collected and why
Third parties you share data with, including vendors and payment processors
Cookies and tracking technologies your website uses
Consumer rights that apply, where a relevant law grants them
Contact information for privacy questions, and a visible last-updated date
An outdated policy is one of the most common gaps donors and auditors notice, usually because it still lists tools the organization stopped using years ago. Clym’s policy management tools can help generate, translate, and version-control privacy and cookie policies as your practices change.
Where a state law applies to your nonprofit, it typically grants supporters rights over their data: access, correction, deletion, portability, and opt-out. Even where you’re not clearly covered, many nonprofits offer some version of these rights anyway, since donors increasingly expect it.
Building a simple, repeatable process, a dedicated contact point, an identity-verification step, and a way to track deadlines and outcomes makes this manageable even for a small team. Clym’s data subject request management tools centralize incoming requests and document each step, which cuts down the manual back-and-forth of tracking requests across email and spreadsheets. Learn more: The complete guide to data subject requests
Three habits do most of the work of keeping a nonprofit’s privacy program healthy: reviewing vendors, minimizing what you keep, and covering basic security.
Vendors. Every donation processor, CRM, email platform, and event tool is a place your supporters’ data lives outside your direct control. Before adopting or renewing one, check what its contract says about how it can use your data, whether it names its own sub-processors, and how quickly it would notify you of a breach.
Retention and minimization. Cheap storage isn’t a reason to keep data indefinitely. Data minimization means keeping only what serves a specific purpose. Set an approximate retention period for lapsed donor records, old volunteer applications, and inactive subscribers, and clean them out on a schedule.
Security basics. Privacy and security are related but distinct: privacy governs what you collect, security governs how well you protect it. A reasonable baseline includes multi-factor authentication on email and financial systems, encryption for sensitive data, regular backups, and a short written plan for what to do if a breach occurs.
Many nonprofits handle sensitive information as a direct result of their mission, not as a side effect: health details, immigration status, financial hardship records, or information tied to domestic violence services, disability services, or faith communities. This is an area where the specific data and population matter more than any general rule, and additional laws or funder requirements may apply on top of general privacy obligations.
Nonprofits serving children face a similar nuance. COPPA generally applies to operators of websites or online services directed to children under 13, or that knowingly collect their data, so it depends on what your website or app actually does, not simply on whether your programs serve children offline. If your organization runs a website or app aimed at kids, it’s worth evaluating COPPA specifically, alongside any state-level protections for minors’ data.
Use this checklist as a working reference, and revisit it whenever you add a new tool, launch a new program, or expand into a new state.
Data inventory
List every category of personal data you collect and where it’s stored.
Identify who inside your organization has access to each category.
Website and tracking
Scan your website to identify every cookie, pixel, and tracking script in use.
Confirm your consent setup matches your visitors’ locations.
Privacy notices
Confirm your privacy policy reflects your current data practices, not last year’s.
Add a visible last-updated date.
Consumer and data subject requests
Publish a clear way for supporters to submit a privacy request.
Set an internal deadline for responding, and assign an owner.
Vendors and retention
List every vendor that touches personal data and review its data terms.
Set a retention period for each major data category, and clean up lapsed records.
Sensitive information
Identify whether your programs involve health, financial, immigration, or children’s data.
Apply extra access restrictions to those records.
Common mistakes to avoid
Data privacy isn’t about checking a box or preparing for the next regulation. It’s about protecting the trust your supporters place in your organization every day.
Whether your nonprofit serves a local community or operates across multiple states, understanding the personal information you collect and managing it responsibly can reduce risk, improve transparency, and strengthen relationships with donors, volunteers, employees, and beneficiaries.
Start with the basics: know what data you collect, keep your privacy notice accurate, review your vendors regularly, and revisit your privacy practices as your organization grows.
Ready to reduce the manual work behind your privacy program? Explore Clym for Good
Most standalone nonprofits fall outside the CCPA because it generally applies only to for-profit “businesses.” However, a nonprofit that is controlled by a covered business, shares common branding with one, or shares consumer data with one can still be pulled into CCPA obligations, so this depends on your specific structure.
Not universally. States like Virginia, Connecticut, and Utah broadly exempt nonprofits, while Colorado, Delaware, Oregon, New Jersey, Maryland, and Minnesota provide little or no nonprofit exemption. Applicability depends on the specific law, your state, and whether you meet its data or revenue thresholds.
A privacy policy is a practical necessity for most nonprofits with a website, even where no specific law strictly requires one for your organization. It builds donor trust, sets expectations for data use, and becomes mandatory the moment any applicable state law’s threshold is met.
Personal information includes names, contact details, donation and payment history, website activity, IP addresses, event registrations, membership records, and employment data. Some nonprofits also handle sensitive categories like health, immigration, or financial hardship information depending on their mission.
Not automatically. COPPA generally applies to operators of commercial websites or online services that are directed to children under 13 or that knowingly collect their personal information, so applicability depends on what your website or app actually does, not simply on whether your programs serve children.
It depends on where your website visitors are located and which tracking technologies your website uses, not on your nonprofit status. A nonprofit with visitors in states or regions that require opt-in or opt-out consent mechanisms needs a consent setup that reflects those requirements.