Our team has worked with nonprofits for over a decade, and the question we hear most often is: what donor data should a nonprofit never collect? It is the right question, because the wrong answer can destroy donor trust, trigger costly legal penalties, and put your tax-exempt status at risk.
In this guide, I will walk you through the specific data types your nonprofit should never ask for, the laws that govern donor data collection, and the practical steps our team uses to audit collection practices. My goal is to give you a clear, defensible framework that protects both your donors and your mission.
Donor data privacy is not just a compliance checkbox. It is the foundation of the trust that allows your nonprofit to operate. When a donor gives, they hand over sensitive information with the implicit promise that you will protect it. Violating that promise has consequences that linger for years.
Table of Contents
- 1What donor data should a nonprofit never collect?
- 2What Donor Data Should a Nonprofit Never Collect?
- 3The Data Minimization Principle Explained
- 4Sensitive Donor Information That Crosses the Line
- 5Legal Compliance: Federal, State, and International Laws
- 6What Happens When Nonprofits Misuse Donor Data
- 7Best Practices for Donor Data Protection
- 8Data Retention and Secure Disposal
- 9Your Donor Data Privacy Checklist
- 10FAQs
- 11Can nonprofits collect donor Social Security numbers?
- 12What happens if a nonprofit misuses donor data?
- 13How long should a nonprofit keep donor records?
- 14Can nonprofits share donor data with third parties?
- 15Final Thoughts on Donor Data Your Nonprofit Should Never Collect
What donor data should a nonprofit never collect?
Nonprofits should never collect Social Security numbers, health and medical information, detailed financial account details beyond payment processing, sensitive personal identifiers (religious beliefs, political affiliation, sexual orientation), children’s information, and any data gathered without transparent consent. The core principle is data minimization: collect only what your mission requires, and never store anything that could cause harm if exposed.
What Donor Data Should a Nonprofit Never Collect?
Our team has reviewed donation forms, CRM databases, and vendor contracts across hundreds of nonprofits. The same problematic data fields keep showing up. Here is the definitive list of donor data your nonprofit should never collect.
Social Security numbers and government-issued IDs. Unless you are processing a specific transaction that legally requires it (and there are very few for nonprofits), do not collect SSNs. A Social Security number is a permanent identifier that cannot be changed if breached. There is no fundraising scenario that justifies storing this data long-term.
Health and medical information. Even if a donor shares a health condition during a fundraising conversation, you should not record it in your CRM. This kind of donor data is protected under HIPAA in healthcare contexts, and storing it without proper safeguards creates massive liability for any nonprofit that experiences a breach.
Detailed financial account information beyond payment processing. You need a credit card number or bank routing number to process a gift. You do not need to store the donor’s full account balance, investment portfolio details, or other banking relationships. That information has no fundraising purpose and creates unnecessary risk.
Personal identifiers unrelated to the mission. Religious beliefs, political affiliations, sexual orientation, immigration status, and criminal history have no place in donor records. Collecting this information is invasive, discriminatory, and could expose you to legal action under civil rights statutes.
Information gathered without transparent consent. Any data collected through deceptive means, hidden cookies, or undisclosed third-party tracking is problematic. If a donor cannot easily understand what you are collecting and why, you should not be collecting it.
The Data Minimization Principle Explained
Data minimization is the practice of collecting only the personal information necessary to accomplish a specific, stated purpose. It is the single most important principle in modern donor data protection, and it is the backbone of regulations like GDPR and CCPA.
Our team applies data minimization in three steps. First, we identify the specific reason for collecting each data point. “Knowing our donors better” is not a valid reason under modern privacy law. “Sending a tax receipt for a $500 gift” is a valid reason and justifies collecting the donor’s name, email, and mailing address.
Second, we evaluate whether the data is necessary for that purpose. A donor’s date of birth, for example, is not required to send a tax receipt. It might be useful for birthday appeals, but that benefit does not outweigh the privacy risk in many contexts.
Third, we delete data when the purpose is fulfilled. There is no legal or ethical reason to keep donor records indefinitely. Once the relationship ends or the data becomes stale, secure disposal protects both the donor and your organization.
The minimum necessary rule, often discussed in healthcare contexts, applies equally to nonprofits. If you would not feel comfortable explaining on a public website why your organization stores a particular data field, that field should not be in your database.
Sensitive Donor Information That Crosses the Line
Some types of donor data sit in a gray area that many nonprofits get wrong. Wealth screening data is a common example. Tools like WealthEngine and iWave pull together estimated net worth, real estate holdings, and giving capacity from public records. Used correctly, this helps you prioritize outreach to donors who can give more. Used incorrectly, it leads to invasive profiling that crosses ethical lines.
The line is crossed when wealth screening data is stored without the donor’s knowledge, used to pressure donors, or shared with third parties. Our team recommends keeping wealth screening data in a separate, access-controlled system, and never pasting it into the main donor record unless the donor has explicitly engaged with your major gifts program.
Personal relationships are another sensitive area. Nonprofit staff sometimes record details about a donor’s spouse, children, employer, or recent divorce. This information feels useful for personalizing outreach, but it creates a privacy risk that most donors never agreed to. I have seen donor databases with detailed notes about family members that the donor never mentioned.
Children’s information deserves special mention. If a minor donates, you have additional obligations under COPPA and similar laws. Even if a child is mentioned in a parent’s donor record, you should think carefully about what you store. Donor privacy is not just about the person who gave the gift; it extends to their family members.
Legal Compliance: Federal, State, and International Laws
The legal framework governing nonprofit data privacy is fragmented, but the consequences are real. Federal law starts with the FTC Act, which prohibits unfair or deceptive practices. If your nonprofit collects data under one set of promises and uses it another way, the FTC can take action. This is the most common federal enforcement mechanism that nonprofits face.
State laws add another layer. Every state has its own data breach notification requirements, and an increasing number have comprehensive privacy laws like the California Consumer Privacy Act (CCPA), Virginia’s CDPA, and Colorado’s CPA. These laws grant donors rights to access, delete, and opt out of the sale of their personal information.
If your nonprofit has donors in Europe, GDPR applies. GDPR requires explicit consent, clear purpose limitation, and strong data subject rights. Fines can reach 4% of annual global revenue, which is enough to bankrupt even large nonprofits. Our team has seen small charities accidentally trip GDPR requirements by using email marketing tools that did not have proper consent mechanisms.
Canada’s PIPEDA, Australia’s Privacy Act, and similar laws in other jurisdictions create additional obligations for nonprofits with international donors. The practical takeaway: if you collect donor data from people in multiple countries, you need to meet the strictest applicable standard.
Sector-specific laws also apply. If your nonprofit works with healthcare providers, HIPAA may govern certain data. If you serve youth, COPPA applies to anyone under 13. Knowing which laws apply to your specific mission is essential.
What Happens When Nonprofits Misuse Donor Data
Consequences of donor data misuse fall into three categories: trust, legal, and operational. The trust category is the most immediate and the most damaging. Once a donor feels their privacy has been violated, they almost never return. I have seen donors declare they will “never donate another dollar” after a single misuse incident, and they usually follow through.
On Reddit’s r/nonprofit, a nonprofit worker described being asked by their boss to “track down a donor’s home address” without consent. The community response was swift and unanimous: this was described as “absolutely, completely wrong” and a clear violation of donor privacy. The post highlighted how shaky the ethical ground can be inside organizations without clear data policies.
Legal consequences are real but less common. The FTC has gone after nonprofits for deceptive data practices. State attorneys general have penalized organizations for failing to notify donors about breaches. Class action lawsuits under CCPA have resulted in settlements ranging from thousands to millions of dollars.
Operational consequences include the cost of breach response, forensic investigations, legal fees, and credit monitoring services for affected donors. A data breach report estimated the average cost of a data breach at $4.45 million. For most nonprofits, even a fraction of that amount would be devastating.
Donor list sharing is a particularly common pain point. The same Reddit thread revealed widespread frustration with “social media agencies requesting excessive donor data access.” Nonprofit staff pushed back, arguing that donor lists should never be shared with anyone who “cannot articulate a specific, business reason” for needing them. This is good advice.
Best Practices for Donor Data Protection
Protecting donor data requires a combination of policy, technology, and culture. Our team has developed a framework that addresses all three.
Write a privacy policy donors can actually understand. Most nonprofit privacy policies are written by lawyers for lawyers. They use legal jargon, bury important details in subclauses, and leave donors more confused than informed. Write a plain-language summary alongside the legal text. A donor should be able to read it in two minutes and know exactly what you collect and why.
Implement clear consent mechanisms. Every data collection point needs a clear, opt-in consent mechanism. Pre-checked boxes do not meet modern standards. “By donating, you agree to our privacy policy” is too vague. Be specific: “I agree to receive emails about my donation and quarterly impact reports. I can unsubscribe at any time.”
Limit third-party sharing. Never share donor data with a third party without explicit consent. Vendor agreements should specify how data is handled, stored, and deleted. If a vendor cannot explain their data practices in writing, do not give them donor data.
Train staff and volunteers regularly. The biggest data breaches usually start with human error. A staff member who clicks a phishing link, sends donor data to the wrong email, or leaves a laptop unattended can compromise your entire database. Training should happen at onboarding and at least annually thereafter.
Use secure donation platforms. Your donation platform should be PCI DSS compliant, use encryption in transit and at rest, and offer multi-factor authentication for admin access. Do not roll your own payment processing; use a reputable platform with a security track record.
Establish a data breach response plan. Know what you will do, who you will contact, and how you will communicate if a breach occurs. Waiting until a breach happens to figure out your response is too late.
Data Retention and Secure Disposal
Data retention is the area where most nonprofits fall short. Donor records are kept indefinitely “just in case” they become useful. This is exactly the wrong approach.
The IRS requires nonprofits to keep donation records for at least seven years for tax purposes. That is the minimum. Beyond that, retention should be tied to a specific, ongoing purpose. If a donor has not given in five years and your policy is to remove inactive donors from active outreach, their record should be archived or deleted.
Secure disposal is just as important as secure storage. Simply deleting records from a database does not remove them from backups or employee laptops. You need a documented process that includes digital wiping, physical destruction of paper records, and verification that vendors have disposed of data when contracts end.
Our team recommends a written retention schedule that specifies how long each type of data is kept and how it is destroyed. This schedule should be reviewed annually and updated to reflect changes in law or operations.
The case for shorter retention windows is straightforward: data you do not have cannot be stolen. Every donor record you keep is a potential liability. The longer you hold it, the greater the risk.
Your Donor Data Privacy Checklist
Use this checklist to audit your nonprofit’s current data collection practices. I recommend running through it at least once a year and after any major change in your fundraising operations.
Audit your donation forms. Remove any field that is not essential for processing the gift or sending a tax receipt. If you cannot explain why a field exists, delete it.
Review your CRM and database. Look for sensitive fields that should not be there at all (SSN, detailed health info) and historical data that has no current purpose. Archive or delete based on your retention schedule.
Update your privacy policy. Reflect current practices, list all data you collect, explain how you use it, and describe donor rights including access, correction, and deletion.
Audit third-party vendors. Review every vendor with access to donor data. Confirm they have appropriate security measures, contractual data protection obligations, and proper breach notification procedures.
Test your breach response plan. Run a tabletop exercise with your leadership team. Walk through a hypothetical breach and identify gaps in your response.
Train your staff. Schedule a refresher on data privacy for everyone who handles donor information. Include phishing recognition, secure password practices, and incident reporting procedures.
Our team has used this checklist with dozens of nonprofits and the pattern is consistent: most organizations discover at least a few pieces of donor data they should never have been collecting. Catching them before a breach occurs is the goal.
FAQs
Can nonprofits collect donor Social Security numbers?
No, nonprofits should not collect donor Social Security numbers unless legally required for a specific transaction. SSNs are permanent identifiers that cannot be changed if exposed, creating massive liability. There is no fundraising scenario that justifies storing this data long-term, and collecting it without proper consent may violate state and federal privacy laws.
What happens if a nonprofit misuses donor data?
A nonprofit that misuses donor data faces three main consequences: loss of donor trust (donors often permanently stop giving), legal liability under FTC Act, state breach notification laws, and potentially GDPR or CCPA, and operational costs from breach response, forensic investigations, and legal fees. State attorneys general and the FTC have pursued enforcement actions against nonprofits for deceptive data practices.
How long should a nonprofit keep donor records?
The IRS requires nonprofits to keep donation records for at least seven years for tax purposes. Beyond that, retention should be tied to a specific, ongoing purpose. Our team recommends a written retention schedule that specifies how long each data type is kept and how it is securely destroyed. Data you do not have cannot be stolen, so shorter retention windows reduce breach risk.
Can nonprofits share donor data with third parties?
Nonprofits should never share donor data with third parties without explicit donor consent. Vendor agreements should specify how data is handled, stored, and deleted. As nonprofit staff on Reddit have emphasized, donor lists should never be shared with anyone who cannot articulate a specific, business reason for needing them. If a vendor cannot explain their data practices in writing, do not give them donor data.
Final Thoughts on Donor Data Your Nonprofit Should Never Collect
The list of donor data your nonprofit should never collect comes down to a simple principle: collect only what serves your mission, obtain clear consent for everything you keep, and remove anything that no longer has a purpose. Social Security numbers, health information, sensitive personal identifiers, and any data gathered without transparent consent belong on the never-collect list.
When you apply data minimization, comply with federal and state privacy laws, and build a culture of donor privacy, you protect your donors and your organization at the same time. Our team has seen this approach build stronger donor relationships, reduce legal exposure, and free up resources for the mission that matters. Start with the checklist above, and revisit your practices every year.