Charities collecting donor personal information must secure that data, limit its use to stated purposes, provide clear privacy notices, honor opt-out requests, and comply with breach notification requirements under federal and state law. Donor data protection isn't optional—it's a legal obligation that affects every nonprofit accepting online donations.
Key takeaways
- Federal law (FTC Act) and state privacy statutes require charities to implement reasonable data security measures
- Donor information may only be used for purposes disclosed in the charity's privacy policy
- Selling or sharing donor data without explicit consent violates donor trust and often state privacy laws
- GDPR applies to any charity collecting data from EU residents, regardless of where the charity operates
- Breach notification laws in all 50 states require charities to report data compromises within specific timeframes
What donor data do charities collect?
Charities typically collect names, email addresses, mailing addresses, payment information, donation amounts, and IP addresses when supporters make contributions. On a charity prize giveaway platform like The Daily Deed, the Sponsor Charity receives this donor information directly because donations settle directly to the charity's own merchant account. The Daily Deed operates as a service provider; the charity remains the data controller responsible for protecting supporter information. Payment card data specifically falls under PCI-DSS standards, which require secure handling by payment processors.
What are charities legally required to do with donor data?
Nonprofit privacy obligations begin with transparency: charities must publish a clear privacy policy explaining what data is collected, how it will be used, and whether it will be shared. The Federal Trade Commission enforces data security requirements under Section 5 of the FTC Act, holding nonprofits to the same standard as commercial entities. State attorneys general increasingly pursue nonprofits for privacy violations.
Charities must implement reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the data. This includes encryption for data in transit and at rest, access controls limiting who can view donor records, regular security audits, and staff training on data handling. According to The Daily Deed's compliance framework, charities running giveaway campaigns should apply the same security standards to entry data as they do to traditional donation records.
GDPR requirements for U.S. charities
Charity GDPR compliance is mandatory for any nonprofit collecting data from individuals in the European Union, even if the organization has no physical EU presence. The General Data Protection Regulation requires explicit consent for data collection, the right for donors to access their data, the right to erasure ("right to be forgotten"), and data portability. Violations carry fines up to €20 million or 4% of global revenue. U.S. charities accepting international donations must implement GDPR-compliant processes or geofence their campaigns to exclude EU participants.
What should charities never do with donor information?
Selling donor lists without explicit opt-in consent violates trust and increasingly violates state privacy laws. California's CCPA, Virginia's CDPA, and similar statutes in a growing number of states grant consumers—including nonprofit donors—the right to opt out of data sales. Charities should never share supporter data with third parties for marketing purposes unless the donor has explicitly consented to that specific use.
Using donor data for purposes not disclosed in the privacy policy constitutes deceptive practice. If a charity collects an email address "to send donation receipts," using that same address for unrelated fundraising campaigns without separate consent crosses legal and ethical lines. The Daily Deed provides tools for charities to manage communication preferences, but the Sponsor Charity remains responsible for honoring those preferences in all contexts, not just giveaway campaigns.
Retaining data longer than necessary increases breach risk and may violate data minimization principles under GDPR and state privacy laws. Charities should establish retention schedules and purge outdated donor records systematically.
How should charities handle data breaches?
Every state now has breach notification laws requiring charities to notify affected individuals when personal information is compromised. Notification timelines vary—some states require notice within 30 days, others "without unreasonable delay." Charities must also notify state attorneys general in many jurisdictions. The Daily Deed maintains a verified draw record using a provably fair cryptographic commit-reveal protocol, ensuring campaign integrity, but charities remain responsible for securing all donor data they collect through their campaigns.
Breach response plans should be documented before an incident occurs, including forensic investigation procedures, legal counsel contacts, notification templates, and credit monitoring service arrangements for affected donors.
What privacy practices build donor trust?
Transparency builds confidence: publish your privacy policy prominently and write it in plain language. Make opt-out mechanisms simple and honor requests immediately. Limit data collection to what you genuinely need—asking for a donor's birthday when it serves no campaign purpose creates unnecessary risk.
Regularly audit third-party service providers. When charities use platforms like The Daily Deed for giveaway campaigns, they should verify that the service provider implements appropriate security controls. The Daily Deed's architecture, where donations settle directly to the charity's merchant account, reduces the number of entities handling sensitive payment data.
Consider appointing a data protection officer (even if not legally required) to centralize privacy oversight. Train all staff and volunteers who access donor data on proper handling procedures. For detailed guidance on charitable solicitation compliance, consult the charity resources and seek qualified legal counsel familiar with nonprofit privacy law in your state.
FAQ
Can charities share donor email addresses with partner organizations?
Only with explicit donor consent for that specific purpose, disclosed in your privacy policy before collection. Sharing without consent violates most state privacy laws and donor trust.
Does GDPR apply to a U.S. charity with no European offices?
Yes. Charity GDPR compliance is required whenever you collect data from EU residents, regardless of your organization's location. If you accept donations from European supporters, you must comply with GDPR.
What counts as a reportable data breach?
Any unauthorized access to or acquisition of personal donor information that compromises its security or confidentiality triggers breach notification laws in most states. Even if no misuse occurs, notification is typically required.
How long should nonprofits retain donor records?
Retain donation records as long as required for tax, audit, and legal purposes (typically seven years for IRS records), then implement a documented destruction schedule. Consult your legal and financial advisors for your organization's specific requirements.
