Nonprofit Privacy Compliance Canada: PIPEDA Requirements for Charities and NGOs
Privacy compliance for Canadian nonprofits and charities: when PIPEDA applies, the personal information you collect, CASL rules and your privacy policy.
Canadian nonprofits and charities often assume they're exempt from privacy law. They're not. While PIPEDA has limited application to nonprofits, provincial laws, CRA requirements, and donor expectations create substantial privacy obligations that many organizations overlook.
When Does PIPEDA Apply to Nonprofits?
The General Rule
PIPEDA applies to organizations engaged in "commercial activity." Most nonprofit activities are NOT commercial. However, PIPEDA DOES apply to nonprofits when they:
- Sell products or services (gift shop, event tickets, merchandise)
- Rent or sell donor/member lists to third parties
- Operate commercial enterprises (social enterprises, revenue-generating programs)
- Exchange personal information for consideration (selling contact lists)
Provincial Laws That DO Apply
Even when PIPEDA doesn't apply, provincial laws may:
| Province | Law | Applies to Nonprofits? |
|---|---|---|
| Quebec | Law 25 | Yes — all organizations collecting PI |
| Alberta | PIPA | Only for commercial activities (s. 56) |
| BC | PIPA | Yes — all organizations |
| Ontario | No comprehensive law | Limited (health, children) |
Key Insight: If your nonprofit operates in Quebec or BC, you have comprehensive privacy obligations regardless of commercial activity. In Alberta, PIPA applies to non-profit organizations only for personal information collected, used or disclosed in connection with commercial activity (PIPA s. 56).
Types of Personal Information Nonprofits Collect
Donor Data
- Names, addresses, phone numbers, email
- Donation amounts and history
- Payment information (credit cards, bank details)
- Tax receipts and CRA reporting data
- Communication preferences
- Wealth screening data
- Relationships and connections
Volunteer Data
- Contact information
- Background check results (criminal record checks)
- Skills and availability
- Health information (allergies, emergency contacts)
- Training records
- Hours and performance data
Client/Beneficiary Data
- Often includes highly sensitive information
- Health conditions, disabilities
- Immigration status
- Income and financial situation
- Family composition
- Housing status
- Mental health information
Member Data
- Membership applications
- Voting records
- Committee participation
- Event attendance
- Communication history
Key Privacy Obligations for Nonprofits
1. Donor Privacy
Fundraising Consent:
- Obtain consent before adding donors to mailing lists
- Separate consent for email, mail, phone solicitation
- Respect CASL for commercial electronic messages
- Do not share donor lists without explicit consent
Tax Receipting:
- Duplicate donation receipts must be kept for 2 years after the end of the last calendar year to which they relate (Income Tax Regulations s. 5800(1)(f))
- Protect financial information used for receipting
- Secure digital and physical receipt records
Wealth Screening:
- Donor research must comply with privacy principles
- Only use publicly available information or consented data
- Don't collect information disproportionate to fundraising purpose
- Disclose wealth screening practices in privacy policy
2. Volunteer Privacy
Background Checks:
- Obtain written consent before conducting checks
- Collect only what's relevant to the volunteer role
- Store results securely with limited access
- Define retention period (destroy when no longer needed)
- Don't share results beyond those who need to know
Volunteer Health Information:
- Collect only for safety purposes (allergies, emergency contacts)
- Store separately from general volunteer files
- Limited access (program coordinators only)
- Delete when volunteer relationship ends
3. Client/Beneficiary Privacy
Sensitive Data Handling:
- Collect minimum necessary information
- Obtain informed consent (plain language, appropriate reading level)
- Consider literacy and language barriers
- Provide alternative consent methods for accessibility
- Strong security for sensitive categories
Case File Management:
- Clear access controls (need-to-know basis)
- Secure storage (physical and digital)
- Defined retention and destruction policies
- Client access to their own files
- Anonymize data for program reporting
CASL Compliance for Nonprofits
When CASL Applies
CASL applies to nonprofits sending "commercial electronic messages" (CEMs):
Exempt (Not CEMs):
- Messages sent by or on behalf of a registered charity whose primary purpose is raising funds for the charity (Electronic Commerce Protection Regulations s. 3(g))
- Volunteer communications
- Program updates to beneficiaries
- Membership communications
- Advocacy and awareness campaigns
Subject to CASL:
- Selling event tickets via email
- Promoting merchandise or gift shop
- Third-party promotional partnerships
- Revenue-generating program promotion
Best Practices Even When Exempt
- Include unsubscribe mechanism in all emails
- Identify your organization clearly
- Include contact information
- Respect unsubscribe requests promptly
- Maintain consent records
Privacy Policy for Nonprofits
What to Include
Your nonprofit privacy policy should address:
- Types of personal information collected (donors, volunteers, clients, members)
- Purposes for each type (fundraising, service delivery, reporting)
- Consent mechanisms (how you obtain and manage consent)
- Third-party sharing (CRA, funders, partners, platforms)
- Security measures (how you protect information)
- Retention periods (how long you keep each type)
- Individual rights (access, correction, complaints)
- Privacy contact (who handles privacy inquiries)
Special Considerations
- Plain language (many beneficiaries may have literacy challenges)
- Multiple languages if serving diverse communities
- Accessible formats (large print, audio)
- Child-friendly version if serving minors
CRM and Technology Compliance
Donor Management Systems
Popular nonprofit CRMs and privacy considerations:
| Platform | Data Location | Privacy Features |
|---|---|---|
| Salesforce NPSP | US (Canada option) | Strong access controls, encryption |
| Blackbaud | US | Audit trails, data retention tools |
| Little Green Light | US | Basic privacy controls |
| Keela | Canada 🇨🇦 | Canadian data residency |
| Sumac | Canada 🇨🇦 | Canadian data residency |
Recommendation: For Quebec organizations or those handling sensitive beneficiary data, consider Canadian-hosted CRMs.
Email Marketing Platforms
- Mailchimp: US-based, GDPR features available
- Constant Contact: US-based
- Campaign Monitor: US/Australia
- Consider consent management features and data residency
Compliance Checklist for Canadian Nonprofits
Foundation (Do First)
- Determine which privacy laws apply (PIPEDA, provincial, both)
- Designate a privacy contact person
- Create or update privacy policy
- Conduct data inventory (what do you collect and why)
Donor Privacy
- Review donor communication consent practices
- Implement unsubscribe mechanisms
- Secure donation processing systems
- Review and limit donor data sharing
- Establish donor data retention policy
Volunteer Privacy
- Create volunteer privacy notice
- Implement consent for background checks
- Secure volunteer records
- Define volunteer data retention period
Client/Beneficiary Privacy
- Develop informed consent forms (plain language)
- Implement access controls for case files
- Create secure data storage procedures
- Establish data retention and destruction policies
- Train staff on confidentiality obligations
Technology
- Review CRM privacy and security settings
- Assess email marketing platform compliance
- Implement basic cybersecurity (MFA, encryption)
- Create data breach response plan
Frequently Asked Questions
Q: Is my nonprofit exempt from PIPEDA? Probably for most activities, but not for commercial activities like selling products, renting donor lists, or operating revenue-generating enterprises. Provincial laws may apply regardless.
Q: Can we share donor lists with partner organizations? Only with explicit donor consent. Sharing without consent is a PIPEDA violation even for nonprofits.
Q: Do we need a privacy officer? It's strongly recommended. In Quebec, it's legally required for all organizations including nonprofits.
Q: Can funders require us to share client data? Funders can require aggregated/anonymized reporting. Sharing identifiable client data requires client consent unless legally mandated.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Related Articles:
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Financial Services Compliance in Canada: PIPEDA + Provincial Requirements for Fintech Startups
Complete fintech compliance guide for Canada. Navigate PIPEDA, OSFI requirements, open banking, and ...
PIPEDA for Marketing Agencies: Client Data, Campaign Consent & CASL Integration
PIPEDA compliance guide for Canadian marketing agencies. Navigate client data privacy, CASL requirem...