Industry Specific
Featured

Nonprofit Privacy Compliance Canada: PIPEDA Requirements for Charities and NGOs

Privacy compliance for Canadian nonprofits and charities: when PIPEDA applies, the personal information you collect, CASL rules and your privacy policy.

Canada Compliance AI• Compliance Team
March 5, 2026
Updated September 12, 2026
13 min read
Nonprofit
Charity
PIPEDA
Donor Privacy
NGO Compliance

Canadian nonprofits and charities often assume they're exempt from privacy law. They're not. While PIPEDA has limited application to nonprofits, provincial laws, CRA requirements, and donor expectations create substantial privacy obligations that many organizations overlook.

When Does PIPEDA Apply to Nonprofits?

The General Rule

PIPEDA applies to organizations engaged in "commercial activity." Most nonprofit activities are NOT commercial. However, PIPEDA DOES apply to nonprofits when they:

  1. Sell products or services (gift shop, event tickets, merchandise)
  2. Rent or sell donor/member lists to third parties
  3. Operate commercial enterprises (social enterprises, revenue-generating programs)
  4. Exchange personal information for consideration (selling contact lists)

Provincial Laws That DO Apply

Even when PIPEDA doesn't apply, provincial laws may:

ProvinceLawApplies to Nonprofits?
QuebecLaw 25Yes — all organizations collecting PI
AlbertaPIPAOnly for commercial activities (s. 56)
BCPIPAYes — all organizations
OntarioNo comprehensive lawLimited (health, children)

Key Insight: If your nonprofit operates in Quebec or BC, you have comprehensive privacy obligations regardless of commercial activity. In Alberta, PIPA applies to non-profit organizations only for personal information collected, used or disclosed in connection with commercial activity (PIPA s. 56).


Types of Personal Information Nonprofits Collect

Donor Data

  • Names, addresses, phone numbers, email
  • Donation amounts and history
  • Payment information (credit cards, bank details)
  • Tax receipts and CRA reporting data
  • Communication preferences
  • Wealth screening data
  • Relationships and connections

Volunteer Data

  • Contact information
  • Background check results (criminal record checks)
  • Skills and availability
  • Health information (allergies, emergency contacts)
  • Training records
  • Hours and performance data

Client/Beneficiary Data

  • Often includes highly sensitive information
  • Health conditions, disabilities
  • Immigration status
  • Income and financial situation
  • Family composition
  • Housing status
  • Mental health information

Member Data

  • Membership applications
  • Voting records
  • Committee participation
  • Event attendance
  • Communication history

Key Privacy Obligations for Nonprofits

1. Donor Privacy

Fundraising Consent:

  • Obtain consent before adding donors to mailing lists
  • Separate consent for email, mail, phone solicitation
  • Respect CASL for commercial electronic messages
  • Do not share donor lists without explicit consent

Tax Receipting:

  • Duplicate donation receipts must be kept for 2 years after the end of the last calendar year to which they relate (Income Tax Regulations s. 5800(1)(f))
  • Protect financial information used for receipting
  • Secure digital and physical receipt records

Wealth Screening:

  • Donor research must comply with privacy principles
  • Only use publicly available information or consented data
  • Don't collect information disproportionate to fundraising purpose
  • Disclose wealth screening practices in privacy policy

2. Volunteer Privacy

Background Checks:

  • Obtain written consent before conducting checks
  • Collect only what's relevant to the volunteer role
  • Store results securely with limited access
  • Define retention period (destroy when no longer needed)
  • Don't share results beyond those who need to know

Volunteer Health Information:

  • Collect only for safety purposes (allergies, emergency contacts)
  • Store separately from general volunteer files
  • Limited access (program coordinators only)
  • Delete when volunteer relationship ends

3. Client/Beneficiary Privacy

Sensitive Data Handling:

  • Collect minimum necessary information
  • Obtain informed consent (plain language, appropriate reading level)
  • Consider literacy and language barriers
  • Provide alternative consent methods for accessibility
  • Strong security for sensitive categories

Case File Management:

  • Clear access controls (need-to-know basis)
  • Secure storage (physical and digital)
  • Defined retention and destruction policies
  • Client access to their own files
  • Anonymize data for program reporting

CASL Compliance for Nonprofits

When CASL Applies

CASL applies to nonprofits sending "commercial electronic messages" (CEMs):

Exempt (Not CEMs):

  • Messages sent by or on behalf of a registered charity whose primary purpose is raising funds for the charity (Electronic Commerce Protection Regulations s. 3(g))
  • Volunteer communications
  • Program updates to beneficiaries
  • Membership communications
  • Advocacy and awareness campaigns

Subject to CASL:

  • Selling event tickets via email
  • Promoting merchandise or gift shop
  • Third-party promotional partnerships
  • Revenue-generating program promotion

Best Practices Even When Exempt

  • Include unsubscribe mechanism in all emails
  • Identify your organization clearly
  • Include contact information
  • Respect unsubscribe requests promptly
  • Maintain consent records

Privacy Policy for Nonprofits

What to Include

Your nonprofit privacy policy should address:

  1. Types of personal information collected (donors, volunteers, clients, members)
  2. Purposes for each type (fundraising, service delivery, reporting)
  3. Consent mechanisms (how you obtain and manage consent)
  4. Third-party sharing (CRA, funders, partners, platforms)
  5. Security measures (how you protect information)
  6. Retention periods (how long you keep each type)
  7. Individual rights (access, correction, complaints)
  8. Privacy contact (who handles privacy inquiries)

Special Considerations

  • Plain language (many beneficiaries may have literacy challenges)
  • Multiple languages if serving diverse communities
  • Accessible formats (large print, audio)
  • Child-friendly version if serving minors

CRM and Technology Compliance

Donor Management Systems

Popular nonprofit CRMs and privacy considerations:

PlatformData LocationPrivacy Features
Salesforce NPSPUS (Canada option)Strong access controls, encryption
BlackbaudUSAudit trails, data retention tools
Little Green LightUSBasic privacy controls
KeelaCanada 🇨🇦Canadian data residency
SumacCanada 🇨🇦Canadian data residency

Recommendation: For Quebec organizations or those handling sensitive beneficiary data, consider Canadian-hosted CRMs.

Email Marketing Platforms

  • Mailchimp: US-based, GDPR features available
  • Constant Contact: US-based
  • Campaign Monitor: US/Australia
  • Consider consent management features and data residency

Compliance Checklist for Canadian Nonprofits

Foundation (Do First)

  • Determine which privacy laws apply (PIPEDA, provincial, both)
  • Designate a privacy contact person
  • Create or update privacy policy
  • Conduct data inventory (what do you collect and why)

Donor Privacy

  • Review donor communication consent practices
  • Implement unsubscribe mechanisms
  • Secure donation processing systems
  • Review and limit donor data sharing
  • Establish donor data retention policy

Volunteer Privacy

  • Create volunteer privacy notice
  • Implement consent for background checks
  • Secure volunteer records
  • Define volunteer data retention period

Client/Beneficiary Privacy

  • Develop informed consent forms (plain language)
  • Implement access controls for case files
  • Create secure data storage procedures
  • Establish data retention and destruction policies
  • Train staff on confidentiality obligations

Technology

  • Review CRM privacy and security settings
  • Assess email marketing platform compliance
  • Implement basic cybersecurity (MFA, encryption)
  • Create data breach response plan

Frequently Asked Questions

Q: Is my nonprofit exempt from PIPEDA? Probably for most activities, but not for commercial activities like selling products, renting donor lists, or operating revenue-generating enterprises. Provincial laws may apply regardless.

Q: Can we share donor lists with partner organizations? Only with explicit donor consent. Sharing without consent is a PIPEDA violation even for nonprofits.

Q: Do we need a privacy officer? It's strongly recommended. In Quebec, it's legally required for all organizations including nonprofits.

Q: Can funders require us to share client data? Funders can require aggregated/anonymized reporting. Sharing identifiable client data requires client consent unless legally mandated.


Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Related Articles:

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.