PIPEDA for Non-Profits and Charities: Privacy Compliance Guide
Do PIPEDA and CASL apply to Canadian charities and non-profits? Yes — for commercial activities, fundraising, and email marketing.
Many Canadian non-profits and charities assume privacy law doesn't apply to them — after all, they're not "commercial" organisations. This is partially true but significantly misunderstood. PIPEDA applies to non-profits engaged in commercial activities, and CASL has a fundraising exemption but not a blanket exemption for all communications. Here's what the non-profit sector needs to know.
Last updated: April 2026
Does PIPEDA Apply to Non-Profits?
PIPEDA's application test is "commercial activities" — not profit motive. This means:
PIPEDA applies to non-profits when:
- The organisation conducts commercial activities (selling goods, renting facilities, providing fee-for-service programmes)
- The organisation handles employee personal information in connection with the operation of a federal work, undertaking or business (s. 4(1)(b))
- The commercial aspect of the organisation's operations is substantial
PIPEDA may NOT apply to purely non-commercial activities:
- Pure charitable activities with no commercial component
- Member-to-member communications within an advocacy organization
- Religious organizations for purely religious activities
In practice: Most Canadian non-profits have PIPEDA obligations because most have some commercial activity — a retail operation, fees for programming, or space rental.
Provincial note:
- Alberta: PIPA Alberta applies to non-profits with commercial activities
- BC: PIPA BC applies to non-profits with commercial activities
- Quebec: Law 25 applies to enterprises, which includes non-profits with commercial activities
CASL and Charities: The Fundraising Exemption
CASL's fundraising exemption is one of the most important distinctions for the sector:
Electronic Commerce Protection Regulations, Section 3(g): Registered Charity Fundraising Exemption
Under section 3(g) of the Electronic Commerce Protection Regulations, section 6 of CASL does not apply to a commercial electronic message sent by or on behalf of a registered charity (as defined in the Income Tax Act) where the message has as its primary purpose raising funds for the charity. This means:
- A CRA-registered charity can email asking for donations without needing CASL consent
- Fundraising appeals, annual giving campaigns, and emergency relief campaigns whose primary purpose is raising funds fall under this exemption
What's NOT covered by the exemption:
- Messages whose primary purpose is not raising funds — e.g., marketing for commercial operations (a charity's retail store, fee-for-service programming)
- Communications from non-registered charities (e.g., non-profit associations without registered charity status)
The practical takeaway: For messages whose primary purpose is fundraising: the CASL exemption applies if you're a registered charity. For all other commercial electronic messages: standard CASL rules apply.
Key Privacy Obligations for Non-Profits
1. Donor Data Management
Donor information is personal information:
- Names, addresses, donation history, financial information
- Donor preferences and communication preferences
- Planned giving and estate information (highly sensitive)
- Corporate donor contacts (business contact information rules apply)
PIPEDA principles apply:
- Collect only what's needed for donor relationship management
- Use only for the purposes disclosed at collection (not for selling or sharing with other organisations without consent)
- Retain only as long as the donor relationship continues plus reasonable period
- Respond to donor access requests within 30 days
Common non-profit issue: Donor lists shared with chapter organizations, affiliated charities, or partner organisations without donor consent. Donor data sharing requires either consent or a legal basis.
2. Volunteer Data
Volunteers provide personal information to help an organisation they support. While volunteers aren't employees, their personal information is still subject to PIPEDA for commercial-activity-adjacent organisations:
- Collect only what's needed (contact info, skills, emergency contact)
- Don't share volunteer data with third parties without consent
- Retain only while the volunteer relationship continues, then securely delete
3. Client and Beneficiary Data
Non-profits often serve vulnerable populations — people experiencing homelessness, mental health challenges, domestic violence, immigration issues, poverty. This creates:
- Sensitive personal information obligations (heightened security and consent requirements)
- Ethical obligations beyond PIPEDA — non-profits serving vulnerable people should handle their data with exceptional care
- Trust obligations — clients come to the organisation in need; their data must not be used in ways that harm or embarrass them
Specific considerations:
- Intake forms for social services should collect the minimum necessary
- Case files often contain deeply sensitive information — access controls are essential
- Photos or stories used in fundraising or communications require explicit consent
- Client data should not be shared with funders in identifiable form without consent
4. Employee Privacy
PIPEDA covers employee personal information only where it is handled in connection with the operation of a federal work, undertaking or business (s. 4(1)(b)); otherwise, provincial law may apply (for example, PIPA Alberta and PIPA BC cover employee information). Good practice for any employer:
- Collect only necessary employment information
- Implement appropriate HR record security
- Respond to employee access requests
Many non-profits also hold volunteer health records (e.g., for volunteers working with vulnerable clients) — treat these as sensitive personal information.
5. Event Registration
Non-profits often run events with registration systems that collect participant personal information:
- Event attendance data is personal information
- Don't add event registrants to fundraising email lists without their consent (beyond the event itself)
- Event photos: obtain consent before using identifiable photos in fundraising materials or social media
6. CRM and Fundraising Database Systems
Many non-profits use fundraising CRM systems (Raiser's Edge, Salesforce Nonprofit, DonorPerfect, Little Green Light). These systems hold your entire donor relationship history. Key obligations:
- Review the vendor's data security practices
- Understand where data is stored (many are US-based cloud systems)
- Ensure there's a data processing agreement
- Configure retention and deletion settings
CASL Beyond the Fundraising Exemption
For non-profits that send marketing-type emails beyond fundraising appeals:
Event invitations with ticket sales: These are commercial electronic messages. If ticket purchase is involved, CASL consent applies (or the recipient must be an existing donor/supporter with implied consent within 24 months).
Programme marketing: A non-profit marketing paid workshops or fee-based services needs CASL consent for marketing emails about those commercial programmes.
Advocacy campaigns: Non-commercial advocacy emails (asking recipients to sign a petition, contact their MP, attend a rally) may not be commercial electronic messages and therefore not subject to CASL. But be cautious — any commercial element in the message may change this analysis.
Privacy Policy for Non-Profits
A non-profit's privacy policy should cover:
- What information is collected from donors, volunteers, event attendees, clients/beneficiaries
- How information is used (specific to your organisation's purposes)
- Who information is shared with (affiliated chapters, funders, service partners)
- Donor rights (access, correction, deletion)
- Your approach to vulnerable populations' data (if relevant)
- How long information is retained
- How to contact your Privacy Officer
Compliance Checklist for Non-Profits
- Assess whether PIPEDA applies to your commercial activities
- Designate a Privacy Officer (Board member, ED, or senior staff)
- Publish a privacy policy on your website
- Review consent language on donation forms and event registrations
- Review and update your fundraising CRM data practices
- Establish client/beneficiary data handling policies (especially for vulnerable populations)
- Conduct a data inventory (what personal information do you hold and why)
- Create a breach response procedure
- Train staff and key volunteers on privacy obligations
Frequently Asked Questions
Q: Our charity is very small (2 staff, 100 donors). Does PIPEDA really apply? A: If you conduct commercial activities (fee programmes, fundraising galas), yes. The minimum programme for a small charity is: a designated Privacy Officer (the ED), a basic privacy policy, and sensible handling of donor data. This takes a few hours to implement.
Q: We share our donor list with a sister organization for a joint campaign. Is that allowed? A: Only with donor consent or if donors were informed at collection that their information might be shared with affiliated organizations. Sharing donor lists between organizations without consent is a PIPEDA violation.
Q: Can we use photos of clients in our annual report without consent? A: No — identifiable photos of individuals are personal information. Obtain explicit written consent, specifying where the photos will be used. For vulnerable clients, consider whether using their photos serves their dignity and interests, not just your fundraising purposes.
Privacy Compliance for the Non-Profit Sector
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — mission-focused compliance for mission-driven organizations.
Related reading: CASL Exemptions Guide | PIPEDA Compliance Guide | Data Retention Policy Canada
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Open Banking Canada: Consumer Privacy and Data Rights in the New Framework
Canada's consumer-driven banking (open banking) framework will allow consumers to share banking data...
FINTRAC and AML Compliance for Canadian Businesses: Privacy and Reporting Obligations
FINTRAC reporting and privacy together: verifying client identity, reporting suspicious transactions...