The operational reality

What Makes Non-Profit Different

Your donation page is the target, and it is third-party code. Classy, Givebutter, Network for Good, DonorPerfect - the payment flow runs through embedded scripts and widgets. That is precisely the client-side skimming surface the current PCI requirements around payment page scripts were written to address (PCI SSC document library).

Board members are privileged users on personal devices. Volunteer directors receive donor lists and financial reports on personal email and personal laptops that your organization does not manage and cannot wipe.

One person wears every hat. An office manager or part-time bookkeeper owns IT, vendor relationships, and compliance, alongside the actual job. That is not a governance failure - it is the operating reality, and any program that ignores it will not be followed.

Grantors and auditors ask for documents, not tools. A written data security policy, a business continuity plan, and evidence of board-level oversight of financial controls surface at the annual audit and in grant applications. Increasingly the application asks before the money arrives.

Fundraising itself is regulated separately from anything on this page. Charitable solicitation registration is its own obligation with its own deadlines, administered in Florida by the Department of Agriculture and Consumer Services.

Failure patterns

What Usually Goes Wrong

  • Donor exports are emailed as unencrypted spreadsheets to board members and auditors, then live in those mailboxes indefinitely.
  • The bookkeeper or executive director is phished and a payment platform is used to redirect vendor payments.
  • Volunteer credentials are never revoked. Access follows the person out the door and stays live for years.
  • A donation page widget goes unpatched, which is how a page that takes cards becomes a page that leaks them.
  • The written data security policy does not exist until a grant application asks for it, at which point it gets written in an afternoon and never used.
  • Board members use personal devices and personal email for organizational finance with no policy behind it.
  • Backups are configured and never restore-tested.
  • Charity registration renewal is treated as a compliance item owned by IT. It is not - it is a separate legal obligation with its own calendar, and confusing the two means one of them gets missed.

Questions people ask

Frequently Asked Questions

Does a 501(c)(3) have to comply with any cybersecurity laws?
There is no single nonprofit cybersecurity statute. Obligations arrive through what you do: PCI DSS if you take cards, HIPAA if you provide and bill for treatment, federal award terms if you hold grants, and state breach notification law for the personal information you hold. Tax exemption does not change any of them.
Are nonprofits exempt from breach notification laws?
Do not assume so. Florida's §501.171 defines the entities it covers in statutory terms, and whether and how it reaches a particular charitable organization is a question for your counsel reading the current definition at flsenate.gov. Meanwhile, donors in other states bring those states' laws with them.
Do we need PCI compliance for our online donation page?
If you accept payment cards, you are a merchant and the standard applies. Using a hosted donation platform can substantially reduce your scope, but it does not eliminate your responsibility for the page the donor lands on and the scripts running on it. Confirm your validation requirements with your acquirer.
Do federal grant recipients have to follow specific IT security rules?
Federal awards are subject to the Uniform Guidance at 2 CFR Part 200, which sets internal control expectations, and individual awards can impose specific security requirements by reference. Your award terms are the authoritative source - read them at the award level, not the program level.
What does our grant funder actually require for IT security?
Most commonly a written data security or acceptable use policy, a business continuity or disaster recovery plan, evidence of board oversight, and a statement of how personal data is protected. Increasingly this is asked at application rather than at audit.
Our auditor is asking about IT controls. What do they need?
Typically segregation of duties in the finance system, access provisioning and removal records, approval workflows for disbursements, and backup and recovery evidence. Financial controls with a technology dependency - not a security audit.
Can a nonprofit be sued after a breach if we do not charge for services?
Litigation risk follows the data you hold, not the fees you charge. Donor records contain personal and financial information, and statutory notification obligations and contractual commitments to funders apply regardless of your revenue model.
Do we need multi-factor authentication if we are small and volunteer-run?
The accounts that can move money and export the donor database are the ones that matter, however few they are. Multi-factor on those accounts is the highest-value control available to a small organization and it usually costs nothing.
What if a board member's laptop with donor data is stolen?
The question is whether the data was encrypted and whether you can determine what was on it. That is why donor exports to personal devices should be governed by a short written policy - it converts an unbounded incident into a bounded one.
Do we have to register as a charity in every state where we fundraise?
Charitable solicitation registration is state by state, and soliciting across state lines can trigger obligations in multiple states. In Florida, registration is administered by FDACS under Chapter 496, with statutory exemptions that must be read carefully. This is a legal filing question rather than an IT question, but it lands on the same person.