Non-Profit

Your Donation Page Is a Payment Page, With All That Follows

Nonprofit status is a tax classification. It is not a security exemption, a breach notification exemption, or a reason a card network treats your donation page differently from a retailer's checkout.

Your donor database holds names, addresses, giving history, and payment relationships - which is exactly the profile that makes a small organization worth attacking.

The operational reality

What Makes Non-Profit Different

Your donation page is the target, and it is third-party code. Classy, Givebutter, Network for Good, DonorPerfect - the payment flow runs through embedded scripts and widgets. That is precisely the client-side skimming surface the current PCI requirements around payment page scripts were written to address (PCI SSC document library).

Board members are privileged users on personal devices. Volunteer directors receive donor lists and financial reports on personal email and personal laptops that your organization does not manage and cannot wipe.

One person wears every hat. An office manager or part-time bookkeeper owns IT, vendor relationships, and compliance, alongside the actual job. That is not a governance failure - it is the operating reality, and any program that ignores it will not be followed.

Grantors and auditors ask for documents, not tools. A written data security policy, a business continuity plan, and evidence of board-level oversight of financial controls surface at the annual audit and in grant applications. Increasingly the application asks before the money arrives.

Fundraising itself is regulated separately from anything on this page. Charitable solicitation registration is its own obligation with its own deadlines, administered in Florida by the Department of Agriculture and Consumer Services.

Frameworks

Your Compliance Landscape

What applies depends on how you take money, whose money it is, and what services you deliver. Your counsel and your auditor make the determination.

Almost always applies

  • Any organization accepting card donations is a merchant. Version 4.0.1 addresses scripts on payment pages and change detection, which is directly relevant to embedded donation widgets. The standard is published by the PCI Security Standards Council.
  • Florida charitable solicitation registration (Ch. 496, F.S.)
    Administered by the Florida Department of Agriculture and Consumer Services, with registration and annual renewal obligations for organizations soliciting contributions in Florida and specific statutory exemptions - including one for smaller organizations operated entirely by unpaid personnel. Read Chapter 496 and the FDACS charities pages rather than relying on a summary of the threshold.
  • The structure to write your policy against, and the vocabulary a funder's questionnaire will use (NIST CSF).

Applies in some cases

  • Federal award recipients are subject to the Uniform Guidance (2 CFR Part 200), which carries internal control expectations, and specific awards may impose named security controls. Read your award terms - they, not general guidance, define what you owe.
  • Community health centers, clinics, and counseling organizations providing and billing for treatment (HHS).
  • Substance use disorder treatment programs, with consent requirements stricter than HIPAA (42 CFR Part 2).
  • Organizations operating programs on behalf of schools and handling education records (FERPA).
  • Youth programs collecting information online from children under thirteen (16 CFR Part 312).
  • International donors and program participants in the EU (Regulation 2016/679).
  • Something to request from your donor CRM and payment platform during major foundation diligence, not something you obtain.

The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.

Failure patterns

What Usually Goes Wrong

  • Donor exports are emailed as unencrypted spreadsheets to board members and auditors, then live in those mailboxes indefinitely.
  • The bookkeeper or executive director is phished and a payment platform is used to redirect vendor payments.
  • Volunteer credentials are never revoked. Access follows the person out the door and stays live for years.
  • A donation page widget goes unpatched, which is how a page that takes cards becomes a page that leaks them.
  • The written data security policy does not exist until a grant application asks for it, at which point it gets written in an afternoon and never used.
  • Board members use personal devices and personal email for organizational finance with no policy behind it.
  • Backups are configured and never restore-tested.
  • Charity registration renewal is treated as a compliance item owned by IT. It is not - it is a separate legal obligation with its own calendar, and confusing the two means one of them gets missed.

Our services

How We Work With Non-Profit

  • Governance, Risk & Compliance (GRC)

    The written data security policy, the continuity plan, and the board-level oversight evidence that grantors and auditors ask for - documents you can hand over, sized to your organization.

  • Cyber Risk Management

    Multi-factor authentication, email protection, and monitoring focused on the accounts that can move money: the executive director, the bookkeeper, and the finance platform.

  • Helpdesk Support

    Day-to-day support for an organization with no IT staff and a mix of managed and personal devices.

  • Third-Party Assessments

    Review of the donor CRM, payment processor, and accounting platforms that hold your data and take your donations.

  • Fractional CIO, CTO & CISO

    Security oversight the board can point to, which is often what the governance question in a grant application is actually asking about.

  • Digital Forensics & Incident Response

    Response when an account is compromised or a fraudulent payment goes out, including the notification analysis.

Questions people ask

Frequently Asked Questions

Does a 501(c)(3) have to comply with any cybersecurity laws?
There is no single nonprofit cybersecurity statute. Obligations arrive through what you do: PCI DSS if you take cards, HIPAA if you provide and bill for treatment, federal award terms if you hold grants, and state breach notification law for the personal information you hold. Tax exemption does not change any of them.
Are nonprofits exempt from breach notification laws?
Do not assume so. Florida's §501.171 defines the entities it covers in statutory terms, and whether and how it reaches a particular charitable organization is a question for your counsel reading the current definition at flsenate.gov. Meanwhile, donors in other states bring those states' laws with them.
Do we need PCI compliance for our online donation page?
If you accept payment cards, you are a merchant and the standard applies. Using a hosted donation platform can substantially reduce your scope, but it does not eliminate your responsibility for the page the donor lands on and the scripts running on it. Confirm your validation requirements with your acquirer.
Do federal grant recipients have to follow specific IT security rules?
Federal awards are subject to the Uniform Guidance at 2 CFR Part 200, which sets internal control expectations, and individual awards can impose specific security requirements by reference. Your award terms are the authoritative source - read them at the award level, not the program level.
What does our grant funder actually require for IT security?
Most commonly a written data security or acceptable use policy, a business continuity or disaster recovery plan, evidence of board oversight, and a statement of how personal data is protected. Increasingly this is asked at application rather than at audit.
Our auditor is asking about IT controls. What do they need?
Typically segregation of duties in the finance system, access provisioning and removal records, approval workflows for disbursements, and backup and recovery evidence. Financial controls with a technology dependency - not a security audit.
Can a nonprofit be sued after a breach if we do not charge for services?
Litigation risk follows the data you hold, not the fees you charge. Donor records contain personal and financial information, and statutory notification obligations and contractual commitments to funders apply regardless of your revenue model.
Do we need multi-factor authentication if we are small and volunteer-run?
The accounts that can move money and export the donor database are the ones that matter, however few they are. Multi-factor on those accounts is the highest-value control available to a small organization and it usually costs nothing.
What if a board member's laptop with donor data is stolen?
The question is whether the data was encrypted and whether you can determine what was on it. That is why donor exports to personal devices should be governed by a short written policy - it converts an unbounded incident into a bounded one.
Do we have to register as a charity in every state where we fundraise?
Charitable solicitation registration is state by state, and soliciting across state lines can trigger obligations in multiple states. In Florida, registration is administered by FDACS under Chapter 496, with statutory exemptions that must be read carefully. This is a legal filing question rather than an IT question, but it lands on the same person.

Florida & the Treasure Coast

Non-Profit on the Treasure Coast

Florida charitable solicitation is governed by Chapter 496, F.S. and administered by the Florida Department of Agriculture and Consumer Services, including registration, annual renewal, and statutory exemptions for smaller organizations run entirely by unpaid personnel. Breach notification for Florida residents runs under §501.171 on a 30-day clock - and whether that section reaches a given charitable organization is a definitional question worth putting to counsel rather than assuming in either direction.

The Treasure Coast nonprofit sector is heavily seasonal and event-driven, with a large share of annual revenue arriving through winter galas and end-of-year giving. Two consequences follow: donation processing volume is concentrated into a few high-stakes weeks, and volunteer and temporary access spikes at exactly the same time. That is when both the payment page and the access list deserve attention.

[NEEDS: client proof for this vertical]