Protecting Donor Data: A Guide for California Nonprofits
Donors trust you with their names, addresses, and payment details. California law expects you to protect them.
· 5 min read

Nonprofits often assume privacy laws are aimed at big tech companies. While many nonprofits are not subject to the California Consumer Privacy Act, other California laws still apply.
Reasonable security is expected
California Civil Code § 1798.81.5 requires businesses that own or license California residents' personal information to maintain reasonable security procedures — and the definition of business in that part of the code includes nonprofit organizations. Civil Code § 1798.82 requires notifying affected individuals when certain unencrypted personal information is breached.
Practical steps
- Keep donor records in your CRM, not in spreadsheets emailed around
- Turn on multi-factor authentication for every staff account
- Use a reputable payment processor so card numbers never touch your systems
- Limit who can export donor lists
- Encrypt laptops and back up your donor database off-site
Trust is the real asset
A breach can damage donor relationships far more than it costs in fines. Simple, consistent safeguards protect your reputation and your fundraising. This article is general information, not legal advice.
This article is general information about IT and security practices, not legal advice.

