How should a not-for-profit protect donor and client data?
With the ordinary controls done properly: multi-factor authentication everywhere, access granted by role, managed devices, tested backups, and an offboarding step that actually happens. What differs is the sensitivity of the data and the number of people coming and going.
Be clear-eyed about what you hold. Donor records with payment details. Participant or client files that in disability, health, youth, family and community services describe people's circumstances in ways they would not want shared. Volunteer details. Sometimes information about people who are at risk from specific individuals, where a disclosure is not embarrassing but dangerous. That inventory is what sets the standard, and it is usually more sensitive than an equivalently sized business would handle.
The Privacy Act position deserves establishing rather than assuming. Coverage depends on the organisation's circumstances, and many not-for-profits are within scope, including those providing health services regardless of size. The Notifiable Data Breaches scheme requires assessment and, where serious harm is likely, notification. Working out where you stand is a question for advice rather than an article, and the useful point is that the assumption of exemption runs one way while the consequences of being wrong run the other.
Access control is where the sector's structural difference bites. Staff, volunteers, students, contractors and board members come and go, often quickly, often onboarded by whoever was available. That produces many accounts created informally and rarely removed with equal energy. The most common serious finding in a not-for-profit is not a weak password; it is a live account belonging to somebody who stopped volunteering two years ago, still able to open participant records.
Fixing it is procedural rather than technical. Grant access by role rather than individually, so joining a role gives the right access and leaving removes it. Put account removal on the same checklist as returning a key or a uniform. And review the user list quarterly, which for most organisations takes twenty minutes and reliably finds several accounts nobody could account for. That single habit closes more real exposure than most security purchases.
Personal devices are the second structural feature, because equipment budgets are thin and people use their own phones. Refusing that is unrealistic and having no control is unacceptable when participant data is involved. Modern device management resolves it by managing the organisation's applications and data on a personal device while leaving the personal side alone, so access can be removed cleanly when someone finishes. TAPS applied Zero Trust security across both organisation computers and staff-owned mobiles for exactly this reason.
Then the foundations, which are the same as anywhere and are often unfunded here. Multi-factor authentication on every account without exception. Backups that have actually been restored, including whatever holds your participant records, since a client management system being hosted does not mean your data is backed up in the way you need. Managed, encrypted devices. Patched systems. None of this is sector-specific and all of it is what an incident would test.
Funders increasingly ask, which is worth knowing before a grant acquittal or a tender. Government-funded programmes and larger philanthropic funders now include data handling and security questions, and an inability to answer can affect funding. An Essential Eight assessment produces a dated, control-by-control report that answers most of what is asked, and the not-for-profit accounting firm we support reached Maturity Level 1 alongside replacing ageing servers with AWS Remote Desktop and deploying ThreatLocker and device management.
The board dimension is specific to this sector and often missing. Boards carry governance responsibility for risk, and technology risk is frequently the one nobody on the board feels equipped to ask about. A short annual briefing covering what data the organisation holds, what protects it, when it was last assessed and what an incident would look like is enough to make that oversight real, and it is a conversation better had before an incident than during one.
The honest caveats. Budget is a genuine constraint and the honest sequence is nonprofit licensing first, then identity and backups, then the rest. Volunteers are an asset and cannot be an accountability structure. And no arrangement makes an incident impossible; the aim is that it is unlikely, contained, and something you can explain to the people whose data it was. If you want your controls reviewed at sector pricing, call 1800 456 567.
Protect the people you serve
We put proper identity, access and backup controls around donor and participant data, at nonprofit pricing wherever it is available.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business