← University
Regulatory and Compliance Governance for Non-Profits
0 of 6

A letter from the Canada Revenue Agency's Charities Directorate arrived at the registered office of a federally incorporated charitable organization that had operated community support programs in a mid-sized Canadian city for 14 years. The correspondence identified concerns arising from a desk audit of the charity's T3010 filings and requested documentation regarding the organization's disbursement quota compliance, the characterization of certain activities as charitable versus related business undertakings, and the accuracy of official donation receipts issued over the preceding 3 fiscal years. The board chair, a volunteer director serving in her 4th year on the board, convened an emergency meeting of the 7-member board to address the letter's implications.

The charity employed 23 staff members, including an executive director who had held the position for 6 years, and engaged approximately 140 active volunteers across its programming. Its annual revenues had grown from $1.2 million to $2.8 million over the preceding 5 years, funded through a combination of individual donations, 2 major government contribution agreements, foundation grants, and fee-for-service contracts with municipal agencies. The organization maintained a donor database containing personal information on more than 4,500 individuals, a volunteer management system with detailed records including vulnerable sector check results, and employment files reflecting a workforce that had doubled in size since the current executive director's appointment.

As the board began examining the CRA's concerns, additional governance gaps became apparent. The organization had not updated its privacy policy since 2017, when amendments to provincial private sector privacy legislation imposed new breach notification requirements. Employment practices had evolved informally as the organization grew, with inconsistent documentation of overtime arrangements, classification of certain service providers as independent contractors rather than employees, and incomplete records of workplace harassment training required under occupational health and safety legislation. A provincial funder had recently requested evidence of compliance with its contribution agreement terms, including requirements for specific financial controls and conflict of interest policies that the board had not formally reviewed in over 2 years.

The charity's most recent audited financial statements showed adequate reserves, but the board now faced questions about whether those reserves might be needed to address potential reassessments, penalties, or the costs of remediating compliance deficiencies across multiple regulatory domains. The executive director reported that staff morale had declined as word of the CRA inquiry circulated, and 2 long-serving program managers had raised concerns about being asked to implement policies that had never been formally approved by the board. The directors found themselves confronting not a single compliance failure but an accumulated pattern of governance gaps that had developed incrementally as the organization's growth outpaced its internal systems.

Privacy Law Compliance for Non-Profits: PIPEDA, PIPA, and Organizational Obligations

Privacy law compliance represents one of the most consequential governance obligations facing non-profit organizations in Canada today. As organizations collect, use, and disclose personal information about donors, members, clients, volunteers, and employees, they assume significant legal responsibilities that demand board-level attention and organizational commitment. The regulatory landscape governing privacy in Canada reflects a layered framework of federal and provincial legislation, each establishing obligations that non-profit leaders must understand and implement through appropriate policies, procedures, and oversight mechanisms.

The foundational federal legislation governing privacy in the private sector is the Personal Information Protection and Electronic Documents Act, which applies to organizations engaged in commercial activities across Canada. While many assume this statute applies only to for-profit businesses, PIPEDA captures non-profit organizations when they engage in activities that are commercial in nature, including selling goods or services, renting membership lists to third parties, or operating social enterprises that generate revenue. The determination hinges not on the organization's corporate status but on the character of its activities. A charitable organization that sells educational materials, operates a thrift store, or provides fee-for-service programs may find itself subject to PIPEDA with respect to the personal information collected in connection with those commercial activities. As of the date of authorship, PIPEDA establishes ten fair information principles that form the backbone of compliance obligations: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Organizations subject to the statute must designate an individual accountable for compliance, typically titled a privacy officer, and must implement policies that operationalize each principle throughout the organization's information-handling practices.

Three Canadian provinces have enacted private sector privacy legislation that the federal government has deemed substantially similar to PIPEDA, meaning these provincial statutes apply in place of the federal law for activities occurring within those provinces. British Columbia's Personal Information Protection Act, Alberta's Personal Information Protection Act, and Quebec's Act respecting the protection of personal information in the private sector each establish comprehensive frameworks for the collection, use, and disclosure of personal information. Non-profit organizations operating in these provinces must comply with the applicable provincial regime rather than PIPEDA for intra-provincial activities, though PIPEDA continues to apply to interprovincial and international transfers of personal information. The practical consequence is that a national non-profit operating across multiple provinces may need to navigate multiple privacy regimes simultaneously, requiring governance frameworks flexible enough to accommodate the most stringent applicable requirements while maintaining operational coherence.

Quebec's privacy framework warrants particular attention given recent legislative amendments that have significantly strengthened organizational obligations. Law 25, which came into force in stages beginning in September 2022 and continuing through September 2024, introduced substantial new requirements including mandatory privacy impact assessments for certain information systems, breach notification obligations, enhanced consent requirements, and new individual rights including the right to data portability and the right to be forgotten in certain circumstances. Organizations operating in Quebec or handling the personal information of Quebec residents must now designate a person responsible for the protection of personal information, publish detailed privacy policies, implement processes for responding to access requests within prescribed timeframes, and maintain registers of confidentiality incidents. The penalties for non-compliance under Quebec's modernized regime can reach $25 million or four percent of worldwide turnover, representing a dramatic escalation from previous maximum penalties. For non-profit boards governing organizations with any Quebec nexus, these amendments demand immediate attention to compliance infrastructure.

Beyond the private sector privacy regimes, non-profit organizations must also consider the application of public sector privacy legislation depending on their funding sources and operational relationships with government. The federal Privacy Act governs personal information held by federal government institutions, and while non-profits are not directly subject to this statute, those delivering services under contract with federal departments may assume obligations through contractual provisions requiring compliance with Privacy Act standards. Similarly, provincial freedom of information and protection of privacy legislation in each province establishes frameworks that may extend to non-profits receiving public funding or performing delegated public functions. British Columbia's Freedom of Information and Protection of Privacy Act, Ontario's Freedom of Information and Protection of Privacy Act, and equivalent legislation in other provinces each define circumstances in which organizations outside the core public sector may be designated as public bodies subject to statutory obligations. Board members must understand whether their organization's relationship with government triggers any such designation or contractual obligation.

The governance dimension of privacy compliance begins with board accountability for establishing an appropriate compliance framework. While operational implementation necessarily falls to management and staff, the board bears ultimate responsibility for ensuring the organization possesses adequate policies, resources, and oversight mechanisms. This accountability mirrors the broader principle embedded in Canadian corporate and non-profit legislation that directors must manage or supervise the management of the organization's affairs. Under the Canada Not-for-profit Corporations Act, directors owe duties of care and loyalty that encompass ensuring the organization complies with applicable laws, including privacy legislation. Provincial societies acts and incorporating legislation across British Columbia, Alberta, Saskatchewan, and Ontario establish parallel obligations, though the specific articulation varies. Quebec's Civil Code of Quebec establishes fiduciary obligations for directors and officers of legal persons that similarly encompass compliance with statutory requirements. In all jurisdictions, directors cannot insulate themselves from responsibility by claiming ignorance of privacy obligations or delegating entirely to staff without appropriate oversight.

Establishing a privacy governance framework requires several foundational elements that boards should ensure exist within their organizations. The designation of a privacy officer or person responsible for privacy compliance provides a clear locus of accountability and expertise. This individual need not be a dedicated role in smaller organizations but must possess sufficient authority and resources to implement and monitor compliance. Many non-profits assign privacy responsibilities to an existing senior staff member such as an executive director, director of operations, or chief financial officer, though the allocation should reflect the nature and sensitivity of information the organization handles. The privacy officer should report periodically to the board or an appropriate committee on compliance matters, incidents, and emerging risks.

Written privacy policies form the documentary backbone of any compliance program. At minimum, organizations should maintain a comprehensive privacy policy addressing the ten PIPEDA principles or equivalent provincial requirements, along with operational procedures governing specific activities such as fundraising, membership management, client services, employment, and volunteer coordination. These policies must be more than aspirational statements; they should provide practical guidance enabling staff and volunteers to make appropriate decisions about information handling in their daily work. The board should approve the overarching privacy policy as a governance instrument while delegating approval of detailed operational procedures to management. Regular review cycles, typically annual, ensure policies remain current with evolving practices and legislative requirements.

Privacy impact assessments represent an increasingly important governance tool, particularly for organizations contemplating new programs, technologies, or information practices. Quebec's modernized privacy framework now mandates privacy impact assessments before implementing certain information systems or electronic service delivery projects, but this practice holds value for organizations in all provinces regardless of specific legislative requirements. A privacy impact assessment systematically evaluates how a proposed initiative will affect personal information, identifies privacy risks, and documents mitigation measures. Boards should expect management to conduct such assessments for significant new undertakings and should receive summary reports enabling informed governance decisions about proceeding with or modifying proposed initiatives.

The consent framework underlying Canadian privacy law presents particular challenges for non-profit organizations. Consent must be meaningful, which requires organizations to clearly communicate what information they collect, why they collect it, and how they will use and disclose it. The form of consent varies based on context and sensitivity: express consent is required for sensitive information such as health information, financial details, or information about children, while implied consent may suffice for less sensitive information used for purposes that would be obvious to a reasonable person. Non-profits frequently encounter consent complexities when they wish to use information collected for one purpose, such as program delivery, for a different purpose, such as fundraising appeals. Unless the secondary purpose falls within reasonable expectations or the organization has obtained fresh consent, such use may violate consent requirements. Boards should ensure their organizations maintain clear consent mechanisms, typically through enrollment forms, membership applications, and website privacy statements, and should verify that staff understand the boundaries of authorized use.

Data breach response represents a critical governance responsibility that too many organizations address only after an incident occurs. Federal and provincial privacy legislation now universally requires organizations to notify affected individuals and regulatory authorities when breaches of security safeguards create a real risk of significant harm. Under PIPEDA, organizations must report breaches to the Office of the Privacy Commissioner of Canada and maintain records of all breaches regardless of whether notification is required. Quebec's legislation similarly mandates notification to the Commission d'accès à l'information du Québec and affected individuals when a confidentiality incident presents a risk of serious injury. British Columbia and Alberta's provincial statutes establish comparable notification frameworks. Beyond legislative requirements, effective breach response demands advance planning: incident response procedures, designated response teams, communication templates, and clear escalation protocols. Boards should verify that their organizations possess documented breach response plans and should understand their own role should a significant incident occur.

Consider a regional community foundation based in Edmonton operating programs across Alberta and British Columbia. The organization maintains a donor database containing names, contact information, giving histories, and in some instances, financial information provided for major gift planning. It also operates a scholarship program collecting detailed personal information from applicants including academic records, financial circumstances, and sometimes health-related information explaining personal challenges the applicants have overcome. The foundation employs twelve staff members and engages approximately forty volunteers who assist with events and program delivery. Several volunteers have access to applicant information during the scholarship review process.

The foundation's executive director departed suddenly after eight years, and during the transition, the incoming executive director discovered that privacy practices had developed informally without comprehensive documentation. Some donor records dated back fifteen years with no clear retention justification. The scholarship application form, last updated in 2018, collected more information than the program required and lacked any consent statement explaining how information would be used. Volunteer access to applicant files occurred through shared login credentials rather than individual accounts, making it impossible to track who accessed specific records. The foundation had no documented breach response procedure and had never conducted a privacy audit. The board, focused primarily on fundraising and grant-making, had never received any reporting on privacy matters and had not discussed privacy compliance within recent memory.

The implications of this scenario illuminate several governance failures that accumulated over time. First, the board failed to establish accountability for privacy compliance, allowing practices to evolve without oversight or documentation. While the previous executive director likely understood operational practices, that knowledge walked out the door with their departure, leaving the organization unable to demonstrate compliance to any external authority. Second, the absence of regular board reporting on privacy matters meant directors remained unaware of growing compliance gaps. The board's fiduciary duty to ensure legal compliance cannot be fulfilled without information, yet no mechanism existed to bring privacy matters to board attention. Third, specific operational failures created real legal exposure: the outdated consent mechanisms likely failed to meet current standards, retention of records beyond reasonable necessity violated limiting retention principles, and shared credentials violated safeguard requirements while creating accountability gaps for any potential breach investigation. Fourth, the scholarship program's collection of sensitive information, including financial circumstances and health-related details, demanded heightened protections that the organization's informal practices could not provide.

Addressing this situation requires coordinated governance and operational responses. At the governance level, the board should immediately designate a director or committee to oversee privacy compliance during the transition period, ensuring this critical area receives explicit attention. The board should direct the incoming executive director to commission a comprehensive privacy audit, either internally or through external consultation, to identify all compliance gaps and prioritize remediation. The board should establish an expectation of regular privacy reporting, perhaps quarterly during the remediation phase and annually thereafter, and should add privacy compliance to its annual agenda for policy review.

Operationally, the incoming executive director should designate a staff privacy lead and ensure that individual possesses or obtains adequate training. The organization should develop a comprehensive privacy policy for board approval and operational procedures for management implementation. Immediate steps should address the highest-risk gaps: updating the scholarship application form with appropriate consent language and minimizing information collection to what the program genuinely requires, transitioning volunteer access to individual credentials with appropriate access logging, and establishing a defensible retention schedule with procedures for secure destruction of records no longer needed. The organization should develop and test a breach response procedure, ensuring staff understand their obligations to report suspected incidents promptly.

Non-profit leaders across Canada can draw broader lessons from this scenario applicable to their own organizations. Every organization handling personal information should be able to answer fundamental questions: Who is accountable for privacy compliance, and does that person have adequate authority and resources? Do our written policies accurately reflect our actual practices, and when were they last reviewed? Can we demonstrate compliance if a regulator, auditor, or affected individual asks us to? Do we collect only the information we genuinely need, use it only for purposes individuals understand and accept, retain it only as long as necessary, and protect it with appropriate safeguards? Do our staff and volunteers understand their privacy obligations, and do we provide adequate training? Do we have a plan for responding to a breach, and have we tested it?

Directors should incorporate privacy oversight into their regular governance activities. During strategic planning, consider privacy implications of proposed new programs, partnerships, or technologies. When approving budgets, ensure adequate resources for compliance infrastructure, training, and where necessary, external expertise. During executive director performance reviews, include privacy compliance among the domains assessed. When reviewing risk registers, verify that privacy risks receive appropriate treatment. When onboarding new directors, include privacy obligations among the fiduciary responsibilities discussed.

The regulatory environment for privacy continues to evolve rapidly. The federal government has proposed significant amendments to PIPEDA through successive iterations of legislation intended to modernize the private sector privacy framework and establish new enforcement mechanisms. While no such legislation had been enacted as of the date of authorship, non-profit leaders should monitor developments and prepare for heightened obligations in areas including consent, algorithmic transparency, and individual rights. Provincial regimes similarly continue to evolve, with Quebec having enacted the most ambitious reforms and other provinces potentially following. The Office of the Privacy Commissioner of Canada and provincial counterparts have become increasingly active in providing guidance, conducting investigations, and publishing findings that inform organizational practice. Non-profit leaders should ensure their organizations remain connected to these regulatory developments through professional associations, legal advisors, or sector networks.

Ultimately, privacy compliance is not merely a legal obligation but an expression of organizational values. Non-profit organizations exist to serve their communities, and the individuals who share their personal information with these organizations place trust in them to handle that information responsibly. Donors trust that their giving history will not be sold to telemarketers. Scholarship applicants trust that their financial struggles will remain confidential. Program clients trust that their participation will not become fodder for unauthorized purposes. Honoring that trust through robust privacy practices strengthens the relationships that sustain non-profit organizations and reinforces the legitimacy that enables them to fulfill their missions. Board members who understand privacy obligations and ensure their organizations meet them contribute to this broader purpose while fulfilling their own fiduciary duties.

The intersection of privacy compliance and good governance thus presents both obligation and opportunity. Non-profit directors who approach privacy as a governance responsibility, who ask appropriate questions, who ensure adequate policies and resources exist, and who maintain appropriate oversight contribute to organizational resilience and public trust. In an era of increasing digitization, data-driven operations, and regulatory attention, such governance engagement is not optional but essential to responsible non-profit leadership.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options