← University
Regulatory and Compliance Governance for Non-Profits
0 of 6

A letter from the Canada Revenue Agency's Charities Directorate arrived at the registered office of a federally incorporated charitable organization that had operated community support programs in a mid-sized Canadian city for 14 years. The correspondence identified concerns arising from a desk audit of the charity's T3010 filings and requested documentation regarding the organization's disbursement quota compliance, the characterization of certain activities as charitable versus related business undertakings, and the accuracy of official donation receipts issued over the preceding 3 fiscal years. The board chair, a volunteer director serving in her 4th year on the board, convened an emergency meeting of the 7-member board to address the letter's implications.

The charity employed 23 staff members, including an executive director who had held the position for 6 years, and engaged approximately 140 active volunteers across its programming. Its annual revenues had grown from $1.2 million to $2.8 million over the preceding 5 years, funded through a combination of individual donations, 2 major government contribution agreements, foundation grants, and fee-for-service contracts with municipal agencies. The organization maintained a donor database containing personal information on more than 4,500 individuals, a volunteer management system with detailed records including vulnerable sector check results, and employment files reflecting a workforce that had doubled in size since the current executive director's appointment.

As the board began examining the CRA's concerns, additional governance gaps became apparent. The organization had not updated its privacy policy since 2017, when amendments to provincial private sector privacy legislation imposed new breach notification requirements. Employment practices had evolved informally as the organization grew, with inconsistent documentation of overtime arrangements, classification of certain service providers as independent contractors rather than employees, and incomplete records of workplace harassment training required under occupational health and safety legislation. A provincial funder had recently requested evidence of compliance with its contribution agreement terms, including requirements for specific financial controls and conflict of interest policies that the board had not formally reviewed in over 2 years.

The charity's most recent audited financial statements showed adequate reserves, but the board now faced questions about whether those reserves might be needed to address potential reassessments, penalties, or the costs of remediating compliance deficiencies across multiple regulatory domains. The executive director reported that staff morale had declined as word of the CRA inquiry circulated, and 2 long-serving program managers had raised concerns about being asked to implement policies that had never been formally approved by the board. The directors found themselves confronting not a single compliance failure but an accumulated pattern of governance gaps that had developed incrementally as the organization's growth outpaced its internal systems.

Privacy Law Compliance for Non-Profits: PIPEDA, PIPA, and Organizational Obligations

Privacy law compliance represents one of the most consequential governance obligations facing non-profit organizations in Canada today. As organizations collect, use, and disclose personal information about donors, members, clients, volunteers, and employees, they assume significant legal responsibilities that demand board-level attention and organizational commitment. The regulatory landscape governing privacy in Canada reflects a layered framework of federal and provincial legislation, each establishing obligations that non-profit leaders must understand and implement through appropriate policies, procedures, and oversight mechanisms.

The foundational federal legislation governing privacy in the private sector is the Personal Information Protection and Electronic Documents Act, which applies to organizations engaged in commercial activities across Canada. While many assume this statute applies only to for-profit businesses, PIPEDA captures non-profit organizations when they engage in activities that are commercial in nature, including selling goods or services, renting membership lists to third parties, or operating social enterprises that generate revenue. The determination hinges not on the organization's corporate status but on the character of its activities. A charitable organization that sells educational materials, operates a thrift store, or provides fee-for-service programs may find itself subject to PIPEDA with respect to the personal information collected in connection with those commercial activities. As of the date of authorship, PIPEDA establishes ten fair information principles that form the backbone of compliance obligations: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Organizations subject to the statute must designate an individual accountable for compliance, typically titled a privacy officer, and must implement policies that operationalize each principle throughout the organization's information-handling practices.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $149 course — purchasing unlocks it, or sign in if you already have access.