Donor trust is the asset you cannot replace.
Rich donor data and the assumption of weaker defences make not-for-profits an easy, high-reward target. We protect donor and beneficiary information with the same calm rigour we bring to any regulated business, because the people behind that data deserve it.
Dossier 07 / 10
Not-for-Profit
Lean budgets and rich donor data make not-for-profits an easy, high-reward target.
- Privacy Act 1988 / APPs
- Donor & beneficiary data protection
- Grant & funder security conditions
What the obligation actually requires of you.
- 01
Privacy Act 1988 / APPs
Where the Privacy Act applies, donor and beneficiary information requires reasonable protection; coverage depends on the organisation and its activities.
- 02
Donor & beneficiary data protection
Beneficiaries are often vulnerable people; a breach of their data is a duty-of-care failure as much as a security one.
- 03
Grant & funder security conditions
Government and philanthropic funders increasingly write security requirements into grant agreements — requirements worth meeting before they're tested.
controls to review
Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.
A volunteer laptop targeting a donor database.
Illustrative scenario — In this example, A volunteer's personal laptop, used to access the organisation's donor and case-management platform, was compromised through a phishing link opened outside work hours. The attacker attempted to log in to the donor CRM using cached credentials.
Example response — A suitable response is to isolate the volunteer device, revoke its access, reset affected credentials and review donor-system logs before restoring least-privilege access.
What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.
Control evidence to collect
Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.
Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.
Run it yourself, before we ever speak.
- MFA enforced on the donor database and fundraising or CRM platforms
- Volunteer and casual-staff access reviewed and revoked promptly when roles end
- Donor and beneficiary data encrypted at rest and access-logged
- Grant and funder security conditions mapped against your actual controls
- Backup and recovery tested for the donor and case-management database
- Staff and volunteers trained to spot phishing targeting donation processing
- An incident response plan naming a board member and a communications lead
These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.
The questions this vertical always asks.
The opposite. Not-for-profits are targeted precisely because attackers expect weaker defences and rich donor data. Priority has nothing to do with size.
Donor databases are rich, high-value targets precisely because attackers don't need financial data to profit from a mailing list built on genuine trust.
We tighten who can see what without slowing anyone down — role-based access that matches how your organisation actually runs, reviewed as volunteers come and go.
Find out exactly where your donor data is exposed.
The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.
Melbourne VIC · Australia · gmanit.com.au