The California Consumer Privacy Act (CCPA) governs how for-profit businesses handle California residents’ personal data, but its applicability to nonprofit organizations depends on specific activities and thresholds. Nonprofits generally operate outside CCPA as long as they do not meet the act’s criteria for a “business.” However, when a nonprofit engages in commercial activities that resemble a business, or handles personal data in ways that meet the CCPA thresholds, CCPA/CPRA obligations can apply. This article explains when CCPA applies to nonprofits, common scenarios, and practical steps for compliance.
Understanding The CCPA Framework For Nonprofits
The CCPA applies to a “business,” defined as a legal entity that collects personal information, determines the purposes and means of processing, and meets one of these thresholds: annual gross revenue over $25 million; buys, receives, or sells personal data of 100,000 or more California residents, households, or devices; or earns more than half of its annual revenue from selling California residents’ personal data. Nonprofits typically do not fit the traditional profit-seeking model, but certain activities can trigger CCPA obligations if the thresholds are met or if data processing is commercial in nature.
When Nonprofits Might Trigger CCPA Obligations
Several scenarios could bring a nonprofit under CCPA scrutiny:
- Commercial Activities: If a nonprofit runs a paid program, membership system, or marketplace that collects and uses personal data for fundraising, marketing, or service delivery, those data practices could be considered a business activity under CCPA.
- Data Thresholds: If the nonprofit processes the personal data of California residents in ways that push it over the CCPA thresholds (for example, large donor databases or extensive data brokerage within fundraising networks), CCPA/CPRA obligations may apply.
- Third-Party Vendors: Using commercial service providers (CRM systems, donor platforms) that process personal data on behalf of the nonprofit can create responsibilities, especially around contracts and data processing agreements.
- Sale Of Personal Data: Selling or sharing donor data beyond essential fundraising purposes could trigger CCPA provisions, including consumer rights requests and privacy notices.
What Is Exempt Or Not Exempt For Nonprofits
Not all nonprofit activities are exempt. Important considerations include:
- Household And Personal Data Processing: CCPA’s personal data rights may not apply to data processing conducted in a purely personal, household, or household-like context, which can cover certain volunteer or internal communications. However, activities beyond these contexts may not be protected by such exemptions.
- Employee Data: Data about employees or job applicants listed under labor laws may be exempt from certain CCPA requirements, though other data handling practices might still fall under CCPA if the business thresholds apply.
- Publicly Available Information: Information that is lawfully made available from federal, state, or local government records is typically exempt from CCPA’s core provisions, but this does not automatically shield all nonprofit data practices.
- CPRA Changes: The California Privacy Rights Act (CPRA) expands and clarifies several CCPA provisions, adding new sensitive data categories and a Privacy Enforcement network. Nonprofits should monitor CPRA developments as they may broaden applicability or alter exemptions.
Practical Steps For Nonprofits To Assess Compliance
Nonprofits can take concrete steps to determine CCPA relevance and improve data governance:
- Data Inventory: Catalog all personal data collected from California residents, including donors, volunteers, members, and program participants. Map data flows to understand who processes data and for what purposes.
- Assess Thresholds: Evaluate annual revenue, donor data volumes, and potential data sales or sharing to see if any CCPA thresholds are exceeded.
- Privacy Notice: If operations approach CCPA relevance, craft a clear privacy notice outlining data collection, use, sharing, retention, and rights. Include opt-out options for data sales where applicable.
- Vendor Management: Review contracts with CRM platforms, email marketers, and fundraising networks. Add data processing agreements that specify security measures, data retention, and data subject rights handling.
- Data Subject Rights: Prepare processes to respond to California residents’ rights requests (access, deletion, data portability, and opt-out of sale). Establish timelines and verification procedures.
- Security And Retention: Implement strong data security practices and retention schedules to minimize unnecessary personal data storage.
- Training And Governance: Educate staff and volunteers about data privacy practices, approvals for data sharing, and handling sensitive donor information appropriately.
Impact On Donor Data And Fundraising Practices
CCPA considerations can influence how nonprofits collect and use donor information. For example, consent and opt-out mechanisms become meaningful when donor data is used for targeted outreach or sold to partners. Transparent fundraising disclosures help maintain trust with supporters and reduce privacy-related friction. When a nonprofit operates a donor database, compliance efforts should focus on lawful processing, minimal data usage, and clear communication about data rights.
Common Red Flags And Avoidable Pitfalls
Avoid assuming exemption without evidence. Common issues include over-collecting data, opaque privacy notices, weak vendor contracts, and slow responses to data requests. Nonprofits should also avoid selling donor data without explicit, lawful justification and appropriate disclosures. Staying aligned with CPRA expansions is essential as they may alter obligations over time.
Resources For Nonprofits Navigating CCPA
Key sources include:
- California Attorney General’s CCPA/CPRA guidance and FAQs, which outline core obligations and evolving enforcement priorities.
- Industry analyses from reputable law firms and privacy organizations that translate CCPA thresholds and exemptions into practical steps for nonprofits.
- Privacy rights organizations and nonprofit associations that provide templates for notices, data maps, and vendor agreements.
Conclusion: Navigating The Line Between Nonprofit And For-Profit Data Practices
Nonprofits may avoid CCPA obligations when operations remain below thresholds and data processing stays within a non-commercial, household-like context. However, when fundraising activities, donor data handling, or commercial partnerships push data practices into for-profit territory, CCPA/CPRA requirements can apply. A careful data inventory, robust governance, and clear rights management will help nonprofits stay compliant while preserving trust with supporters.
