Donor Privacy Laws – Contact Information Disclosure and Fundraising Data Practices
Donor privacy rules determine when nonprofits may need to disclose contributor information, what remains confidential, and how fundraising records should be handled. There is no single nationwide rule covering every donor-data situation. Federal tax requirements, constitutional protections, state charity laws, privacy statutes, and an organization’s own promises can all affect the answer.
The practical starting point is simple: collect only information the organization needs, know why it is being retained, and understand which disclosures are legally required.
What Donor Information Becomes Public?
Federal tax law requires many tax-exempt organizations to make Form 990 and certain exemption documents available for public inspection. However, IRS instructions state that organizations generally aren’t required to publicly disclose contributor names and addresses appearing on Schedule B or specified exemption applications.
The distinction matters because financial transparency does not automatically mean public access to a nonprofit’s complete donor database. The IRS Form 990 disclosure guidance explains which filings are subject to public inspection and identifies contributor information that can be withheld.
Organizations reviewing their disclosure procedures may also encounter regional information resources while researching broader administrative practices, but federal and state authorities should control legal decisions.
State Reporting Can Create Different Requirements
States regulate charitable solicitation independently, so organizations operating across state lines can face different registration and reporting obligations. A regulator may request information that isn’t ordinarily available to members of the public.
The constitutional limits of compulsory donor disclosure also matter. In Americans for Prosperity Foundation v. Bonta, the U.S. Supreme Court struck down California’s blanket requirement that charities provide Schedule B donor information to the state Attorney General under the system challenged in that case.
That decision did not create a rule that donor information can never be required. Organizations still need to examine the specific statute, regulator, purpose, and disclosure procedure involved.
Fundraising Databases Need Practical Privacy Controls
A nonprofit may hold names, addresses, email addresses, donation histories, communication preferences, and payment-related records. Keeping everything indefinitely can create unnecessary exposure.
Fundraising teams should define who can access the database, how corrections are made, when records are deleted, and how exports are controlled. Broader local publishing material may illustrate how organizations communicate with audiences, but fundraising-data decisions should follow applicable privacy and charity rules rather than informal web practices.
| Data Issue | Typical Concern | Practical Response |
|---|---|---|
| Donor identity | Unnecessary disclosure | Restrict access |
| Contact details | Marketing misuse | Track preferences |
| Donation records | Excessive retention | Set retention rules |
| Data exports | Unauthorized copying | Limit permissions |
Rules beyond charity law can also become relevant when organizations send promotional email, use automated communications, suffer a data breach, or collect information from residents of jurisdictions with applicable privacy statutes. The exact duties depend on the facts and location.
Fundraising Promises Can Matter
A nonprofit should be careful about telling contributors that donations are “anonymous,” “confidential,” or “never shared” unless it can honor that representation subject to legal requirements.
Privacy notices should describe actual practices rather than aspirational ones. An organization researching communication approaches through community-oriented online material should still ensure its own donor-facing language matches what staff, vendors, and fundraising systems actually do.
Contracts with payment processors, fundraising consultants, mailing vendors, and cloud platforms should also address permitted use of donor information and reasonable controls over access.
Where Donor Privacy Assumptions Go Wrong
One common mistake is assuming that nonprofit status automatically makes every organizational record public. Another is assuming the opposite—that donor records can never be disclosed.
Form 990 transparency rules, regulator access, subpoenas, corporate-record rights, campaign-finance rules in applicable situations, and state requirements can produce different results. The correct question is usually not “Is donor information private?” but “Who is requesting it, under what legal authority, and for what purpose?”
When Legal Guidance Is Worth Getting
Legal review is particularly useful when a regulator demands donor identities, a significant data breach occurs, a donor challenges a disclosure, or an organization operates fundraising campaigns across several states.
Counsel can also help before a nonprofit promises complete anonymity, transfers a large donor database during a merger, or allows a third-party fundraiser to reuse contributor information. Those situations can involve facts and laws that a general privacy policy doesn’t resolve.
Frequently Asked Questions
Does Form 990 reveal every nonprofit donor?
No. IRS public-inspection rules generally allow contributor names and addresses reported in specified Schedule B information to be withheld from public disclosure, although other reporting obligations can still apply.
Can a state government request donor information?
Potentially. State charity regulation differs, and constitutional restrictions can limit particular disclosure requirements. The Supreme Court’s 2021 Americans for Prosperity Foundation v. Bonta decision is an important example of those limits.
Should nonprofits publish donor names without permission?
Organizations should first consider applicable law, donor expectations, their privacy notice, grant agreements, and any commitments made during solicitation. Public recognition practices should be clearly communicated rather than assumed.
Build Privacy Into Fundraising Operations
Donor privacy works best when it is treated as a record-management responsibility instead of a last-minute disclosure question. Limit unnecessary collection, control database access, make accurate privacy promises, and check jurisdiction-specific requirements before releasing sensitive information.
For organizations operating nationally, periodic legal review can help reconcile fundraising practices with changing state requirements.
This article provides general legal information and is not a substitute for advice from a qualified attorney.
