Practical AI Readiness
Data and Privacy Risk Basics for Nonprofit Leaders
Most data breaches at nonprofits do not look like hacks. They look like helpfulness. Here is what nonprofit leaders actually need to know, and what to do about it.

There is a version of the data privacy conversation written for compliance officers and IT directors. It is full of frameworks, certifications, and regulatory acronyms. It is thorough and most nonprofit leaders stop reading after the second paragraph.
This is not that conversation.
This is for the executive director or COO who knows data privacy matters, has read enough to be concerned, and needs to understand just enough to ask better questions, recognize the situations that need more attention, and know when to get help.
You do not need to become a technical data privacy expert. You need to understand three things.
The Three Things To Understand
A donor name is not that sensitive on its own. A donor name connected to giving history, a home address, a health condition mentioned in a thank you note, sitting inside a platform with an AI assistant that can read all of it, is a different situation entirely.
Most leaders think about data categories in isolation. Risky data feels like it should be obvious: health records, Social Security numbers, financial information. And yes, those categories matter.
But the real exposure for most nonprofits is not a single sensitive field. It is the combination of ordinary data points that, connected together inside a tool nobody fully reviewed, creates something far more sensitive than any individual piece.
Before your organization adds a new tool, a new integration, or AI feature, the question is not just what information does this touch. It is what information does this connect, and what does that connection make possible.
Your clients consented to share information with your organization. They trusted you with details about their lives, their circumstances, their needs.
They did not consent to have that information processed by an AI tool your organization adopted three years after they signed an intake form. They did not consent to have their data exported to a vendor platform to improve segmentation. They did not consent to appear in the training data of a model they will never know existed.
That gap, between what people consented to and what your organization has since done with their information, is where most nonprofit data risk quietly lives. It does not feel like a violation, because each step seemed reasonable at the time. But reasonable steps in sequence can create an outcome nobody would have chosen deliberately.
When evaluating a new tool or renewing a vendor contract, the question worth asking is not just whether this is legal. It is whether the people whose data is involved would recognize what you are doing with it as consistent with why they shared it in the first place.
Leaders think about hackers. The external threat. The malicious actor. The dramatic incident.
The real exposure is usually much more mundane. It looks like this:
A marketing vendor says it can build better segmentation tools and needs a data integration to get started. It seems helpful. Someone configures the integration.
An internal IT person is genuinely trying to solve a problem. They build something quickly in a low-code tool, connect it to the CRM because the data is right there, and ask the web developer to embed the app on the public website. Each step made sense in isolation.
A platform your organization has used for years quietly updates its terms of service to include new language about AI features. Nobody reads the update. The features go live. Live Salesforce data is now flowing through a system nobody reviewed, accessible in ways nobody intended, on a public-facing page.
Nobody in any of these stories had bad intentions. That is exactly what makes the risk hard to catch and hard to talk about. The threat did not come from outside. It came from the inside, wrapped in helpfulness and momentum.
What the CEO is Supposed To Do About It
The answer is not to become a technical expert or personally approve every IT decision. Neither is realistic and neither would actually solve the problem.
Three things will.
Before any new tool, integration, connection, or AI feature is deployed: what data does this touch and who reviewed it? Not a committee review. Not a formal process. One question that creates a pause. The pause is the point. Most of the scenarios above did not have a single moment where someone stopped and asked.
Not you. A specific, named person with the actual authority to say not yet, or not without review. In most nonprofits, this is an operations director or a senior technical staff member. Your job is to make sure that person exists, knows they have the authority, and is genuinely consulted before things go live. In most organizations that person is either not named or not empowered. One of those is easy to fix today.
This is the one that costs organizations the most when they get it wrong.
"We need to show that we started building something." I have heard that sentence in more rooms than I can count, and I have watched it send well-meaning teams straight past every question that should have been asked, because momentum and speed felt more valuable than review.
The person who raises their hand and asks what does this connect to and who reviewed it is not a blocker. They are the most valuable person in the room. Your job as a leader is to make sure they know that, because if your culture rewards speed and innovation above everything else, your most careful people will eventually stop raising their hands. They have learned that slowing down is not valued. So they let it go.
And the app goes live.
That is a culture problem before it is a technology problem. It starts at the top and it is entirely within your control to change.
A Practical Starting Point
If this post raised questions about what your organization is currently doing with data, or where AI tools may already be touching information nobody has reviewed, the Nonprofit AI Readiness Toolkit is where to start.
It walks you through the process of mapping sensitive information, documenting current AI use, and evaluating vendor risk. It gives the person you named in point two a structure to work from.
Lisa Montague is Partner and CEO at Coat Rack, a nonprofit technology consulting firm based in Cedar City, Utah.