Small nonprofits hold genuinely sensitive data: financial details, giving capacity notes, sometimes beneficiary information. Enterprise governance frameworks are unusable at this scale. These six rules are not.
1. Every field has one owner
Name one role — not one person — accountable for each domain: donor identity, financial records, programme evidence, communication consent. Ownership means the right to decide the definition, not the exclusive right to edit.
2. Access follows the job, and is reviewed twice a year
Roles rather than individual grants. Two calendar reminders a year to review who holds what. Departures remove access the same day, including shared logins, which should not exist.
3. Consent is a record, not a memory
Store how, when and for what channel each person consented, and honour suppression across every channel from one place. A suppression that only applies to one email tool is not a suppression.
4. Notes are discoverable
Write every capacity, health or family note as if the donor will read it, because under an access request they may. This one rule prevents most of the damage governance policies are written to prevent.
5. Retention has a number
Decide how long you keep receipts, payment metadata, event data, applicant data and inactive contacts. Financial records usually have a statutory floor; marketing engagement data does not, and keeping it forever is a liability, not an asset.
6. Deletion is a workflow
A deletion request needs an owner, an identity check, a defined scope that excludes records you are legally required to keep, a completion record and a reply to the requester. Decide this before the first request arrives.
What to write down
- A one-page table: domain, owning role, access level by role, retention period.
- A consent map: channel, lawful basis or permission source, where suppression is enforced.
- A deletion runbook: five steps, one owner, one log.