Design-partner program · Core donor operations in active build

See the roadmap
Skip to content
Beneora

Operating model

Data governance for teams with no data team

Six rules that a five-person nonprofit can actually keep, covering ownership, access, consent, retention and deletion.

8 min readBeneora product team

Takeaway

Governance for a small team is six written decisions, not a policy document. Write them down once and enforce them in the system rather than in training.

Small nonprofits hold genuinely sensitive data: financial details, giving capacity notes, sometimes beneficiary information. Enterprise governance frameworks are unusable at this scale. These six rules are not.

1. Every field has one owner

Name one role — not one person — accountable for each domain: donor identity, financial records, programme evidence, communication consent. Ownership means the right to decide the definition, not the exclusive right to edit.

2. Access follows the job, and is reviewed twice a year

Roles rather than individual grants. Two calendar reminders a year to review who holds what. Departures remove access the same day, including shared logins, which should not exist.

3. Consent is a record, not a memory

Store how, when and for what channel each person consented, and honour suppression across every channel from one place. A suppression that only applies to one email tool is not a suppression.

4. Notes are discoverable

Write every capacity, health or family note as if the donor will read it, because under an access request they may. This one rule prevents most of the damage governance policies are written to prevent.

5. Retention has a number

Decide how long you keep receipts, payment metadata, event data, applicant data and inactive contacts. Financial records usually have a statutory floor; marketing engagement data does not, and keeping it forever is a liability, not an asset.

6. Deletion is a workflow

A deletion request needs an owner, an identity check, a defined scope that excludes records you are legally required to keep, a completion record and a reply to the requester. Decide this before the first request arrives.

What to write down

  • A one-page table: domain, owning role, access level by role, retention period.
  • A consent map: channel, lawful basis or permission source, where suppression is enforced.
  • A deletion runbook: five steps, one owner, one log.

Keep reading

Related to this

GuideReconciliation

The nonprofit month-end close playbook

A sequenced close for organizations taking online, offline and recurring gifts across multiple funds.

12 min
GuideDonor data

Migrating donor data without inheriting its errors

A dry-run-first approach to imports, duplicates, households and recognition preferences.

10 min
GuideOperating model

Operating a recurring giving programme with two staff

Owners, cadences and escalation rules for a monthly programme that does not depend on heroics.

9 min

Design-partner program

We write these from partner sessions

If this matches your week, a working session is the fastest way to make the product fit it. Partners see the honest status of every module and are never charged for a prototype.