3.4 Research Ethics, Apra Ethics Guidance, Donor Privacy & Security Controls

Key Takeaways

  • Apra's ethics guidance for prospect development requires information to be gathered lawfully, honestly, and relevantly, which rules out pretexting, misrepresentation, and covert surveillance.
  • Privacy frameworks such as the GDPR, UK GDPR, and Canada's PIPEDA give individuals enforceable rights, including access to their data and (subject to exceptions) erasure, while separate e-marketing rules govern consent for fundraising emails and texts.
  • The common 'front page' test holds that CRM contact reports, prospect profiles, and biographical records should contain objective, professional, and verifiable facts that could withstand direct donor review or public scrutiny without embarrassment.
  • Volunteer prospect review and screening sessions require strict physical and procedural security controls: executed confidentiality agreements, numbered paper rosters, private meeting settings, and immediate roster collection and shredding.
  • Technical safeguards typically include Role-Based Access Control (RBAC) enforcing least privilege, multi-factor authentication (MFA), strong encryption in transit and at rest, PCI DSS compliance for card data, and tested 3-2-1 backups.
Last updated: September 2026

Research Ethics, Apra Ethics Guidance, Donor Privacy & Security Controls

Quick Answer: Ethical prospect development follows Apra's ethics guidance and the donor-privacy standards of the AFP Code of Ethical Standards, gathering information lawfully and honestly while barring pretexting, deceptive inquiry, and covert surveillance. CRM notes should pass the common front-page test—recording only objective, defensible facts that a donor could read without organizational embarrassment. Data governance must satisfy applicable privacy laws (such as the GDPR and UK GDPR), enforce strict physical security during volunteer screening sessions, and maintain robust technical safeguards: Role-Based Access Control (RBAC), multi-factor authentication, PCI-DSS tokenization, and 3-2-1 backup protocols.

Modern philanthropic fundraising relies heavily on intelligence. To identify prospective donors, understand their personal motivations, and estimate giving capacities, development professionals collect, analyze, and synthesize substantial volumes of personal, financial, and relational data. However, the pursuit of charitable contributions does not grant development professionals a license to invade personal privacy, violate data protection laws, or compromise human dignity.

Fundraisers operate at the delicate intersection of public accountability, donor trust, and institutional advancement. Candidates preparing for the CFRE examination must master the professional ethics codes governing prospect research, navigate data privacy frameworks (such as the GDPR and PIPEDA), apply the "front page" test in CRM record-keeping, execute secure volunteer screening sessions, and implement comprehensive information security controls.


1. Professional Ethical Codes: Apra & AFP Standards

Two professional associations publish widely used ethical guidance for prospect research and donor data management: Apra (founded as the Association of Professional Researchers for Advancement) and the Association of Fundraising Professionals (AFP).

Apra's Ethics Guidance

Apra's ethics statement is the core code of conduct for prospect development, research, and analytics professionals. Its principles call for researchers to:

  • Uphold the mission of their institutions while demonstrating fundamental respect for the dignity and privacy of constituents.
  • Gather information lawfully and ethically, verifying accuracy and documenting sources.
  • Maintain absolute honesty and transparency, never misrepresenting their identities or institutional affiliations to obtain information.
  • Protect all confidential information from unauthorized internal or external dissemination.
  • Adhere to the principle of data relevance: recording only data that directly informs philanthropic cultivation and institutional advancement.

How the AFP Code of Ethical Standards Reinforces These Principles

The AFP Code (amended December 2023) addresses research and data use directly:

  • Standard 2: Comply with all applicable local, regional, and national laws and regulations.
  • Standard 19: Protect confidential information from disclosure to unauthorized parties, as defined by organizational policies and procedures.
  • Standard 20: Treat donor and prospect information created on behalf of an organization as that organization's confidential property, never taking it or transferring it to other entities.
  • Standards 21–22: Tell donors they can request omission of their personal information from future organizational use and from lists that are sold, rented, or exchanged.

2. Lawful vs. Illicit Information Gathering

Fundraising professionals must maintain an unyielding distinction between legitimate public records research and unethical, illicit surveillance:

Research DimensionLawful, Ethical Public Research (PERMITTED)Illicit, Deceptive Surveillance (PROHIBITED)
Corporate & Equity WealthReviewing public Securities and Exchange Commission (SEC) filings: Forms 3, 4, 5 (insider stock trades), DEF 14A proxy statements (executive compensation), Form 10-K.Misrepresenting identity to phone corporate accounting departments; pretexting as a tax authority or auditor to obtain private bonus figures.
Real Estate AssetsExamining public county property tax assessor records, deeds of trust, parcel maps, and recorded mortgage values.Trespassing on private property, using drones to survey private estates, or bribing title company staff for unrecorded personal documents.
Foundation & PhilanthropyAccessing IRS Form 990-PF returns of private foundations, published charity annual reports, and donor honor rolls.Hiring private investigators to conduct covert surveillance, follow donors, or eavesdrop on private family conversations.
Political GenerosityReviewing public campaign contribution registries published by the Federal Election Commission (FEC) and state ethics commissions.Attempting to access private personal bank accounts, credit scores, or credit bureau files (violating the Fair Credit Reporting Act).
Digital & Social MediaViewing public LinkedIn profiles, company websites, press releases, and published news media.Infiltrating private, password-protected social groups under fictitious aliases; hacking accounts; purchasing leaked dark-web data.

3. Global and Regional Data Privacy Regulations

Charitable nonprofits are not exempt from data protection statutes. In the interconnected digital era, organizations routinely solicit, communicate with, and process contributions from constituents across state, provincial, and national borders.

General Data Protection Regulation (GDPR / UK GDPR)

Enacted by the European Union, the GDPR represents the world's most stringent data privacy regime. Crucially, the GDPR has extraterritorial reach: it can apply to an organization outside the EU that offers goods or services to, or monitors the behavior of, people in the EU, and the UK applies its own UK GDPR in parallel.

  • Lawful Basis for Processing: To store data or communicate with a constituent, an organization must establish a lawful basis under Article 6. In fundraising, the two primary bases are Consent (freely given, specific, informed, unambiguous opt-in) and Legitimate Interests (a rigorous balancing test proving the charity's mission justifies processing without infringing individual privacy). Electronic direct marketing (email, SMS) is also governed by e-privacy rules, such as the UK's PECR, which generally require prior consent unless a specific exemption applies, so check the current rules in each jurisdiction.
  • Data Minimization (Article 5): Personal data must be adequate, relevant, and limited to what is necessary for the stated purpose, so hoarding speculative personal data breaches the principle.
  • Subject Access Requests (SAR - Article 15): Any constituent has the legally enforceable right to submit a SAR. The organization must generally respond within one month (extendable by up to two further months for complex requests), usually free of charge, providing the personal data it holds—including contact logs, prospect ratings, and wealth screening estimates—subject to limited exemptions.
  • The Right to Erasure / Right to be Forgotten (Article 17): A constituent can ask for deletion of their personal data. The right is qualified—an organization may retain data it must keep for legal obligations such as tax and accounting records—and requests must generally be answered within one month.

California Consumer Privacy Act (CCPA) / CPRA

The CCPA/CPRA generally applies to for-profit businesses rather than most nonprofits, but it still shapes nonprofit operations:

  • Commercial CRM vendors (e.g., Salesforce, Blackbaud) are bound by CCPA, establishing standard technical privacy frameworks across software.
  • Nonprofits operating commercial cause-marketing ventures or retail arms must comply.
  • It has raised donor expectations about notice at data collection, access to personal data, and opting out of data sharing.

Canadian Privacy Standards: PIPEDA and CASL

Canadian organizations must consider the Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to personal information handled in commercial activities (for many charities, activities such as selling, renting, or exchanging donor lists), along with applicable provincial privacy laws. Canada's Anti-Spam Legislation (CASL) requires consent for commercial electronic messages, but its regulations exempt messages sent by or on behalf of a registered charity when the primary purpose is raising funds for the charity; messages that also promote a commercial sponsor may lose that exemption.


4. The "Front Page" Test & Defensible CRM Notes

A widely used rule of thumb in prospect research and frontline gift management is the "front page" test:

"Never enter any comment, observation, or detail into a CRM contact report, research dossier, or staff email that you would not be entirely comfortable having the donor read aloud to you in person, or having published on the front page of a newspaper."

Because constituents can legally demand their files under GDPR Subject Access Requests or state disclosure laws, and because records can be subpoenaed in litigation, development professionals must maintain strict factual discipline:

┌─────────────────────────────────────────────────────────────────────────┐
│                     ETHICAL DO'S AND DON'TS IN CRM NOTES                │
├────────────────────────────────────┬────────────────────────────────────┤
│ ETHICAL PRACTICE (DO)              │ UNETHICAL PRACTICE (DON'T)         │
├────────────────────────────────────┼────────────────────────────────────┤
│ • Record objective, verifiable     │ • Record subjective gossip, rumors,│
│   public facts with dates & sources│   or domestic character judgments  │
│ • "Assessor records show 2024 home │ • "Heard through a mutual friend   │
│   purchase of $2.5M."              │   that they are having a messy     │
│                                    │   divorce and hiding assets."      │
│ • Record articulated philanthropic │ • Record private medical diagnoses,│
│   interests and programmatic goals │   mental health notes, or personal │
│ • Document explicit communication  │   religious/political beliefs      │
│   opt-outs and anonymity requests  │ • Share, sell, or rent donor lists │
│   immediately across all systems   │   without affirmative donor consent│
└────────────────────────────────────┴────────────────────────────────────┘

5. Operational Security for Volunteer Screening & Peer Reviews

Engaging board members, campaign steering committees, and trusted volunteers in prospect review sessions provides invaluable intelligence—validating capacity ratings, identifying personal linkages, and selecting natural solicitors. However, these sessions carry immense reputational and legal risks. If sensitive financial estimates or personal observations leak, the organization faces catastrophic donor backlash and potential defamation liability.

Common safeguards for volunteer screening sessions include these five controls:

  1. Mandatory Non-Disclosure Agreements (NDAs): Before receiving any materials, every volunteer and staff participant must sign a legally binding confidentiality agreement stating that all data is strictly proprietary and privileged.
  2. Controlled, Sequentially Numbered Paper Rosters: Never distribute prospect review rosters electronically via email or thumb drives. Materials must be printed on physical paper, with each packet sequentially numbered (e.g., "Copy 04 of 12 assigned to Trustee Miller").
  3. Executive Closed-Door Environment: Sessions must occur in private, closed conference rooms with no unauthorized personnel present.
  4. Facilitator Ground Rules Against Gossip: The meeting leader must establish firm ground rules at the outset: "We are here strictly to discuss professional connections, philanthropic passions, and broad capacity ranges. We do not discuss personal health, domestic disputes, or rumors." If a volunteer shares gossip, the facilitator must immediately intervene and prohibit its entry into official notes.
  5. Universal Collection & Immediate Shredding: Volunteers are strictly prohibited from removing packets or taking photographs. At the conclusion of the meeting, every numbered packet is collected, accounting for all copies. Staff transfer legitimate linkage notes into the secure CRM and immediately cross-cut shred the physical rosters.

6. Information Security Controls & Technical Compliance

A donor database stores highly sensitive biographical, financial, and relational data. Securing this infrastructure requires multi-layered technical controls:

Role-Based Access Control (RBAC) & Principle of Least Privilege (PoLP)

Access governance must enforce the Principle of Least Privilege (PoLP): staff receive access only to the data and system tools strictly required for their job functions:

  • Gift Processing Specialists: Access to gift entry, pledge creation, receipt generation, and batch deposits. Prohibited from viewing confidential wealth screening ratings or deleting records.
  • Major Gift Officers: Access to view assigned donor portfolios, enter contact reports, and view capacity ratings. Prohibited from executing global data exports or modifying financial ledger setups.
  • Direct Response Coordinators: Access to extract mailing lists and track appeal response rates. Prohibited from accessing unmasked financial accounts or executive contact notes.
  • System Administrators: Full configuration access, user provisioning, and audit log oversight. Prohibited from daily gift entry (enforcing segregation of duties).

Multi-Factor Authentication (MFA) & Encryption Standards

  • MFA: Multi-Factor Authentication must be strictly mandatory across all CRM accounts, requiring a time-based one-time password (TOTP) or biometric verification to sharply reduce credential-stuffing risk.
  • Encryption in Transit & at Rest: Data in transit should use current Transport Layer Security (TLS 1.2 or 1.3), and stored data should use strong encryption such as Advanced Encryption Standard (AES-256).

Payment Card Industry Data Security Standard (PCI-DSS)

Organizations accepting credit card donations must comply with PCI-DSS:

  • Prohibition on Raw Card Storage: Nonprofits must never store unencrypted credit card numbers (PAN) or Card Verification Values (CVV) in CRM text fields, custom attributes, spreadsheets, or staff notes.
  • Tokenization: Recurring gifts and online contributions must route through certified, PCI-compliant third-party gateways. The gateway executes the charge and transmits an encrypted digital token to the CRM, allowing recurring charges without nonprofit servers ever storing sensitive card data.
  • Physical Remittance Safeguards: Paper pledge slips containing handwritten credit card details should be secured during processing and securely destroyed once no longer needed.

Business Continuity, Disaster Recovery & The 3-2-1 Backup Rule

Organizations must protect institutional memory against ransomware attacks, hardware disasters, and cloud outages:

  • Recovery Point Objective (RPO): The maximum tolerable age of data lost during an outage (a common target: 24 hours or less).
  • Recovery Time Objective (RTO): The maximum acceptable duration of system downtime before restoration (a common target: 4 to 8 hours or less).
  • The 3-2-1 Backup Strategy: Maintain at least three (3) copies of organizational data, across two (2) different media types (e.g., local encrypted storage and cloud backup), with at least one (1) copy off-site in an immutable, air-gapped environment protected against ransomware propagation. Routine restoration drill testing must be executed semi-annually.
Loading diagram...
Data Governance, Ethical Standards and Information Security Architecture
Test Your Knowledge

A major gift officer completes an exploratory discovery lunch with a prospective donor. Under the front-page test and professional record-keeping ethics, which statement represents an appropriate, defensible entry in the CRM contact log?

A
B
C
D
Test Your Knowledge

When organizing a prospect review session where board members and campaign steering committee volunteers evaluate major gift ratings, what operational protocol is required to protect constituent confidentiality?

A
B
C
D
Test Your Knowledge

Under Payment Card Industry Data Security Standards (PCI-DSS), how must a nonprofit development department process and manage recurring credit card donations?

A
B
C
D
Test Your Knowledge

Under Apra's ethics guidance for prospect research, which method is legitimate and permissible for determining a prospect's philanthropic capacity and background?

A
B
C
D