A foundation director receives a call from her most important donor. He has just learned, through a notification, that the foundation suffered a data breach.
His contact details, donation preferences, contribution amounts and terms over ten years, all of it information he thought was strictly confidential, are now circulating on specialist forums. He announces an immediate freeze on future contributions and is weighing up legal action.
This scenario illustrates something specific to foundations: their major donors are not anonymous contributors. They are long-term partners whose trust is the very foundation of the organisation’s funding.
What this data actually contains
A major donor’s data goes well beyond a name and address. It includes a detailed giving history spanning several years, the terms and reasons behind their commitment, communication and recognition preferences, confidential exchanges with the foundation’s leadership, and sometimes projects under consideration that have not yet been announced.
Making this information public exposes the donor to approaches from rival organisations, to unwanted media attention, and in some cases to personal safety risks. For the foundation, it is the relationship itself, built over years, that is at stake.
The most concrete threats
Targeted phishing is particularly sophisticated in this context. Attackers study the relationship between the foundation and its donors, then impersonate directors or trusted partners to obtain fraudulent transfers or system access. These attacks exploit real working patterns and communication channels.
Ransomware targets foundations deliberately. Encrypting the donor database not only paralyses operations but directly threatens relationships with essential financial partners, creating extra pressure to pay a ransom quickly.
Human error remains the most frequent cause: a document sent to the wrong recipient, a donor list shared through an unsecured tool, sensitive data accessed on a public network. These incidents often go unnoticed until their consequences become visible. The same principles apply beyond foundations: see also protecting your donors’ data in a nonprofit.
The measures that matter
Role-based access controls. Only staff and board members who genuinely need it access complete major donor records. Rights are defined precisely, reviewed regularly, and revoked immediately when someone leaves, including volunteers.
Encryption of sensitive data. Donor databases, confidential communications, and backups must be encrypted. Encryption keys are stored separately and protected.
Multi-factor authentication. Required for all access to systems containing donor data. A compromised password alone should not be enough to take control of an account.
Access audit trails. Knowing who looked at what, and when, helps you spot unusual behaviour and work out who is responsible if an incident happens. These logs must be kept and reviewed.
Donors who come from a business background apply the same standards to their philanthropic commitments as to their professional activities. IT security has become a real selection criterion for philanthropic partners, no longer a formality.
To find out more about data protection for foundations and nonprofits, visit /en/nonprofits/.
