Skip to main content
CY6Check Your Six

Donor data deserves the same care as any client file

Non-profits hold donor records, payment details, and often the personal information of the people they serve — frequently the most sensitive data of all. They do it with a small staff, rotating volunteers, granted budgets and a board that has to be able to answer for it.

What you are carrying

  • Donor and beneficiary records are highly sensitive and highly targeted
  • Volunteers and seasonal staff mean constant access changes
  • Grant agreements increasingly carry data-protection conditions
  • Payment processing brings card-security obligations
  • Boards are asked about cyber risk and often have no answer prepared

What we do about it

  • Access that is easy to grant and, more importantly, easy to remove
  • Donor and beneficiary data separated and protected appropriately
  • Card-handling reviewed so obligations shrink rather than grow
  • Plain-language reporting a board can actually use
  • Non-profit licensing pursued wherever it exists, to keep costs down
  • Continuity planning for the events and campaigns you cannot move
Straight answer

A large amount of non-profit technology cost is avoidable through donated and discounted licensing. Finding it is part of the job, not an extra.

How it usually works

What we find in non-profits and associations

The licensing landscape changed underneath the sector in 2025, and a lot of organisations have not been told.

  1. TechSoup no longer performs Microsoft non-profit validation. That changed in August 2025.

    How it got that way

    TechSoup was the route for so long that it is still the first answer most boards give. The process moved rather than disappeared, but nobody sends a letter about it.

    What we do

    We do the eligibility and the validation, which is the part nobody has time for.

    TechSoup (opens in a new tab)
  2. Google Workspace for Nonprofits is free, not discounted. Eligible organisations pay nothing for the base tier.

    How it got that way

    It is a grant rather than a price, so it does not appear on the pricing page a board member would find by searching. Plenty of organisations are paying for something they qualify to have.

    What we do

    We check entitlement before we quote anything, including where that means quoting less.

    Google for Nonprofits (opens in a new tab)
  3. Microsoft discontinued some donated grants at renewals from 1 July 2025. Organisations on Business Premium or E1 grants are the ones affected.

    How it got that way

    The grant programme was restructured toward a smaller set of donated licences with discounts above it. Renewal dates are staggered, so it reaches each organisation on a different day and rarely with warning.

    What we do

    We check what you are actually entitled to now rather than what you were entitled to when it was set up.

    Microsoft for Nonprofits (opens in a new tab)

Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.

Compared honestly

What a generalist provider brings to non-profits and associations

Non-profits are usually offered either a discount or a compromise. The useful version is neither.

  • A generalist

    Quotes the standard rate, sometimes with a discount applied.

    CY6

    Pursues donated and discounted non-profit licensing first, because a large share of the cost is avoidable and finding it is part of the job.

  • A generalist

    Grants access to volunteers on request.

    CY6

    Builds access that is easy to grant and, more importantly, easy to remove — which is the half that gets skipped with rotating volunteers.

  • A generalist

    Reports in technical terms.

    CY6

    Reports in terms a board can act on, because someone on that board has to answer for cyber risk and currently has no answer prepared.

Plenty of generalist providers are good at their job. The distinction here is context, not competence.

Rules in play

What you are likely to be measured against

We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.

  • PCI DSS, where donations are processed
  • Grant and funder data-protection conditions
  • State charitable and breach-notification law
  • HIPAA, for organisations delivering health services

Not sure where you stand?

Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.

Or call 1-855-966-2967