DONOR PRIVACY POLICY
1. PURPOSE
This Policy establishes standards for protecting donor information, ensuring legal compliance, and promoting transparency and trust. It applies to board members, officers, employees, contractors, and volunteers.
2. SCOPE
This Policy applies to all donor information collected through online platforms, events, direct mail, broker transfers, IRA distributions, grants, and third-party fundraising tools.
3. LEGAL COMPLIANCE (WASHINGTON STATE)
The organization shall comply with applicable federal and Washington State laws including:
- Washington Nonprofit Corporation Act (RCW 24.03A)
- Washington Consumer Protection Act (RCW 19.86)
- Washington Data Breach Notification Law (RCW 19.255.010)
- Washington Charitable Solicitations Act (RCW 19.09)
- IRS disclosure requirements under IRC Section 6104
- Payment Card Industry Data Security Standards (PCI-DSS)
The organization shall maintain registration with the Washington Secretary of State Charities Program and comply with required annual filings.
4. DATA COLLECTION PRINCIPLES
- Collect only information necessary for charitable purposes.
- Inform donors how their information will be used.
- Do not sell, rent, or trade donor information.
- Respect donor anonymity requests when legally permissible.
5. USE OF DONOR INFORMATION
Donor data may be used for processing donations, issuing tax receipts, stewardship, donor recognition (unless anonymous), analytics, and legally required reporting.
6. DATA SHARING
Donor data may be shared only with authorized personnel, contracted service providers under confidentiality agreements, professional advisors, and government agencies when legally required.
7. DATA SECURITY
- Use secure, password-protected systems.
- Limit access by role.
- Encrypt online transactions.
- Avoid storing full credit card numbers unless PCI compliant.
- Conduct periodic risk assessments.
- Maintain cybersecurity insurance protection and insurance.
8. DATA RETENTION
Donation records shall be retained for at least seven (7) years. Governing documents are retained permanently. Sensitive payment information shall not be retained unless PCI compliant.
9. DONOR RIGHTS
Donors may request access, correction, anonymity, removal from mailing lists, or deletion where legally permissible. Requests will be acknowledged within 30 days.
10. DATA BREACH RESPONSE
In the event of a suspected or confirmed breach:
- Contain and assess the breach immediately.
- Notify the Executive Director and Board Chair.
- Consult legal counsel.
- Determine scope and affected individuals.
- Provide notification consistent with RCW 19.255.010.
- Document incident and corrective action.
- Report to Board of Directors.
11. BOARD OVERSIGHT
The Board shall review this Policy annually, monitor compliance, ensure appropriate internal controls, and oversee risk management practices.
12. Publication of Donor Privacy Policy
RFK will display the donor privacy policy statement on the RFK website and any software tools used by RFK that collect donor data.
PUBLIC DONOR PRIVACY NOTICE
This Donor Privacy Notice explains how we collect, use, and safeguard your personal information.
We collect your name, contact information, donation history, and payment details solely for charitable purposes. We do not sell, rent, or trade donor information.
We maintain appropriate physical, electronic, and procedural safeguards to protect your information. Donors may request access, correction, or removal from communications at any time.
Our organization is registered with the Washington Secretary of State Charities Program as required under RCW 19.09.
For questions regarding this Notice, please contact:
Rehema for Kids
Adopted by the Board of Directors
Effective Date: 2026.04.28
Last Reviewed: 2026.04.28
DATA BREACH RESPONSE FLOWCHART
Step 1: Incident Detected
↓
Step 2: Contain & Secure Systems
↓
Step 3: Notify Executive Director & Board Chair
↓
Step 4: Engage IT & Legal Counsel
↓
Step 5: Assess Scope & Identify Affected Individuals
↓
Step 6: Determine Reporting Obligations (RCW 19.255.010)
↓
Step 7: Notify Affected Individuals (if required)
↓
Step 8: Implement Corrective Actions
↓
Step 9: Report to Board & Document Incident