If you collect it, protect it: privacy and cybersecurity for nonprofits 

Picture a small arts nonprofit. Somebody calls the office and wants to give $500 a month. Outstanding! A staffer writes down the card number, drops it into a spreadsheet, and next month, according to plan, a colleague pulls it up and runs the charge again. 

That’s four things that would make Lauren Wu wince. 

In this episode of How to Market Your Nonprofit, host Lee Wochner and privacy and compliance attorney Lauren Wu walk through common scenarios (things that people unwittingly do every day) and give you the three steps you need to do this week before a breach costs you the trust you’ve spent years building. 

Lauren is an expert in privacy law, compliance, and technology — and gives straight answers to questions you may not have known to ask: 

  • Where donor credit card information should actually live (and why your spreadsheet is not it) 
  • The difference between privacy and security, in one sentence you will remember 
  • Why passwords stopped being enough, and why the annoying text message code is worth it 
  • How to run a phishing test on your own team for almost nothing 
  • What should never, ever go into an AI chatbot, and how to use AI safely on contracts, policies, and social media anyway 
  • The questions to ask any vendor before you hand over donor or client data 
  • Where to find attorneys who want a seat on your board seat 

Wondering where to start? 

Lauren breaks it down to three things: Write a basic privacy policy (and then take twenty minutes to walk your team through it). Turn on multi-factor authentication. And limit who can see the sensitive stuff. That’s it. Do those, and you are ahead of most organizations your size. 

Here’s a bonus tip: Stop collecting data you do not need, because the best protected data is the data you never collected. And if it turns out you do need it later, you get to go back and ask, which is one more excuse to talk to a donor. 

Lauren’s advice is clear and doable, even for organizations that are already stretched thin. Give it a listen and share it with your team. 

Find How to Market Your Nonprofit on Apple Podcasts, Spotify, or iHeart Podcasts

Frequently asked questions 

Where should a nonprofit store donor credit card information? 

In a protected, vendor-controlled environment certified for credit card processing. Spreadsheets, note-taking apps, and shared documents are not built to hold payment data, and they leave no record of who accessed or processed a charge. Several payment processors offer nonprofit pricing, and most donation platforms already include this protection. 

What is the difference between privacy and security? 

Security is the locked door. Privacy is what you do behind it. Security covers the physical and technical protections, including passwords, multi-factor authentication, and IT infrastructure. Privacy covers autonomy and how data is collected, used, and shared. You cannot have one without the other. 

What is data minimization? 

Data minimization means collecting as little data as possible, using it for as few purposes as possible, being honest upfront about those purposes, and limiting how many people can access it. As Lauren puts it, the best protected data is the data you never collected. 

Does a small nonprofit really need multi-factor authentication? 

Yes. Passwords alone no longer provide adequate protection, particularly as AI tools make password cracking faster. Multi-factor authentication is inexpensive, often free, and quick to install. Most staff already use it for online banking. 

What should a nonprofit never put into an AI chatbot? 

Donor information, tax records, patient or client data, and identifying company information. Before uploading a contract or a policy for review, substitute placeholder names for people and organizations. AI can still help you review terms and flag concerns without the identifying details. 

Does a nonprofit need an AI policy? 

Yes, and it can be short. Gather a few tech savvy people, agree on which tools staff will use, define what the tools may be used for, and specify what data must never go into them. Include a human reviewer for anything AI produces, since AI can state incorrect information with complete confidence. 

What should a nonprofit ask a vendor before sharing donor data? 

Start by mapping the data you already hold. Then ask the vendor about their data protection and security certifications, whether your data will be used for training and whether that can be limited or turned off, how many people at their organization will have access and at what level, and how and how quickly they will notify you of a breach. Notification responsibilities belong in the contract. 

How can a nonprofit test its staff against phishing? 

Run internal phishing simulations. These send realistic but fake emails or texts to your team, then provide short training to anyone who clicks. The exercises are inexpensive, quick to run, and one of the most effective ways to strengthen security. 

Where should an overwhelmed nonprofit leader start? 

Three things. Write a basic privacy policy and spend twenty minutes walking your team through it. Turn on multi-factor authentication. Limit who can access sensitive data. Then stop collecting data you do not need. 

How can a nonprofit find privacy or legal expertise for its board? 

Post the opening on LinkedIn. Many attorneys are actively looking for board service opportunities, and privacy and compliance lawyers often volunteer advisory time to the boards they join. 

Topics covered in this episode: nonprofit data privacy, compliance, cybersecurity, donor data protection, data minimization, multi-factor authentication, AI policy for nonprofits, phishing prevention, vendor due diligence, breach notification, board governance, and privacy policy templates. 

About the guest: Lauren Wu is a privacy and compliance attorney working at the intersection of privacy law, compliance, and technology. She has served as a chief privacy officer and a data protection officer, primarily in healthcare, where compliance decisions carry direct consequences for patient safety. She teaches as an adjunct professor at Northwestern School of Law and sits on the board of the Surveillance Technology Oversight Project, a nonprofit working in privacy and civil rights. She is also a keynote speaker and executive coach focused on heart-led leadership, and she speaks frequently on AI as an accessibility tool for people with disabilities and neurodifferences. 

Heart Led Leadership, Lauren’s keynote speaking and executive coaching practice 

Surveillance Technology Oversight Project (S.T.O.P.), the privacy and civil rights nonprofit where Lauren serves on the board 

Lee Wochner: 

Data leaks, hacks, phishing scams. Every day, nonprofits face more and more threats to their data. What to do about it? And where to start? Enter our guest, Lauren Wu, a privacy and compliance attorney and expert in cybersecurity, who helps us understand that securing your data is part of how you honor the promises you make. 

To your donors and the people you serve. The good news? It turns out that you don’t need a big budget or an entire tech team. That just adopting a few simple habits will make a big difference in helping you secure your data and the data of people who count on you. No panic required, just a great place to start in keeping your vital information safe on this episode of How to Market Your Nonprofit. 

Jaclyn Uloth: 

Welcome to How to Market Your Nonprofit, the Counterintuity podcast featuring interviews with experts in marketing, fundraising, strategy, and leadership who offer how-tos and inspiration about how you can help your nonprofit succeed and grow during a time of chaos and change. Bringing his 25 plus years of experience in marketing, strategy, and nonprofit management, here’s our host, Lee Wochner. 

Lee Wochner: 

Lauren, thank you for joining us today. It’s really nice to meet you. And I’m going to tell you in just a moment why I’m even more excited than usual to have this conversation today. 

Lauren Wu: 

thank you so much, Lee. I am thrilled to be here. It’s gonna be a lot of fun to have this conversation. 

Lee Wochner: 

So you’ve spent your career at the intersection of privacy law, compliance, technology, chief privacy officer, data protection officer, adjunct professor at Northwestern School of Law. Exactly the expertise nonprofits need right now and don’t always have access to. And let me tell you what happened half an hour ago. So we have a no, no. Thank you, though. 

It, we frequently find that nonprofits for whatever reason have not stayed abreast of these things. They’ve not stayed on top of them. And, one lovely client who do, who does really important work. when we, they were having problems with their website and processing gala tickets and, and donations and all of that. Right. And when we took a look at the site. 

There were two separate installs of the site competing with each other. And part of it was actually being run from a no disrespect to other places in the world. Part of it was being run by a person in Russia who was difficult to get a hold of. So we fixed that. So this morning, we got an urgent message from a brand new client, really good people. They got their site went down. I saw it yesterday. There’s we haven’t, we’ve done nothing with them yet. We just started. We’re starting actually today and here’s why. they, their site went down. They, they don’t trust their current host who is some gentleman and they think it’s him and they wanted us to port it very quickly. So these things happen in the world and people aren’t quite sure where to turn or how to handle these things. 

So this conversation we’re about to have with you is incredibly relevant. 

Lauren Wu: 

Yeah. 

Lauren Wu: 

Yeah, I mean it’s it’s oftentimes not thought of to have a cyber or a privacy person even on the board of these nonprofits, let alone a a person on the team. it’s you know, just not someone that naturally gets thought of, but it’s an essential component. 

Lee Wochner: 

There’s a lot of, and look, I’ll admit in my personal life, I have this every day too, the, I just hope it’s all okay. As they say, hope is not a plan. It’s like, is that all okay? You know? so, so I’m going to just jump in, right? Cause there’s a lot of ground to cover here. And, and I, I’m not sure most of our listeners would even know what to ask or where to go with this, but you are a font of information. here we go. So. 

Lauren Wu: 

No. 

Lauren Wu: 

Yeah. 

Lauren Wu: 

Here we go. 

Lee Wochner: 

Let’s talk about compliance before we get to some of the other aspects. So compliance, complying with privacy laws, complying with the legal arena of what you have to do with your digital presences. When a nonprofit hears the word compliance, I think they often think of red tape, right? It’s like, I’m trying to save the world and… 

Lee Wochner: 

you know, God bless them for doing that, right? We want clean water, we want kids to be healthy, long list of things. We like the trees and the plants and the animals. What does compliance actually mean for a nonprofit, for an organization like that? Why should they care about compliance? 

Lauren Wu: 

Yeah. And you know, I think before I was a compliance officer, that’s what I would have thought too. I would have been like, compliance equals laws equals rules. And who who likes rules? I mean, I speed on the speed limit, right? Like I I mean, okay, no, no cops here, right? Right. No, just kidding. But no, think of it of a in a different way. Instead of thinking of compliance as 

Lee Wochner: 

Right? 

Lauren Wu: 

The rules that are binding you and making things harder. Think of compliance as the promises that you are keeping to the people that you care about the most, your donors, the people you are helping, the the causes that you are trying to do right by. And I always, you know, so I work in healthcare primarily. So I work in the compliance and privacy space of healthcare. 

The people I support, this is life and death. When I do my compliance work, if something goes wrong, this is people’s lives on the on the line. And if it’s not their individual lives, it’s someone’s mother, someone’s father, someone’s sister, child, et cetera. And so I always try to put myself in the place of the patient. 

Or when I’m making a decision or explaining something to someone, I say, put yourself in the position of the patient. So what I would say to all of those folks out there and nonprofits is put yourself in the position of your donor. Put yourself in the position of the person who this quote unquote red tape is meant to protect. And then you’re gonna be on the right side of things, right? And and that process. 

Promise is really a good thing. And 99.9% of the time, if you’re doing that promise, you’re gonna be on the right side of the law. There might be a few things you need to tweak to get the thing right. You know, there might be some organizational thing you need to do, some some checkbox you need to click, but 99.9% of the time, that promise is gonna get you there. 

Lee Wochner: 

So when we say, I just wanna be really specific to help people who work hard and are busy to understand quickly, okay? So when we say compliance with regard to this, what are we proposing that they comply with? What are we talking about here? 

Lauren Wu: 

Yeah. 

Lauren Wu: 

Sure. 

Lauren Wu: 

Sure. So when I talk about compliance in healthcare, what I’m talking about are laws, regulations, and statutes. And that would be true in the nonprofit space, no matter what area you’re talking about. So this could be ethics laws. This could be your financial reporting. This could be your board governance or just your governance in general, right? So your bylaws, your corporate governance. 

Lee Wochner: 

Mm-hmm. 

Lauren Wu: 

This could be how you collect donations, how you do your accounting principles, all of these things. And that’s before we get to privacy. Privacy has its own set of governance, right? And they’re very important governing principles that apply in privacy. And then, of course, if you’re so one of the organizations that I’m sure we’ll talk about later. 

Lee Wochner: 

Mm-hmm. 

Lauren Wu: 

that I’m a part of is called the Surveillance Technology Oversight Project, which is acronym as STOP. that’s one of the nonprofits I sit on the board of. They’re in the space of privacy and civil rights. So, because of the work that they do, they have their own set of governance on top of that because they’re involved in a lot of litigation. So we have additional like legal governance that we need to abide by. 

And so depending on what space your nonprofit is in, there may be additional governance that you need to consider. And that is all what compliance is. It’s compliance, i.e. doing the thing that you need to do to quote, comply, to follow the laws, regulations, statutes, and sometimes organizational principles that apply to your particular nonprofit. 

Lee Wochner: 

So let’s talk about some of the sensitive data, for instance. So donor records, financial data, client, patient data. We have clients we work with in the, that we’ve worked with clinics and hospitals for sure. So if you have a nonprofit that has sensitive data, what should you be doing right now? And what are most of them probably not doing that they should be doing? 

Lauren Wu: 

Healthcare, yeah. 

Lauren Wu: 

Yeah, I mean, so I always I my my quick joke is if you, you know, collect it, protect it, right? Quick little line. So and so that sounds easy to say, harder to do. So MFA, multi-factor authentication. Some of you might have just blacked out right now, being like, what does that mean, Lauren? Well, you’re doing it with your bank records right now. 

Lauren Wu: 

And it’s actually very easy to install. There’s lots of free MFA out there. And a lot of them, the vendors are totally legit, but this is stuff like doing your text message verification or doing where you have a passcode sent to email. Having a multi factor authentication before you access these records internally is key. Designating one 

Person or a few people, very limited people, able to access this sensitive data is also key. If the whole organization is able to access sensitive data, that is inappropriate. Sensitive data should be handled with sensitive care. Think about it this way. Again, put yourself in the position of the individuals whose data that that is. Would you want your medical, your 

Lauren Wu: 

Financial data being accessed by everyone in an organization? No, you would want it handled and accessed by as few people as possible. This is also called the principle of data minimization. Data minimization is about collecting as little data as possible, using it for as few purposes as possible, being honest about the usages that you’re using it for up front. 

and having it accessed by as few people as possible. And that access should be, again, limited to the purposes for which you said you are collecting it. 

Lee Wochner: 

Okay, so let me ask you some purposely dumb questions. So let’s say I have a nonprofit. We’re a small arts organization, right? We just want to put on our shows and Jim calls and makes a donation. He wants to donate $500. I write down his credit card number, his information, all of that. then so, and he says, you know, bill me every month. 

Lauren Wu: 

Love. 

Lauren Wu: 

Okay. 

Lee Wochner: 

another 50 bucks. And so I take that and I just type that into Excel somewhere. No, you’re making a face. I type that into Excel. how about Evernote? I put it in my Evernote. I mean, whatever it is, just I enter it into something. So I have it. then later I say to Sally, who’s on my team, it’s the next month. Look up, look that up and just charge Jim’s credit card. How do you feel about all that? 

Lauren Wu: 

I am in a face. 

Okay. 

Lauren Wu: 

Okay. Well, first of all, using Excel for a purpose like that sounds like a disaster because Excel is not only not necessarily, you didn’t tell me it was a password-protected Excel document. You didn’t tell me that Excel was, you know, in an instance that is, you know, limited to that person. You didn’t tell me it was, exactly, right? And it’s Excel for goodness sakes. Like this. 

Lee Wochner: 

you 

Lee Wochner: 

No, of course not. 

Lee Wochner: 

No, we’re too busy for any of that. We didn’t do any of that. 

Lauren Wu: 

This should that credit card information should be living in a protected vendor controlled environment that has credit card protection, right? But then there are certain vendors that will help nonprofits and give nonprofits credit card information. And I can look those up for someone, I don’t have them top of mind, right? 

Lee Wochner: 

Yeah, yeah. 

Lauren Wu: 

But there are definitely services out there for nonprofits that will help with credit card processing. and you they are certified to do that, right? Excel is not a place, Excel and various other data spreadsheets, not picking on Microsoft and not picking on Excel or Google Sheets. those are not, right? Those are not places. 

Yeah, yeah, yeah. that’s even better. Yeah. 

Lauren Wu: 

That are meant to hold credit card information or Evernotes or what have you. So now passing that off to some rando in the company, I don’t know if this person has been trained on privacy. I don’t know if this person has been told this is sensitive information. And I don’t know if this company even does any kind of privacy information or training to be like, hey, don’t reuse this information. Don’t tell this information to anyone else. 

Lauren Wu: 

And so my concern here is that this information is available to pretty much anyone. There’s no system set up to make sure that this wasn’t already billed. So has this person already been billed monthly? Has this, you know, and then also what is the control for making sure that this information wasn’t changed, making sure that I mean, there’s just so many things wrong with this from a process perspective, let alone a privacy and compliance one. I mean. 

Lauren Wu: 

I’m putting on my business hat and my lawyer hat, being like, this is just messed up. Right. and I think from a board member perspective, I would, I would also be very, very concerned about the lack of traceability and accountability, because I would not, as a board member, be able to audit this. 

Lee Wochner: 

Yeah. 

Lee Wochner: 

What’s that mean? 

Lauren Wu: 

So every year boards should require, a board of director should require that there be an accounting audit. And typically in the audit, there would be an accounting of records, right? Almost in in internet land, that would be like blockchain, right? But there would be a record of who processed accounts payable, who processed accounts receivable, and 

Lauren Wu: 

That’s typically, you know, kept by accounting software. There’s no record in this instance of who processed that credit card information. So how would the accounting audit later say? I think you named her Susie, Sally, okay, sorry. there’s no record of Sally processing this credit card information. So if there is a problem down the line. 

Lee Wochner: 

Sally, think. 

Lauren Wu: 

How would we go back and troubleshoot? How would we go back and audit this? So there’s just so many issues with this process, right? 

Lee Wochner: 

So the probably the probable most beneficial aspect of this part of our conversation, I think, is this. So if you have if you have accounting software, you already have some of this in place. If you have donation software, you probably have this. And we certainly see that with a lot of people we work with. But just the idea of having the conversation and raising the questions makes you think about the data you collect and what might happen with it and how you have to protect it. 

And to be really specific, when you talk about multi-factor authentication, it annoys me, frankly, that I have to do that to access Microsoft Word and anything I’m using. And I have to go to the authenticators on my phone. But every time that I get annoyed, Lauren, I’m like, no, I know we need this, but it’s so annoying. I’m impatient, I want to get stuff done. I’m glad when I go to my online banking the various accounts, whenever I go on, it texts me a number and I enter the number and I’m like, it seems childish, but it’s incredibly important to have all of this. 

Lauren Wu: 

It’s so important. It’s so important. And in the age of AI, where hackers are able to recreate passwords at an just astronomical number, passwords are not sufficient protection anymore in this day and age. And I just cannot emphasize that enough. It is a wonderful first layer. And when I say a password, I do not mean 

Something very basic like one, two, three, four. I do not mean your pet’s name. I do not mean, you know, just changing a few letters here and there. You should be using phrases. You should be using lots of substitutions. Or even, you know, I have to say Apple does a really good job of doing password substitution. I don’t love shouting certain companies out, but I I will say they’re they do a great job on privacy-related products. 

Lauren Wu: 

I use a lot of password holders that are available available virtually for say for things. Make sure if you are in a nonprofit that you are abiding by your policies if you are using one, if you don’t have a policy, write, write a simple one, right? so that you are all doing the same things in one company. 

so that everything’s consistent across people about passwords and protections. And multi-factor authentication, yeah, it it can be annoying, but think of how much safer the data is. And this goes back to our earlier conversation about the promises that you’re making to the most important people in your organization, which are your donors and the people and causes that you are protecting. 

Lee Wochner: 

So, and by the way, we still live in a world where the most popular password is password. It’s true. 

Lauren Wu: 

I mean, it’s true. And and the thing is, right, there’s so again, come from healthcare. A lot of machines that some of my former employers have, they have hard-coded passwords when they first get deployed. And then you’re supposed to change the passwords once it’s deployed into a hospital or what have you. I’m and I’m talking about like your CAT scan machines and things like that. Do you know how often people in those facilities don’t change the hard-coded passwords. I mean, that’s terrifying to me as a privacy person. and so, you know, one of the things that I would do is make sure my sales teams would be like, hey, once we’ve deployed like part of the relationship is, hey, have you changed your password from the hard-coded password so that, you know, it’s 

Lauren Wu: 

Not the standard password that’s in the, you know, manufacturer’s handbook that can be looked up by any hacker or random person online. and think about that, right? Like this is people’s medical technology. So yes, change your passwords, please. 

Lee Wochner: 

So let’s talk about cybersecurity for a little bit. there are multiple problems here that you wanna head off by having better policies and processes. What’s the difference between a privacy problem and a security problem? And how should these be handled a little differently or in conjunction? Privacy problem, security problem. 

Lauren Wu: 

I love this question because security is your locked door and privacy is the stuff you do behind the door, right? Privacy is your autonomy, your data, your your infrastructure. But security is the locked door, whether that’s physical, like my physical front door being locked, or whether that’s your computer, password, and an MFA. And the two go together. You can’t have one without the other. Now, when it comes to protecting privacy, how you do that protection is not only through cybersecurity, but also through collecting less data, collecting only the data you need, and making sure that access is limited. You do it through cyber, through the MFA that we talked about, through having good IT infrastructure, through having 

Contact with a CISO, a chief information security officer, or someone similar if you can’t, if the nonprofit is not at a position where they can afford someone like that, which can be outsourced, by the way. And or you can get someone on the board like me who has knowledge about that and can help advise on cyber matters. 

And you know, one of the things about cybersecurity that is fascinating is, you know, you can build cyber into things like your infrastructure relatively easily nowadays. what I’m seeing that is a really easy cyber and I think kind of fun, but I’m kind of geeky about this, exercise that you can do internally is. 

Phishing, and I don’t mean F-I-S-H-I-N-G, but P H fishing. And those are exercises that you do where you send out fake emails or fake texts, and you basically pretend to be someone trying to get at information in the company. And you see who falls for the exercise, and then give those folks privacy training or security training to be like. 

Lauren Wu: 

Hey, this was fake. And if this had been a hacker, they would have gotten access to our infrastructure. And that is a quick, easy, and super cheap way to help bolster security inside of your nonprofit. 

Lee Wochner: 

You know, I’m glad you just brought that up. We have that as a protocol here. So every week, everybody on the counterintuity team is asked to, it’s an outsourced program, it’s very inexpensive, and we watch a little video and we answer some questions and it informs us on what to watch out for. And then it will send out what look like real emails now and then. And then we… 

Lauren Wu: 

Yeah. 

Lee Wochner: 

On the weekly team meeting, we’ll hear about, know, somebody clicked on it. We would have been hacked. never out who it was. Anybody could make the mistake. It was me once. I wasn’t proud. Yeah. Right. But you got to look very closely. The thing that looks like it’s from your bank, but instead of an, it says it’s a zero. If you look really closely, it was not your bank and you could have lost your, your money. So I’m glad. Yeah. 

Lauren Wu: 

If it makes you feel better, I almost fell for one at my last job. And I’m an expert, right? and I remember what it was because it really almost got me. It was, it was a fake email from HR claiming to be giving every employee during COVID times an Amazon gift card because they were working from home and they wanted to just reward everyone. And I was like, 

Lauren Wu: 

Wow, that’s so generous of HR. And I was like, wait a minute, HR’s not that nice. And that’s what triggered me was I was like, wait a minute, that seems suspicious. 

Lee Wochner: 

Yeah. 

Lee Wochner: 

want to, I want to ask you a little bit about AI because you brought up AI and, we know nonprofits are adopting AI tools quickly and, you know, we’re using AI and there’s a lot of benefit there, but what about the level of scrutiny? I mean, what privacy and compliance risks come with using AI and what might you be able to do to mitigate those? If you’re a nonprofit in particular where. 

Lauren Wu: 

Yeah. Sure. 

Lee Wochner: 

know, frequently understaffed, overworked, trying to heal the world. And there are predators out there just trying to get access. 

Lauren Wu: 

Yeah, phenomenal question. AI is essential for moving forward and scaling. And frankly, and this is something I talk about when I give keynote speeches, AI is an accessibility tool. So for those nonprofits that also employ folks with disabilities, different abilities, neuro differences, AI can also be a way to kind of level the playing field across. 

people and a way of ADA accommodation. So AI, amazing. AI is also a way you can get into trouble very quickly with data. So I love this question. Here’s how you can protect yourself and your company and still use AI very safely. First, you should have an a very basic AI policy governing your use of company AI and AI tools. So 

Pull together a group of people or one person who is pretty tech savvy in your company or nonprofit rather, and say, hey, what tools are we gonna all agree to use for now? And that can change. It can be fluid, right? this is not set in stone or cement. And agree on those tools and then agree to a basic framework of what you’re willing to use it for, and just set up some parameters of. 

What the use of cases are, what data you’re willing to put into it and not willing to put into it. And here’s the data that should never, ever, ever, ever, ever be put into it. People like your donors’ information, tax information. I know you’ll hear on there, throw tax information in there and you’ll discover all of these amazing tax savings. No, do not do that. Do not, as a nonprofit, do that. 

Lauren Wu: 

without anonymizing all of the information. And anonymizing means pulling out any identifiable information. there are really great ways that these services can help find deductions and things, but you need to be extremely careful about the data that you’re putting in. So I would recommend at this point in time not doing that. 

Lauren Wu: 

Do not put in any patient information. Do not put in company information. I would always fill in like X company, blah, blah, blah, blah, blah. If you’re negotiating a contract, for instance, take out the names of the company, put in an X or put in ABC company, put in substitute names. 

Never use the actual names of individuals, never use the actual names of companies. Always substitute those things. And then the AI can actually still help you negotiate the contract. It could help you review the terms. It can help you with social media, but never use people or companies’ actual names. And that will help protect you. 

what I would also recommend with AI is never use it as your actual therapist, by the way. I’m just gonna shout that out. That’s there’s a lot of prote so this goes beyond nonprofits, but I just would be remiss to your listeners to not mention this. There are extra protections for individuals for mental health records that are not available to chatbots. 

Lee Wochner: 

You 

Lauren Wu: 

But are available to actual psychiatrists and therapists. And the next generations, especially Gen Z and Gen Alpha, are using chatbots as therapists and sometimes even as doctors. And those HIPAA protections do not extend to chatbots. So please, please, please do not use them if you ever were to go to court and wanted to protect your medical records. 

Lauren Wu: 

Those protections would not extend. And I just would be remiss to not mention that. And that’s another reason why you would never want to upload patient information into these bots, is because those protections don’t apply. So use them, but have this infrastructure. Another thing I would recommend with AI is always have a human decision maker involved. 

And I say this because AI hallucinates. So, and hallucinates by the me way for those who don’t speak AI, means it makes mistakes. And when AI makes mistakes, it will say it with the fullest gut, you know, yes, I am right. I have had AI tell me a case exists when it doesn’t. And I have been like, 

Lee Wochner: 

Mm-hmm. 

Lauren Wu: 

I know for a fact that that case does not exist, AI, and it’ll be like, yes, it does. It is this and this and this in this court. And I’m like, it does not exist. Please stop telling me it exists. It is this case in this district, in this thing. And they’ll be like, you’re right. And I’m like, yes, I know I’m right. I’m the lawyer. You are not the lawyer. And so, you know. You have to push back and you need to be the human element and the reviewer and decision maker. And I really want to make sure that that is emphasized. Always review what AI gives you, always push back. And there’s cheat codes in certain AI bots where you can help. So, like in Claude, if you I think it’s bac front slash devil, it’ll give you the devil’s advocate side of things. uh-oh. TA is another one where it will do military style reasoning in Claude. Yeah, there’s different cheat codes you can look up in Claude. ChatGPT just released their their answer to Claude co-work. I haven’t played around with that as much because it’s brand new. And I imagine there’ll be similar cheat codes. But there are different ways that you can challenge the vis. 

Lauren Wu: 

Spots so that they’re arguing with themselves to get to the right answer. But ultimately remember the it’s the human being who’s responsible. And in your policies, I highly recommend there always be an element of human judgment involved. and also this should be there just because we’re humans, and that is part of ensuring that we maintain. 

emotional and you know integrity in our workplaces and make sure that you know we are humanizing the work environment and not just relying on our AI counterparts. They should help with capacity and help with the work and not become the work, if that makes sense. 

Lee Wochner: 

Excellent advice. We’re gonna take a short break here, but when we come back, Lauren and I dig into some of the bigger picture thinking behind all this and advice for nonprofit leaders navigating all this. Stick around. 

Jaclyn Uloth: 

Most people assume their hosting company handles website security. It doesn’t — not all of it. There’s a gap between what hosting covers and what WordPress requires, and cybercriminals know exactly where it is. We broke it all down in our latest Counterintelligence briefing. Read the full article at counterintuity.com. 

Lee Wochner: 

And we’re back with privacy and compliance attorney and expert, Lauren Wu. I want to follow up on a couple of things we were talking about. What questions should a nonprofit ask a vendor before feeding donor or client data into anything, an AI product or anything else? How do you, if you’re installing a new platform you’re working with, et cetera, 

What are the safeguards that you can erect to get started? 

Lauren Wu: 

Yeah, this is this is really important. and it’s, you know, first necessary to understand what data you have in your environment. So I would always recommend starting there, do a data mapping exercise and really understand the data you have in your own environment before you ever start approaching vendors or putting it into an AI space. So first start with your own data map and understand what’s there. 

understand your own data categories because especially if you deploy a vendor infrastructure into your own environment that will potentially map the data. If you don’t have a base idea of what’s there, what if it’s wrong? Right. And then you you won’t know like it’s wrong because you haven’t taken the time to be like, okay, we have vendor data, we have donor data, we have this data, right? So when you go to the vendor 

Lauren Wu: 

Some the first questions I would ask is what are your certifications for data protection and security? If they don’t have any, why don’t they have any? Right? And if they’re brand new, okay, cool, but like how are you going to protect my data? and you know, with the newer AI companies, that’s kind of an issue because a lot of them are startups. And so again, how are you protecting my data? Two. 

Lauren Wu: 

Are you going to use my data to train anything in your environment? If so, can you keep it isolated so that it doesn’t train outside of my environment? It only trains internally to my ecosystem. And if not, if it will automatically go outside, is that a requirement or is that something I can turn off? Right? Because a lot of times you can say, I only want the training done on my own environment. 

Lauren Wu: 

Or I don’t want any training done on my data. And that’s something, by the way, you can you can and should also when we were talking about AI earlier, make sure in your AI instances that you have memory set to only your own environment, that you’re not training on everything else. Cause that’s a protection I always have set for myself as well. And frankly, that should be your own personal thing, not just for your company. 

Lauren Wu: 

Another question I would ask is what access is going to be given to the data in my account in your organization? So who’s going to have access, how many people, what levels of access, though that type of information. Because just like you want to have internal limitations on access to data, you want them to have limited or limited access. Then you want to also kind of kick the tires on 

what exactly they’re doing with your data, how they’re doing it. Then you want to start talking about if there is a breach of data, how will they give you notice? How quickly they will give you notice, who will handle giving notice to the affected individuals. And this is all stuff that you would negotiate in the contract because are you the responsible party or are they? Because 

So this is where we get into some of the lawyer terms, like data controller, like who’s the one who controls the data? And that should be you, by the way. You are the data controller if it’s your data, like your donors, your patients, versus data processor, which is typically the vendor. if we’re in HIPAA land, that would be a 

Lauren Wu: 

business associate is the vendor versus you know your your your covered entity sorry it took me a minute to find that word covered entity which is your typically your doctor your hospital etc so you know depending on the law that is applying there’s a different term but basically it all comes down to the same types of concepts 

Lauren Wu: 

Who’s the person who has the relationship with the data subject? And who is the person that has the obligation if there’s a breach? And who is the person that is touching the data, maybe analyzing the data, processing the data, doing things with the data? All of that needs to be negotiated in the contract, but you need to understand what is happening. 

Also, sometimes you might want to know what their policies are. that’s something I always ask for. that’s helpful. Nonprofits may not have time for that. And that’s fair. that’s something that I would do when I would be in my big corporations, but honestly, I could see a nonprofit not necessarily asking for the policies. And that’s sometimes, you know, you you have to give and take a little bit depending on the size of your organization. 

Lauren Wu: 

On what you have time to do for a review of contracts. And that’s okay. but cheat code here from you know attorney Lauren, if you ask for the policies, that’s always something you could upload into AI to review. Again, taking out the company information because you don’t want to upload the company information, but just say, hey, AI, review these company policies on privacy and security, and tell me if there’s anything 

Lauren Wu: 

that’s a red flag or substandard that I should be concerned about, I’m considering hiring them as a vendor. 

Lee Wochner: 

Excellent tip. Excellent. Using AI for good. 

Lauren Wu: 

Right? 

Yes. And that’s also a great way to review that contract if you don’t have a lawyer. Send the contract in, take out the con the company names. Hey AI, I’m a nonprofit. I am in the process of potentially hiring this vendor. Here are the contract terms. Here’s what I’m concerned about. Please review this contract. These are great uses of AI. 

Lee Wochner: 

Yeah. 

It’s also good to have an attorney on your board though, or have someone who will do some pro bono work for you. Yeah. 

Lauren Wu: 

And that’s why people hire attorneys for their boards. Honestly, I volunteer a lot of my time doing this type of advisory work for the boards that I sit on. And I have lots of colleagues who do the same thing. And I have to tell you, there’s a lot of attorneys out there that are looking for board opportunities. So, you know, how I found my not my stop board opportunity, but my one of my other board opportunities was via LinkedIn. 

So if you are looking for a board member, advertise on LinkedIn and you would be surprised how many folks you might get who would be interested. 

Lee Wochner: 

Awesome. So this is a lot, right? Everything you’re talking about and we really want to make sure that people can do what they need to do. And I appreciate your sensitivity to, if you don’t have this, do that, right? And that’s important. So let me ask the money question here, the big question. So the big question, here it comes. And I’ve run nonprofits, Lauren. So you’re like triggering me. No, no, it’s real. This is a very important conversation. We see people getting hacked all the time. Sadly, you know, we’ve gone in and fixed a whole bunch of situations in our two decades in business here where, you know, something wasn’t operating right or, you know, somebody was nefarious. So if you’re a nonprofit leader, who is listening right now and there’s cold sweat running down your forehead from this conversation and you feel overwhelmed by all this, right? Because it’s a lot. So if you know, there’s compliance, there’s cybersecurity, there’s AI, they’re on top of everything else on their plate. How should they get started? What’s the baseline thing that gets them on the path to where we hope they can get to? 

Lauren Wu: 

for life. 

Lauren Wu: 

First, don’t panic. It’s gonna be okay. And it really will be. It really will be. And it’s it, you know, truly the fact that you’re worrying about it is actually like the best thing because it shows you care. And that to me is everything. The fact that you care about privacy, the fact that you want to do the right thing as a compliance officer and privacy officer. 

That means everything. So the first thing you do is remember: if you collect it, protect it. So write a very basic privacy policy. That’s it. That’s your first step. And if you’re like Lauren, I don’t know how to do that, you go to AI, you say, or you Google, if you’re like Lauren, I don’t do AI, you Google or Bing, or whatever search engine you want, you say, Please help me with a nonprofit template privacy policy. Done. Fill in the blanks. Done. And then you train your team on it. And what you say is to your team, and when I say train, I’m not talking about a boring hour-long presentation. I’m talking a 20-minute, hey everyone, we collect a lot of. Very sensitive information like people’s donor information, people’s patient information, et cetera. Whatever it is, it’s important we protect it. I created this privacy policy, or whoever created this privacy policy, we’re gonna do our best to abide by it. It’s a first draft. We’re gonna iterate as we grow. And it’s important that we just do our best to make sure we don’t. 

XYZ, right? Like abuse the data, you know, use it for purposes that we didn’t collect it for, access it when we don’t need it, etc. And that’s it. That’s the first step. And then you protect it, you make sure it’s password protected, you put in the MFA. And again, MFA is very easy to install and very inexpensive, and you limit access. And if you do those two things, you are already doing a lot. 

Lauren Wu: 

And again, if you don’t need it, don’t collect it. The best protected data is the data you didn’t collect. So don’t collect it if you don’t need it. And I tell this to my my folks, my the you know, who I work with all the time. And I always hear this in response. But Lauren, we might need the data. Well, then collect it when you need it. Right? Like if you might need the data, great. You will have the contact information to collect it later. And that’s awesome because then every time you’re in front of that person, that’s another opportunity to collect more money because you’ll be like, hey, look, we have this new cause. Please give us more money. Isn’t that smarter than using up all of your opportunities to collect money and contact them in one swoop? No. 

Think, collect it later when you’re like, hey, we’ve got this new avenue. Here you go. And by the way, this is like going to be this new drive. Would you happen to want to make another donation? It’s the perfect opportunity for another reach out. So collect it later. 

Lee Wochner: 

And I think if you’re talking to donors and saying you protect data, it just makes them feel better about supporting you. 

Lauren Wu: 

Yes. It goes back to our start of our conversation. This is the promise that you are giving them. I am more likely to donate to a cause that has a good privacy policy that is willing to protect my data than some fly by night cause that I’m like, can I even trust your website? Like, I’m not gonna give you my credit card information if it looks shady. Like, I mean, come on. So honestly. 

Lauren Wu: 

Three things, right? Don’t collect it if you can’t protect it. Basic privacy policy with a training, super simple training, MFA with passwords. Three things. You can do that. 

Lee Wochner: 

Wow, really, really helpful information. And I gotta say again, just the shift in mindset will be helpful for people after listening to this. Lauren, if people wanna reach out to you, if they wanna get in touch, what’s the best way? 

Lauren Wu: 

Yeah, you can reach me at my email address at HeartLed Lauren at gmail. I have a website, heartledleadership.org. When you go to it, you’re gonna be like, this has nothing to do with privacy. And you’re right, it doesn’t. It’s all about keynote speaking and executive coaching, which is really my what I’m doing right now and focusing on. but my daytime job is all about privacy and compliance. And that’s the best way to reach me. I’m also on LinkedIn at Lauren Foster Woo. I’m on Insta at HeartLed Lauren. And those are the different ways you can reach me. But I’m always happy to get help and give advice where I can. you know, it’s this stuff is really important, and I don’t want anyone to feel overwhelmed. it’s a lot, but 

There are so many great people out there looking for board members. I really want to emphasize that. I can’t, I know at least five attorneys right now who are like, Lauren, I’d love to be on a board. And I so if you are looking for board members, like put it out there in the universe and you would be surprised. because there are some really great privacy lawyers who would love to sit on boards. And you might get what you’re asking for. So I’m always a big fan of just putting things out there in the universe and you never know what you might get. 

Lee Wochner: 

Lauren, thank you for joining us today and thank you for the work you’re doing to help organizations use data responsibly and protect the people they serve. Thank you so much. 

Lauren Wu: 

it’s my pleasure. This has been wonderful. 

Jaclyn Uloth:  

Thanks for listening. How to Market Your Nonprofit is available on Apple Podcasts, Spotify, and wherever you get your podcasts. Please like and follow the show. Visit counterintuity.com to learn more. 

Scroll to Top