Overview
Some non-profit organizations are not subject to the Personal Information Protection Act (PIPA), except for information collected, used or disclosed for commercial activity.
It depends how a non-profit organization is incorporated whether or not they fall fully under PIPA. Organizations need to determine this and they should be able to tell you. For example, trade unions, condo boards, schools councils and churches are subject to PIPA entirely due to the manner in which they are incorporated.
Commercial activity includes any transaction that is of a commercial character, such as:
- the selling, bartering and leasing of donor or membership lists
- the operation of a private school or early childhood program under the Education Act or a private college under the Post-secondary Learning Act
Accepting donations for charitable purposes is not a commercial activity.
Whether an organization is required to follow PIPA or not, the rules of PIPA provide best practices for the care of personal information. Even when not required, non-profits can voluntarily comply with PIPA.
Resources for non-profits
The following resources are available to help non-profit organizations understand the requirements under PIPA.
Protecting Personal Information: A Workbook for Non-Profit Organizations
- provides space to take stock of personal information your organization collects, uses or discloses
- provides a sample privacy policy and sample privacy statement
PIPA – A Summary for Organizations
Worksheets
- 1 – Is your organization subject to PIPA?
- 2 – Personal information list
- 3A – Purposes for collecting personal information
- 3B – Match it up
- 3C – List the ‘leftovers’
- 3D – Plan to dispose of the ‘leftovers’
- 4 – Our privacy contact
- 5A – Forms your organization uses to collect personal information
- 5B – Sample notice and consent statements
- 6 – Purposes for collecting personal employee information
- 7 – Security practices
Samples
Contact
Connect with the FOIP/PIPA help desk.