DPDP compliance for nonprofits and NGOs
NGOs process donor, beneficiary, and volunteer data — often including sensitive health and financial information. Here is how the DPDP Act applies to the social sector.
What personal data do NGOs process under DPDP?
NGOs collect: donor personal and payment data (name, address, PAN for 80G receipts, bank details); beneficiary data (which may include health conditions, disability status, income, family composition, and location for field programmes); volunteer records (identity, skills, availability); partner organisation contact data; and grant management data from funders. Beneficiary data in health, child welfare, or disability programmes is sensitive — it requires explicit consent and the highest security standards.
Is beneficiary data in health or welfare programmes sensitive under DPDP?
Yes. If your programme serves beneficiaries with health conditions (TB patients, HIV-positive individuals, persons with disabilities, cancer survivors), collects income and financial data for financial inclusion, or documents family circumstances in child welfare work, this is sensitive personal data. Processing it requires explicit consent from beneficiaries or their guardians. Consent must be informed — beneficiaries must understand why their data is collected, who can see it, and how long it is retained, in a language and format accessible to them.
Do donors need to consent to having their data in your CRM?
Donors who make financial contributions implicitly consent to their contact and donation data being retained for the purpose of managing the donation relationship — issuing receipts, sending programme updates, managing 80G certificates. However, using donor data for: public recognition (naming in reports), sharing with partner organisations, or marketing the NGO's other campaigns requires disclosure and, for sensitive uses, explicit consent. Many donor CRMs are used for marketing purposes beyond what donors expected at the time of donation.
How does DPDP apply to international donors and FCRA compliance?
NGOs receiving foreign contributions under FCRA already have significant disclosure obligations. DPDP adds data protection obligations for the personal data of foreign donors in the same way as Indian donors. If your donor management platform is hosted outside India (Salesforce in the US, Donorbox), this involves a cross-border transfer — once the government's transfer list is published, ensure your platform is in an approved country. Many NGOs use global platforms without realising the transfer implications.
What DPDP obligations arise from field data collection on mobile devices?
NGOs collecting field data through mobile apps — health surveys, needs assessments, beneficiary registration — process personal data in the field, sometimes in low-connectivity environments with offline data. Field collection apps must: obtain and record beneficiary consent before collecting data; encrypt data on-device before sync; restrict who can access collected data; and delete data from field devices after sync and verification. Train field staff on consent procedures — a beneficiary who does not understand why their photo is being taken has not given informed consent.
Are NGOs exempt from DPDP because of their public interest purpose?
No. The DPDP Act does not provide a blanket exemption for nonprofits or public interest activities. Certain research and public health processing may have specific exemptions in the Rules, but these are narrow and apply to specific activities, not to the organisation type. NGOs must comply with DPDP in the same way as commercial entities — privacy notices, lawful basis, security safeguards, rights mechanisms, and breach response.
Frequently asked questions
Do we need consent from beneficiaries to share case data with our donors for programme reporting?
Sharing individual beneficiary case data (name, photo, story) with donors for programme reporting requires the beneficiary's explicit informed consent — not just a general programme consent. Many NGOs share identifiable beneficiary data in donor reports, impact stories, and social media without specific consent. Obtain a specific consent for each public use case, and offer beneficiaries the option to participate without their identity being disclosed (anonymised case study). Children's data requires parental consent for any public identification.
How long should we retain donor records?
Retain donation records and 80G certificates for the statutory period under the Income Tax Act — typically 8 years. After the statutory period, delete personal contact data from your marketing database unless the donor has consented to ongoing communication. Donors who have not engaged for several years should be subject to a re-consent or suppression exercise — continuing to hold and market to non-responsive donors without reviewing consent is a DPDP risk.
Does the DPDP Act apply to our volunteer database?
Yes. Volunteers are individuals whose personal data you hold — identity, contact, skills, police verification results in some cases — and they have the same DPDP rights as any data principal. Issue a volunteer privacy notice at onboarding covering what data is collected, how long it is retained, and who can access it. Police verification data (for child protection programmes) is sensitive and should be retained only for the minimum necessary period with strict access controls.
Assess your NGO DPDP compliance
Niti Bharat's DPDP Readiness Assessment covers nonprofits and NGOs — beneficiary data consent, donor CRM obligations, field data collection, and international platform transfer risks.
Start NGO DPDP Assessment