Privacy · Multi-state requirements

Your nonprofit may be holding rights—not merely data.

Oregon, Delaware and Maryland have moved qualifying nonprofits into comprehensive privacy frameworks. CauseWorkHub turns those rights into connected, accountable work.

CauseWork Research Desk · Updated August 24, 2026 · General information, not legal advice
A protected central person record connected through controlled pathways to nonprofit forms, CRM profiles and case records
Privacy rights reach every place a nonprofit collects, uses, shares, corrects, retains or deletes personal data.

Nonprofits have spent years hearing that consumer privacy laws are mainly a problem for technology companies and commercial data brokers. That assumption is no longer safe.

Oregon, Delaware and Maryland have each enacted comprehensive privacy laws that can reach qualifying nonprofit organizations. The exact thresholds and exemptions differ, but the operational message is consistent: an organization that collects personal data may need to explain what it holds, minimize what it keeps, protect sensitive information and respond when a person asks to access, correct, delete or obtain their data.

CauseWorkHub is the solution.

Privacy rights should not create another disconnected compliance system. CauseWorkHub is being built so the person record, consent, request, responsible employee, affected forms, connected case or CRM data, decision, exception and completion evidence can remain inside one nonprofit operating system.

One governed identity →Find the individual across supporter, donor, community, CRM and organizational relationships without recreating them in separate lists.
First-party request forms →Receive privacy requests through accessible CauseWork forms rather than surrendering the request and its data to another form vendor.
Permission-aware review →Locate responsive records without exposing restricted case, vulnerability or program information to people who should not see it.
Assigned response work →Give each request an owner, deadline, verification steps, discussion and documented completion.
Visible accountability →Leadership can see request volume, unresolved risk, policy decisions and recurring failures without reading sensitive contents.
Evidence and provenance →Preserve what was requested, what systems were checked, what decision governed the response and when it was completed.

Three states already make the nonprofit question unavoidable

DelawareEffective January 1, 2025The Delaware Department of Justice says the law applies to both for-profit and nonprofit businesses that meet its thresholds.
OregonNonprofits since July 1, 2025Oregon applies the same comprehensive privacy requirements to qualifying nonprofit controllers.
MarylandEffective October 1, 2025The Maryland Attorney General states plainly that nonprofits are not categorically exempt.
The practical lessonLocation is not the whole testAn organization outside a state may still be covered when it targets or serves residents and crosses the applicable data threshold.

The thresholds differ—and must be tracked honestly

Delaware applies to entities conducting business in Delaware or targeting Delaware residents when they controlled or processed personal data for at least 35,000 consumers in the prior calendar year, or at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data.

Maryland uses the same 35,000-consumer threshold and the same 10,000-consumer plus 20-percent-of-revenue alternative. Its Attorney General expressly says nonprofits are not exempt if they meet the threshold and lack another applicable exemption.

Oregon applies at 100,000 consumers, or 25,000 consumers plus more than 25 percent of annual gross revenue from selling personal data. Oregon’s nonprofit effective date was July 1, 2025.

Do not turn the thresholds into false comfort.

A nonprofit below a current statutory threshold still needs to know what it collects, where it lives, which vendors receive it and how a person can obtain meaningful help. Thresholds change, organizations grow, and contracts can impose duties even when a statute does not apply directly.

The rights become operational workflows

These laws are not satisfied by adding a paragraph to a privacy policy. Delaware, Oregon and Maryland establish combinations of rights involving access, correction, deletion, portability, consent and opt-outs. The organization needs a reliable way to receive the request, verify the requester appropriately, locate responsive data, apply lawful exceptions, act across processors and preserve the response history.

Access requires an inventory

An organization cannot reliably tell a person what it holds if data is scattered across a CRM, form service, email platform, spreadsheets, case software, event tools and cloud drives. CauseWorkHub reduces that fragmentation by connecting people, forms, CRM relationships, cases, community interactions and governed files around one identity spine.

Correction requires provenance

Changing a mailing address is simple. Changing a disputed program record, eligibility fact or case note may require context, authorization and preservation of history. CauseWorkHub’s direction is to distinguish correction from silent overwriting: who requested the change, what changed, who approved it and what prior record must legally remain.

Deletion is a governed decision

A deletion request does not mean every record can always disappear immediately. Grant, tax, employment, litigation, safeguarding and service obligations may require retention. CauseWorkHub can route the request to the responsible people, document the applicable decision and delete or restrict data where appropriate without pretending every record has the same rule.

Opt-outs and consent must reach the systems that act on them

An opt-out trapped in a form inbox is not a functioning opt-out. Preference and consent status must connect to the communication, community, CRM and public-form workflows that use the data. CauseWorkHub’s first-party model allows the request and the operating action to share the same accountable environment.

THE CAUSEWORKHUB SOLUTION

CauseWorkHub puts privacy rights in the operating backbone.

Connected in CauseWorkHubOrganization-controlled hosting, people and organization records, role-aware workspaces, cases, files, forms, assignments, conversations and activity history.
CauseWorkHub workflowRequest intake, identity verification, data-location mapping, consent and preference handling, controlled exports, deletion review and processor coordination.
Continuously expandingA dedicated privacy-request workspace, statutory deadline tracking, exception decisions, processor tasks, portable response packages, recurring assessments and System Health reporting.

Self-hosting changes the power relationship

CauseWorkHub does not centralize every nonprofit’s operational data inside CauseWork. Each nonprofit controls its own isolated Hub and its own hosting relationship. That does not eliminate privacy responsibility, but it removes an unnecessary platform-level copy of donor, client, employee and community data from CauseWork’s possession.

The nonprofit still needs appropriate hosting, security, contracts, policies and legal advice. CauseWorkHub’s job is to make the organization’s own responsibilities easier to perform and easier to prove—without charging enterprise-software prices for basic stewardship.

This is why CauseWork connects the entire request

A privacy request can touch People and CRM, Community, Forms, Cases, Files, Governance, Work and Audit Readiness at the same time. Buying a separate privacy portal does not automatically connect those systems. CauseWorkHub is the solution because the request resolves where the data and responsibility already live.

Primary sources

Accessibility is operational accountability.

Explore how CauseWorkHub connects forms, people, assignments, documents, product status and organizational responsibility in one nonprofit operating environment.

Explore the live demo

THE BUILD KEEPS MOVING

Stay close to what CauseWork solves next.

Release news, product commitments, nonprofit research and the path to purchase—sent deliberately, never constantly.