Nonprofits have spent years hearing that consumer privacy laws are mainly a problem for technology companies and commercial data brokers. That assumption is no longer safe.
Oregon, Delaware and Maryland have each enacted comprehensive privacy laws that can reach qualifying nonprofit organizations. The exact thresholds and exemptions differ, but the operational message is consistent: an organization that collects personal data may need to explain what it holds, minimize what it keeps, protect sensitive information and respond when a person asks to access, correct, delete or obtain their data.
CauseWorkHub is the solution.
Privacy rights should not create another disconnected compliance system. CauseWorkHub is being built so the person record, consent, request, responsible employee, affected forms, connected case or CRM data, decision, exception and completion evidence can remain inside one nonprofit operating system.
Three states already make the nonprofit question unavoidable
The thresholds differ—and must be tracked honestly
Delaware applies to entities conducting business in Delaware or targeting Delaware residents when they controlled or processed personal data for at least 35,000 consumers in the prior calendar year, or at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data.
Maryland uses the same 35,000-consumer threshold and the same 10,000-consumer plus 20-percent-of-revenue alternative. Its Attorney General expressly says nonprofits are not exempt if they meet the threshold and lack another applicable exemption.
Oregon applies at 100,000 consumers, or 25,000 consumers plus more than 25 percent of annual gross revenue from selling personal data. Oregon’s nonprofit effective date was July 1, 2025.
A nonprofit below a current statutory threshold still needs to know what it collects, where it lives, which vendors receive it and how a person can obtain meaningful help. Thresholds change, organizations grow, and contracts can impose duties even when a statute does not apply directly.
The rights become operational workflows
These laws are not satisfied by adding a paragraph to a privacy policy. Delaware, Oregon and Maryland establish combinations of rights involving access, correction, deletion, portability, consent and opt-outs. The organization needs a reliable way to receive the request, verify the requester appropriately, locate responsive data, apply lawful exceptions, act across processors and preserve the response history.
Access requires an inventory
An organization cannot reliably tell a person what it holds if data is scattered across a CRM, form service, email platform, spreadsheets, case software, event tools and cloud drives. CauseWorkHub reduces that fragmentation by connecting people, forms, CRM relationships, cases, community interactions and governed files around one identity spine.
Correction requires provenance
Changing a mailing address is simple. Changing a disputed program record, eligibility fact or case note may require context, authorization and preservation of history. CauseWorkHub’s direction is to distinguish correction from silent overwriting: who requested the change, what changed, who approved it and what prior record must legally remain.
Deletion is a governed decision
A deletion request does not mean every record can always disappear immediately. Grant, tax, employment, litigation, safeguarding and service obligations may require retention. CauseWorkHub can route the request to the responsible people, document the applicable decision and delete or restrict data where appropriate without pretending every record has the same rule.
Opt-outs and consent must reach the systems that act on them
An opt-out trapped in a form inbox is not a functioning opt-out. Preference and consent status must connect to the communication, community, CRM and public-form workflows that use the data. CauseWorkHub’s first-party model allows the request and the operating action to share the same accountable environment.
CauseWorkHub puts privacy rights in the operating backbone.
Self-hosting changes the power relationship
CauseWorkHub does not centralize every nonprofit’s operational data inside CauseWork. Each nonprofit controls its own isolated Hub and its own hosting relationship. That does not eliminate privacy responsibility, but it removes an unnecessary platform-level copy of donor, client, employee and community data from CauseWork’s possession.
The nonprofit still needs appropriate hosting, security, contracts, policies and legal advice. CauseWorkHub’s job is to make the organization’s own responsibilities easier to perform and easier to prove—without charging enterprise-software prices for basic stewardship.
This is why CauseWork connects the entire request
A privacy request can touch People and CRM, Community, Forms, Cases, Files, Governance, Work and Audit Readiness at the same time. Buying a separate privacy portal does not automatically connect those systems. CauseWorkHub is the solution because the request resolves where the data and responsibility already live.
