Donor Data Security: What Nonprofits Need to Know About PCI Compliance

Published On: September 9, 2026

Every time a donor enters their card number to give, they’re trusting an organization with more than just a payment.

That trust comes with a legal responsibility most nonprofits didn’t sign up to think about when they started fundraising: PCI compliance.

PCI DSS, the Payment Card Industry Data Security Standard, is a set of security requirements created by the major card networks to protect cardholder data. It isn’t optional, and it isn’t just for large retailers. Any organization that accepts, processes, stores, or transmits credit card data has to comply, including nonprofits accepting donations online, by phone, or at in-person events.

Why This Applies to Nonprofits Too

It’s an easy mistake to assume PCI compliance is a problem for e-commerce companies and banks, not a small nonprofit running a few campaigns a year.

But the requirement isn’t based on organization size or sector. It’s based on whether card data touches your systems at all. A donation form on a website, a virtual terminal used to take gifts over the phone, and a card reader at a fundraising gala are all covered under the same standard.

The current version, PCI DSS 4.0, became fully mandatory in 2025, and it raised the bar in several ways that specifically affect how nonprofits run their donation pages.

What Changed With PCI DSS 4.0

A few of the updated requirements matter most for organizations running online donation forms:

  • Every script that can access the payment page, including third-party analytics or tag manager code, now needs to be authorized, inventoried, and monitored, to guard against skimming attacks hidden in seemingly unrelated code
  • Multi-factor authentication is now required for anyone with access to systems that touch cardholder data, not just system administrators
  • Donation pages need regular external vulnerability scans performed by an Approved Scanning Vendor

These changes exist because card-skimming attacks have increasingly targeted the checkout page itself, not just backend databases, which makes donation forms a real target, not a theoretical one.

The Easiest Way to Reduce the Burden

Full PCI compliance sounds like a significant undertaking, and for an organization handling card data directly, it can be. But most nonprofits never need to take on that burden themselves.

If a donation form redirects to, or is hosted entirely by, a payment processor that is itself PCI compliant, the card data never actually touches the nonprofit’s own servers. This dramatically reduces both the compliance scope and the risk, since there’s no cardholder data sitting in the organization’s own systems to protect in the first place.

This is the arrangement most small and mid-sized nonprofits should be using. The key responsibility shifts from “secure the card data ourselves” to “verify our payment processor is doing this correctly.”

Questions Worth Asking Any Payment Processor

Before choosing or continuing with a donation platform, it’s worth confirming a few things directly:

  • Is the platform PCI DSS 4.0 compliant, and can they confirm their compliance level?
  • Does cardholder data ever pass through or get stored on the nonprofit’s own website or servers?
  • Does the platform handle the required vulnerability scanning and script monitoring on the organization’s behalf?

A platform that can answer these clearly is doing the heavy lifting of compliance for you. One that can’t is a sign the organization may be carrying more risk than it realizes.

What Happens If an Organization Isn’t Compliant

Non-compliance isn’t just a technicality. Card networks can levy fines against non-compliant organizations, and in the event of an actual data breach, an organization found to be non-compliant faces significantly higher liability.

Beyond the financial risk, a breach involving donor card data is a serious trust event. Donors who provided their card information in good faith may not give again to an organization that failed to protect it, regardless of how strong the mission is.

For a deeper technical reference, the PCI Security Standards Council maintains the current standards, requirement documents, and self-assessment questionnaires organizations can use to determine their exact compliance obligations.

How Ideali Handles PCI Compliance for Nonprofits

Ideali’s secure payment processing is built so that cardholder data never touches an organization’s own website or systems, removing the vast majority of PCI compliance burden from nonprofits using the platform.

Whether donors give through credit or debit cards, Apple Pay, Google Pay, or in person through Tap to Pay, payment data is handled through Ideali’s secure infrastructure rather than being stored or processed on the nonprofit’s own servers.

Sign up for Ideali for free to start accepting donations without taking on PCI compliance yourself.

Final Thoughts

PCI compliance isn’t the most exciting part of running a fundraising program, but it’s one of the most consequential to get wrong.

The good news is that most nonprofits don’t need to become security experts to comply. They just need to choose a payment partner that takes on that responsibility, and confirm they actually do.

Because protecting donor data isn’t just a compliance checkbox. It’s part of the trust that makes them willing to give in the first place.

This article is intended as a general overview and isn’t legal or compliance advice. PCI DSS requirements can vary based on how an organization processes payments, so it’s worth confirming specific obligations with your payment processor or a qualified security assessor.

Share The Insight, Choose Your Platform!