Blogs

Insurance policy marked excluded beside a privacy shield and lock, for churches and nonprofits

Nonprofit Data Privacy: Why Churches and Nonprofits Need AI Privacy Center

Your ministry is a data company now

Most pastors and nonprofit directors don’t think of their organization as handling sensitive data. But look at what passes through a typical church or nonprofit every week: online giving records, member directories, children’s check-in rosters, prayer requests, counseling notes, volunteer background checks, and a website quietly running analytics and advertising pixels.

Every one of those is personal information. And nonprofit data privacy rules on how you collect, store, and share it are tightening at the same moment insurance carriers are pulling back on paying for privacy mistakes. That combination is why we now recommend every church and nonprofit client put a real privacy program in place, and why we point them to AI Privacy Center.

Insurers are writing data privacy out of church and nonprofit coverage

Many ministries assume their general liability policy will step in if someone sues over how they handled member or donor information. Increasingly, the policy language says otherwise.

  • General liability policies now carry data exclusions. In 2014, ISO, the organization that drafts the standard policy forms most carriers use, released endorsements that exclude claims arising from access to or disclosure of confidential or personal information (forms CG 21 06, CG 21 07 and CG 21 08). ISO said at the time that data breaches were “not necessarily contemplated” by the general liability policy and belong in standalone cyber coverage. (Insurance Journal)
  • Cyber insurance for nonprofits and churches is narrowing too. As website-tracking lawsuits have multiplied, cyber insurers have added specific exclusions for pixel and tracking-code claims and for “wrongful collection” of data, or capped that exposure with sublimits or defense-only coverage. (ABA Litigation Section; Bloomberg Law, Sept. 2025)
  • Carriers are going to court to deny these claims. Bloomberg Law reported that units of Berkshire Hathaway and The Hartford have filed suits seeking declarations that their general liability policies don’t cover web-tracking cases. (Bloomberg Law)

The practical result: a privacy claim against your church or nonprofit may land on a policy that was never built to pay it, or one that has been rewritten specifically so it won’t. Before you renew, read our guide to church cyber insurance and protecting donor data so you know what a policy should include.

Insurance has never been a substitute for following the law

The newer data exclusions sit on top of a much older principle: liability policies are not designed to pay for an organization breaking a statute. Standard liability forms have long carried a “violation of law” exclusion aimed squarely at how information is collected and shared.

One carrier’s version of this endorsement names the Telephone Consumer Protection Act, the CAN-SPAM Act and the Fair Credit Reporting Act, then adds a catch-all for any “statute, ordinance, regulation or law” that “addresses, prohibits, or limits the printing, dissemination, disposal, collecting, recording, sending, transmitting, communicating or distribution of material or information.” (CNA endorsement CNA80052)

Read that list again: collecting, recording, transmitting, distribution of information. That describes nearly every privacy law on the books. Courts enforce it, too. In AMCO Insurance Co. v. Van Laningham & Associates (M.D.N.C. 2021), the court held the insurer owed no defense on a privacy-statute claim, relying in part on this exclusion. (Carlton Fields)

The takeaway for church and nonprofit boards is simple. Insurance protects you from accidents. It is not built to protect you from non-compliance. The only dependable protection against a privacy-law claim is being compliant in the first place, and being able to prove it.

“We’re a nonprofit, so privacy laws don’t apply to us” isn’t safe anymore

Nonprofit status does not put your organization outside privacy law, including in California. California’s data-security and breach-notification laws apply to any organization “whether or not organized to operate at a profit” (Cal. Civ. Code § 1798.80), and its wiretap statute, the basis of today’s pixel lawsuits, has no nonprofit exemption.

California’s consumer privacy act can reach nonprofits too; for example, one that controls or is controlled by a for-profit it shares branding with (Benesch). Beyond California, the newer state laws are not uniform, and several reach nonprofits directly:

  • No nonprofit exemption: Colorado, Delaware, New Jersey and Oregon.
  • Narrow exemptions only: Maryland and Minnesota exempt only nonprofits in specific roles, such as insurance-fraud prevention.
  • Partial exemptions tied to 501(c) status in Kentucky, New Hampshire, and Rhode Island.

(Wagenmaker & Oberly; Napa Legal Institute) These laws follow where your donors and website visitors live, not where your building is. A Riverside church with online givers in Colorado or Oregon has to consider those states.

Website tracking is the second exposure. AARP, a nonprofit, agreed to a $12.5 million settlement in 2025 over claims that its website shared visitors’ video-viewing data with Meta through the Meta Pixel without consent. (Legal Tech Monitor) In California, plaintiffs are using a 1967 wiretap statute, the California Invasion of Privacy Act, to pursue “$5,000 per person, per violation” against businesses, nonprofits, and public agencies over ordinary cookies and pixels. (Daily Journal)

If your church streams sermons, runs Facebook or Google ads, or uses an analytics tool, your website is part of this picture.

What we learned the hard way, and why we use AI Privacy Center

We learned this lesson on our own website first. For a while, we paid for another privacy service and assumed we were covered. When we looked closely at what it actually did, we discovered it gave us no real protection under any of the 20-plus state privacy laws now on the books. It put a pop-up on the site. It didn’t handle data requests, keep proof of consent, or produce the records those laws require.

That’s the gap AI Privacy Center was built to close. A cookie banner answers one question: did the visitor click “yes”? Privacy laws ask a harder one: can you prove it, and what happens next? AI Privacy Center gives a church or nonprofit:

  • Proof of consent. A tamper-evident record of who consented, to what, and when, plus a one-click evidence pack you can hand to an auditor or insurer.
  • A way to answer data requests. When a donor or member asks to see or delete their information, a request console handles intake, verifies identity, tracks each state’s deadline, and logs the response.
  • The records regulators ask for. Records of processing, risk assessments, a vendor register, and a breach log, generated rather than written from scratch.
  • Coverage that follows your people. Requirements are mapped to the states where your donors and visitors actually live, and kept current as laws change.
  • Trackers a banner can’t see. Server-side controls that catch tracking a browser popup never touches.

There’s an insurance benefit, too. Cyber and privacy underwriters increasingly ask about these exact controls on applications and renewals. An organization that can document them is a cleaner risk to quote.

Five questions to ask at your next board meeting

  1. What personal information do we collect online and in person: giving, check-in, directories, prayer and counseling requests?
  2. Does our website run analytics, video embeds, or Facebook and Google tracking pixels?
  3. In which states do our donors and website visitors live?
  4. If someone asked us today to show or delete their data, who would handle it, and how fast?
  5. Does our current insurance contain data, privacy, or violation-of-law exclusions? (It probably does. Ask us to review it.)

If any answer is “we’re not sure,” that’s the place to start. Integrity Now Insurance Brokers can review your current policies for privacy exclusions, and AI Privacy Center can put the compliance program in place that insurance won’t replace. Request a church quote or request a nonprofit quote to start both conversations.

This article is general information, not legal advice. Talk with your attorney about how specific privacy laws apply to your organization.

Frequently asked questions

Are nonprofits exempt from state data privacy laws?

No, not across the board. Colorado, Delaware, New Jersey and Oregon have no nonprofit exemption in their consumer privacy laws. In California, the breach-notification and data-security laws apply to organizations whether or not they operate for profit, and the state wiretap statute behind pixel lawsuits has no nonprofit exemption.

Does church general liability insurance cover data privacy claims?

Often it does not. Since 2014, standard endorsements (ISO forms CG 21 06, CG 21 07 and CG 21 08) have excluded claims arising from access to or disclosure of confidential or personal information. Many policies also exclude claims arising from laws that limit how information is collected or shared. Have your broker review your policy wording.

Does cyber insurance for nonprofits cover website tracking lawsuits?

Not always. Some cyber insurers now add exclusions for pixel and tracking-code claims or for wrongful collection of data, or limit that coverage with a sublimit or defense-only terms. Check how your policy defines a covered privacy event.

Will insurance pay if our church violates a privacy law?

You should not count on it. Liability policies commonly exclude claims arising from violations of statutes that govern collecting, recording or distributing information. The dependable protection is a documented privacy compliance program.

Sources

Accessibility Toolbar

Scroll to Top