Nonprofits

Trustees report the incident, not the vendor.

Schedule a meeting

Charities and NGOs under GDPR, PCI DSS and Charity Commission rules

Security built for mission-driven organizations

Stop donor and beneficiary data leaving by email or upload, with a signed record of what happened.

Duties

Who asksWhat they ask forARRTECHNot covered
Charity CommissionA prompt report of a significant data breach.A signed record and case timeline. →Filing the report.
PCI DSSProtection of cardholder data on donation pages.Card numbers checked by algorithm before mail or upload leaves. →The payment page itself.
Federal grantees, 2 CFR 200.303(e)Reasonable measures to safeguard personal information.DLP inspection of mail before Send and uploads from any application. →The single audit.
GDPRNotice within 72 hours for EU donors.A case timeline. →The notice.
Your CRM vendor— →Data held inside the vendor’s systems.

PCI DSS

Protect donor card and bank details

Any organization that takes card donations must follow PCI DSS. ARRTECH DLP recognizes real card and bank numbers and stops them leaving by email or upload.

Trustee duty

Report serious incidents to the Charity Commission

In England and Wales, trustees must report serious incidents, including significant data breaches, to the Charity Commission promptly. ARRTECH keeps a signed record and case timeline of what happened.

Civil society guidance

Defend against spearphishing and spyware

CISA’s 2024 guidance for civil society warns that these groups are targeted with spearphishing and spyware. Cyberdroid AI Detection flags accounts acting unlike themselves.

Managed service

Get protection without a security team

Many nonprofits have no security staff. A managed service provider can run ARRTECH for you, with each organization kept separate.

By rule

Charity Commission

A prompt report of a significant data breach. ARRTECH: A signed record and case timeline.

Federal grantees, 2 CFR 200.303(e)

Reasonable measures to safeguard personal information. ARRTECH: DLP inspection of mail before Send and uploads from any application.

GDPR

Notice within 72 hours for EU donors. ARRTECH: A case timeline.

Your CRM vendor

A breach inside your CRM vendor’s systems. Not covered: ARRTECH cannot see inside a vendor’s systems; it covers the email, uploads and computers you run.

Questions

Can donor bank details leave by email?

ARRTECH DLP recognizes real card and bank account numbers, checks email before it is sent, and inspects uploads from any application.

What about state-backed targeting?

The 2024 joint guidance for civil society describes spearphishing and spyware. Cyberdroid AI Detection flags users and computers acting unlike their own history and never changes anything.

We have no security staff.

ARRTECH DLP can run as a hosted service or through a managed provider, so someone else can operate it for you.

What stays with you?

Data held by your donor CRM vendor, your donation page, and the report to your regulator.

Sources

Guide

Do nonprofits need to follow PCI DSS?

Yes, if they take card donations. PCI DSS applies to anyone who stores, processes or transmits cardholder data.

When must a charity report a data breach?

In England and Wales, trustees report serious incidents to the Charity Commission as soon as reasonably possible.

How can nonprofits get security without staff?

A managed service provider can run monitoring and data protection for you.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.