For nonprofits

Governance and technology: a guide for nonprofit boards

The board doesn't need to choose the tools: that isn't its role. It does need to know who decides, who holds the access, who owns the data and what it all costs. This guide offers ten questions to ask before adopting or commissioning an app.

By Téo Blanc, Adm.A. · Updated

Why this concerns the board

Technology problems in a nonprofit are rarely technical. They are almost always governance problems: accounts opened with the personal email address of an employee or volunteer, subscriptions that add up without ever being voted on, sensitive data nobody can locate, one person who "looks after IT" and on whom everything depends. None of these risks appears in the minutes until it materializes.

Ten questions to ask before adopting an app

  1. Who is responsible for this tool? A specific person must answer for it, with a designated backup.
  2. Who owns the accounts and domain names? They should be in the organization's name, not a person's.
  3. What personal information will the tool hold? Members, donors, volunteers, participants, employees: knowing which determines the level of caution.
  4. Where is the data hosted, and who can access it? Including the vendor and its subcontractors.
  5. Can we get our data back? In a readable format, if the vendor shuts down, doubles its prices or changes its terms.
  6. What does it cost over three years? Subscription, training, upkeep and staff time, not just the starting price.
  7. Who will train and support the users? A good tool poorly adopted solves nothing.
  8. Who approves changes? New subscriptions, new features, new vendors.
  9. How will we know it works? One or two simple indicators, set at the outset.
  10. What happens if the person in charge leaves tomorrow? Does the organization regain control of its accounts, and how fast?

Who decides what?

BodyRole regarding technology
Board of directorsApproves the technology use policy and significant recurring financial commitments, makes sure the person responsible for the protection of personal information is designated and known, and receives an annual risk report.
Executive directorChooses and deploys tools within the approved framework, keeps the inventory of accounts and subscriptions, manages vendors and reports to the board.
Staff and volunteersUse the tools according to the access rules and promptly report any incident or unusual behaviour.

An inventory to do this month

  1. List the tools and subscriptions, with the monthly or annual cost of each.
  2. For each tool, note who holds the administrator access.
  3. Check which email address each essential account was opened with.
  4. Locate where sensitive information sits (files, emails, apps).
  5. Ask when a backup restore was last tested. A backup that has never been tested is a hypothesis, not protection.

What Law 25 changes for your apps

Law 25 provides no exemption based on size or non-profit status. As soon as an organization collects personal information, the following obligations directly affect its tools: designating a person responsible for the protection of personal information and publishing their title or name, publishing a plain-language privacy policy when information is collected by technological means, keeping a register of confidentiality incidents, and carrying out a privacy impact assessment before communicating information outside Québec.

This guide does not replace the law or legal advice. To verify an obligation, consult the official sources: the Commission d'accès à l'information and the text of the Act respecting the protection of personal information in the private sector (P-39.1).

Going further

Téo Blanc, Adm.A.

Chartered administrator based in Montréal, member of the Ordre des administrateurs agréés du Québec, with experience in nonprofit management. LinkedIn · Cap Commun

FAQ

Frequently asked questions

No. It has neither the role nor the expertise to do so. It must know who decides, who holds the access, who owns the data and what it costs.

The law provides no exemption based on size or non-profit status. The amount of work varies, but the existence of the obligations doesn't. For a specific case, contact the Commission d'accès à l'information or a lawyer.

With the inventory: the list of tools, costs, access holders and places where sensitive information sits. It takes a few hours and informs every other decision.

Contact

A topic for your board's agenda?

I can help you take inventory of your current tools or assess an app to adopt or have built. Write to me or book a 30-minute exploratory call.

contact@teozapps.com