Why this concerns the board
Technology problems in a nonprofit are rarely technical. They are almost always governance problems: accounts opened with the personal email address of an employee or volunteer, subscriptions that add up without ever being voted on, sensitive data nobody can locate, one person who "looks after IT" and on whom everything depends. None of these risks appears in the minutes until it materializes.
Ten questions to ask before adopting an app
- Who is responsible for this tool? A specific person must answer for it, with a designated backup.
- Who owns the accounts and domain names? They should be in the organization's name, not a person's.
- What personal information will the tool hold? Members, donors, volunteers, participants, employees: knowing which determines the level of caution.
- Where is the data hosted, and who can access it? Including the vendor and its subcontractors.
- Can we get our data back? In a readable format, if the vendor shuts down, doubles its prices or changes its terms.
- What does it cost over three years? Subscription, training, upkeep and staff time, not just the starting price.
- Who will train and support the users? A good tool poorly adopted solves nothing.
- Who approves changes? New subscriptions, new features, new vendors.
- How will we know it works? One or two simple indicators, set at the outset.
- What happens if the person in charge leaves tomorrow? Does the organization regain control of its accounts, and how fast?
Who decides what?
| Body | Role regarding technology |
|---|---|
| Board of directors | Approves the technology use policy and significant recurring financial commitments, makes sure the person responsible for the protection of personal information is designated and known, and receives an annual risk report. |
| Executive director | Chooses and deploys tools within the approved framework, keeps the inventory of accounts and subscriptions, manages vendors and reports to the board. |
| Staff and volunteers | Use the tools according to the access rules and promptly report any incident or unusual behaviour. |
An inventory to do this month
- List the tools and subscriptions, with the monthly or annual cost of each.
- For each tool, note who holds the administrator access.
- Check which email address each essential account was opened with.
- Locate where sensitive information sits (files, emails, apps).
- Ask when a backup restore was last tested. A backup that has never been tested is a hypothesis, not protection.
What Law 25 changes for your apps
Law 25 provides no exemption based on size or non-profit status. As soon as an organization collects personal information, the following obligations directly affect its tools: designating a person responsible for the protection of personal information and publishing their title or name, publishing a plain-language privacy policy when information is collected by technological means, keeping a register of confidentiality incidents, and carrying out a privacy impact assessment before communicating information outside Québec.
This guide does not replace the law or legal advice. To verify an obligation, consult the official sources: the Commission d'accès à l'information and the text of the Act respecting the protection of personal information in the private sector (P-39.1).
Going further
- Board governance self-assessment grid (Cap Commun, in French): 36 statements across six dimensions, including technology governance.
- The six dimensions of nonprofit governance (Cap Commun, in French): what a board should monitor, dimension by dimension.
- Law 25 obligations for a nonprofit (Cap Commun, in French): each obligation with its official source.
- Replacing Airtable or Excel in your nonprofit: when and how to change tools.