Charity & Non-Profit Payment Compliance Guide
PCI compliance guidance specifically for charities and non-profits. Covers why charities are increasingly targeted, the risks of taking donations over the phone, how to achieve compliance on a limited budget, and Fundraising Regulator requirements.
What you'll learn
- Why charities are increasingly targeted by payment fraud
- Risks specific to donation-over-phone and telephone fundraising
- How to achieve PCI compliance on a charity budget
- Fundraising Regulator requirements and how they interact with PCI DSS
PDF · 9 pages · 12 min read
Trusted by banks, law firms, and regulated businesses worldwide.
Why fraudsters target charities
Charities make tempting targets, and not by accident. Donation volumes spike around appeals and disasters, which is exactly when controls are stretched thinnest. A lot of the people taking payments are volunteers rather than trained contact-centre staff. And the public assumes a charity is safe, so a caller pretending to donate, or a fraudster testing stolen cards through a donation line, meets less friction than they would at a bank. The result is that charities see more than their share of card-testing fraud and social-engineering attempts on their phone lines.
The donation-over-the-phone problem
Telephone fundraising is where most charities get caught out. The moment a supporter reads their card number aloud and a volunteer writes it on a form or types it into a laptop, that card data is live in the room — on the device, in the call recording, sometimes on a sticky note. Every one of those becomes part of your cardholder data environment, and a single lost notepad or breached laptop can turn into a reportable incident. DTMF masking closes that gap: the donor keys their card on their own phone, the tones are flattened before anyone hears them, and the digits go straight to your payment provider. The volunteer stays on the line to help, but never handles the number.
PCI compliance on a charity budget
Compliance feels like a cost a charity can't justify, but the expensive version is the one you're probably running now. Keeping card data out of your environment is what shrinks the bill — once volunteers and recordings are out of scope, most charities drop to SAQ A, the shortest self-assessment there is, and the annual effort collapses. You don't need a security team; you need a setup where there's nothing sensitive to protect in the first place. That's a far cheaper place to be than insuring against a breach you've left the door open for.
Where the Fundraising Regulator fits
PCI DSS isn't the only rulebook in play. The Fundraising Regulator's Code of Fundraising Practice expects you to handle donors' personal and financial data securely and to treat vulnerable supporters fairly — and the two sets of rules pull in the same direction. If a donor never has to say their card number aloud to a volunteer, you've satisfied a chunk of both at once: the data is protected, and a confused or vulnerable supporter isn't being asked to read out sensitive details under pressure. Getting the payment design right is the quiet way to tick both boxes.
We work with charities and non-profits taking donations by phone, and the pattern is always the same — take the card data out of the volunteer's hands and most of the compliance problem disappears with it. If you want to see how a masked donation call works end to end, how Paytia works walks through it.
For the full feature set behind these recommendations, see our PCI DSS v4 solution.
What the SAQ question means for a charity
Being a charity changes nothing about whether PCI DSS applies. There's no charitable exemption, no small-donor threshold and no volunteer carve-out. What it does change is your capacity to deal with it.
If donors read card numbers to a person who hears, sees or keys them, you're on SAQ D — several hundred questions, annually. If the number goes from the donor's keypad straight to the payment platform, you're on SAQ A. For an organisation without a compliance team that isn't an administrative difference; it's the difference between something a finance manager can complete and something needing outside help every year. Our free Comply app will tell you which one you're on.
Volunteers are an argument for this, not an obstacle
The usual worry is that secure capture is too complicated for volunteers. It's the other way round. Once the card number never reaches the volunteer, you don't need to train them on handling it, vet them for it, or worry about what's written on the pad in front of them. They stay on the call and keep the conversation going — they simply never hear the number. That's a smaller ask than any policy you could write.
Appeals, events and the seasonal problem
Charity payment volume is spiky. A telethon, a gala, an emergency appeal — you need capacity for a weekend and not for the rest of the quarter. That makes per-agent licensing a poor fit, because you're paying for seats you use twice a year. See choosing your charging model for the trade-off.
For overflow, payment links sent by SMS during or after a call add capacity without adding phones, and automated capture takes routine donations when nobody's available.
Gift Aid and donor records
Gift Aid needs donor identity and a declaration, not card data. Keeping the two apart is the whole point — you can hold everything you need for Gift Aid and reporting while holding none of the card details that create the risk. If your CRM currently contains card numbers, that's the first thing to fix.
For the sector detail, see charity and events payments.
Related Compliance 101 Guides
Related Glossary Terms
Ready to simplify your PCI compliance?
Book a personalised demo and we'll show you how Paytia can descope your telephone payment environment.
Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia