Skip to content
← Back to Blog

The Nonprofit Privacy Exemption That Does Not Exist

The belief that nonprofits are exempt from state privacy laws is the most common misreading we encounter. Most trade associations sit in 501(c)(6), and a statute exempting (c)(3) organizations does not exempt them. Here is what applies.

Somebody on your board forwards an article about state privacy laws with a one-line note: does this apply to us? Your operations director replies within the hour that nonprofits are exempt. Everyone moves on, and the answer felt authoritative because it is the answer almost everybody gives. For a trade association with members in the wrong six states, it is also wrong.

There are now more than twenty comprehensive state privacy laws in the United States, and the nonprofit exemption people are thinking of is neither universal nor consistent. Two specific gaps catch associations and nonprofits, and the second one catches 501(c)(6) organizations almost exclusively.

One thing said plainly up front. We build and maintain websites. We are not lawyers, this is not legal advice, and whether any particular statute applies to your organization depends on facts about your revenue, your tax classification and your per-state data volumes that only your counsel can weigh. What we can tell you is what these laws ask a website to do, because that part lands on us.

Gap One: Six States With No Meaningful Exemption

In these states, being a nonprofit does not remove you from scope. Some exempt a narrow category of insurance-fraud-prevention nonprofits and nothing else; one does not exempt nonprofits at all.

  • Colorado. No nonprofit exemption whatsoever. Thresholds are 100,000 Colorado residents in a year, or 25,000 combined with revenue from selling data.
  • New Jersey. Applies regardless of tax status.
  • Delaware. The exemption was narrowed to insurance-fraud-prevention nonprofits only, with a 35,000-resident threshold.
  • Oregon. Exempts only nonprofits established to detect and prevent insurance fraud.
  • Maryland. Limited insurance-related exemptions only. Enforcement began in April 2026.
  • Minnesota. Narrow insurance-fraud-prevention exemption only.

Gap Two: The One That Hits Trade Associations

Several states exempt 501(c)(3) organizations specifically, not tax-exempt organizations generally. Indiana, Kentucky and Rhode Island write their exemptions by reference to particular sections of the Internal Revenue Code, primarily 501(c)(3).

A trade association is usually a 501(c)(6). A 501(c)(6) is not a 501(c)(3). Professional societies, business leagues, chambers of commerce and most trade associations sit in (c)(6), and a statute that exempts (c)(3) organizations does not exempt them. This is the single most common misreading we encounter, and it is not obvious from any summary that simply says "nonprofits are exempt."

States that do exempt broadly by tax-exempt status include Virginia, Connecticut, Iowa, Montana, Nebraska, New Hampshire, Texas, Tennessee and Utah, joined by Oklahoma and Louisiana when their laws take effect on January 1, 2027. If your membership is concentrated there, the picture is much simpler.

Why a National Membership Makes This Harder

A regional business hits these thresholds only in its own state. An association with a national membership collects data about people in all fifty, which means the question is not whether your organization is covered but which of twenty-odd statutes reach you and at what volume.

Note the overlap that matters. Colorado, New Jersey, Delaware, Oregon, Maryland and Minnesota appear on the no-exemption list above. They also all require honoring a universal opt-out signal. So the states most likely to cover you are the same states with the most specific technical demand.

What These Laws Ask a Website To Do

Setting the legal analysis aside, the website obligations across these statutes are fairly consistent, and four of them are concrete build items.

  • A privacy notice that describes actual practice. Not a template with another organization's name replaced. It has to name the categories of data you collect, why, who you share it with, and how someone exercises their rights.
  • A working rights-request path. Access, correction, deletion and portability, with a route that a member can actually find and that reaches a person who can act on it. A form that emails an unmonitored inbox is not compliance.
  • An opt-out link where required. Typically presented as "Your Privacy Choices," for sale and targeted-advertising opt-outs.
  • Honoring the Global Privacy Control signal. Twelve states require recognizing a universal opt-out mechanism. This is the one that surprises people, so it gets its own section.

A Cookie Banner Does Not Satisfy This

Global Privacy Control is a signal the browser sends, not a box the visitor clicks. Your site has to read it and act on it before any tracking fires. A consent banner asks the visitor a question; GPC means the visitor already answered, in their browser settings, and your site is obliged to respect that without asking.

Most association sites we look at do not honor it. They have a banner, often added in a hurry, and the banner is doing nothing about the signal. Testing this is not hard: install a browser extension that sends GPC, load your site, and check whether your analytics and advertising tags still fire. If they do, the banner is decoration.

California is about to make this considerably more visible. AB 566, the Opt Me Out Act, takes effect on January 1, 2027 and requires browser developers to offer an opt-out preference signal. When sending the signal becomes a setting rather than an extension, the number of visitors sending it goes up sharply.

What Is Coming on January 1

Nothing new lands between now and the end of the year, which makes this quarter a preparation window rather than a deadline. Three things take effect on January 1, 2027.

  • Oklahoma's Consumer Data Privacy Act. Nonprofits are exempt at the entity level. No universal opt-out requirement.
  • Louisiana's Data Privacy Act. Nonprofits exempt at the entity level.
  • California's AB 566. The browser opt-out signal requirement described above.

And one for the 2027 budget conversation. Alabama's law takes effect May 1, 2027, and its nonprofit exemption is conditional: nonprofits with fewer than 100 employees are exempt only if the organization does not sell personal data.

When You Can Reasonably Set This Aside

If your organization is a 501(c)(3) with a regional membership concentrated in states that exempt nonprofits broadly, and you do not sell or share member data for advertising, the exposure here is low. Confirm that with counsel and spend the quarter on something else.

It is also worth saying that a good privacy posture is mostly not a legal project. Collecting less, keeping it for less time, and being able to explain what you hold to a member who asks are all things worth doing whether or not a statute reaches you.

The Data Associations Forget They Hold

When people picture regulated personal data they picture a customer database. An association's exposure is usually wider than that and more scattered, because it accumulated one program at a time.

  • The member directory. Often public, often scraped, and rarely governed by an explicit opt-in about what appears to whom.
  • Form submissions nobody prunes. Scholarship applications, grant submissions, conference proposals with attached CVs, award nominations, committee interest forms. Some of these sit in a website database for a decade.
  • Event and CE records. Attendance, credentials earned, sometimes dietary and accessibility requirements, which are more sensitive than the rest.
  • Advertising and analytics identifiers. The pixels on your donation and dues pages are the ones most likely to constitute "sharing" under these statutes, and the ones most likely to have been added by someone in marketing without a conversation.

What Your Site Is Actually Doing

Point us at your website and we will tell you what data it collects, which third-party scripts are loading and what they send, whether your site honors the Global Privacy Control signal today, and whether your privacy notice matches what is actually happening on the page. What comes back is a summary with a specific recommendation next to every finding, the technical facts your counsel needs in order to give you an answer, rather than a legal opinion we are not qualified to offer.

83 Creative

We're a web development studio that works exclusively with trade associations, professional societies, and membership organizations.

← Previous Article Four Deadlines Are Already Written Into Your 2027 Website Budget