At a glance
An NGO handles two distinct pools of personal data most organisations don’t combine — donor data (often financial detail and, for foreign contributions, identity data reported under the Foreign Contribution (Regulation) Act, or FCRA) and beneficiary data (often health or child-related, collected from people in vulnerable circumstances). The DPDP Act applies to both, alongside FCRA’s separate donor-reporting duty rather than instead of it. The nuance is less about a legal carve-out — NGOs don’t get one — and more about the extra care beneficiary data involving children or health information warrants.
Educational resource only. This explains how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to NGOs and non-profits; it is not formal legal advice.
The situation
NGOs sit outside the usual “business collecting customer data” frame DPDP guidance is often written for, but the Act doesn’t carve out non-profits. A donor’s payment and contact details, a beneficiary’s income or health information collected for a welfare programme, and a grant funder’s own reporting requirements all move through the same organisation — often with fewer dedicated compliance resources than a commercial business of similar data volume.
Does DPDP apply to an NGO the same way it applies to a business?
Yes — an NGO deciding why and how it processes donor or beneficiary personal data is a Data Fiduciary, non-profit status notwithstanding. The DPDP Act doesn’t distinguish by organisational purpose or tax status; a registered trust, society or Section 8 company running a welfare programme carries the same baseline duties as a commercial business of comparable size — notice, a lawful basis, security, breach reporting, and rights fulfilment.
The donor and beneficiary data NGOs handle
- Donor data — name, contact details, payment information, and for larger or foreign contributions, identity detail required for FCRA reporting.
- Beneficiary data — often the most sensitive data an NGO holds: income level, health status, family circumstances, sometimes collected from people with limited practical ability to decline (a welfare applicant, a patient at a health camp).
- Children’s data — common across education, health and child-welfare programmes, triggering the DPDP Act’s specific children’s-data rules.
- Grant-funder reporting data — beneficiary counts and sometimes case-level detail shared with funders as a condition of grant reporting.
- Volunteer and staff data — the standard employment-adjacent data any organisation holds.
The obligation that actually bites: FCRA reporting alongside DPDP
Foreign-contribution reporting under FCRA is a separate, mandatory disclosure duty that supplies its own lawful basis under the DPDP Act (Section 7, legal obligation) — it doesn’t reduce the Act’s other requirements. NGOs registered under FCRA must file an annual return (Form FC-4) disclosing details of foreign contributions received, which in practice discloses identifying information about foreign donors to the government. That statutory reporting duty is a legal-obligation basis under the Act for collecting and disclosing the specific donor detail FCRA requires. It doesn’t touch the rest of the NGO’s duties under the Act: donor data used beyond what FCRA reporting needs (a marketing newsletter, a donor-recognition wall) needs its own basis (typically Section 6 consent), and beneficiary data — which FCRA says nothing about — carries the full weight of the Act’s ordinary rules, with the added children’s-data provisions where beneficiaries are minors.
Common mistakes NGOs make
- Beneficiary intake forms collecting more than the specific programme needs — income, health and family detail gathered “in case it’s useful” rather than tied to a defined purpose.
- No verifiable parental consent process for programmes serving children, treating institutional trust (a school partnership, a community relationship) as a substitute for actual consent.
- Donor and beneficiary data mixed in the same system with no access distinction, when the two carry very different sensitivity and consent bases.
- Case studies and photos used in fundraising materials without a separate, clear consent step from the beneficiary (or their parent, for a child) distinct from the consent to receive services.
- Grant-funder reporting sharing more beneficiary detail than the funder’s own requirement calls for.
Collecting donor and beneficiary data compliantly
Separate consent for donor administration from consent for any public use of beneficiary stories or images, and collect beneficiary data proportionate to the specific programme, not a maximal intake form. A donor should know clearly what their contribution data is used for (receipting, FCRA reporting where applicable, communications) and be able to opt out of communications separately from the transaction itself. A beneficiary — or their parent, where a child is involved — needs a plain explanation of what’s collected and why before service delivery, with photo or story use for fundraising and communications treated as a distinct, optional consent, never a condition of receiving help.
Sharing beneficiary data with corporate CSR funders
A corporate CSR grant typically comes with its own reporting expectation, and unlike FCRA’s statutory filing, this one is a contractual ask from the funder — which changes what basis the NGO can rely on for sharing beneficiary detail. Corporate Social Responsibility (CSR) funding under the Companies Act is a major funding source for Indian NGOs, and funders routinely want impact reporting that goes beyond aggregate numbers — case studies, photos, sometimes beneficiary-level detail to demonstrate the programme’s reach. Because this reporting obligation comes from a funding contract rather than a law the NGO is directly subject to, it doesn’t carry the same automatic “legal obligation” basis that FCRA’s donor-reporting duty does — the NGO needs its own basis (typically beneficiary consent, obtained at the same point as consent for service delivery, naming CSR reporting as one of the possible uses) before sharing identifiable beneficiary detail with a corporate funder. Aggregate, de-identified reporting (beneficiary counts, outcome statistics with no identifying detail) sits on much safer ground and should be the default; anything beneficiary-identifiable — a named case study, a recognisable photo — needs the same explicit, separate consent this piece already recommends for fundraising use generally.
FAQ
Can an NGO share beneficiary case studies with a corporate CSR funder without separate consent?
Not defensibly if the case study identifies the beneficiary — aggregate, de-identified reporting is the safer default; anything beneficiary-identifiable needs the same explicit consent as fundraising use of a beneficiary’s story or photo.
Does an NGO’s non-profit status create any exemption from the DPDP Act?
No — the Act applies based on the processing activity, not organisational purpose or tax status. Non-profits carry the same baseline duties as any other Data Fiduciary.
Does FCRA’s foreign-donor reporting requirement satisfy the DPDP Act on its own?
It supplies a lawful basis for the specific reporting FCRA requires — it doesn’t cover donor data used beyond that reporting purpose, and it says nothing about beneficiary data at all.
Can an NGO use a beneficiary’s photo or story in fundraising materials without separate consent?
Not defensibly — that’s a distinct use from service delivery and needs its own clear, optional consent (from a parent, where the beneficiary is a child), never bundled into or made a condition of receiving assistance.
Do NGOs need verifiable parental consent for programmes serving children?
Yes — the DPDP Act’s children’s-data rules apply the same way they would to any organisation processing a minor’s data, regardless of the NGO’s welfare mission or existing institutional relationships.