Online giving makes it easy for supporters to help, but it also puts your nonprofit in the payment business. Every donation form, event card reader, and phone pledge handles card data. Securing online donations protects donors, keeps your processor account in good standing, and preserves the trust your fundraising depends on.
PCI DSS applies to nonprofits too
The Payment Card Industry Data Security Standard (PCI DSS) applies to any organization that accepts, processes, or stores card payments. Tax-exempt status does not change that. In fact, your merchant agreement with your processor or bank usually requires compliance.
Most small organizations show compliance with an annual self-assessment questionnaire. The right questionnaire depends on how you take payments. As a result, the way you design your donation process directly affects how much work compliance takes.
Protect online donations with hosted payment pages
The simplest way to reduce risk is to keep card numbers off your systems entirely. Instead of building your own form, use a donation page or embedded form that your payment processor or giving platform hosts.
With this approach, the card number goes straight to the processor, and your staff never see it. However, you still need to protect the website that links to the payment page. An attacker who changes that link can send donors to a fake form.
For recurring gifts, rely on the processor’s stored tokens. That way, you can charge monthly donors without keeping card numbers in your donor database.
Stop card testing attacks
Criminals with stolen card numbers need a quick way to learn which cards still work. Online donations make a favorite target, because forms often accept small amounts with no account required.
A card testing attack looks like hundreds of tiny gifts in a short time, and many of them fail. Consequently, you may face processor fees, chargebacks, and even a frozen merchant account.
To defend your form, turn on the fraud tools your processor offers. Also add a bot challenge, set a sensible minimum gift, and limit repeated attempts from the same source. Finally, set alerts for unusual spikes in declined transactions.
Handle phone, mail, and event gifts safely
Not every gift arrives through the website. Staff and volunteers also take card numbers over the phone, on pledge cards, and at galas. These channels often carry more risk than the website does.
- Enter phone gifts directly into the processor’s virtual terminal instead of writing them down.
- Never accept card numbers by email, text, or voicemail.
- Shred paper pledge cards after processing, and lock up any you have not processed yet.
- Use card readers from your processor at events, and keep them updated.
- Check readers for tampering before and after each event.
- Give each staff member a separate login to the payment portal, protected with MFA.
- Limit refund permissions to a small number of trusted people.
Also, train event volunteers on these rules before each event. A short briefing at check-in works well.
Watch for refund and overpayment fraud
Some criminals pose as generous donors. They make a large gift with a stolen card, then claim a mistake and ask for a partial refund to a different card or by wire.
When the real cardholder disputes the charge, your nonprofit loses both the original gift and the refund. So set a clear rule: refunds go only to the original payment method, and a second person approves any unusual request.
Keep your website and plugins secure
Even with a hosted form, your website still matters. Many nonprofit sites run on a content management system with donation plugins, event plugins, and themes from many developers.
Therefore, keep the core software and every plugin updated. Remove plugins you no longer use, and protect admin logins with MFA. In addition, make sure someone receives security alerts from your web host and actually reads them.
Finally, choose a reputable host that provides backups and monitoring. If your site goes down during a campaign, you want a fast way back.
How WEBIT helps
WEBIT helps nonprofits map how card data flows through each donation channel, then reduce the number of systems that touch it. We protect the computers staff use for payment portals with Security Essentials, including DNS filtering that blocks many known malicious sites.
We also roll out MFA and help you answer the technical questions on your PCI self-assessment. See our cybersecurity services or our pricing page to learn more.
Key takeaways
- PCI DSS applies to nonprofits that accept cards, regardless of tax status.
- Hosted payment pages keep card numbers off your systems and shrink your compliance scope.
- Bot challenges, minimum gifts, and alerts help stop card testing on online donations.
- Phone and event gifts need clear handling rules for staff and volunteers.
- Refunds should go only to the original payment method.