Showing posts with label Donor Privacy. Show all posts
Showing posts with label Donor Privacy. Show all posts

Sunday, May 25, 2008

The Donor-Centric Pledge

take the pledgeThanks yto TexasNonProfits at TXNP.org for this article:

We, [fill in the name of your nonprofit organization here], believe…

1. That donors are essential to the success of our mission.

2. That gifts are not "cash transactions." Donors are not merely a bunch of interchangeable, easily replaceable credit cards, checkbooks and wallets.

3. That no one "owes" us a gift just because our mission is worthy.

4. That any person who chooses to become our donor has enormous potential to assist the mission.

5. That having a program for developing a relationship with that donor is how organizations tap that enormous potential.

6. That we waste that potential when donors are not promptly thanked.

7. That "lifetime value of a donor" is the best (though often overlooked) way to evaluate "return on investment" in fundraising.

8. That donors are more important than donations. Those who currently make small gifts are just as interesting to us as those who currently make large gifts.

9. That acquiring first-time donors is easy but keeping those donors is hard.

10. That many first-time gifts are no more than "impulse purchases" or "first dates."

11. That you'll have to work harder for the second gift than you did for the first.

12. That a prerequisite for above-average donor retention is a well-planned donor-centric communications program that begins with a welcome.

13. That donors want to have faith in us, and that it's our fault if they don't.

14. That donors want to make a difference in the world -- and that our mission is one of many means to that end.

15. That donors are investors. They invest in doing good. They expect their investment to prosper, or they'll invest somewhere else.

16. That we earn the donor's trust by reporting on our accomplishments and efficiency.

17. That individual donors respond to our appeals for personal reasons we can only guess at.

18. That asking a donor why she or he gave a first gift to us will likely lead to a amazingly revealing conversation.

19. That fundraising serves the donors' emotional needs as much as it serves the organization's financial needs.

20. That we are in the "feel good" business. Donors feel good when they help make the world a better place.

21. That a prime goal of fundraising communications is to satisfy basic human needs such as the donor's need to feel important and worthwhile.

22. That the donor's perspective defines what is a "major" gift.

23. That every first gift can open a door to an entirely new world for the donor, through participation in our cause.
Read the full article here:
http://www.txnp.org/articles/articles.asp?ArticleID=8754

On a related note, you can read the Donor Bill of Rights here:
http://www.afpnet.org/ka/ka-3.cfm?content_item_id=9988

----------------------------------
What do you think? Please click the COMMENTS button below.

Thursday, May 15, 2008

New Laws for Organizations that Accept Online Payments

Thanks to TechSoup for publishing this important article:
New Laws for Organizations that Accept Online Payments

Nonprofit organizations that accept credit card donations should pay particular attention to the Payment Card Industry Data Security Standard (PCI DSS) and state identity theft and breach notification laws.

Most nonprofits process fewer than 20,000 transactions and will fall into Level 4. The standard consists of 12 requirements that cover a broad range of security issues, from network protection to access controls to creating an information security policy.

  1. Install and maintain a firewall configuration to protect cardholder data.
  2. Do not use vendor-supplied defaults for system passwords and other security parameters.
  3. Protect stored cardholder data.
  4. Encrypt transmission of cardholder data across open, public networks.
  5. Use and regularly update antivirus software.
  6. Develop and maintain secure systems and applications.
  7. Restrict access to cardholder data by business need-to-know.
  8. Assign a unique ID to each person with computer access.
  9. Restrict physical access to cardholder data.
  10. Track and monitor all access to network resources and cardholder data.
  11. Regularly test security systems and processes.
  12. Maintain a policy that addresses information security.
Sounds like quite a change -- but don't be worried. There is an alternative that you can consider:

"The simplest and cheapest way to get compliant with PCI is to not have the data," said David Taylor, Vice President of Data Security Strategies at Protegrity, which provides data security products and consulting to Fortune 2000 clients.

Learn more here:
http://www.techsoup.org/learningcenter/webbuilding/page6432.cfm

----------------------------------
What do you think? Please click the COMMENTS button below.

Sponsored By