M.A.I. Consulting
GuidePractitioner22 September 20264 min read

Donor and funder intelligence without a compliance incident

Which donor and funder research with AI is safe public-source work, and where compiling wealth estimates or personal characteristics on a named individual becomes personal data processing needing sign-off.

Fundraising teams increasingly use AI to speed up donor and funder research: summarising a foundation's published priorities, drafting a landscape scan of who funds a particular issue area, pulling together a prospect's public giving history before a first meeting. Most of this work is genuinely safe. A smaller set of specific practices cross a line this series drew early on, in the four-class data scheme, and the line is not always obvious to someone doing prospect research at speed.

This piece is a practical guide to which parts of donor and funder intelligence stay safely on the research side of that line, and which parts quietly become something else.

What most donor research safely touches

A foundation's published funding priorities, a public annual report, a board list on an organisation's own website, a donor's publicly announced major gift: all of this is already Public-class information under the classification scheme this series covered earlier. Drafting a landscape summary from published sources with AI assistance does not change that classification, because nothing in the process compiles anything that was not already open to anyone who looked.

Where donor research crosses into personal data

The line moves the moment research stops summarising what an organisation or a donor chose to publish and starts assembling a profile of a named individual: net worth estimates, family relationships, giving patterns pieced together across unrelated sources, anything touching health or political affiliation. Each fact taken alone might be publicly findable, but compiling them into a single profile is a new act of processing personal data, and for anything touching health, politics, or other special categories, that processing sits under a stricter regime than an internal memo ever does.

What is safe to research and what needs a different process

Compiling scattered public facts into one profile is not research. It is new processing of personal data.

The trade-off in slowing down for this

Routing wealth-screening data and personal-profile research through a data-processing-agreement check and a sign-off step costs real time, exactly when a development team is under pressure to move fast ahead of a campaign or an ask. The honest answer is that this is precisely the kind of research most likely to end up in a shareable document, because it feeds directly into a briefing note someone hands to a board member, and a data protection complaint from a major donor, or a leaked wealth profile, costs the relationship and the organisation's reputation far more than a slower prospecting pipeline ever would.

The practical takeaway

Treat published giving history and public board information as safe Public-class research, but route anything that compiles wealth estimates or personal characteristics about a named individual through the same data-processing-agreement and sign-off checks this series set out for Confidential and Restricted data.

No external statistic cited; this article presents an internal practical guide rather than third-party evidence.

Series · Role-by-role patterns · part 2 of 6
Keep reading
02 ยท AI Use Policy

What are our people allowed to do, and how?

If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.