Training University of Wyoming Foundation Gift Officers to Protect Donor Trust through Privacy

Gift officers handle some of the most sensitive information in a donor's life — and the reputational and legal risk of mishandling it is real. UWF engaged Agility Lab to build a role-specific training curriculum that gave advancement staff practical guidance for the situations they actually face. Together, we addressed what belongs in email versus secure systems, how to verify donor identity in sensitive interactions, and how to write contact reports that are strategically useful without crossing privacy lines.

Frontline fundraising carries privacy risk by default.

Any advancement team handling major gifts, planned giving, and donor stewardship faces the same set of inherent privacy pressures. Development officers take notes in the field and need to know where those notes belong. Staff share donor information internally and need a clear framework for what's appropriate in which channel. Contact reports capture sensitive context and need to reflect what's strategically useful without crossing privacy lines. These aren't signs of a problem — they're the normal operational reality of fundraising work.

What UWF recognized is that staff doing this work well deserves more than good intentions. They deserve clear guidance, defined escalation paths, and the confidence that comes from knowing exactly what to do — and who to ask — when a situation is ambiguous. A privacy gap analysis surfaced the specific workflows where that clarity was most needed. The result was a staff training curriculum built to address them directly.

Agility Lab's approach

Rather than delivering generic compliance training, Agility Lab developed a curriculum built around the specific roles, tools, and daily decisions of UWF's advancement team. Each module was designed as a practical, scenario-based session — giving staff the language and judgment to handle privacy-sensitive situations with confidence, not just rules to follow.

Three areas emerged as highest priority:

  1. How donor information moves through internal email
  2. How staff verify donor identity in sensitive interactions
  3. How contact reports should capture strategic insight without crossing privacy lines

We built a separate module for each.

The training curriculum

Three core training modules were developed and delivered to UWF advancement staff:

Protecting Donor Privacy: What Belongs in Email and What Doesn't
Most privacy issues in advancement operations don't come from bad intent — they come from using familiar tools for data those tools were never designed to protect. This session gave staff a clear framework for what donor information belongs in email versus secure systems like DocFinity and the CRM, with practical guidance for daily scenarios: handling daily gift reports, writing gift officer strategy communications, taking notes after donor conversations, and managing situations where donors share sensitive information unprompted. The session addressed FOIA and public records law exposure directly — helping staff understand that internal emails can be requested and reviewed out of context — and introduced the principle that email should point to sensitive information, not contain it.

Donor Identity Verification and Information Protection Standards
Advancement staff regularly encounter situations that require them to confirm a donor's identity before sharing or updating records, and the stakes of getting it wrong are high. This session covered when verification is required, what methods are acceptable, and how to conduct verification in a way that feels like an extension of good donor care rather than a security interrogation. The training addressed the most sensitive edge cases: next-of-kin calls following a donor's passing, requests from financial advisors and estate attorneys, and situations where third parties seek information on a donor's behalf. Staff left with sample language, documentation protocols, and a clear understanding of the difference between verification and disclosure. Verification is also required for honoring Data Subject Access Requests (DSAR) under privacy law, so this training provided added compliance benefit.
 

Balancing Strategy and Privacy to Write Strong, Compliant Contact Reports
Contact reports are the institutional memory of a fundraising operation — and they're also a potential liability if they capture the sensitive details in the wrong way. Emerging privacy laws now treat information like inferred financial capacity, health status, religious affiliation, and political views as sensitive data, raising the bar for what advancement teams can record. This session introduced a practical risk spectrum — Green, Yellow, Red — to help staff assess what level of detail belongs in a contact report, how to reframe useful but risky observations into neutral, strategic language, and when to leave something out entirely. Scenario-based exercises gave staff practice applying the framework to realistic donor interactions, including planned giving conversations and situations involving third-party intel.

Concrete deliverables

What we accomplished together:

  • Three staff training modules — on email hygiene, donor identity verification, and contact report writing — each built around UWF-specific workflows, tools, and scenarios
  • Sample language and conversation scripts for high-stakes interactions, including next-of-kin calls, third-party advisor requests, and donor identity verification
  • A practical contact report risk framework (Green / Yellow / Red) giving staff a repeatable tool for assessing what detail level is appropriate
  • Scenario-based exercises built from realistic advancement situations, designed to build judgment rather than rote rule-following
  • Clear escalation paths so staff know exactly who to ask and where to turn when a situation is ambiguous

The outcome

UWF advancement staff now have the specific knowledge and judgment they need to handle donor information responsibly in the workflows that matter most — not as an abstract policy obligation, but as a practiced skill embedded in how they do their jobs. The training curriculum gives the Foundation a repeatable model for onboarding new staff and reinforcing standards over time.

The training approach reflects a core Agility Lab belief that privacy governance only works when it reaches the people doing the work. Policy documents protect organizations in audits. Trained staff protect donors every day.

What this means for your organization

You don't need a full privacy program overhaul to start building staff capability. If your advancement team handles major gifts, planned giving, or donor stewardship, the workflows covered in this training series apply to you — regardless of where your broader privacy program stands.

Agility Lab's training modules can be delivered as standalone sessions or as part of a larger privacy program engagement. If your team would benefit from clearer guidance, better escalation paths, and the confidence that comes from knowing exactly how to handle sensitive donor situations, we welcome the conversation.

STAY AGILE NEWSLETTER

Stay sharp on privacy without the overwhelm.

Strategic guidance, legislative updates, and analysis of Big Tech changes for nonprofit leaders who need to stay ahead.