Regulatory Compliance

Federal, state, and international regulatory obligations mapped to advancement AI use cases.

Regulatory compliance

No federal statute specifically governs AI in advancement. Compliance obligations arise from applying existing regulations (FERPA, HIPAA, state privacy laws) to AI use cases, and from emerging state AI governance laws that define advancement-related activities as consequential decisions.

Compliance map by institution type

RegulationApplies toAdvancement relevance
FERPA All institutions receiving federal education funding Student records used in alumni identification, young alumni engagement, student philanthropy. AI that ingests enrollment, academic, or financial aid data.
HIPAA Healthcare institutions, academic medical centers Patient data in grateful patient programs. AI-based prospect identification from clinical encounter data.
NY SHIELD Act Effective 2020. Any organization holding NY resident PII, including nonprofits. No exemption by size or tax status. Requires data inventory, vendor management, and risk assessment for all PII processing. AI data flows must be inventoried and documented. Vendor contracts must include reasonable safeguard commitments.
NY NYHIPA Passed both chambers June 2026; awaiting governor's signature. Regulates health-related information including inferences derived through AI/ML. If signed: advancement offices handling health-related constituent data would need separate authorization for processing. Covers health-related inferences, not just direct clinical data. No nonprofit exemption.
New Jersey NJDPA Effective January 2025. No nonprofit exemption. Cure period expired July 2026. Consumer financial information classified as sensitive data requiring opt-in consent. Prospect research and wealth screening inherently process financial information on NJ residents.
Minnesota MCDPA Effective July 2025 (postsecondary: July 2029). No nonprofit exemption. Consumers can question and challenge automated profiling decisions, demand reasoning, and request reevaluation. Covers education and financial services decisions.
Oregon OCPA Effective July 2025 for nonprofits. No exemption. GPC mandatory January 2026. Profiling opt-out covers education and financial services decisions. Institutions must honor Global Privacy Control signals.
Montana MTCDPA Effective October 2025 (as amended by SB 297). No nonprofit exemption. Removed the "solely" modifier from profiling opt-out. Covers AI-assisted decisions even with human review in the loop.
Maryland MODPA Effective October 2025. No nonprofit exemption. Universities explicitly covered. Strict data minimization. Advancement offices must justify each data element (wealth screening, real estate records, SEC filings) as reasonably necessary.
Colorado SB 26-189 Effective January 1, 2027. Covers deployers of AI for consequential decisions affecting Colorado residents. Education enrollment decisions are consequential. AI scoring that determines which admitted students receive outreach triggers notice and disclosure requirements.
California CCPA/CPRA ADMT Finalized September 2025. Covers automated decision-making technology for significant decisions. Education and employment decisions are significant. Risk assessments required for high-risk profiling. Profiling in education contexts triggers specific obligations.
Connecticut SB 1103 Enacted June 2026. Requires notice for automated employment and education decisions. Pre-use notice required when automated processes are a substantial factor in decisions. Explanation of principal reasons required for adverse decisions.
Delaware DPDPA Effective January 2025. No nonprofit exemption. Profiling opt-out for automated decisions producing legal or significant effects. Standard data protection assessment requirements.
GDPR Institutions with constituents in EU member states International campaign operations, alumni engagement in EU. Automated profiling subject to Article 22 restrictions.
EU AI Act Organizations deploying AI systems affecting EU residents AI systems determining access to education are classified as high-risk under Annex III, Area 3. Transparency obligations under Article 50 for chatbots and AI-generated content.

State law coverage

Hover or tap a state to see its current AI and privacy law obligations for advancement offices. Color indicates enacted law, limited coverage, or pending legislation.

Enacted
Enacted — limited scope for advancement
Pending / future effective date
No specific AI/privacy law affecting advancement

State AI and privacy legislation

The table below provides the same state compliance data accessible from the interactive map above.

State Law Status Effective date Key provisions
California CCPA/CPRA ADMT Enacted September 2025 Risk assessments required for high-risk profiling in education and financial services.
Colorado SB 26-189 Pending January 2027 AI for consequential decisions affecting CO residents. Education enrollment decisions are consequential.
Connecticut SB 1103 Enacted June 2026 Pre-use notice required when automated processes are a substantial factor in decisions.
Delaware DPDPA Enacted January 2025 Profiling opt-out for automated decisions producing legal or significant effects.
Illinois HB 3773 Enacted (limited scope) January 2026 AI in employment decisions: notice, strict liability for disparate impact. Applies to advancement staffing, not donor operations.
Maryland MODPA Enacted October 2025 Strict data minimization. Must justify each data element as reasonably necessary. Universities explicitly covered.
Minnesota MCDPA Enacted July 2025 Consumers can question automated profiling, demand reasoning, and request reevaluation. Postsecondary institutions delayed to July 2029.
Montana MTCDPA (SB 297) Enacted October 2025 Removed ‘solely’ modifier from profiling opt-out. Covers AI-assisted decisions even with human review.
New Jersey NJDPA Enacted January 2025 Consumer financial information classified as sensitive data requiring opt-in consent. Prospect research and wealth screening on NJ residents requires explicit consent.
New York SHIELD Act + NYHIPA (pending) Enacted (limited scope) 2020 (SHIELD); pending (NYHIPA) SHIELD Act: PII safeguards, data inventory, vendor management. NYHIPA: if signed, covers health-related AI inferences. Local Law 144: employment AI only.
Oregon OCPA Enacted July 2025 Profiling opt-out covers education and financial decisions. Global Privacy Control mandatory January 2026.
Texas TDPSA Enacted (limited scope) July 2024 Profiling opt-out for decisions producing legal or significant effects.
Vermont VDPOSA Pending January 2028 Privacy notices must disclose LLM training data use. Profiling challenge rights.
Virginia VCDPA Enacted (limited scope) January 2023 Profiling opt-out for decisions producing legal or significant effects.

FERPA and AI

No FERPA guidance specifically addresses AI. The Department of Education's Privacy Technical Assistance Center (PTAC) applies existing FERPA principles to AI use cases through vendor FAQ guidance on the school official exception (34 CFR § 99.31(a)(1)(i)(B)).

For an AI vendor to receive education records without student consent under the school official exception, the vendor must: (a) perform a service the institution would otherwise use employees for; (b) operate under the institution's direct control regarding use and maintenance of education records; (c) use records only for the purpose specified in the agreement; and (d) meet the criteria in the institution's annual FERPA notification for school official status.

  • AI models do not train on protected student records unless a legitimate educational interest determination is documented
  • If a vendor uses education records to train a model that serves other clients, that use exceeds the school official exception scope. Verify that your vendor's AI training practices do not cross this boundary.
  • Student opt-outs of directory information are enforced in AI training datasets and output datasets
  • AI vendor contracts include FERPA-required provisions for data handling by school officials
  • HECVAT 4 assessment is completed for vendors processing student data (includes FERPA alignment questions)

HIPAA and healthcare philanthropy

No published HHS guidance addresses the intersection of AI, HIPAA, and grateful patient fundraising. HHS OCR issued a Dear Colleague letter on January 10, 2025 confirming that Section 1557 nondiscrimination protections apply to AI use by covered entities, effective May 1, 2025.

Grateful patient programs operate in a space where development offices receive limited directory information under HIPAA's treatment, payment, and health care operations (TPO) provisions or through patient authorization. When AI enters this process (e.g., a model scoring patients for philanthropic capacity), the question is whether that processing constitutes a health care operation or exceeds the TPO scope. No OCR guidance addresses this question directly.

  • AI-based grateful patient identification does not access protected health information without authorization compliant with 45 CFR § 164.508
  • Any AI vendor processing PHI operates under a Business Associate Agreement
  • De-identification standards (Safe Harbor per 45 CFR § 164.514(b) or Expert Determination per 45 CFR § 164.514(a)) are applied before clinical data enters AI workflows
  • Grateful patient program AI workflows are reviewed by the institutional privacy officer
  • AI systems do not use clinical encounter data to infer diagnoses, conditions, or treatments for prospect identification unless the data has been properly authorized or de-identified

New York

New York does not yet have a comprehensive consumer privacy law, but several enacted and pending laws affect AI data processing by advancement offices with NY-based constituents or operations.

SHIELD Act (GBL §§ 899-aa, 899-bb)

Effective since 2020. Applies to any organization holding NY resident PII, including nonprofits. No exemption by size or tax status (a small business safe harbor applies only below 50 employees, $3M revenue, or $5M in assets).

  • Inventory all points where PII is collected, stored, processed, or transferred, including AI data flows. When constituent PII enters an AI system, that data flow must be documented.
  • AI vendors receiving constituent PII require contractual commitments to reasonable safeguards, not just a terms-of-service checkbox.
  • Assess AI-specific risks to PII: model training on PII, data leakage through prompts, retention by third-party AI services, and inference of sensitive attributes from non-sensitive data.
  • Maintain data retention and destruction policies that cover PII sent to AI vendors. Indefinite retention by a vendor for model training creates a compliance problem.

NY Health Information Privacy Act (NYHIPA, S-9269)

Passed both chambers June 2026. Awaiting governor's signature. If signed, effective six months after signing. No nonprofit exemption. The prior version was vetoed December 2025.

NYHIPA would regulate "regulated health information" (RHI), defined to include health-related inferences derived through algorithms or machine learning. This provision is directly relevant to advancement: organizations cannot evade regulation by inferring health status rather than collecting it directly. Advancement offices handling health-related constituent data (disability accommodations, wellness program participation, health-related gift designations) would need separate, plainly written authorization for processing. Penalties up to $15,000 per violation with a six-year lookback.

NYC Local Law 144

Effective since 2023. Requires annual bias audits, public disclosure, and candidate notice when automated tools are used for hiring or promotion decisions in NYC. Relevant to institutional HR operations using AI in advancement staffing. Does not apply to donor scoring or prospect research.

State AI and privacy laws

State privacy laws increasingly define AI-based profiling and automated decisions in education, employment, and financial services as consequential or significant decisions, triggering notice, opt-out, and impact assessment requirements. The triggering factor is where constituents reside, not where the institution is located. Institutions with a national constituent base face overlapping obligations across multiple jurisdictions.

Several states do not exempt nonprofits or educational institutions. The states with the highest operational impact for advancement offices:

States requiring immediate attention

  • New Jersey (NJDPA, effective January 2025, cure period expired July 2026): Consumer financial information is classified as sensitive data requiring opt-in consent. Prospect research and wealth screening inherently process financial information on NJ residents. Draft regulations require disclosure of how profiling software works and whether it has been evaluated for bias.
  • Montana (MTCDPA as amended by SB 297, effective October 2025): Removed the "solely" modifier from profiling opt-out. Consumers can opt out of AI-assisted decisions even when a human reviews the output. This closes the human-in-the-loop defense that most advancement offices rely on.
  • Minnesota (MCDPA, effective July 2025; postsecondary institutions: July 2029): Consumers can question automated profiling decisions, demand reasoning behind outcomes, learn what actions would change the result, and request reevaluation after data correction. No other state provides this affirmative challenge right. Covers education and financial services decisions.
  • Oregon (OCPA, effective July 2025 for nonprofits): Profiling opt-out covers education and financial services decisions. Global Privacy Control (GPC) signal must be honored as of January 2026. Data protection assessments required for profiling that presents foreseeable risk of harm.
  • Maryland (MODPA, effective October 2025): Strict data minimization requirement. Advancement offices must justify each data element collected on MD residents (wealth screening results, real estate records, SEC filings, demographic appends) as reasonably necessary and proportionate to the disclosed purpose. Universities explicitly covered.

Additional state obligations

  • Colorado (SB 26-189, effective January 2027): AI scoring that determines which admitted students or donors receive outreach may fall within the "education enrollment or opportunity" category of consequential decisions, triggering notice and disclosure requirements.
  • California (CCPA/CPRA ADMT regulations, finalized September 2025): Determine whether Tier 2 or Tier 3 use cases qualify as "significant decisions" in education or financial services. If so, conduct the required risk assessments.
  • Connecticut (SB 1103, enacted June 2026): Pre-use notice required when automated processes are a substantial factor in decisions. Must disclose AI-generated content in certain contexts.
  • Delaware (DPDPA, effective January 2025): No nonprofit exemption. Profiling opt-out for automated decisions producing legal or significant effects.
  • Virginia and Texas: Review opt-out obligations for profiling that produces legal or significant effects.
  • Vermont (VDPOSA, effective January 2028): Will require privacy notices to disclose whether personal data is used to train large language models. Profiling challenge rights mirror Minnesota's.

Operational implication: Institutions with a national constituent base should treat New Jersey's opt-in consent requirement for financial data, Montana's removal of the human-in-the-loop defense, and Minnesota's challenge right as the high-water marks for compliance planning. Meeting the most restrictive state's requirements generally satisfies less restrictive jurisdictions.

  • Map which state laws apply to your constituent base by geography. Most state laws are triggered by constituent residency.
  • Document which state law requirements apply to each Tier 2 and Tier 3 use case in the system inventory.
  • Review whether your institution honors GPC signals. Oregon and Montana require it for nonprofits.
  • Assess whether NJ residents in your prospect research pipeline require opt-in consent for financial data processing.

EU AI Act (for institutions with EU constituents)

AI systems used to determine access to education are classified as high-risk under Annex III, Area 3 of the EU AI Act. This classification carries obligations under Articles 8 through 17, including risk management, data governance, technical documentation, transparency, and human oversight requirements.

Most advancement operations at US institutions will not fall under EU AI Act jurisdiction unless they deploy AI systems that affect decisions about EU residents' access to educational programs, financial services, or employment. Institutions with EU campuses or substantial international enrollment should assess whether their AI use cases fall within scope.

Separate from the high-risk classification, Article 50 transparency obligations apply to any AI system that interacts directly with persons (chatbots must identify themselves as AI) and to AI-generated content (must be marked as AI-generated where technically feasible).

Donor privacy standards

Beyond regulatory requirements, professional association standards and donor expectations impose additional constraints on AI use with constituent data.

  • AI-generated solicitation strategies respect donor-stated communication preferences and opt-outs
  • Anonymous and confidential gift designations are enforced in AI training data and outputs
  • APRA Statement of Ethics principles (accuracy, confidentiality, relevance, donor dignity) apply to AI-generated prospect research outputs
  • APRA's Ethics in AI for Fundraising Toolkit recommends ongoing human oversight of AI tools, ethical review of third-party vendors, and attention to bias in training data
  • Donors are informed if AI contributes to communications directed to them, per institutional policy and applicable state law

Need help implementing AI governance for your advancement program?

Start a conversation