Digital Conduct Policies for Nonprofit Staff and Board
Your nonprofit's reputation increasingly lives online, and most of the people who can damage it do not work in communications. A board member's divisive social media post, an employee sharing confidential information, a staff member representing the organization unprofessionally: each of these lands on your credibility, and through your credibility on your mission. A digital conduct policy sets expectations for how staff and board members represent the organization online, what they can share, and how they communicate digitally. Written well, it is not a technology document at all. It is a conduct document that happens to apply to digital spaces, and it works by making the organization's existing values legible in the places where people actually behave.
Why the Policy Exists at All
Most nonprofits write a digital conduct policy after an incident rather than before one, which is the wrong order. The value of the policy is not that it punishes people who have already caused harm; it is that it removes ambiguity before anyone has to guess. When a program director is asked on a public thread why a service changed, when a board member wants to post about a decision the board is still debating, when a volunteer coordinator is handed the login to the organizational account, each of them is making a judgment call alone, under time pressure, using private instincts about what is acceptable. A policy replaces that guesswork with a shared answer.
The second reason is fairness. Organizations without a policy still have expectations, and unwritten expectations get applied unevenly: enforced against the person whose post annoyed a funder, ignored for the person whose post annoyed nobody. Writing the standard down is what makes consistent application possible, and consistency is the only thing that gives a conduct standard any authority.
Key Areas to Address
A workable policy covers a small number of areas thoroughly rather than every conceivable scenario shallowly. The six areas below are the ones that actually generate incidents in nonprofit organizations: social media, representation, confidentiality, communication norms, device security, and remote work. For each area, the pattern is the same. First define what you are talking about, in concrete terms your staff would recognize. Then state the rules plainly. The definitions matter more than people expect, because most conduct disputes turn out to be disagreements about scope rather than disagreements about right and wrong.
1. Social Media Use
Start by defining the landscape. What social platforms does your organization actually use, whether that is Facebook, Instagram, TikTok, LinkedIn, or Twitter/X? Who holds access to the official accounts, and what happens to that access when someone leaves? What are the rules for posting, and does anything need review before it goes live? Answering those questions in writing usually surfaces a surprise, such as an account nobody has logged into in a long while, or a password shared with a former contractor.
Rules might include:
- Official accounts must be approved by [person/committee] before posting
- Posts should reflect organizational values and mission
- No sharing of confidential information or unpublished plans
- All opinions shared in professional context (as staff/board) should be fact-based and respectful
- Engage in comments professionally. Don't engage in personal arguments or flame wars
The harder question is personal accounts. Should staff and board post personally about the organization? Most policies allow it, with conditions: be truthful, don't share confidential information, be respectful. Staff posting personal opinions about work should make clear these are personal opinions, not organizational positions. That last condition does most of the work, because the reputational risk in personal posting is rarely the opinion itself. It is the reader who cannot tell whether they are hearing from an individual or from the organization, and who therefore assumes the organization.
2. Online Representation of the Organization
Define the moment at which someone stops speaking for themselves and starts speaking for you. Someone is clearly acting as a representative of the organization when they are using an organization email address, speaking at an organizational event, or running an organizational page. Naming those situations explicitly gives people a test they can apply in the moment, rather than a vague instruction to use good judgment. It also protects staff, because it tells them when they are entitled to speak freely.
Rules might include:
- Represent the organization honestly and accurately
- Be professional and respectful, even in disagreement
- Don't make commitments the organization can't keep
- Don't make public statements about organizational conflicts without approval from leadership
- Don't badmouth partners, funders, or other organizations publicly
The rule about commitments deserves emphasis. A well-meaning staff member answering a question in a comment thread can create an expectation the organization never agreed to, and walking that back publicly costs far more trust than declining to answer would have.
3. Confidentiality and Information Sharing
Define what information is confidential, and be specific: financial data, personnel issues, strategic plans, donor information, and participant information all belong on the list. Then state what the penalty is for sharing it. A confidentiality clause with no stated consequence reads as advice rather than as a rule, and people treat it accordingly.
Confidential usually includes:
- Personal information about members, participants, or beneficiaries
- Financial information (budget, revenue sources, donor names)
- Personnel matters (salaries, performance issues, hiring decisions)
- Strategic plans before they're public
- Board discussions marked as confidential
- Legal proceedings or disputes
Just as importantly, define the exceptions, because a confidentiality rule with no exceptions is one that people will quietly break rather than openly test. Say when sharing is required or allowed: whistleblowing for illegal activity, consulting with a personal attorney, and responding to public records requests are the cases most policies name. Writing the exceptions down signals that the policy is about protecting people and information, not about suppressing legitimate disclosure, and it makes the rest of the clause easier to enforce.
4. Communication Norms
Define how staff and board should communicate with each other digitally. This is the section people skip because it feels like etiquette rather than conduct, and it is also the section that prevents the most day-to-day friction. Norms about channel choice, response time, and after-hours contact are what stop a distributed team from drifting into a state where nobody knows which platform holds the real decision and everyone feels permanently on call.
Norms might include:
- Email is for formal communication. Use it when you need a record
- Respond to work email within 24 hours during business days
- Don't send work emails on nights/weekends unless urgent. Respect people's off-hours
- Use appropriate platforms: confidential info via email, not Slack. Major decisions documented in writing, not just chat
- Avoid "reply all" unless necessary
- Be respectful in all digital communication, especially when disagreeing
Two of these norms are really records-management rules wearing a courtesy disguise. Deciding that email is the channel of record, and that major decisions get documented in writing rather than left in chat, is what makes it possible to reconstruct a decision a year later when a funder, an auditor, or a new board member asks how it was made.
5. Device Security and Data Protection
Define what devices staff can use for work and how those devices should be secured. In small nonprofits this section almost always has to account for personal hardware, because the organization cannot supply a laptop and a phone to everyone. That is a legitimate arrangement, but it needs stating rather than assuming, since the security expectations attached to a personal device are different from the ones attached to an organizational one.
Rules might include:
- Use organizational devices when available for organizational work
- If using personal devices, install [required security software]
- Lock your computer/phone when leaving it unattended
- Use strong passwords and change them quarterly
- Don't connect to public WiFi when accessing organizational data
- Report lost/stolen devices immediately
The reporting rule is the one worth protecting culturally. People report a lost phone quickly when they expect help and slowly when they expect blame, and the gap between those two responses is where most of the actual exposure happens. Write the rule so that prompt reporting is treated as compliance, not as a confession.
6. Remote Work Communication
If staff work remotely, define expectations for video calls, response times, and availability. Remote work turns a set of previously invisible assumptions into decisions someone has to make: which meeting platform counts as official, whether cameras are expected, how people signal that they are offline, and where it is safe to discuss sensitive matters when the office is a spare room.
Rules might include:
- Use organizational platforms (Zoom, Google Meet) for work meetings, not personal accounts
- Be visible in video calls (unless you have accessibility needs)
- Communicate your working hours and availability
- Use background blur or organizational background in video meetings
- Don't discuss confidential organizational matters in places where household members might overhear
The accessibility carve-out on the camera rule is not decoration. A blanket cameras-on requirement excludes people for reasons that have nothing to do with engagement, and building the exception into the rule is cheaper than handling it as a series of individual accommodations later.
Enforcement Approach
A digital conduct policy is only as good as its enforcement, and consistency matters more than severity. The useful structure is a tiered one, so the response scales with the harm rather than with how visible the incident happened to be.
Minor violations, such as a slow email response or a slightly unprofessional tone, warrant a gentle reminder and a conversation. Nothing goes on a record; the point is to correct drift early, while it is still cheap to correct.
Moderate violations, such as sharing minor confidential information accidentally, warrant a written warning, training on the policy, and an agreement to change behavior. The training step is what distinguishes this tier from the one below it: the assumption is still that the person did not understand the standard, and the organization owes them the chance to learn it properly.
Serious violations, such as sharing sensitive donor information or participant data online, or making public statements that damage the organization, warrant escalation to a supervisor or the board and carry the possibility of termination. These are the cases where third parties have been harmed, and the organization's obligation runs to them as well as to the employee.
The key is consistency. If you enforce standards for some staff but not others you lose credibility, and a policy understood to be selectively applied is worse than no policy, because it now looks like a tool rather than a standard. Board members are the hardest case, since nobody supervises them in the ordinary sense, which is why the policy should name them in its scope from the first line.
Policy Template Outline
A complete policy does not need to be long. It needs a clear purpose, a clear scope, and one short section for each of the areas above, followed by the consequences. The outline below is a working skeleton; the bracketed sections are where your organization's own decisions go.
- Purpose: "This policy guides staff and board member digital conduct to protect our organization's reputation and values, and to protect confidential information."
- Scope: "This applies to all staff, board members, and contractors when they're representing the organization or discussing organizational matters."
- Social Media: [Your rules around personal vs. organizational accounts]
- Confidentiality: [What's confidential, what's not, penalties for breaches]
- Professional Communication: [Email norms, response times, respectfulness]
- Online Representation: [How to represent the organization, what statements require approval]
- Device Security: [Device use, passwords, data protection]
- Consequences: [Minor to serious violations and corresponding actions]
Two lines carry more weight than the rest. The scope line decides whether contractors and board members are covered, which is where most disputes about applicability start, and the consequences line decides whether the document is a rule or a suggestion. If you have limited time to negotiate wording, spend it there.
Common Mistakes
Too restrictive. Banning all personal social media use or all personal opinions isn't realistic, and a rule nobody can follow trains people to ignore the document that contains it. Give people space for personal expression while protecting organizational interests. The workable line is almost always about attribution and confidentiality rather than about content.
Only about technology. The policy should be about conduct, not just technology. It is less about how you communicate and more about what you communicate. A policy organized around tools ages badly and misses the behaviors that actually cause harm; a policy organized around conduct survives the arrival of the next platform.
Not updated for new platforms. When TikTok or whatever new platform emerges, your policy might not address it. Review annually and update for new tools. The annual review is also the natural moment to check whether anything in the policy has quietly become unenforceable.
Enforcement gaps. Many organizations have great policies but don't enforce them consistently. Either enforce consistently or don't bother having the policy. An unenforced policy still creates the expectation of protection for the people it names, and failing that expectation is its own harm.
Building Your Policy
Draft a policy that addresses the areas above, then get feedback from staff before you finalize it. Staff will tell you what is realistic, and they will catch the rules that sound reasonable in a leadership meeting and are impossible in practice, such as a response-time expectation that ignores how frontline schedules actually work. Take that feedback seriously; a policy that survives contact with the people it governs is worth more than one that reads well.
Then get board approval, which matters both because the board is covered by the policy and because approval is what gives it standing. Roll it out with training rather than an email attachment, so people encounter the reasoning and not only the rules, then enforce it consistently, which is the step that turns a document into a norm. Review it annually and ask three questions honestly. Is it working? Do staff understand it? Are we enforcing it fairly? If the third answer is uncertain, that is the one to fix first.
Anti-Patterns
- Writing the policy after the incident, and about the incident. A document drafted in the week after a specific post reads as a rebuke of one person, and the rest of the staff will read it that way. Write the standard generally, and handle the incident separately.
- A confidentiality clause with no list and no exceptions. "Do not share confidential information" is not a rule, because it delegates the definition to the reader. Name the categories, and name the cases where disclosure is permitted or required.
- Policing personal opinion instead of attribution. Trying to control what staff think, rather than requiring them to be clear about whether they speak for themselves or for the organization, produces a rule that is both unenforceable and corrosive.
- Exempting the board in practice. If the policy names board members in its scope but nobody is willing to raise a violation with one, the scope clause is decorative, and staff will notice before leadership does.
- Treating a lost device as misconduct. Punishing the report rather than the risk teaches people to delay reporting, which is the opposite of what the security rule exists to achieve.
- Rolling out by attachment. Sending the policy as a file and asking for a signature produces acknowledgment without understanding, and acknowledgment is not what you need on the day someone has to make a judgment call.
Practice Prompts
- Inventory your accounts. List every social platform where your organization has a presence, who currently has access to each, and what happens to that access when the person leaves. Mark any account whose access you could not fully account for.
- Write the scope sentence. Draft a single sentence naming exactly who the policy covers and in what situations. Test it against three real cases: a board member posting personally, a contractor using an organizational email address, and a volunteer running an event page.
- Build the confidentiality list. Using the categories in this lesson, write your organization's version, then add the exceptions. Ask one program staff member and one finance staff member whether anything is missing.
- Test the tiers. Take three incidents that have actually happened at your organization, or three plausible ones, and place each into the minor, moderate, or serious tier. Where two people place the same incident differently, the policy language needs work.
- Run the realism check. Show the draft communication norms to the staff whose schedules are least like leadership's, and ask which expectations they could not meet in a normal week.
- Schedule the review. Put the annual review on the calendar with a named owner, and note which platforms have appeared since the policy was last touched.
Reflection
Think about the last time someone at your organization posted something that made leadership uncomfortable. Was the discomfort about a genuine breach of confidentiality or representation, or about a personal opinion leadership disagreed with? The answer tells you which policy you actually need, and which one you might be tempted to write instead. Then ask the harder version: if that post had come from your longest-serving board member rather than a junior staff member, would the response have been the same? Consistency is easy to endorse in the abstract and expensive in the specific case, and the specific case is the only place it counts.
Glossary
- Digital conduct policy: A document setting expectations for how staff and board members represent the organization online, what they can share, and how they communicate digitally.
- Scope: The clause defining who the policy applies to, typically all staff, board members, and contractors, and in which situations it applies.
- Organizational representation: Acting in a context where a reasonable observer would take you to be speaking for the organization, such as using organization email, speaking at an organizational event, or running an organizational page.
- Confidential information: Information the organization has committed to protect, typically covering participant and member data, financial details, personnel matters, pre-public strategic plans, confidential board discussions, and legal disputes.
- Exception clause: The part of a confidentiality section naming when disclosure is required or permitted, such as whistleblowing on illegal activity, consulting a personal attorney, or responding to public records requests.
- Channel of record: The communication channel the organization treats as authoritative for decisions and commitments, commonly email rather than chat.
- Tiered enforcement: Matching the organizational response to the severity of the violation, from a conversation for minor issues through written warning and training to escalation and potential termination.
Related Lessons
- How to Write a Code of Conduct for Your Nonprofit Community
- Community Guidelines vs Code of Conduct vs Terms of Service: Differences
- Why Community Is Your Nonprofit's Most Undervalued Asset
- Inclusive Community Guidelines: Dominant-Culture Norms Hidden in Policies
- Donor Data Privacy: Your Legal and Ethical Obligations
- Cybersecurity for Nonprofits: The Essential Checklist
- Staff Cybersecurity Training: The 1-Hour Program That Sticks
Closing
The organizations that handle digital conduct well are rarely the ones with the longest policies. They are the ones whose staff and board can answer three questions without looking anything up: what counts as confidential here, when am I speaking for the organization, and what happens if I get it wrong. If your document answers those clearly, covers the areas where incidents actually occur, and applies the same way to the board chair and to the newest program assistant, it is doing its job.
Key Takeaways
- A digital conduct policy is a conduct document, not a technology document; organize it around behavior so it survives the next platform.
- Cover the areas that generate real incidents: social media, organizational representation, confidentiality, communication norms, device security, and remote work.
- Define terms before stating rules, because most conduct disputes are disagreements about scope rather than about right and wrong.
- Allow personal expression and require clear attribution; the risk is the reader who cannot tell whether they are hearing from a person or from the organization.
- A confidentiality section needs both a list of categories and a list of exceptions, or people will break it quietly rather than test it openly.
- Tier enforcement from conversation, to written warning with training, to escalation and possible termination, and apply the tiers to the board as well as to staff. Selective enforcement is worse than no policy.
- Draft, take staff feedback, get board approval, roll out with training, enforce, and review annually.
Frequently Asked Questions
Can we monitor staff's social media or email? You can monitor organizational email and devices. Many organizations monitor social media where staff are using organizational accounts. You can't monitor personal social media without consent and for a legitimate reason, such as a security investigation. Always inform staff of monitoring and have a clear policy.
What if a staff member posts something politically controversial on their personal account? If it's on their personal account and they're not identifying as representing the organization, it's generally their protected speech. You can only take action if it violates organizational values and they're clearly identified as organizational staff. Most policies avoid policing personal views.
Should we require staff to disclose their social media accounts? You can ask for accounts used professionally. But requiring disclosure of all personal accounts is invasive and rarely enforceable. Most policies ask for disclosure only of professional accounts.
What if a staff member accidentally shares confidential information online? Treat it seriously but proportionally. First, have them take down the post and report what happened. Then have a conversation about the mistake and provide training. The right response depends on whether the information was clearly labeled confidential, whether they knew, and how much damage resulted. Usually this is a learning moment, not a firing offense.
Does the policy apply to board members the same way it applies to staff? It should, and the scope clause is where you say so. Board members are covered when they are representing the organization or discussing organizational matters, which is the same test applied to staff and contractors. What differs is the escalation path, since board conduct is handled through board leadership rather than through a supervisor.
Skill.re