Policy issue
State Data Privacy Patchwork
A growing set of state consumer-data laws now reaches member associations that hold dues, event, and certification records, with no uniform standard for nonprofits.
Our position
NANA's position
Twelve states now have comprehensive consumer-data-privacy statutes, and most were written with retailers and advertisers in mind, not member associations. Even so, several of the laws sweep in any organization that processes a threshold number of consumer records each year, and a 400-org trade association's dues roster, event registration list, and CAE credential records can clear that threshold without the association ever selling data to anyone. NANA's position is that a 501(c)(6) or 501(c)(3) association's ordinary membership recordkeeping should not trigger the same compliance obligations written for a data broker.
None of the twelve state laws is currently unreasonable on its own. The problem is the number of them, each with its own definitions of "sale," its own notice-and-cure period, and its own deadline for responding to a member's data-access request. An association with chapters or members in six or more states, which describes most of NANA's own membership, is functionally required to comply with the strictest state law in force anywhere it has members, because building six separate compliance programs is not realistic for a small staff.
Moira Kavanagh-Pratt, general counsel at the Society of Rural Hospital Administrators and the author of NANA's brief on this issue, has been blunt with the policy team about what she is seeing in member calls: associations are treating every state's law as if it were the strictest one, by default, because no one on staff has time to track which provision applies where.
Why it matters to members
Member associations that hold any of the following are affected: dues and payment records, event registration data, CAE or certification records, or an emailable roster of more than a few thousand contacts. That describes nearly every NANA member association above a small volunteer-run chapter. The exposure is not hypothetical — several states allow a private right of action or statutory damages for a documented failure to honor a data-access or deletion request within the statute's deadline, and deadlines range from 45 to 60 days depending on the state.
The practical risk for most associations is not a headline-grabbing breach. It is a missed 45-day response window on a routine member request, triggered because no one on a four-person staff owned the intake process. Associations that operate a member portal or an AMS with self-service login are generally better positioned, since a portal can route access requests automatically; associations still working from spreadsheets and shared inboxes are the ones most exposed.
What we're asking Congress/agencies
NANA is not asking Congress to override state consumer-protection law wholesale. The ask is narrower: a federal floor that would let an association satisfy every state's recordkeeping and response-timeline requirement by meeting the single strictest standard in effect, rather than requiring a state-by-state compliance calendar for the same underlying data. This would leave state attorneys general their existing enforcement authority intact while removing the multiplicity problem that falls hardest on organizations too small to run a compliance department.
Until any such floor exists, NANA's brief recommends associations build to the strictest current state standard as a practical shortcut, and the policy team is tracking each new state law as it passes so members are not caught by a deadline they did not know applied to them.