You cannot trust your own data. The same donor exists three times under three spellings. Your program numbers in one system do not match the other. Nobody actually owns the database, so it has quietly rotted. Your systems do not talk, so your people retype the same information into each one and mistakes creep in.
And the numbers you report to funders and your board are assembled by hand each time, with a quiet prayer that they are right. This work helps you know what data you hold and where, put someone in charge of it, keep it clean, and connect the systems that should share information, so your data becomes something you can rely on instead of something you fight. It is not the legal side of data, privacy law, breach duties, the protection of sensitive information, which lives in the compliance and risk work; this is the operational side, the ownership, cleanliness, and connection of your data. It is not the technical work of migrating or integrating systems, which is a technology professional's job where it gets complex. Use this if your data is siloed, duplicated, or untrustworthy, or your systems do not share what they should. And a boundary: if your concern is the legal protection of sensitive data, whether you are allowed to hold it, what you must do if it leaks, that is the compliance and risk work, and this guide will point you there.
You cannot own or trust data you have not located. List the important information your organization holds, donors and gifts, the people you serve, program activity, finances, staff, and for each note where it lives, who maintains it, and who relies on it. Then mark where the same data lives in more than one place, where it disagrees between systems, where it is entered by hand into several systems, and where no one is clearly in charge.
Open the Data Inventory →Data with no owner rots, and dirty data misleads every decision made from it. Assign a data owner for each important set, responsible for its accuracy, its rules, and who may change it. This is not a technical role; it is accountability for the data being right. Then agree the basic rules that keep data clean: one agreed way to enter a name or a gift, one place that is the source of truth for each kind of data, a periodic cleanup of duplicates, and a backup so it cannot be lost.
Its legal protection, whether you may hold it and what you owe if it leaks, is the compliance, legal and risk work. This guide keeps it clean; that work keeps it legal. This is a route, not a stop.
When systems do not share information, your people retype it, and every retype is a chance for error and a waste of time. Map your systems and mark where the same information has to move between them, and where your people are retyping it by hand today. Prioritize the connections that would save the most rekeying and error. Then either link the systems, with a professional where it is technical, or where a real connection is not worth it, set a clean, owned manual routine for moving the data once and correctly.
Building an integration, moving data between systems safely, that is a technology professional's job, and a botched integration can corrupt or lose data. Bring in the right help for the technical connection. This is a route to an honest edge, not a stop; deciding what should connect and why stays yours.
Clean, connected data decays the moment attention lapses. Set a light periodic check: spot the duplicates creeping back, confirm the systems are still in sync, confirm the backups are running, and confirm the numbers you report can be traced to a trusted source. Then, for the key numbers you report to funders and your board, set a clear, repeatable way to produce them from the source data, so reporting stops being a hand-assembled guess. Feed persistent data problems into your improvement habit.
Open the Data Trustworthiness Check →The legal side of data, especially sensitive information about the people you serve, is a compliance and legal matter, and this work sends the question of what you may hold and what you owe if it leaks to the compliance, legal and risk work and the right professional. And the technical work of moving and connecting data safely is a technology professional's job, because a mistake there can lose or expose exactly the information you were trying to protect. This work gives you ownership, cleanliness, and connection; it does not replace the legal and technical professionals the serious parts require, and it says so plainly.
You know what data you hold and someone owns each set. The worst duplication is cleaned up, and the systems that should share data do. And the numbers you report can be traced to a trusted source rather than assembled by hand and hoped over.
If your plan named other priorities, return to your plan for the next one, and keep your improvement habit running so the systems you built stay healthy. If the concern is the legal protection of sensitive data, go to compliance, legal and risk. If you need to prove your programs change lives, that is impact measurement and evaluation; operational data is not the same as impact evidence.
And if you came to this framework in a crisis, handled the acute thing, and worked your way here to build the operation underneath it, then this is the moment the door that was wrong when you arrived is finally right. You were overwhelmed then, and a full look across the whole organization would have been the wrong thing to hand you. You are steadier now, running on systems instead of heroics. When you are ready, there is a short check-up that looks across the whole organization and shows you what deserves attention next. That is not an offer and it is not a sale. It is the next honest thing to look at, the way a doctor says come back in a few weeks now that you are on your feet. The whole-organization check-up →