TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Corporate
№ 339 Case Study — Corporate

A board member's side project outgrew the not-for-profit that hosted it

A Cobourg not-for-profit board discovered that a volunteer-run side program had quietly become a real business, and that the files behind it were sitting wide open before anyone started asking to see them.

Corporate8 min readCobourg, OntarioProtecting trade secrets
All Corporate case studies
ClientNuwan, a board member of a small Cobourg not-for-profit
The issueA self-funding side program had grown into a real revenue stream with no access controls on its records
ServiceConfidentiality and access policies drafted to formalize a lockdown the board had already started on its own
ResolutionThe files were secured and the arrangement documented before outside eyes ever saw them, though the underlying fix was mostly practical, not legal

The situation

The call came in on a weekday evening, and Nuwan opened with an apology for the hour before explaining why he could not wait until morning. He sat on the board of a small not-for-profit in Cobourg that ran a few community programs, and one of them, a modest resale and repair operation staffed mostly by volunteers, had stopped being modest. What had started three years earlier as a way to keep a spare room busy was now moving close to a hundred thousand dollars a year through informal books, and a regional partner organization had asked to review the program before agreeing to a joint funding arrangement.

Nuwan worked days as a gas station attendant and had joined the board because a friend needed a third signature on a grant application. He had never expected to be managing anything resembling a business. The program's day-to-day records, supplier contacts, pricing notes, and a rough client list built up over years of word of mouth, lived in a shared folder that every volunteer, current and former, could still open. Dilshan, another board member who drove for the regional transit authority, had raised the access question at the last meeting almost as an aside, and it had stuck with Nuwan ever since.

The trigger was not a threat. It was a date. The partner organization wanted to send someone in three weeks to look at the program's records as part of its own due diligence before committing funding. Nuwan did not know what that review would actually touch, and he did not want to find out that a departed volunteer, or worse a current one with a competing idea, had access to everything the moment outside eyes started looking. Hanna, who had helped build the program in its early years and had since drifted away from active involvement, still had full access to the shared folder and had recently mentioned to another volunteer that she was thinking about starting something similar on her own.

None of this amounted to an accusation. Hanna had done nothing wrong. But the board had never turned the program's informal habits into anything resembling a policy, and Nuwan could see, now that the stakes were about to include an outside reviewer, how exposed that left them. He wanted to know, plainly, what a not-for-profit board was even allowed to protect, and how fast it could be done.

What the review found

We asked Nuwan to send over what existed in writing before we asked anything else, and what came back was almost nothing. There was no volunteer agreement that mentioned confidentiality, no policy distinguishing board records from program records, and no record of who currently had access to the shared folder versus who had simply never been removed once their involvement ended. The organization's governing documents, entirely standard for a small not-for-profit, said nothing about proprietary information because nobody drafting them years earlier had anticipated that one of its community programs would eventually generate anything worth protecting.

The first useful finding was jurisdictional rather than dramatic: a not-for-profit can hold and protect confidential business information the same way any other organization can, even when the underlying activity supports a charitable or community purpose rather than private profit. The label 'not-for-profit' describes what happens to surplus revenue at the end of a fiscal year, not whether the organization's day-to-day operating information deserves legal protection while it is being generated. That distinction mattered to the board, because more than one member had quietly assumed, incorrectly, that because nobody personally profited from the resale program, there was nothing here legally worth guarding in the first place.

The second finding was more uncomfortable to sit with. The shared folder's access list included at least six people who no longer had any active role with the program, Hanna among them, and there was no record anywhere of when or why any of them had originally been granted access. Nobody had deliberately removed anyone from that list, but nobody had added anyone deliberately either; access had simply accumulated year over year as volunteers came and went. That is an extremely common pattern in small volunteer-run organizations, and on its own it is rarely a sign of malice. It is, however, exactly the kind of gap a due diligence reviewer notices within minutes, because it signals plainly that an organization does not actually know what information it holds or who can currently see it.

The third finding was the one that reframed the whole engagement for Nuwan and the rest of the board. The fix the board actually needed was not primarily a legal document at all. It was housekeeping: a proper access audit, a shortened and current list of volunteers with a genuine ongoing reason to see the records, and a considered decision about which files belonged to the program's sensitive core versus which were routine, low-stakes, and safe to leave broadly accessible. The legal work existed to formalize that housekeeping once the board had actually done it, not to substitute for the housekeeping itself.

What we did

  1. Mapped who actually had access to the shared folder, name by name, and cross-checked that list against current, active volunteer roles, because the board could not decide what to restrict until it understood how far access had already spread beyond anyone's original intention, and nobody on the board had ever actually counted the names before, let alone matched each one against a person still doing anything for the program today.
  2. Advised the board to complete the access cleanup itself before any legal paperwork went out, since removing stale permissions and consolidating scattered files was faster done directly by the people who knew the folder structure than routed through us as a legal task, and doing it themselves meant the board understood exactly what it was protecting once the documentation followed.
  3. Classified the program's records into three tiers, ordinary operational notes, financial summaries, and the small set of supplier and client information that gave the program its practical value, so the confidentiality obligations that followed would apply where they actually mattered rather than blanket the whole folder in a way that would frustrate day-to-day volunteer work or make ordinary tasks harder than they needed to be.
  4. Drafted a short confidentiality undertaking for current volunteers with access to the sensitive tier, written in plain language a volunteer without a legal background could read and actually understand in one sitting, rather than a dense agreement nobody would remember signing or feel bound by six months later, once the initial urgency of the review had faded, covering what needed to stay confidential, for how long, and what happened to the obligation once a volunteer's involvement ended.
  5. Wrote a board-approved access policy setting out who could request access to sensitive program records, who approved it, and how access was removed the moment someone's role ended, closing the exact gap that had let Hanna's access outlive her active involvement by more than a year without anyone noticing, a gap the policy now closes automatically rather than relying on someone remembering.
  6. Prepared a short briefing note for the board explaining, without alarming anyone, that Hanna's continued access reflected an administrative oversight rather than any wrongdoing, so the eventual conversation with her could stay factual and calm and not read as an accusation aimed at a volunteer who had given years to the program, and suggesting the conversation happen in person rather than by email, so tone and context would not be lost in a message Hanna might read as more formal or more pointed than anyone actually intended.
  7. Reviewed the due diligence request from the partner organization line by line and identified which records could be shared exactly as requested and which needed a narrower, summarized version to protect the sensitive tier without the board appearing evasive or unprepared to the reviewer, since a reviewer reading hesitation into a routine redaction can do as much damage as the underlying gap itself.
  8. Confirmed the timeline against the three-week deadline and sequenced the housekeeping, the undertakings, and the policy adoption so the board had a defensible, fully documented position ready well before the reviewer arrived, with several days of buffer built in for anything unexpected, which turned out to matter when one volunteer took longer than planned to return a signed undertaking, a delay that would have looked far worse without the buffer already built into the schedule.

The outcome

The board completed its access cleanup within ten days, well ahead of the reviewer's visit, and removed access for everyone, including Hanna, who no longer had an active role. The confidentiality undertakings were signed by the remaining volunteers with access to sensitive records, and the board adopted the access policy at a short special meeting called for that purpose. When the partner organization's reviewer arrived three weeks later, the board had a clean, documented answer to every question about who could see what and why, and the review itself passed without any follow-up questions about governance.

The engagement did not produce a dramatic win, and it was not meant to. The real work, sorting the folder, deciding what mattered, and removing stale access, was done by the board and its volunteers, not by us. Our contribution was narrower: turning that housekeeping into something the organization could point to and stand behind, and making sure the eventual conversation with Hanna happened as a routine administrative correction rather than an accusation that could have damaged a long-standing volunteer relationship built over several years. Hanna took the news well once it was framed as policy rather than suspicion, and she has since offered to help with the program again in a smaller, defined role with narrower access.

Nuwan later said the hardest part had been realizing how much exposure had built up simply through inattention, not through anyone's carelessness in any single moment. The program continued to grow after the review, and the board treated the access policy as a standing item to revisit annually rather than a one-time fix put in a drawer and forgotten. Nothing about the outcome undid the years of open access that had come before it, and the board could not point to any single incident it had definitely prevented. But the organization went into its funding review with its records in order and its risk meaningfully reduced, and that was the loss it managed to contain rather than a problem it could claim to have solved outright.

What you can learn from this

  • Not-for-profit status affects what happens to surplus revenue, not whether an organization's operating information deserves protection; both can matter at once.
  • Access to shared files tends to accumulate quietly over years of good-faith volunteering; schedule a periodic review rather than waiting for a due diligence request to force one.
  • A legal fix works best after the practical housekeeping is done, not instead of it; sort and classify your records before you draft anything.
  • When someone's continued access turns out to be an oversight rather than a problem, treat the correction as routine administration, not confrontation.
  • If an outside review is coming with a deadline, start your internal cleanup as early as possible; documentation prepared under time pressure is harder to trust, including your own.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a corporate problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →