Data Breach - Notifying Constituents

Options
We have a database of about 120,000 constituents. Not all are donors, not all are active and not all have good addresses. We've decided to send an email communication regarding the data breach to everyone we have an email for. We've worked together with our attorney to write the letter and we will post it on our website as well.


What are others doing about determining who to send the communication to?


We are also considering putting the information on our Facebook page. Have others used Facebook? What type of message did you use?


Thanks for your help!

Comments

  • We're still trying to work that out. I'm meeting with my manager and others high up in the company to discuss what's to be done.

    Several people I work with have received notices from nonprofits they are associated with about this, so it looks like most companies are casting a wide net.
  • We are also still working it out.  We have over 370,000 records in our database.  I've pulled exports for valid address and/or email and have 250,000+ records across all 50 states and many foreign countries.  The only exclusion I've made is deceased.  This may change once we hear from IT and Legal, but this is where I've started.
  • I'm assuming that you have been notified by Blackbaud that your org was one of the ones compromised in which case would you not send your notification to all constituents just to err on the side of caution?


    On the other hand if your orgs data was not compromised (and Blackbaud has been fairly clear on which those were) I don't see the need to say anything to your constituents. 

     
  • Is anyone sending letters as well as emails to your constituents?  We have constituents that do not have an email address so we thought we would mail a letter to the mailing address on record.  What is everyone else doing?
  • I'm curious - - for those organizations who have chosen to end out a communication about the data breach, can you speak to what kind of feedback you've had from your constituents?  How may have you heard from?  What is the tone of their reactions?


    Thanks.
  • JoAnn Strommen
    JoAnn Strommen Community All-Star
    Ancient Membership 2,500 Likes 2500 Comments Photogenic
    We've heard back from less than 00.1%. Very, very small response. Covered the range of "remove me from your data base" to "these things happen and will happen again." 


    Of concern are comments coming back now from those who report not getting our email. Have found a percentage blocked by some providers due to it being mass email and found several blacklisted by Blackbaud. Working through that issue.
  • Stacey Brake:

    Is anyone sending letters as well as emails to your constituents?  We have constituents that do not have an email address so we thought we would mail a letter to the mailing address on record.  What is everyone else doing?

    We sent emails to all non-deceased individuals for which we had an email address on file. We sent snail-mail letters only to those our lawyer determined we were legally obligated to notify based on the personal data (e.g., birthdate) on their records.


    I guess we should go back and see which emails might have been flagged as spam and therefore not received...

Categories