Home Articles Get your free assessmentComing soon

Tag: member data

  • If You Lose Member Data, Who Do You Have to Tell?

    If You Lose Member Data, Who Do You Have to Tell?

    It’s a Monday. The office administrator can’t get into her email, and when she finally does, the sent folder contains forty messages she didn’t write.

    Or: the laptop was in the back of the car outside the hospital, and now it isn’t.

    Or: someone calls to say the church’s membership spreadsheet is on a website they’ve never heard of.

    Whatever the route, you now stand in a specific place, and the question in the room is not technical. It is: do we have to tell people?

    The honest answer is: probably, sometimes, and it depends on facts you don’t have yet. Which is deeply unsatisfying — so this post explains the general shape of how these laws work, so you can recognize the situation and act fast enough to handle it properly.

    Everything below is a description of how these rules generally work. It is not legal advice. Requirements vary substantially by state, and you need a lawyer — early.

    These laws are not just for corporations

    Start here, because this is the assumption that gets churches into trouble.

    The National Conference of State Legislatures summarizes the landscape plainly: “All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring private businesses, and in most states, governmental entities as well, to notify individuals of security breaches of information involving personally identifiable information.”

    Nonprofit status is not, by itself, an exemption. These statutes are generally drafted around whoever holds the data rather than around a particular tax classification. Whether a specific state’s law reaches your specific organization is a question with a real answer, and only a lawyer licensed in that state can give it to you. But do not walk into it assuming your 501(c)(3) letter is a shield. It isn’t designed to be one.

    What actually triggers a notice

    Here is the most useful thing in this article, and the part most people have backwards.

    Not every exposure of personal information triggers a notification duty. These laws generally attach to specific, defined categories of data — and a name plus an email address, on its own, very often isn’t one of them.

    NCSL describes the common structure: these laws typically contain “definitions of ‘personal information’ (e.g., name combined with SSN, drivers license or state ID, account numbers, etc.); what constitutes a breach (e.g., unauthorized acquisition of data); requirements for notice (e.g., timing or method of notice, who must be notified); and exemptions (e.g., for encrypted information).”

    In practice, the categories that most commonly appear across state definitions are a person’s name combined with one or more of:

    • Social Security number
    • Driver’s license or state identification number
    • A financial account, credit card, or debit card number, usually together with whatever code would let someone use it
    • In a growing number of states, medical or health insurance information, biometric data such as a fingerprint, or the username and password to an online account

    Look at that list against what your church actually holds. Your membership directory of names, addresses, and emails is sensitive and worth protecting — but its exposure may not trigger a statutory notice. Your payroll file, your background-check drawer, and your donation records with bank account details almost certainly could.

    That distinction is not a reason to relax. It’s a reason to know precisely where your organization keeps the high-consequence categories, before anything goes wrong.

    The obligation usually follows the person, not the church

    This surprises people, and it matters for churches more than for most small organizations.

    These laws are generally written to protect residents of that state. So the question is usually not “which state is the church in?” but “where do the affected people live?”

    A congregation with members who retired to Florida, a college student in another state, and a missionary family supported from a third has, potentially, three sets of rules to satisfy from a single incident. The deadlines may differ. The required content of the letter may differ. Whether a state official has to be told may differ.

    You do not need to memorize any of that. You need to know two things: that the number of applicable laws is driven by your people’s addresses, and that your lawyer will need that address list early. Which is a quiet argument for keeping your member records accurate and for not keeping records of people who left twenty years ago.

    What the notices generally have in common

    Details vary by state — always — but the family resemblance is strong.

    A deadline measured in days from discovery. Some states set a specific number of days; others use a reasonableness standard along the lines of the most expedient time possible and without unreasonable delay. These deadlines are not stable, either — California, which used the reasonableness language for more than twenty years, moved to a fixed 30-calendar-day notification deadline effective 1 January 2026, with notice to the Attorney General due within 15 calendar days after individuals are notified. Either way the clock starts near the beginning of the incident, usually well before you understand what happened. This is the single biggest reason to call counsel on day one rather than day ten, and to ask them what the current deadline is in each state where your people live rather than relying on anything you read a year ago.

    Required content in the notice. States commonly specify what the letter has to say: what happened, what categories of information were involved, what the organization is doing about it, what the individual can do, and who to contact with questions. Some prescribe the format and the delivery method. This is not a letter to draft yourself from a template you found online.

    Notice to a state official. Several states require that the attorney general or a similar office be told, often once the number of affected residents crosses a threshold. California, for example, requires a sample copy of the notice to be submitted to the Attorney General by any organization “required to issue a security breach notification to more than 500 California residents as a result of a single breach of the security system” (Cal. Civ. Code §§ 1798.29(e), 1798.82(f)). Other states set different thresholds, and some set none.

    Notice to the credit bureaus. Some states require the nationwide consumer reporting agencies to be notified once the affected population passes a threshold that state sets. Separately, the FTC’s breach response guidance for businesses says that “if Social Security numbers have been stolen, contact the major credit bureaus for additional information or advice,” regardless of whether a statute compels it.

    And an encryption exemption that is worth real money. This is the most actionable point in the whole area of law. Many state statutes are written around unencrypted personal information. California’s, for example, requires disclosure to a resident “whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person” — and also where encrypted information was acquired along with the encryption key or security credential (Cal. Civ. Code §§ 1798.29(a), 1798.82(a)). So encryption is not a blanket exemption anywhere, and the details differ by state. Ask your lawyer how it works in the states that apply to you.

    Encryption means the data is stored scrambled, readable only with a key. Turning on full-disk encryption on your laptops is free — it’s built into Windows and macOS — and it takes about ten minutes per machine. It will not stop a phished mailbox. But a laptop stolen from a car is one of the most common ways a small organization loses data, and encryption can be the difference between a stolen laptop and a notifiable breach. That is an extraordinary return on ten minutes, and it is a genuine, concrete reason to do it this month rather than someday.

    The first days: what to do so that you can comply

    Whether you’ll owe notice is a question for later. What you do in the first hours decides whether you’ll be able to answer it.

    Preserve everything. Do not clean up. The instinct — reset the machine, delete the bad messages, wipe it and start fresh — destroys the only record of what happened. The FTC’s guidance for businesses is direct: “Do not destroy any forensic evidence in the course of your investigation and remediation,” and “don’t turn any machines off until the forensic experts arrive.” Disconnect an affected computer from the network by unplugging the cable or switching off Wi-Fi, but leave it running and leave it alone.

    Stop the bleeding without destroying the evidence. Change passwords from a different device, sign out all active sessions, and turn on multi-factor authentication if it wasn’t already on. Preserving evidence does not mean leaving the door open.

    Write down the timeline as it happens. A plain notebook or a single document. When you first noticed something. Who reported it. What time. What you did and when. Who you called. Your lawyer will need this, your insurer will need this, and memory reconstructed three weeks later is not good enough. Start it in the first ten minutes.

    Call your lawyer before you call anyone else you’re tempted to call. Not because you’ve done something wrong, but because the deadline has probably already begun, and because counsel can often direct the investigation in a way that protects the organization. Ask specifically about a legal hold — an instruction to stop any routine deletion of records that might be relevant.

    Call your insurer the same day. Read this twice: many policies impose their own notice deadlines that are shorter than the law’s, and some require you to use their approved forensic and legal panel. Calling them late, or hiring your own investigator first, can jeopardize coverage on a policy you’ve been paying for. If you have cyber liability coverage, the hotline number is the most valuable thing in the policy.

    Report it. If money moved or fraud was attempted, report to the FBI at ic3.gov immediately. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process works far better inside the first 24 to 72 hours. Point affected individuals to identitytheft.gov, which walks them through recovery steps at no cost.

    Say less publicly, sooner privately. Do not speculate from the pulpit about what happened. Do tell your board chair and your leadership immediately.

    Notifying well is a trust-building act

    There’s a fear underneath all of this: that telling the congregation will destroy confidence in the church’s leadership.

    The pattern runs the other way.

    Congregations are generally forgiving about incidents. People understand that criminals exist, that a determined attack can succeed against anyone, and that ministry staff are not security professionals. What congregations do not forgive is finding out later that leadership knew and said nothing. The first is a misfortune. The second is a character question, and it is the one that ends tenures.

    A good notification is short and specific: here’s what happened, here’s what information was involved, here’s what we’ve done, here’s what we recommend you do, here’s who to call with questions, and here’s the change we’re making so it doesn’t happen again. No hedging, no passive voice, no “an incident may have occurred.” Take responsibility for the response even where you couldn’t have prevented the event.

    Handled that way, a breach notification is one of the clearer demonstrations a church can give that it treats people’s information as a trust rather than an asset. That’s not spin. It’s just what integrity looks like on a bad week.

    What to do this week

    Turn on full-disk encryption on every laptop your organization owns — BitLocker or device encryption on Windows, FileVault on Mac. Ten minutes a machine, no cost, and in many states it changes the legal character of a stolen laptop.

    Then write two phone numbers on the same card and put it where your leadership can find it: your attorney, and your insurance carrier’s claims line. Add whether you have cyber liability coverage at all — if nobody in the room knows, that’s this week’s second task, and it’s a five-minute email to your broker.

    Preparing before anything happens is far cheaper than improvising afterwards. MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including whether you’d be able to answer the questions above on the worst morning of the year.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: National Conference of State Legislatures, Security Breach Notification Laws; California Office of the Attorney General, Reporting a Data Breach; California Legislature, SB 446, Data breaches: customer notification; Federal Trade Commission, Data Breach Response: A Guide for Business; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • What Do You Actually Have? A One-Afternoon Data Inventory

    What Do You Actually Have? A One-Afternoon Data Inventory

    Someone in the office asks a simple question: where do we keep the allergy list for the kids?

    Four answers come back. It’s in the check-in system. It’s also on a printed sheet in the nursery binder. Sarah keeps a copy on her phone because the tablet is slow on Sunday mornings. And there’s a spreadsheet somebody emailed around before the fall kickoff, which is still sitting in maybe nine inboxes.

    All four answers are true. That’s the problem.

    This isn’t a story about carelessness. It’s what happens when a small organization runs on goodwill and improvisation for a decade. Nobody decided to keep four copies of children’s medical information. It accumulated, the way things accumulate in a building that’s been used by a lot of people for a long time.

    You cannot protect what nobody has written down. Every other security decision you’ll make — who gets multi-factor authentication first, what to back up, what to shred, what to tell people if something goes wrong — depends on knowing what you’re holding and where it lives. That knowledge almost never exists in one place. Building it takes an afternoon.

    Why this is the first job, not the fifth

    Most security advice starts with a control: turn on this setting, buy this tool, write this policy. Those are all reasonable, and they’re all guesses until you know what you have.

    The Federal Trade Commission’s guide for businesses puts inventory first, before locks and disposal, in a single sentence: know what personal information you have in your files and on your computers. Not because it’s exciting, but because everything downstream is unanswerable without it.

    Consider what you can’t decide today. Is your backup adequate? Depends what needs backing up. Should the giving system have stricter access than the calendar? Obviously — but who has access to the giving system right now? If a laptop went missing tonight, what would be on it? If you had to notify people that their information was exposed, which people, and how would you reach them?

    Every one of those is a lookup against a list you don’t have yet.

    The four questions, and a table to hold them

    For each thing you find, you’re answering four questions. That’s the whole method.

    What is it? In plain words. Not “member records” — names, home addresses, phone numbers, birthdays, and marital status for about 340 households. Be specific enough that a stranger reading the line understands the sensitivity.

    Who can reach it? Not who should. Who actually can, today, if they tried. This includes anyone who knows a shared password, anyone whose account was never turned off, and the person who has a key to the cabinet.

    Where does the copy live? Plural, almost always. The system of record, plus the export somebody made, plus the printout, plus the backup, plus the attachment in the email thread.

    Do we still need it? The most useful question on the list, and the one that shrinks the problem fastest. Data you deleted cannot be stolen.

    Put the answers in a table — one row per thing. A single shared document, or a printed sheet on a clipboard. Either works.

    What it isWhere the copies liveWho can reach itSensitivityStill need it?
    Member directory — names, addresses, phones, birthdays, ~340 householdsChMS; export on office PC desktop; printed pictorial directory (2021)3 staff logins; 1 shared “office” login; anyone with the printed copyHighYes — but delete the desktop export
    Children’s check-in, allergies, emergency contactsCheck-in system; nursery binder; volunteer’s phone photo; emailed spreadsheet6 volunteers via shared tablet login; ~9 email recipientsVery highYes — one copy only
    Background check results, 2016–presentVendor portal; paper files, unlocked cabinetVendor login shared by 2 people; anyone in the officeVery highCheck retention rule with counsel
    Giving and pledge recordsGiving platform; QuickBooks; annual statement PDFs on shared driveTreasurer, bookkeeper, pastor; shared drive is open to all staffHighYes — restrict the drive folder
    Old laptop, closetUnknownAnyone who opens the closetUnknownNo — wipe and dispose properly

    The sensitivity column is a judgment call, and a coarse one is fine. High, medium, low. What you’re really flagging is: how bad would it be if this ended up somewhere public, or in the hands of someone who wanted to harm one of these people? A birthday list is not the same as a benevolence file.

    Now go find the rows.

    Walk the building

    Do this part physically. Take a legal pad and actually open the doors.

    The office. Filing cabinets — including the one nobody has a key for, which you should note as an open item rather than skip. Look for personnel files, background check results, old giving envelopes, offering count sheets, contribution statements, and applications from volunteers who came and went years ago.

    The children’s and youth area. Check-in records, allergy and medical information, emergency contacts, permission slips, incident reports. This is usually the most sensitive paper in the building and the least locked.

    The pastor’s study and the counseling room. Care notes, benevolence applications, correspondence. Handle this category with particular seriousness — it deserves its own conversation, and we’ll cover it separately.

    The closet, the storage room, the attic over the fellowship hall. Old computers. Old phones. A retired copier — the FTC’s guidance for businesses is blunt about this: the hard drive in a digital copier stores data about the documents it copies, prints, scans, faxes, or emails, and deleting or reformatting doesn’t actually remove it. Boxes of paper somebody meant to sort.

    The counters and desks. The sticky note with the Wi-Fi password is a minor issue. The sticky note with the login for the giving platform is not.

    Walk the accounts

    Now sit down and list the online services. This is harder, because there’s no door to open. Start from three places: the bank statement (what are you paying for?), the office computer’s saved passwords or bookmarks, and the memory of whoever has been around longest.

    Expect to find: the church management software, the giving or donation platform, the payroll provider, the accounting system, the email and file storage (Microsoft 365 or Google Workspace), the website and its hosting, the domain registrar, the email newsletter tool, the event registration tool, the background check vendor, the livestream and video accounts, the social media pages, and the survey tool somebody used once for a stewardship campaign.

    For each one, the question that matters most is the second one: who can reach it? Log in and look at the user list. Do not rely on memory.

    And then the category that catches everyone: the personal accounts holding church data. The volunteer who built the directory in her own Google Sheets. The worship leader whose personal Dropbox has every service recording. The former treasurer’s home computer, where the QuickBooks file lived. These are not violations of trust — they’re what happens when someone volunteers to help and uses the tools they already have. But that data is outside anything you control, and it walks out the door when they do.

    What you will find, because everyone finds it

    Three discoveries happen in nearly every inventory. Name them in advance so nobody feels caught out.

    The shared login. One username and password for the giving platform, or the check-in tablet, or the Facebook page, used by five people, three of whom no longer serve. It exists because it was easier, and because individual accounts sometimes cost money per seat. The cost of it is that you can never tell who did what, and you can never remove one person without disrupting everyone.

    The departed volunteer who still has access. The youth intern from two summers ago whose account was never disabled. The former board member still in the shared drive. Offboarding is the single most commonly skipped step in small organizations, because there’s rarely a formal offboarding at all — people just stop coming.

    The spreadsheet that was emailed around. Somebody exported the directory to help with a mailing, attached it to a message, and sent it to eleven people. Every one of those copies is now permanent, sitting in eleven mailboxes, four of which are personal accounts with no multi-factor authentication — MFA, the extra code or tap after the password. If any one of those accounts is ever compromised, your directory goes with it.

    None of these are failures of character. They’re the predictable result of a small staff doing a large job. Write them down without commentary, and fix them in order.

    Turning the list into decisions

    The inventory is only worth the afternoon if it changes something. Three immediate moves come almost free.

    Delete. Go down the “still need it” column and act on every no. Old exports, duplicate spreadsheets, applications from people who never served, printed directories from four years ago. Paper goes in a shredder, not a recycling bin. Devices need to be properly wiped, not just deleted from — get help with that if you’re unsure.

    Reduce copies. For anything marked very high, drive it toward a single authoritative copy with controlled access. The nursery binder and the phone photo and the emailed spreadsheet all go away; the check-in system stays.

    Fix the access list. For the three or four most sensitive systems, remove everyone who shouldn’t be there, and put individual logins in place of shared ones where you can.

    Two things to note but not solve today. Records retention — how long you’re required to keep giving records, personnel files, and background checks — has real legal and tax dimensions, and the answer differs by state and by what kind of organization you are. And if information about people is ever exposed, notification requirements exist in all fifty states, the District of Columbia, and several territories, and they vary considerably in who they cover and what they require. Both of those are questions for your attorney, with your inventory in hand. The inventory is what makes that a thirty-minute conversation instead of a three-hour one.

    What to do this week

    Block ninety minutes. Take a legal pad and walk the building — office, children’s area, closets, storage. Write down every place you find information about a person, and note who can reach it. Don’t fix anything yet; just list it.

    Then open the two systems that hold your most sensitive data — usually the check-in system and the giving platform — and look at the user list. Remove anyone who has left.

    That’s it for week one. You’ll have more of a security program than most organizations twice your size.

    Once you know what you hold, the next question is how well it is protected. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first. An inventory like this makes those answers much easier to give.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Protecting Personal Information: A Guide for Business; Federal Trade Commission, Digital Copier Data Security: A Guide for Businesses; National Conference of State Legislatures, Security Breach Notification Laws.