If we need to do a data breach notification...

Preemptively, I'd like to flag that we should connect around strategy if it's appropriate for all WordFly-based orgs to reach out to our patrons about the ransomware data breach.

I have absolutely nothing deeper than that to say yet, but it occurred to me earlier today that, should we need to do this, a good number of tri-state area people may suddenly be on the receiving end of dozens of alarming notifications and make the issue feel even larger. A coordinated notification may be a better approach.

Should today's Town Hall reveal that we ought to pursue this, we'll spin up an initial Zoom or something along those lines.

Please go ahead and use this thread to note ideas or even just interest.

CC: to the NJ folks, and

Parents
  • FTC would be open to this. I don’t think we have an effective way of communicating before we get our unsubs from WordFly -- they were our primary Unsub DB for marketing. Tessitura drops too much info/isn't reliable. Even with another ESP our hands are a bit tied.

    On the town hall - attended the 9AM, wasn't much more information. 

    POP had their lawyers present and they mainly clarified their position. POP/WordFly seems that it didn't trigger a need to notify customers under GPDR which would far overshadow nearly any other US Law (at least that I can think of).

Reply
  • FTC would be open to this. I don’t think we have an effective way of communicating before we get our unsubs from WordFly -- they were our primary Unsub DB for marketing. Tessitura drops too much info/isn't reliable. Even with another ESP our hands are a bit tied.

    On the town hall - attended the 9AM, wasn't much more information. 

    POP had their lawyers present and they mainly clarified their position. POP/WordFly seems that it didn't trigger a need to notify customers under GPDR which would far overshadow nearly any other US Law (at least that I can think of).

Children