[W]hen Lucy Bernholz starts describing all the information nonprofit organizations collect, she can overwhelm you.
When she talks about how secure it all is, she’ll scare you to death.

Bernholz, a research scholar at Stanford University, is an expert on the “civil society” inhabited by a variety of causes and nonprofits — essentially any organization that operates between and outside the boundaries of private for-profit companies or public government entities.
Those “civil society” organizations include everything from the informal local bee and bird-watching club to more highly structured advocacy groups like the Vermont Public Interest Research Group or Gun Owners of Vermont, cooperatives, and loosely organized efforts, such as setting up a rally for presidential candidate Bernie Sanders.
The “civil society” is “where we voluntarily use our private resources for public benefit,” said Bernholz, who shared her views in a series of talks with Vermont nonprofits recently, “and we organize to help make something happen around that, and until it carries directly into the political system or pushes directly against the market, it’s really happening in civil society. So that place is huge and messy and deliberately discordant” and is based largely on Alexander Hamilton’s idea of protecting the rights of minorities in a majority-rule political system.
All those groups, Bernholz said, are collecting enormous amounts of information, much of it personal, like email, phone numbers and home addresses. And just about all of it, she said, is completely insecure.
How insecure?
Consider first, Bernhold said, that the U.S. Defense Department and large corporations like Sony have been hacked, so a small nonprofit doesn’t stand a chance.
Imagine all the information that all of those groups collected was money, Bernholz suggested. The data is so vulnerable that if it were the company cash, it would be like putting it in a big bowl in the middle of a table, then leaving the office door unlocked for the night.
You’d just have to hope nobody stopped by.
The key, Bernholz said, is to figure out what information you already have. Moving forward, think about what information you really need to collect. Too much information can be as invaluable as too little.
Then, find a way to make the data as secure as possible. That means taking practical steps, Bernholz said, such as not keeping all the information in one database site, but instead several, on different servers. And be vigilant, she said, to find out the anti-hacker security used by third-party vendors storing your information, the same way you’d ask questions before hiring a financial adviser or deciding which bank you’d use.
It’s particularly important to protect private information, she said, since many of the organizations she is talking about help people, such as a battered women’s shelter, and preventing further harm should be a prime mission.
Fortunately, she said, an effort by the Internal Revenue Service to require donors to provide Social Security numbers if they make a gift of $250 was rejected. Imagine the implications of all those Social Security numbers out there and the potential for identity theft, she said.
At Stanford, Bernholz works at the university’s Center on Philanthropy and Civil Society, where she directs the Digital Civil Society Lab. A gadget freak, historian and observer of people, Bernholz is fascinated by technology like smartphones, which she said have changed our behavior.
VTDigger caught up with her at the restaurant August First in Burlington.
“Our social interactions have been changed because we’re carrying around supercomputers in our pocket,” Bernholz said.
“That fascinates me.”
