Here is what a donor prospect screening said about me this summer.
That I am an executive with a gross income over a million dollars. That my capacity to give is above a hundred thousand. That I sit on the boards of multiple foundations. That I am affiliated with Mazda USA and the Mazda Foundation. That I might be an SEC insider. It got my age wrong. It found none of my real estate. And out of a number of political contributions, it listed exactly one. That one correctly, which I’ll come back to, because it’s the most interesting thing in the whole report.
I am not an executive. I run a small consulting practice out of Johns Creek. I am not on any foundation board. I have never worked for Mazda.
Then I looked at the Mazda Foundation’s about us page.
Kara Hudson. Treasurer, Mazda Foundation. Director, Network Operations & Dealer Affairs, Mazda North American Operations.
There she is. Not a near miss, not a surname collision: the same first and last name as mine, attached to a public 990 filing, doing a job I have never done for a company I have never worked for.
One mistake, wearing five hats
What makes this worth writing about isn’t that a database got something wrong. Databases get things wrong constantly. It’s that eight wrong things turned out to be one wrong thing, and the report gave me no way to see that.
Read the vendor’s own field definitions and the whole thing unspools. Business Affiliation doesn’t mean works at. The published definition is that the prospect “has been matched to a Dun & Bradstreet firm at an executive level position.” IRS 990PF doesn’t mean is on the board. It identifies whether the prospect is associated with a “namesake” grant-giving foundation. Namesake. The field is built to fire on a name.
So: my name matches a D&B executive record, and I acquire an employer. The employer’s revenue populates a second field, and I acquire a seven-figure income. The employer has a corporate foundation whose 990-PF lists its officers as trustees, and I acquire a board seat. A capacity model ingests the revenue and the title, and I acquire a hundred thousand dollars I do not have. An executive at a large automaker trips a possible insider flag, and I acquire a securities profile.
Five findings. One join. And they all corroborate each other, which is exactly why the report reads as confident rather than uncertain. Nothing in it looks like a guess. It looks like a dossier.
The matching key that started it is thinner than most people would believe. The vendor’s own user guide asks for first name, last name, and state of residence. That’s the minimum viable input.
Which brings me to the part I can’t explain.
I have never lived in California. Texas, Washington, Oregon, Alaska, Louisiana, Georgia. Never California, not for a day. The Kara Hudson whose career I was handed works for a company headquartered in Irvine.
So the one field that exists to tell two people apart, the only disambiguating input the tool asks for, did not tell us apart. Either state of residence isn’t applied to the corporate affiliation match at all, which would make a certain kind of sense given that Dun & Bradstreet’s executive records are keyed to a company rather than to a home address, or it was applied and it failed. I have no way to find out which, and that turns out to be the whole theme of this piece.
What I can say is that the collision wasn’t “same name, same state.” It was same name. Against every executive record in a business database, two thousand miles away, across a state line the tool had been given.
To be clear about the other Kara Hudson: she did nothing. She has a job and a volunteer role and both are a matter of public record, which is how it should be. She isn’t the problem. The problem is a system that treated a matching first and last name as sufficient evidence of same person, ignored the one thing that would have separated us, and then built five stories on top of it.
The part nobody talks about
Everything above is the false-positive story, and the prospect research community is honest about it. Practitioners will tell you screenings produce false hits and need verification. That’s a known, discussed limitation.
Here’s the part I haven’t seen anyone say plainly.
The tool did not just invent wealth I don’t have. It missed the giving I actually do. It found none of my real estate. It caught one political contribution out of several. A product whose entire purpose is to surface evidence of philanthropic behavior was worse at finding my actual philanthropic behavior than it was at fabricating an executive career.
And the misses aren’t random noise. They’re structural.
Federal campaign finance rules only require a committee to disclose your name, address, occupation and employer once your contributions aggregate over $200 in a cycle. Below that, you’re reported as an unitemized lump with no name attached: 11 CFR 104.8. Every small-dollar contribution you have ever made is, to a screening tool, invisible. Not hard to find. Not in the data at all. And state and local giving lives in fifty separate disclosure systems with wildly uneven coverage, so a lifetime of supporting your county commissioner never surfaces either.
Real estate has its own version. Screenings match name-to-name, and property held in a trust, an LLC, or under a former name simply doesn’t connect. Helen Brown Group, who do this work for a living, put it about as well as it can be put: screenings match A to A, and if A sees a, it’s not a match.
So the errors run in the same direction. The tool over-reports the kind of wealth that generates loud public records, meaning corporate titles, large itemized gifts and unencumbered property, and under-reports everything modest, private, distributed, or small. That’s not a noisy instrument. That’s a biased one, and the bias has a shape: it flatters people who look like large donors and it disappears people who give a little, often, quietly.
Prospect researchers have noticed the first half of this. Aspire Research Group says outright that screenings “tend to overestimate people with less wealth.” Sit with who that lands on. Program participants. Public employees. Teachers, social workers, firefighters, paramedics, dispatchers. Anyone whose name is common. Anyone whose money is in a pension rather than a portfolio.
And in most donor CRMs, some version of this score is applied to every individual record automatically, for free, refreshed a couple of times a year, whether anybody asked for it or not. Nobody at your organization requested a capacity rating on the person who came to your program last spring. They have one anyway.
You cannot correct it
I went looking for the dispute process, the way you would with a credit report. There isn’t one.
The Fair Credit Reporting Act gives you the right to dispute and correct, but only for consumer reports, meaning information used for credit, employment, insurance, or housing decisions. Fundraising isn’t on the list. This isn’t a gray area or my reading of it: California requires data brokers to register and to state whether they’re FCRA-regulated, and the wealth screening vendors have each answered no, in writing, on the state’s public registry.
So there’s no federal right. In Georgia there’s no state right either, because we have no comprehensive consumer privacy law. Two bills died, one in 2024 and one in 2025. Californians got a real tool this year: the state’s deletion platform opened to consumers in January, and brokers have had to process those requests since 1 August. It does not reach me.
What’s left is the vendors’ own goodwill. And the relevant page offers removal, not correction, worded, if you read it closely, as suppression from ad targeting rather than deletion from the database. There is no form anywhere that says this affiliation is not mine, take it off.
Which means the wrong record about me is, functionally, permanent. It will refresh. It will propagate to every organization that screens me. And each of those organizations will write it into their own CRM, where it will live on independently, immune to anything the vendor ever does.
What I’d actually do about it
If you run a nonprofit and you screen your donors, three things, and the first two are free.
Stop treating screening output as fact. It is a lead list about a name, and names are not unique. The vendor publishes a confidence score, tells customers that low-scoring data may or may not belong to the person, and instructs them to check. That instruction gets ignored somewhere between the export and the gift officer. Find out whether that confidence score is even visible in your system. Mine wasn’t shown to me.
Never write an unverified affiliation into a constituent record. Capacity ratings are embarrassing when wrong. Affiliations are worse, because they’re specific, they sound researched, and someone will eventually say one out loud in a meeting. Once it’s in your database it has outlived the vendor’s copy and nobody remembers where it came from.
Tell people you do this. No American law requires it. But in 2016 and 2017 the UK’s information regulator fined thirteen charities for wealth screening donors without telling them: the RSPCA, the British Heart Foundation, and eleven more. Note who paid. Not the vendors. The charities. A short, plain paragraph saying that you research prospects, what categories of sources you use, and who to contact to opt out costs you nothing and is rapidly becoming the sector norm.
I’ll add a fourth for anyone who is not a nonprofit and just found this by searching their own name: go upstream. The vendor is a reseller. If the error started at Dun & Bradstreet, deleting the downstream copy buys you a few weeks until the next refresh rebuilds it.
The uncomfortable part of all this isn’t that a computer thought I was rich. It’s that I only know it was wrong because it was wrong about me. I have run this kind of data for other people for years. I have looked at fields like these and treated them as findings.
Somewhere there is a first responder in a database with a capacity rating built out of somebody else’s life, and nobody is ever going to check.
