Court Rules
All enforcement actions
SettlementHigh Risk

CA AG Settles with Blackbaud for $6.75M Over Data Breach and Misleading Disclosures

BlackbaudJune 13, 2024California Attorney General

Penalty Amount

$6,750,000

Summary

California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

Remedy

Blackbaud must pay $6.75 million in penalties. It is also subject to injunctive terms requiring it to implement enhanced data security measures, including minimizing retention of personal information in database backups and securely disposing of such backups, implementing multi-factor authentication or password rotation policies, and improving network segmentation, monitoring, and alerting for suspicious activity. Additionally, Blackbaud must strengthen its breach notification practices to ensure timely and accurate disclosures to impacted individuals.

Monetary PenaltyInjunctionCompliance Program

Contract Impact

In-house legal teams should review vendor agreements with software providers handling personal data, customer agreements with entities storing consumer information, and internal data processing agreements. Key clauses to audit include data security requirements (to mandate multi-factor authentication, network segmentation, and security monitoring), data retention and disposal clauses (to require minimization of backup data and secure deletion), breach notification clauses (to specify strict timelines for timely, accurate disclosures and prohibit misleading statements), and data security representations and warranties (to avoid deceptive pre-breach claims). Teams should also ensure all agreements comply with California’s Reasonable Data Security Law and related consumer protection statutes.

Contract Search Terms

data security safeguardsbreach notification timelinemulti-factor authenticationdata retention policybackup disposal requirementsnetwork segmentationbreach notice accuracysecurity monitoring clause

Laws Cited

Reasonable Data Security LawUnfair Competition LawFalse Advertising Law

Violation Types

Entity Details

Entity

Blackbaud

Industry

Technology

Official Sources

Source Evidence

Title
"Attorney General Bonta Secures $6.75 Million Settlement Against Blackbaud Over 2020 Data Breach"
Event Date
"California Attorney General Rob Bonta today announced a settlement with Blackbaud"
Entity Name
"Blackbaud, a South Carolina-based software company"
Fine Amount
"$6.75 million in penalties"
Laws Cited
"violated the Reasonable Data Security Law, Unfair Competition Law, and the False Advertising Law related to data security"
Violation Types
"Blackbaud’s failure to implement reasonable data security led to a data breach in 2020"

Related Enforcement Actions

NJ

Blackbaud

$49.5M

Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.

NY

Blackbaud

$49.5M

Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.

CA

California Privacy Protection Agency

The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.