Penalty Amount
$6,750,000
California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.
Blackbaud must pay $6.75 million in penalties. It is also subject to injunctive terms requiring it to implement enhanced data security measures, including minimizing retention of personal information in database backups and securely disposing of such backups, implementing multi-factor authentication or password rotation policies, and improving network segmentation, monitoring, and alerting for suspicious activity. Additionally, Blackbaud must strengthen its breach notification practices to ensure timely and accurate disclosures to impacted individuals.
In-house legal teams should review vendor agreements with software providers handling personal data, customer agreements with entities storing consumer information, and internal data processing agreements. Key clauses to audit include data security requirements (to mandate multi-factor authentication, network segmentation, and security monitoring), data retention and disposal clauses (to require minimization of backup data and secure deletion), breach notification clauses (to specify strict timelines for timely, accurate disclosures and prohibit misleading statements), and data security representations and warranties (to avoid deceptive pre-breach claims). Teams should also ensure all agreements comply with California’s Reasonable Data Security Law and related consumer protection statutes.
Entity
Blackbaud
Industry
TechnologyOfficial Press Release
https://oag.ca.gov/news/press-releases/attorney-general-bonta-secures-675-million-settlement-against-blackbaud-over
Complaint[2]
https://oag.ca.gov/system/files/attachments/press-docs/Complaint%5B2%5D.pdf
Blackbaud Judgment final[2]
https://oag.ca.gov/system/files/attachments/press-docs/Blackbaud%20Judgment%20final%5B2%5D.pdf
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
"Attorney General Bonta Secures $6.75 Million Settlement Against Blackbaud Over 2020 Data Breach"
"California Attorney General Rob Bonta today announced a settlement with Blackbaud"
"Blackbaud, a South Carolina-based software company"
"$6.75 million in penalties"
"violated the Reasonable Data Security Law, Unfair Competition Law, and the False Advertising Law related to data security"
"Blackbaud’s failure to implement reasonable data security led to a data breach in 2020"
$49.5M
Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.
$49.5M
Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.
A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
$12.8M
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.
The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.