The FTC finalized a consent order against Blackbaud Inc. for alleged security failures that led to a data breach exposing personal data of millions of consumers. Blackbaud must delete unnecessary data, implement a security program, and not misrepresent its policies. No monetary penalty was imposed.
Blackbaud is required to delete data it no longer needs, develop a comprehensive information security program, establish a data retention schedule, refrain from misrepresenting data security and retention policies, and notify the FTC of future data breaches.
In-house legal teams should review all vendor agreements where Blackbaud is a data processor or service provider (e.g., SaaS, fundraising, financial software contracts) and any customer-facing data processing agreements. Key clauses to scrutinize include data security obligations, breach notification timelines and procedures, data retention and deletion requirements, representations regarding security practices, and indemnification provisions. Given the order's focus on data minimization and deletion of unnecessary data, contracts may need amendments to explicitly require data minimization, mandate encryption of sensitive data (like SSNs and bank accounts), establish clear incident response protocols, and prohibit misrepresentations about security. Teams should also assess audit rights to verify compliance and ensure notification clauses align with the 'without unreasonable delay' standard implied by the FTC's criticism of Blackbaud's two-month delay.
Entity
Blackbaud Inc.
Also known as: Blackbaud
Industry
TechnologyOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2024/05/ftc-finalizes-order-blackbaud-related-allegations-firms-security-failures-led-data-breach
2023181 blackbaud final consent package
https://www.ftc.gov/system/files/ftc_gov/pdf/2023181_blackbaud_final_consent_package.pdf
ftc order will require blackbaud delete unnecessary data boo
https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-order-will-require-blackbaud-delete-unnecessary-data-boost-safeguards-settle-charges-its-lax
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"Blackbaud Inc."
"failed to implement appropriate safeguards to secure and protect the vast amounts of personal data it collects"
"allowed a hacker to breach the company’s network and access the personal data of millions of consumers including Social Security and bank account numbers."
"The company waited nearly two months to notify its customers about the breach and then misled consumers about the extent of the data that was stolen."
$750K
The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.
$2.3M
The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.
The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.
$35.0M
The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.
$1.5M
The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.
The FTC is seeking public comment on a proposed policy statement addressing concerns that AI companies may be manipulating AI system outputs contrary to consumer expectations for objectivity and accuracy. The statement explains that such conduct could be considered deceptive under Section 5 of the FTC Act. The public comment period runs until July 31, 2026.