Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Orders Blackbaud to Boost Data Security After Breach

Blackbaud Inc.May 20, 2024Federal Trade Commission

Summary

The FTC finalized a consent order against Blackbaud Inc. for alleged security failures that led to a data breach exposing personal data of millions of consumers. Blackbaud must delete unnecessary data, implement a security program, and not misrepresent its policies. No monetary penalty was imposed.

Remedy

Blackbaud is required to delete data it no longer needs, develop a comprehensive information security program, establish a data retention schedule, refrain from misrepresenting data security and retention policies, and notify the FTC of future data breaches.

Data DeletionInjunctionCompliance ProgramReporting Requirements

Contract Impact

In-house legal teams should review all vendor agreements where Blackbaud is a data processor or service provider (e.g., SaaS, fundraising, financial software contracts) and any customer-facing data processing agreements. Key clauses to scrutinize include data security obligations, breach notification timelines and procedures, data retention and deletion requirements, representations regarding security practices, and indemnification provisions. Given the order's focus on data minimization and deletion of unnecessary data, contracts may need amendments to explicitly require data minimization, mandate encryption of sensitive data (like SSNs and bank accounts), establish clear incident response protocols, and prohibit misrepresentations about security. Teams should also assess audit rights to verify compliance and ensure notification clauses align with the 'without unreasonable delay' standard implied by the FTC's criticism of Blackbaud's two-month delay.

Contract Search Terms

data retention schedulebreach notification clausedata processing addendumsecurity incident response plandata minimization policyencryption requirementsthird-party audit rightscustomer notification proceduresdata security representationssafeguards for sensitive data

Violation Types

Entity Details

Entity

Blackbaud Inc.

Also known as: Blackbaud

Industry

Technology

Official Sources

Source Evidence

Entity Name
"Blackbaud Inc."
Violation Types
"failed to implement appropriate safeguards to secure and protect the vast amounts of personal data it collects"
Violation Types
"allowed a hacker to breach the company’s network and access the personal data of millions of consumers including Social Security and bank account numbers."
Violation Types
"The company waited nearly two months to notify its customers about the breach and then misled consumers about the extent of the data that was stolen."

Related Enforcement Actions

FTC

Vanilla Chip LLC

$750K

The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.

FTC

RentGrow Inc.

$2.3M

The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.

FTC

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

FTC

Hopper Inc.

$35.0M

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.

FTC

Publishing.com LLC

$1.5M

The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.

FTC

Federal Trade Commission

The FTC is seeking public comment on a proposed policy statement addressing concerns that AI companies may be manipulating AI system outputs contrary to consumer expectations for objectivity and accuracy. The statement explains that such conduct could be considered deceptive under Section 5 of the FTC Act. The public comment period runs until July 31, 2026.