Penalty Amount
$49,500,000
Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.
Blackbaud must pay $49.5 million to the states, implement and maintain incident response plans, enhance security measures including encryption and monitoring, undergo third-party assessments for seven years, and discontinue misrepresentations about data safety.
In-house legal teams should review all vendor and data processing agreements with cloud service providers and SaaS vendors, particularly those handling sensitive donor, customer, or constituent data. Focus on clauses governing data security obligations (e.g., specific security frameworks, encryption, access controls), breach notification requirements (including timelines and content), audit and inspection rights, indemnification for data breaches, and limitations of liability. Given the findings of inadequate security and delayed notification, contracts should be amended to include more prescriptive security controls, shorter notification windows (e.g., 72 hours), mandatory reporting of security audits, and clear remedies for non-compliance. Additionally, review customer agreements to ensure robust data protection commitments are flowed down to end-users.
Entity
Blackbaud
Industry
TechnologyOfficial Press Release
https://ag.ny.gov/press-release/2023/attorney-general-james-and-multistate-coalition-secure-495-million-cloud-company
blackbaud avc ny
https://ag.ny.gov/sites/default/files/settlements-agreements/blackbaud-avc-ny.pdf
blackbaud impacted ny list
https://ag.ny.gov/sites/default/files/2023-10/blackbaud-impacted-ny-list.pdf
New York Attorney General Enforcement Page
https://ag.ny.gov/press-releases
"Blackbaud"
"$49.5 million"
"state consumer protection laws, breach notification laws, and HIPAA"
"failed to implement reasonable data security and fix known security gaps"
"neglected to provide its customers with timely, complete, or accurate information regarding the breach"
$6.8M
California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.
$49.5M
Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.
$17.1B
Attorney General James and a bipartisan coalition of 50 other attorneys general secured a landmark settlement with Meta Platforms, Inc. (Meta) worth up to $17.1 billion to address the company's harmful and addictive features targeting minors on Facebook and Instagram. The settlement requires Meta to implement significant changes, including age verification, time limits for minors, restrictions on notifications, and options to opt out of algorithmic feeds, along with monetary payments to states for mental health and education programs.
$3.3M
New York Attorney General Letitia James announced a multistate settlement with Cal-Maine Foods, Versova/Centrum, and Hickman's Egg Ranch for illegally coordinating to influence a daily price index for eggs, artificially inflating prices for retailers and consumers nationwide. The companies will deliver 53 million eggs to food banks across 17 participating states, pay a combined $3.3 million, and adopt compliance measures to prevent future violations.
$2.0M
New York Attorney General Letitia James, along with four other states and the FTC, settled with Zillow and Redfin after they entered an illegal agreement to stop competing in the multifamily rental advertising market. Zillow paid Redfin $100 million to shut down its advertising business and exclusively display Zillow's listings. The settlement requires the companies to resume competing and pay $2 million.
$400K
New York Attorney General Letitia James secured $400,000 from Thirty Madison, Inc., an online medication provider, for misleading consumers about auto-renewing subscriptions and making cancellation difficult. The company failed to clearly disclose subscription terms and non-refundable fees, and required multiple steps to cancel. The settlement requires payment, refunds to eligible subscribers, and changes to subscription practices.