Penalty Amount
$6,750,000
California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.
Blackbaud must pay $6.75 million in penalties. It is also subject to injunctive terms requiring it to implement enhanced data security measures, including minimizing retention of personal information in database backups and securely disposing of such backups, implementing multi-factor authentication or password rotation policies, and improving network segmentation, monitoring, and alerting for suspicious activity. Additionally, Blackbaud must strengthen its breach notification practices to ensure timely and accurate disclosures to impacted individuals.
In-house legal teams should review vendor agreements with software providers handling personal data, customer agreements with entities storing consumer information, and internal data processing agreements. Key clauses to audit include data security requirements (to mandate multi-factor authentication, network segmentation, and security monitoring), data retention and disposal clauses (to require minimization of backup data and secure deletion), breach notification clauses (to specify strict timelines for timely, accurate disclosures and prohibit misleading statements), and data security representations and warranties (to avoid deceptive pre-breach claims). Teams should also ensure all agreements comply with California’s Reasonable Data Security Law and related consumer protection statutes.
Entity
Blackbaud
Industry
TechnologyOfficial Press Release
https://oag.ca.gov/news/press-releases/attorney-general-bonta-secures-675-million-settlement-against-blackbaud-over
Complaint[2]
https://oag.ca.gov/system/files/attachments/press-docs/Complaint%5B2%5D.pdf
Blackbaud Judgment final[2]
https://oag.ca.gov/system/files/attachments/press-docs/Blackbaud%20Judgment%20final%5B2%5D.pdf
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
"Attorney General Bonta Secures $6.75 Million Settlement Against Blackbaud Over 2020 Data Breach"
"California Attorney General Rob Bonta today announced a settlement with Blackbaud"
"Blackbaud, a South Carolina-based software company"
"$6.75 million in penalties"
"violated the Reasonable Data Security Law, Unfair Competition Law, and the False Advertising Law related to data security"
"Blackbaud’s failure to implement reasonable data security led to a data breach in 2020"
$49.5M
Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.
$49.5M
Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.
Governor Newsom signed the Expanding Privacy Rights Act (SB 923), expanding CCPA deletion rights to cover personal information obtained from third parties and requiring online-only businesses to offer an online method for submitting privacy requests. The law takes effect January 1, 2027, and allows businesses to maintain suppression lists to help keep deleted information from being reacquired.
The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.
A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.
A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.