The FTC finalized a consent order against Blackbaud Inc. for alleged security failures that led to a data breach exposing personal data of millions of consumers. Blackbaud must delete unnecessary data, implement a security program, and not misrepresent its policies. No monetary penalty was imposed.
Blackbaud is required to delete data it no longer needs, develop a comprehensive information security program, establish a data retention schedule, refrain from misrepresenting data security and retention policies, and notify the FTC of future data breaches.
In-house legal teams should review all vendor agreements where Blackbaud is a data processor or service provider (e.g., SaaS, fundraising, financial software contracts) and any customer-facing data processing agreements. Key clauses to scrutinize include data security obligations, breach notification timelines and procedures, data retention and deletion requirements, representations regarding security practices, and indemnification provisions. Given the order's focus on data minimization and deletion of unnecessary data, contracts may need amendments to explicitly require data minimization, mandate encryption of sensitive data (like SSNs and bank accounts), establish clear incident response protocols, and prohibit misrepresentations about security. Teams should also assess audit rights to verify compliance and ensure notification clauses align with the 'without unreasonable delay' standard implied by the FTC's criticism of Blackbaud's two-month delay.
Entity
Blackbaud Inc.
Also known as: Blackbaud
Industry
TechnologyOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2024/05/ftc-finalizes-order-blackbaud-related-allegations-firms-security-failures-led-data-breach
2023181 blackbaud final consent package
https://www.ftc.gov/system/files/ftc_gov/pdf/2023181_blackbaud_final_consent_package.pdf
ftc order will require blackbaud delete unnecessary data boo
https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-order-will-require-blackbaud-delete-unnecessary-data-boost-safeguards-settle-charges-its-lax
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"Blackbaud Inc."
"failed to implement appropriate safeguards to secure and protect the vast amounts of personal data it collects"
"allowed a hacker to breach the company’s network and access the personal data of millions of consumers including Social Security and bank account numbers."
"The company waited nearly two months to notify its customers about the breach and then misled consumers about the extent of the data that was stolen."
The FTC, Utah, and Nevada sued Lens.com Inc., alleging that it advertised artificially low contact lens prices while hiding mandatory checkout charges and misleading consumers about its AutoRefill subscription. The complaint seeks to stop the alleged practices; the court has not yet decided the case, and no penalty or remedy has been imposed.
The FTC issued an advance notice of proposed rulemaking seeking public comment on whether ad-optimization tools offered by online platforms may help scammers impersonate businesses and government agencies. This is a proposed regulatory inquiry, not an enforcement action against a named company; no penalty or remedy was imposed.
$2.5B
A federal court approved a revised order in the FTC's Amazon Prime case under which Amazon will accelerate and expand redress payments under the September 2025 $2.5 billion settlement, which resolved allegations that Amazon enrolled millions of consumers in Prime subscriptions without their consent and knowingly made cancellation difficult. More consumers now qualify for refunds, the maximum payment cap rises from $51 to $200, and all future payments will be distributed automatically starting October 1, 2026, with potential supplemental $149 payments by April 2027. Amazon has already issued more than $845 million in redress payments as of September 2026.
$225.0M
The FTC and the state of Washington filed a joint complaint and proposed stipulated order requiring Amway Corp. and two affiliates—World Wide Group, L.L.C. (WWG) and Leadership Team Development Inc. (LTD)—to pay a $225 million judgment, the largest monetary recovery ever obtained from an MLM in an FTC action, over allegations that they used deceptive earnings claims and unfair tactics to recruit Independent Business Owners. The complaint alleges the companies falsely promised substantial income and recruitment success, pressured IBOs to buy products they could not resell, and instructed IBOs to falsely report sales. Nearly all of the judgment will be used as redress for IBOs who lost money, and the proposed order imposes structural reforms including a 70% resale requirement, independent audits of sales records, and a ban on approved providers charging new IBOs for first-year training.
$100.0M
FleetCor Technologies Inc. (now Corpay Inc.) and its CEO Ronald Clarke agreed to pay $100 million to settle an FTC administrative action alleging the company charged small business customers hidden and unauthorized fees for fuel cards and misrepresented gas savings, fraud-control features, and fees. A federal district court granted the FTC summary judgment on all counts in 2023, and a federal appeals court upheld that judgment and the permanent injunction in 2026. The settlement funds will be used to provide redress to harmed business customers.
FTC staff published FAQs on price transparency to help the automobile industry comply with the FTC Act, reiterating that an advertised vehicle price must be the actual price any consumer can pay, excluding only government-required charges. The guidance follows warning letters the FTC sent to 97 auto dealership groups earlier in 2026 and signals continued litigation against dealers that advertise one price but charge more through undisclosed fees. No specific entity was charged and no penalty was imposed.