Penalty Amount
$49,500,000
Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.
Blackbaud must pay $49.5 million to the states, implement and maintain incident response plans, enhance security measures including encryption and monitoring, undergo third-party assessments for seven years, and discontinue misrepresentations about data safety.
In-house legal teams should review all vendor and data processing agreements with cloud service providers and SaaS vendors, particularly those handling sensitive donor, customer, or constituent data. Focus on clauses governing data security obligations (e.g., specific security frameworks, encryption, access controls), breach notification requirements (including timelines and content), audit and inspection rights, indemnification for data breaches, and limitations of liability. Given the findings of inadequate security and delayed notification, contracts should be amended to include more prescriptive security controls, shorter notification windows (e.g., 72 hours), mandatory reporting of security audits, and clear remedies for non-compliance. Additionally, review customer agreements to ensure robust data protection commitments are flowed down to end-users.
Entity
Blackbaud
Industry
TechnologyOfficial Press Release
https://ag.ny.gov/press-release/2023/attorney-general-james-and-multistate-coalition-secure-495-million-cloud-company
blackbaud avc ny
https://ag.ny.gov/sites/default/files/settlements-agreements/blackbaud-avc-ny.pdf
blackbaud impacted ny list
https://ag.ny.gov/sites/default/files/2023-10/blackbaud-impacted-ny-list.pdf
New York Attorney General Enforcement Page
https://ag.ny.gov/press-releases
"Blackbaud"
"$49.5 million"
"state consumer protection laws, breach notification laws, and HIPAA"
"failed to implement reasonable data security and fix known security gaps"
"neglected to provide its customers with timely, complete, or accurate information regarding the breach"
$6.8M
California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.
$49.5M
Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.
New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.
$400.0M
New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.
New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.
$5.9M
New York Attorney General Letitia James sued Evolutions Festival LLC and 845 Vibrations LLC over the cancellation of the 2025 festival and their failure to refund ticket holders and vendors. The state alleges violations of laws governing advance ticket-sale funds and seeks restitution, civil penalties of $5,000 for each of 1,185 alleged violations, and an order requiring a $500,000 bond before the organizers can hold future cultural events in New York.