Blackbaud Data Breach: Do You Need to Notify Affected Individuals or EU Data Protection Authorities? – Lexology
On July 16, 2020, Blackbaud, a U.S. based cloud computing provider and one of the worlds largest providers of education administration, fundraising, and financial management software, notified users of its services that it had suffered a ransomware attack in May 2020 in relation to personal data stored on their servers. Numerous colleges, universities, foundations, and other non-profits across the U.K., U.S. and Canada were affected.
Blackbauds handling of the attack has raised some questions. Blackbaud has confirmed in a statement on its website that they paid the cyber-criminals ransom demand in return for confirmation that the stolen data had been destroyed. Paying ransom demands is not unlawful, but it goes against the official advice issued by many law enforcement agencies, including the FBI. In addition, Blackbaud has faced criticism for taking many weeks to inform its customers of the breach.
Much of the affected data was of a nature that would not trigger notice requirements in the United States, because the elements that constitute sensitive data in the U.S. (such as usernames, passwords and social security numbers) were encrypted. However, there are a handful of states (notably Washington and North Dakota) that have notification statutes requiring notice to affected individuals if other kinds of information is accessed, such as names together with dates of birth, and was the case for many of Blackbauds customers.
The bigger issue, however, is for those U.S.-based entities who actively target individuals in the European Union. For example, many colleges and universities in the United States actively recruit prospective students or donors in the European Union. These types of recruitment activities are likely to bring them in scope of the EUs General Data Protection Regulation (GDPR).
The GDPR is a far-reaching piece of European legislation which applies to organizations outside the EU and includes draconian financial sanctions for non-compliance. Moreover, the standard for notification to individuals and data protection authorities in the EU is much lower than in most U.S. states. The GDPR requires that data breaches are reported to European data protection supervisory authorities unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. This requires the affected institution to perform a thorough, documented risk assessment in each case.
Larger institutions may have already analyzed the need to comply with the GDPR and will therefore be aware that, if they are in scope of the GDPR, they may be required to report the breach both to the individuals concerned and to the relevant data protection supervisory authority in the EU. However, many smaller institutions may not have performed that analysis. This situation may find them needing to report the breach, but in doing so perhaps also alerting the data protection authorities to the fact that they may be subject to GDPR and may not be compliant in other ways. For instance, the GDPR requires specific contractual terms (including terms relating to the handling of data breaches) to be in place between customers and vendors where vendors process personal data on behalf of the customer.
The attack on Blackbaud is a major data breach. It may serve as a catalyst for U.S. non-profits to take a longer look at the GDPR and analyze their own need to comply.
Affected organizations both in and outside the EU should be working to determine what data has been compromised and whether they need to notify the local supervisory authority. The breach should also prompt all organizations to review any vendor contracts where personal data is involved, with a particular focus on ensuring that (a) the responsibility for data breach falls on the vendor and (b) strict notification timescales are imposed on the vendor (with the aim of preventing the lengthy delay in informing customers that has occurred in the Blackbaud case). Organizations that are subject to GDPR should also ensure that they implement GDPR-compliant vendor contracts.
See more here:
Blackbaud Data Breach: Do You Need to Notify Affected Individuals or EU Data Protection Authorities? - Lexology
- The European Union moves ahead with toughening its migration system - ABC News - December 10th, 2025 [December 10th, 2025]
- Elon Musk calls for abolition of European Union after it hit X with $140M bullst fine - New York Post - December 10th, 2025 [December 10th, 2025]
- Why is Elon Musk in a war of words with the European Union? - Australian Broadcasting Corporation - December 10th, 2025 [December 10th, 2025]
- The European Union moves ahead with toughening its migration system - AP News - December 10th, 2025 [December 10th, 2025]
- The European Union Reportedly Plans to Push Its Ban on New ICE Cars Back to 2040 - Road & Track - December 10th, 2025 [December 10th, 2025]
- Romania aims to become the customs hub of the European Union - European Newsroom - December 10th, 2025 [December 10th, 2025]
- Hungary Becomes Net Contributor to the European Union - Hungarian Conservative - December 2nd, 2025 [December 2nd, 2025]
- European Union and Singapore reinforce digital cooperation - European Interest - December 2nd, 2025 [December 2nd, 2025]
- Morawiecki on the judgment of the Court of Justice of the European Union: a brazen interference in the order of family law - European Newsroom - December 2nd, 2025 [December 2nd, 2025]
- European Union and UNESCO launch a new initiative to strengthen literacy and economic resilience in Afghanistan - Unric - December 2nd, 2025 [December 2nd, 2025]
- Court of Justice of the European Union Strengthens the Rights of Parents With Disabled Children - JD Supra - December 2nd, 2025 [December 2nd, 2025]
- European Union moves to cut off Tanzania over rights record - ZAWYA - December 2nd, 2025 [December 2nd, 2025]
- The Baltic Edge: A Strategic Imperative for NATO and the European Union - Taylor Wessing - December 2nd, 2025 [December 2nd, 2025]
- European Union threatens Tanzania with sanctions, funding freeze over post-election abuses - Business Insider Africa - November 30th, 2025 [November 30th, 2025]
- Europes chance to change the war: How to make the most of the reparation loan - European Union Institute for Security Studies | - November 30th, 2025 [November 30th, 2025]
- Shein faces European Union scrutiny over child safety and illegal products - AP News - November 30th, 2025 [November 30th, 2025]
- European Union's Nickel Market Set for Growth to 445K Tons in Volume and $8.6B in Value by 2035 - IndexBox - November 30th, 2025 [November 30th, 2025]
- European Union-funded Food Security Response in Northern Ghana - Food and Agriculture Organization - November 30th, 2025 [November 30th, 2025]
- European Union's Sweet Biscuit Market Set for Steady Growth With a 3% CAGR in Value - IndexBox - November 30th, 2025 [November 30th, 2025]
- Paris Louvre Museum To Increase Ticket Price For Visitors From Outside The European Union - Southern Minnesota News - November 30th, 2025 [November 30th, 2025]
- European Commission Approves BRINSUPRI (brensocatib) as the First and Only Treatment To Date Approved for Non-Cystic Fibrosis Bronchiectasis in the... - November 18th, 2025 [November 18th, 2025]
- President of Slovakia before ambassadors: Slovakia co-creates the rules of the game in the European Union - European Newsroom - November 18th, 2025 [November 18th, 2025]
- Secretary-General of ASEAN meets with the European Union Heads of Missions based in Jakarta - ASEAN Main Portal - November 18th, 2025 [November 18th, 2025]
- European Union Military Assistance Mission participates in the closing Ceremony of ISEDEF 2025 Courses - EEAS - November 18th, 2025 [November 18th, 2025]
- European Union and Vietnam: A joint path to poultry farming based on immunity and prevention - Laotian Times - November 18th, 2025 [November 18th, 2025]
- Implications of Free Trade between Mercosur and the European Union - PotatoPro - November 14th, 2025 [November 14th, 2025]
- However difficult to sell, the EU must get bigger - European Union Institute for Security Studies | - November 14th, 2025 [November 14th, 2025]
- European Union's Corrugated Paper Box Market Set for Growth to 30 Million Tons in Volume and $57 Billion in Value - IndexBox - November 14th, 2025 [November 14th, 2025]
- Red Cross and the European Union call for increased and local humanitarian investment in Latin America and the Caribbean in response to rising crises... - November 14th, 2025 [November 14th, 2025]
- RUBIO: "I don't think that the European Union gets to determine what international law is. They certainly don't get to determine is how the... - November 14th, 2025 [November 14th, 2025]
- Yes, there are political refugees from the European Union - Washington Times - November 7th, 2025 [November 7th, 2025]
- Kallas: The European Union will not allow a security vacuum in Bosnia and Herzegovina - European Newsroom - November 7th, 2025 [November 7th, 2025]
- The Presidency of Bosnia and Herzegovina Evaluated as Very Successful with the European Union Strategy for the Danube Region - European Newsroom - November 7th, 2025 [November 7th, 2025]
- Transforming Local Economic Opportunities: The European Union-funded ILO PROSPER Project Officially Launched in Southern Belize - EEAS - November 7th, 2025 [November 7th, 2025]
- The European Union supports strengthening cooperation between Bulgaria and the Republic of North Macedonia, said Valentina Superti from the EC -... - November 7th, 2025 [November 7th, 2025]
- The European Union is forging a new strategic alliance with Latin America - Peterson Institute for International Economics - November 7th, 2025 [November 7th, 2025]
- UNDP, DPPA and European Union Renew Partnership to Build National Capacities for Conflict Prevention - Unric - November 7th, 2025 [November 7th, 2025]
- Red Hat introduces confirmed sovereign support for European Union - telecomtv.com - November 7th, 2025 [November 7th, 2025]
- Private security firm says European Union vessel reaches ship raided by pirates off Somalia, all 24 crew on board safe - Yahoo - November 7th, 2025 [November 7th, 2025]
- Progress in Implementing the European Union Coordinated Plan on Artificial Intelligence (Volume 1) - OECD - November 7th, 2025 [November 7th, 2025]
- European Union restricts visas for Russian nationals over Ukraine war - The Hindu - November 7th, 2025 [November 7th, 2025]
- Jumptuit Awarded Trademarks in the European Union (EU) - PR Newswire - November 5th, 2025 [November 5th, 2025]
- Romania welcomes the publication of the Annual Package on the Enlargement of the European Union - European Newsroom - November 5th, 2025 [November 5th, 2025]
- US partners with unexpected ally in faceoff with European Union: 'Could jeopardize existing and future investments' - Yahoo - November 5th, 2025 [November 5th, 2025]
- Exclusive: Zelenskyy says 'Ukraine's future is in the European Union' - Yahoo News UK - November 5th, 2025 [November 5th, 2025]
- Kaja Kallas: Trkiye remains a key partner of the European Union - AnewZ - November 5th, 2025 [November 5th, 2025]
- European Union's SAN and ABS Copolymers Market to Reach 1.2M Tons and $2.6B by 2035 - IndexBox - November 5th, 2025 [November 5th, 2025]
- European Union tries to forge new climate targets before the COP30 summit in Brazil starts next week - The Daily Reporter - Greenfield Indiana - November 5th, 2025 [November 5th, 2025]
- Navigating the grey zone: Readiness, solidarity and resolve - European Union Institute for Security Studies | - October 30th, 2025 [October 30th, 2025]
- European Union's Metal Permanent Magnet Market Poised for Steady Growth with a 3.1% CAGR in Value - IndexBox - October 30th, 2025 [October 30th, 2025]
- European Union's Refined Rapeseed Oil Market Poised for Steady Growth With a 2.3% CAGR in Value - IndexBox - October 30th, 2025 [October 30th, 2025]
- European Union slaps a 1,600-crore fine on luxury brands Gucci, Loewe, and Chlo - Know why - ET BrandEquity - October 30th, 2025 [October 30th, 2025]
- 30th European Union Film Festival in Europe: A Global Cinematic Showcase Promoting European Art, Culture, and Tourism for Audiences Worldwide - Travel... - October 30th, 2025 [October 30th, 2025]
- European Union helps Ukrainian community of Vysoke open its first preschool - Agenparl - October 30th, 2025 [October 30th, 2025]
- European Union's Plastic Tubes and Pipes Market Set for Steady Growth with a 2.4% CAGR in Value - IndexBox - October 28th, 2025 [October 28th, 2025]
- Bulgaria, as a member of Schengen, will continue to contribute to the overall security of the European Union, said the Bulgarian interior minister -... - October 28th, 2025 [October 28th, 2025]
- European Union's Flexible Plastic Tubes and Hoses Market Set for Steady Growth with 3.3% CAGR in Value Through 2035 - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Bridge and Tower Market Set for Steady Growth with 2.8% CAGR in Value - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Yoghurt and Fermented Milk Market Set to Reach 9.8M Tons and $21.2B by 2035 - IndexBox - October 28th, 2025 [October 28th, 2025]
- Flags of China and the European Union together at some event or fair. Flags of the two countries as a symbol of cooperation between the two states.... - October 28th, 2025 [October 28th, 2025]
- European Union's Fruit and Berry Market Set for Steady Growth with 2.5% CAGR in Value - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Frozen Fish and Seafood Market Poised for Steady Growth with a 3.2% CAGR in Value Through 2035 - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Lithium-Ion Battery Market Set for Growth to 944 Million Units and $32 Billion by 2035 - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Frozen Dried and Smoked Fish Market Set for Steady Growth With a 1.6% CAGR - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Paper and Paperboard Market Set to Reach 80 Million Tons and $96 Billion by 2035 - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Jewelry Market Forecast to Expand With a 1.6% CAGR Through 2035 - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union's Meat Market Set for Modest Growth to 30 Million Tons in Volume and $132 Billion in Value - IndexBox - October 28th, 2025 [October 28th, 2025]
- European Union finally approves 19th package of sanctions against Russia: what it entails - - October 26th, 2025 [October 26th, 2025]
- European Union's Coated Arc-Welding Electrode Market to See Modest Growth With a +0.6% CAGR Through 2035 - IndexBox - October 26th, 2025 [October 26th, 2025]
- European Union considers banning ethanol used in hand sanitizers over cancerous fears: What this means - Times of India - October 26th, 2025 [October 26th, 2025]
- Jordanian Exports to the European Union Register Notable Growth - - October 26th, 2025 [October 26th, 2025]
- European Union's Dry Bean Market Set for Growth to 1.2 Million Tons in Volume and $1.3 Billion in Value - IndexBox - October 26th, 2025 [October 26th, 2025]
- European Union's Narrow Woven Fabric Market Poised for Steady Growth with a 2.3% CAGR in Value Through 2035 - IndexBox - October 26th, 2025 [October 26th, 2025]
- European Union among top three trade partners of Russia - Report.az - October 26th, 2025 [October 26th, 2025]
- European Union's Woven Carpet Market Set for Growth to $1.7B and 145M Square Meters by 2035 - IndexBox - October 26th, 2025 [October 26th, 2025]
- European Union Shatters Tourism Ties with Russia by Imposing Total Ban on Travel, Striking a Powerful Blow to Operators and Shaping New Travel... - October 24th, 2025 [October 24th, 2025]
- Kazakhstan and European Union continue to strengthen co-operation, marking the 10th anniversary of strategic partnership - EU Reporter - October 24th, 2025 [October 24th, 2025]
- "We have noted the recent restrictions announced by the European Union, United Kingdom and the United States on crude oil imports from Russia and... - October 24th, 2025 [October 24th, 2025]
- European Union to support Ukraine financially over next two years Zelensky - Ukrinform - October 24th, 2025 [October 24th, 2025]
- European Union agrees on new sanctions against Russia targeting its shadow oil fleet and LNG imports - Newsday - October 23rd, 2025 [October 23rd, 2025]