Blackbaud
Filed here are the firms whose record of you did not begin with a sign-up. What holds the file together is the device rather than an account, so there may be nothing to log into and no delete button. The right to ask does not depend on having an account.
Reported incidents
Stolen backup files held a Catholic diocese's donor, school and staff records
2020-11-19Affected Hosted donor and school databases
The Catholic Diocese of Charlotte said in November 2020 that databases it kept with Blackbaud were in backup files an attacker removed during Blackbaud's 2020 ransomware attack. The diocese first said in August that limited donor details were exposed; Blackbaud later told it that employees, vendors, parents, students, alumni and supporters were also affected. A database of current and former employees and vendors, which the diocese stopped using by 2005, held Social Security numbers, tax identification numbers or bank account details. The FTC's 2024 order says the hacker went undetected for three months and Blackbaud waited nearly two months to tell its customers.
People affected typically ask Blackbaud to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.