Summary
The United States District Court for the District of Minnesota granted without prejudice a defendant’s motion to dismiss claims arising from a data breach. The court held that the plaintiff failed to adequately allege Article III standing because he did not identify what personal information was disclosed, establish a substantial risk of future harm, or show that alleged spam, credit-related harm, emotional distress, and other injuries were fairly traceable to the breach. The court dismissed the action for lack of subject-matter jurisdiction and did not reach the Rule 12(b)(6) arguments.
Holdings
- Plaintiff lacks standing for equitable relief because the complaint fails to establish a 'certainly impending' or 'substantial risk' of a future data breach absent the injunctive relief sought.
- Plaintiff lacks standing for monetary damages because the complaint fails to identify what of plaintiff's own information was accessed or taken in the data breach, and thus fails to allege concrete or particularized harm from loss of privacy.
- The complaint fails to plausibly plead traceability between increased spam emails and the data breach because it contains no allegations that plaintiff's email address was disclosed, does not describe the subject matter of the emails, and alleges only that spam occurred 'in the aftermath' of the breach.
- Plaintiff's allegations of credit score decline and unauthorized inquiries are not fairly traceable to the data breach because credit scores can lower for a variety of reasons, and the timing allegations ('shortly after' and 'following') are insufficient to establish causation.
- Time spent monitoring accounts does not create standing when the plaintiff has not established a substantial and imminent risk of identity theft, because a plaintiff cannot manufacture standing by inflicting harm on themselves based on fears of hypothetical future harm.
- Allegations of diminished value of PII/PHI and lost benefit of the bargain are too general and conclusory to plausibly plead an injury in fact where the complaint does not identify the specific PII/PHI disclosed or explain how its monetary value was reduced.
- Emotional distress allegations are not fairly traceable to the data breach absent allegations that plaintiff's own PII/PHI was disclosed and that this disclosure caused the emotional distress.
Questions Presented
- Whether plaintiff has Article III standing to pursue claims arising from a data breach where the complaint does not allege that plaintiff's own personal identifiable information or protected health information was disclosed in the breach.
- Whether allegations of future risk of identity theft, increased spam, credit score decline, time spent monitoring accounts, diminished value of PII/PHI, and emotional distress are sufficient to establish concrete injury in fact and traceability for standing purposes.
Disposition
dismissed
Cases Cited (21)
- City of Clarkson Valley v. Mineta, 495 F.3d 567 (8th Cir. 2007)(cited)
- Alleruzzo v. SuperValu, Inc. (In re SuperValu, Inc. Customer Data Sec. Breach Litig.), 870 F.3d 763 (8th Cir. 2017)(cited)
- Spokeo v. Robins, 578 U.S. 330 (2016)(cited)
- TransUnion LLC v. Ramirez, 594 U.S. 413 (2021)(cited)
- Lujan v. Defenders of Wildlife, 504 U.S. 555 (1992)(cited)
- Friends of the Earth, Inc. v. Laidlaw Env't Servs. (TOC), 528 U.S. 167 (2000)(cited)
- Clapper v. Amnesty Int'l USA, 568 U.S. 398 (2013)(cited)
- Thomas v. Pawn Am. Minn., LLC (In re Pawn), No. 21-CV-2554 (PJS/JFD), 2022 WL 3159874 (D. Minn. Aug. 8, 2022)(cited)
- Webb v. Injured Workers Pharmacy, LLC, 72 F.4th 365 (1st Cir. 2023)(cited)
- Perry v. Bay & Bay Transp. Servs., Inc., 650 F. Supp. 3d 743 (D. Minn. 2023)(distinguished)
Showing top 10 of 21.
Cited In (0)
No citing cases on record yet.