United States: Eighth Circuit Holds Data Breach Plaintiffs Must Allege Actual Injury To Establish Standing

The U.S. Court of Appeals for the Eighth Circuit held that allegations of a future risk of identity theft resulting from a data breach are not sufficient to establish standing. The August 30 ruling in In re SuperValu Customer Data Security Breach Litigation requires that data breach plaintiffs must allege an actual injury for Article III standing, making it much more difficult for those plaintiffs to survive a motion to dismiss for lack of subject matter jurisdiction. The ruling increases uncertainty in data breach litigation at a time when various appellate courts have been going in different directions on the question of what must be alleged to establish standing to sue.

Background

SuperValu Inc., AB Acquisition LLC and New Albertson Inc. (the defendants) owned and operated a chain of retail grocery stores. In 2014, the defendants suffered two data breaches. In the first breach, from June 22, 2014 through July 17, 2014, hackers gained access to the payment information of defendants' customers including their names, credit or debit card account numbers, card expiration dates, card verification value codes, and personal identification numbers. The second breach took place in late August 2014 or early September 2014 and involved the same type of customer information. After each breach, the defendants issued a press release notifying customers of the breach but indicating that there had been no determination that customer information had in fact been stolen or misused.

Customers from several states allegedly affected by the breaches filed putative class actions in different district courts. The actions were transferred to the U.S. District Court for the District of Minnesota and consolidated. A consolidated amended complaint asserting claims for violations of state consumer protection and data breach notification statutes, negligence, breach of implied contract and unjust enrichment was filed with 16 named plaintiffs who allegedly shopped at the defendants' stores between June and September 2014.

The complaint alleged that the defendant failed to take adequate measures to protect customers' information by using default or common passwords, failing to lock out users after several failed login attempts and not segregating access to different parts of the computer network or using firewalls to protect customer information. The complaint alleged that customers' information was stolen as a result of the breaches, subjecting plaintiffs to "an imminent and real possibility of identity theft." Each of the named plaintiffs allegedly spent time reviewing information about the breaches and impacted locations and monitoring account information to guard against fraud. Only one of the named plaintiffs, David Holmes, alleged that he had suffered a fraudulent charge on his credit card statement, resulting in the replacement of that card. In support of their allegations, the complaint also cited a June 2007 U.S. Government Accountability Office report on data breaches.

The district court evaluated the standing of the named plaintiffs collectively and dismissed the complaint without prejudice, finding that plaintiffs had not alleged an injury in fact and, therefore, lacked standing. Specifically, the district court found that the complaint alleged only an "isolated single instance of an unauthorized charge" that did not "plausibly suggest[] that the hackers had succeeded in stealing the data and were willing and able to use it for future theft or fraud."

Eighth Circuit Decision, Review of Supreme Court Precedent

The Eighth Circuit affirmed the district court's dismissal for lack of standing as to the 15 individual plaintiffs who had not experienced any fraudulent charges or identity theft following the breaches, concluding that the complaint had not sufficiently alleged a substantial risk of future injury. However, the court reversed as to Holmes, finding that his allegation of a fraudulent use of his card gave rise to standing in his individual case.

Reviewing Supreme Court precedent, the Eighth Circuit explained that to establish an injury in fact sufficient for standing, plaintiffs must show that they have suffered an injury that is "'concrete and particularized' and 'actual or imminent, not conjectural or hypothetical.'" In cases involving future injury, plaintiffs must demonstrate that the "the threatened injury is 'certainly impending,' or there is a "'substantial risk" that the harm will occur.'" In addition, to establishing that an injury is fairly traceable to a defendant's conduct, plaintiffs must show "a causal connection between the injury and the conduct complained of" that is "not... th[e] result [of] independent action of some third party not before the court."

Turning to the complaint, the Eighth Circuit found that, although plaintiffs had established that their information was stolen, they had not adequately alleged that, aside from Holmes, stolen information had been misused. The court held that plaintiffs' reliance on the GAO report was misplaced as the report did not demonstrate that data breaches created a substantial risk that plaintiffs would suffer future identity theft. The Eighth Circuit noted that the GAO report concluded that compromised credit or debit card information, such as in the present case, "generally [could] not be used alone to open unauthorized new accounts," and that "most breaches have not resulted in detected incidents of identity theft." The court further held that the costs that plaintiffs incurred to mitigate the risk of future identity theft did not constitute an injury because the risk was "speculative" and plaintiffs could not "'manufacture standing merely by inflicting harm on themselves based on their fears of hypothetical future harm that is not certainly impending.'"

In contrast, the Eighth Circuit held that Holmes had adequately alleged that he had suffered a concrete and particularized injury in the form of the unauthorized fraudulent charge on his credit card account and that this injury was fairly traceable to the data breaches purportedly caused by defendants' failure to enact adequate security measures. The court concluded that "the district court had erred in holding that Holmes' standing was dependent on the standing of the other named plaintiffs and unnamed class members" and that "[e]ach plaintiff's standing must be assessed individually." It observed that, at the pleading stage, Holmes' burden for alleging a causal connection between his injury and the defendants' conduct was "relatively modest" and he had satisfied that burden. The Eighth Circuit also held that Holmes' injury was "likely to be redressed by a favorable judicial decision," as any financial harm that he suffered from the fraudulent charge would be compensable in the present action.

Takeaways

The implications of SuperValu are twofold. First, SuperValu limits the scope of Eighth Circuit's recent decision in Kuhns v. Scottrade (8th Cir. 2017), where the court held that allegations that the security provisions of a privacy policy were violated resulting in a data breach were sufficient to establish standing. Unlike Kuhns, where the injury was the alleged breach of contract, the plaintiffs in SuperValu did not assert breach of an express agreement. Instead, they asserted a breach of an implied contract claim based on the supposedly implied agreement by defendants to take reasonable measures to protect customer information in return for those customers using their credit or debit cards to make purchases at defendants' stores. By affirming the dismissal of the implied contract claim for lack of subject matter jurisdiction, SuperValu limits standing to bring contractual claims in data breach cases to those claims where the terms of the agreement are express and definite. Read more about the Kuhns decision in our case analysis article, " Eighth Circuit Finds Standing in Data Breach Case for Privacy Policy Violation, Dismisses for Lack of Specificity."

Second, SuperValu furthers the split among the Circuit courts concerning the pleading standard for Article III standing in data breach cases. SuperValu places the Eighth Circuit on the side of those Circuit courts that have held that plaintiffs must allege an actual injury in the form of fraudulent charges on existing credit or debit card accounts or the opening of fraudulent financial accounts based upon their stolen personal information to establish an Article III injury and survive a motion to dismiss for lack of standing. Joining the Second Circuit in Whalen v. Michaels Stores (2d Cir. May 2017) and the Fourth Circuit in Beck v. McDonald (4th Cir. 2017), the Eighth Circuit in SuperValu has found that general allegations of a heightened risk of identity theft from stolen personal information alone do not constitute an injury in fact, raising the pleading requirements for plaintiffs in data breach cases. In contrast, the D.C. Circuit in Attias v. CareFirst (D.C. Cir. 2017), the Sixth Circuit in Galaria v. Nationwide Mut. Insur. Co. (6th Cir. 2016), and the Seventh Circuit in Remijas v. Neiman Marcus (7th Cir. 2015) and Lewert v. P.F. Chang's China Bistro (7th Cir. 2016) have held that allegations that the personal information of the plaintiffs was stolen in a data breach resulting in an increased risk of identity theft without more constitute an injury sufficient to confer Article III standing. The Circuit split is likely to continue until—and unless—the Supreme Court weighs in and offers more definitive guidance.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on Mondaq.com.

Click to Login as an existing user or Register so you can print this article.

Authors
Events from this Firm
7 Jan 2019, Other, California, United States

Learn how to effectively take an HR department paperless while protecting company information and complying with ‘personnel file’ disclosure laws.

21 Jan 2019, Speaking Engagement, California, United States

Now entering its fifth year, the Pocket Gamer Connects events series has grown to become the biggest and most influential mobile games conference in the west as well as th​e biggest games event overall in the UK and Helsinki.

28 Jan 2019, Other, California, United States

Legalweek New York is the week in which various segments of the legal industry gather to explore the Business and Regulatory Trends, Technology and Talent drivers impacting the industry.

Similar Articles
Relevancy Powered by MondaqAI
 
In association with
Related Topics
 
Similar Articles
Relevancy Powered by MondaqAI
Related Articles
 
Related Video
Up-coming Events Search
Tools
Print
Font Size:
Translation
Channels
Mondaq on Twitter
 
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).
 
Email Address
Company Name
Password
Confirm Password
Position
Mondaq Topics -- Select your Interests
 Accounting
 Anti-trust
 Commercial
 Compliance
 Consumer
 Criminal
 Employment
 Energy
 Environment
 Family
 Finance
 Government
 Healthcare
 Immigration
 Insolvency
 Insurance
 International
 IP
 Law Performance
 Law Practice
 Litigation
 Media & IT
 Privacy
 Real Estate
 Strategy
 Tax
 Technology
 Transport
 Wealth Mgt
Regions
Africa
Asia
Asia Pacific
Australasia
Canada
Caribbean
Europe
European Union
Latin America
Middle East
U.K.
United States
Worldwide Updates
Registration (you must scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions

Mondaq.com (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of www.mondaq.com

To Use Mondaq.com you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.

Disclaimer

The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.

General

Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions