PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Once Again, Clapper Defeats Data Breach Class Action

Posted on February 15, 2014July 1, 2025 by Dissent

I had noted the Galaria opinion and order over on databreaches.net,  but Judy Selby has a discussion of the ruling in terms of the impact of the Supreme Court’s ruling in Clapper that is worth noting here:

Article III standing has once again proved to be an insurmountable hurdle for data breach class action plaintiffs whose personal information hasn’t been misused.  In Galaria v. Nationwide Mutual Insurance Co., an Ohio federal court relied on the United States Supreme Court’s decision in Clapper v. Amnesty Intern. USA, 133 S.Ct. 1138 (2013), and held that the plaintiffs did not sustain an injury sufficient to confer standing to sue Nationwide following a 2012 hacking incident during which their personally identifying information (PII) was stolen.

The plaintiffs alleged that as a result of the breach, they incurred and will continue to incur damages consisting of (1) the imminent, immediate, and continuing increased risk of identity theft, identity fraud and/or medical fraud; (2) out-of-pocket expenses to purchase credit monitoring, internet monitoring, identity theft insurance and/or data breach risk mitigation products; (3) out-of-pocket expenses incurred to mitigate the increased risk of identity theft, identity fraud and/or medical fraud, including the costs of placing and removing credit freezes; (4) the value of time spent mitigating the increased risk of identity theft, identity fraud and/or medical fraud; (5) the substantially increased risk of being victimized by phishing; (6) loss of privacy; and (7) deprivation of the value of their PII.  The court grouped those alleged damages into three categories: (1) increased risk of harm/cost to mitigate increased risk; (2) loss of privacy; and (3) deprivation of value of PII.  The plaintiffs asserted claims for violation of the Fair Credit Reporting Act (FCRA), negligence, invasion of privacy and bailment, but they did not allege that their PII was misused or that their identity was stolen.  Nationwide moved to dismiss the complaint based on lack of standing and failure to state a claim.

Read more on Data Privacy Monitor.

No related posts.

Category: BreachesBusinessCourt

Post navigation

← UK: Rights groups openly challenge GCHQ in court
PA: Student responsible for ‘CASHS Confessions’ caught →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs
  • Modern cars are spying on you. Here’s what you can do about it.
  • Attorney General James and Multistate Coalition Secure $5.1 Million from Education Software Company for Failing to Protect Students’ Data       
  • EU Parliament committee votes to advance controversial Europol data sharing proposal

RSS Recent Posts at DataBreaches.net

  • NHS providers reviewing stolen Synnovis data published by cyber criminals
  • Gates Down: Third Circuit Says Breaking Employer Computer Access Policies Is Not Hacking
  • Short-term renewal of cyber information sharing law appears in bill to end shutdown
  • Yanluowang ransomware IAB pleads guilty
  • Lawsuit Alleges Ex-Intel Employee Hid 18,000 Sensitive Documents Prior to Leaving the Company
©2025 PogoWasRight.org. All rights reserved.