On February 22, 2019, another proposed amendment to the California Consumer Privacy Act (CCPA) was published. If enacted, this amendment will increase businesses’ potential exposure under the CCPA by, among other things, expanding the scope of private rights of action under the Act and eliminating a cure period prior to a civil enforcement action by the California Attorney General. The CCPA, originally enacted in June 2018 and first amended in September 2018, sets forth an entirely new privacy and security regime for many entities doing business in California. It imposes extensive requirements on the collection, use, and storage of consumer personal information, and applies to many businesses located both in and outside of the state. The deadline for all businesses to comply with the CCPA’s requirements is January 1, 2020, and the California Attorney General may bring an enforcement action six months after the passage of implementing regulations, or July 1, 2020, whichever comes first. The clock is ticking … The CCPA applies to any for-profit entity that (i) does business in California, (ii) collects “personal information” and/or determines the purposes and means of processing “personal information,” and (iii) satisfies at least one of the following threshold criteria: Has annual...
Class Action Plaintiffs Have Standing Based on Actual Injuries and Costs of Mitigation Following Corporate Hacking, Says Seventh Circuit
The Court of Appeals for the Seventh Circuit recently held that class action plaintiffs alleging injuries due to corporate hacking scandals have standing to pursue those claims in federal court, based on both actual injuries suffered repairing damage done by fraudulent charges, as well as costs of mitigating potential future harm, such as credit monitoring. Remijas v. Neiman Marcus Group, LLC, No. 14-3122 (7th Circ. July 20, 2015). As with other cases that come to the same conclusion, the court placed great emphasis on the fact that the data thieves were specifically targeting personal data, as well as the company’s admission of the breach and offer of a year of credit monitoring to those whose information had been exposed.
Class Action Certified in In re Yahoo Mail Litigation for Violations of Stored Communication Act and California’s Invasion of Privacy Act
On May 28, 2015, U.S. District Judge Lucy Koh in the Northern District of California certified a class of email users in a privacy action that claims Yahoo Inc. (“Yahoo”) violated the federal Stored Communications Act (“SCA”) and California’s Invasion of Privacy Act (“CIPA”) through its practice of scanning and analyzing emails of non-Yahoo Mail subscribers in order to display targeted ads to Yahoo Mail subscribers. In re Yahoo Mail Litigation, No. 13-CV-04980-LHK, (N.D. Cal. 2015). Plaintiffs are non-Yahoo Mail subscribers who sent emails to Yahoo Mail subscribers from non-Yahoo email accounts and allege that Yahoo routinely copies and extracts key words from emails and stores this information for later use. Plaintiffs allege that Yahoo’s practices violate § 2702(a)(1) of the SCA, which prohibits, among other items, divulging the contents of a communication without consent and § 631 of CIPA, which prohibits the recording or reading of any type of communication without the prior consent of all parties.
California District Court Denies Class Certification in Consolidated Gmail Litigation for Lack of Rule 23(b)(3) Predominance
In In re: Google Inc. Gmail Litigation, a consolidated multi-district litigation, a California federal court denied the plaintiffs’ motion to certify classes and subclasses because each class failed to satisfy Rule 23(b)(3)’s predominance requirement. The plaintiffs alleged that Google violated anti-wiretapping laws by intercepting messages through its email service, Gmail. The plaintiffs sought to certify four classes and three subclasses of different categories of Gmail users. Here, one of the central questions bearing on liability was whether the plaintiffs and class members consented to the alleged interceptions.