Mealey's Data Privacy

  • March 23, 2020

    Defense Owed For Suit Alleging Insured Violated Biometric Information Privacy Act

    CHICAGO — An Illinois appeals panel on March 20 affirmed a lower court’s ruling that an insurer has a duty to defend its insured against claims that it violated the Biometric Information Privacy Act, further affirming the lower court’s finding that the insured is not entitled to bad faith damages (West Bend Mutual Insurance Company v. Krishna Schaumburg Tan, Inc., et al., No. 19-1834, Ill. App., 1st Dist., 6th Div., 2020 Ill. App. LEXIS 179).

  • March 23, 2020

    J. Crew Asks 3rd Circuit To Again Affirm Dismissal Of FACTA Lawsuit

    PHILADELPHIA — In a March 18 appellee brief, J. Crew Group Inc. tells the Third Circuit U.S. Court of Appeals that most of the arguments raised by a customer claiming violations of the Fair and Accurate Credit Transactions Act (FACTA) by the printing of too many digits on his credit card receipts were already rejected by the court in a previous appeal six months earlier, urging the court to uphold a third dismissal ruling against the customer (Ahmed Kamal v. J. Crew Group Inc., et al., No. 19-3590, 3rd Cir.).

  • March 20, 2020

    Investor Communications Firm Data Breach Suit Dismissed For Lack Of Jurisdiction

    SAN FRANCISCO — Finding that a New York-based investor communications solutions provider did not avail itself of jurisdiction in California and did not purposefully direct any actions toward the state, a California federal judge on March 18 dismissed a putative class action against the company over a 2019 data breach for lack of personal jurisdiction (Phillip Toretto, et al. v. Mediant Communications Inc., No. 3:19-cv-05208, N.D. Calif., 2020 U.S. Dist. LEXIS 47123).

  • March 20, 2020

    Sonic Seeks To Exclude Data Breach Class’s Experts, Opposes Class Certification

    CLEVELAND — One day after Sonic Corp. filed a brief in Ohio federal court opposing certification for a class of financial institutions (FIs) in a lawsuit over its 2017 data breach, the fast food chain on March 18 filed three motions to exclude the plaintiffs’ class certification experts, citing issues of qualification, relevance and reliability (In re:  Sonic Corp. Customer Data Security Breach, No. 1:17-md-02807, N.D. Ohio).

  • March 19, 2020

    $13 Million Settlement Of Google Street View Privacy Suit Receives Final Approval

    SAN FRANCISCO — Four months after a California federal judge granted initial approval of a $13 million settlement between Google LLC and a putative class suing for privacy violations related to data collection connected to the Google Street View feature, he granted the plaintiffs’ motion for final approval on March 18, overruling objections to the cy pres-only nature of the settlement (In re Google LLC Street View Electronic Communications Litigation, No. 3:10-md-02184, N.D. Calif.).

  • March 19, 2020

    Former DHS Official Indicted On Government Data Trade Secret Theft Charges

    WASHINGTON, D.C. — A former Department of Homeland Security (DHS) acting inspector general has been charged with stealing proprietary software, source code and other information from the DHS containing, among other things, the personally identifiable information (PII) of employees of the DHS and U.S. Postal Service to create software to be sold to the Department of Agriculture, according to an indictment unsealed March 6 in District of Columbia federal court (United States v. Charles Kumar Edwards, et al., No. 20-cr-66, D. D.C.).

  • March 19, 2020

    Citing Settlement, Uber Drivers Ask 9th Circuit To Dismiss Data Hack Suit

    SAN FRANCISCO — More than a month after announcing their settlement with Uber Technologies Inc. of claims arising from a 2014 database hacking incident, two of the ride share company’s former drivers on March 18 filed a motion in the Ninth Circuit U.S. Court of Appeals, seeking to voluntarily dismiss their appeal of a trial court’s third dismissal of their putative class action (Sasha Antman, et al. v. Uber Technologies Inc. No. 18-16100, 9th Cir.).

  • March 17, 2020

    Panel Reverses No Coverage Ruling For Suit Alleging Insured Violated Credit Card Act

    PASADENA, Calif. — The Ninth Circuit U.S. Court of Appeals on March 16 held that an underlying lawsuit asserting that an insured violated California’s Credit Card Act alleged an invasion of privacy that is sufficient to trigger the insurer’s duty to defend, reversing a lower court’s no coverage ruling (Brighton Collectibles, LLC v. Certain Underwriters At Lloyd's London, No. 18-56403, 9th Cir., 2020 U.S. App. LEXIS 8245).

  • March 13, 2020

    ACLU Sues DHS, TSA For Information On Use Of Facial Recognition Technology

    NEW YORK — In a complaint filed March 12 in New York federal court, the American Civil Liberties Union seeks to compel the U.S. Department of Homeland Security (DHS) and other government agencies to respond to its Freedom of Information Act (FOIA) request for information about the government’s use of facial recognition technology at airports and borders (American Civil Liberties Union, et al. v. U.S. Department of Homeland Security, et al., No. 1:20-cv-02213, S.D. N.Y.).

  • March 12, 2020

    Privacy Exclusion Bars Coverage For Violation Of DPPA Claim, 4th Circuit Affirms

    RICHMOND, Va. — The Fourth Circuit U.S. Court of Appeals on March 10 affirmed a lower federal court’s finding that a business liability insurer has no duty to defend against an underlying lawsuit alleging that a personal injury law firm and its attorney violated the Driver’s Privacy Protection Act (DPPA), rejecting the appellants’ contention that construing the policy exclusions against the insurer and in favor of coverage is required under North Carolina law (Hartford Casualty Insurance Company v. Davis & Gelshenen, et al., No. 19-1578, 4th Cir., 2020 U.S. App. LEXIS 7448).

  • March 10, 2020

    Judge:  Facebook ‘View As’ Data Breach Suit Settlement Needs Clarifications

    SAN FRANCISCO — After a hearing on a proposed settlement of class claims over a security breach of Facebook Inc.’s social network via the “view as” feature, a California federal judge on March 5 sent the agreement back to the parties to clarify several items, including confidentiality and court notification procedures for post-settlement compliance assessments (Stephen Adkins v. Facebook, Inc., No. 3:18-cv-05982, N.D. Calif.).

  • March 05, 2020

    Online Game Company Hit With Class Suit After Users’ Data Stolen

    SAN FRANCISCO — A Kansas minor and a Michigan resident filed a class complaint on March 3 in a federal court in California accusing the company that operates online games, including Words With Friends, of failing to safeguard more than 218 million users’ personal information from being hacked in September 2019 (I.C., et al. v. Zynga, Inc., No. 20-1539, N.D. Calif.).

  • March 05, 2020

    9th Circuit Affirms Approval Of Facebook Messenger Privacy Class Action

    SAN FRANCISCO — Two and a half years after a trial court granted final approval of a settlement of a class action over Facebook Inc.’s now-discontinued practice of scanning its users’ private messages (PMs) for certain information, a Ninth Circuit U.S. Court of Appeals panel on March 3 affirmed the approval over one class member’s objections, finding that the injunctive relief attorney fees established by the settlement were proportionate to the claimed privacy injuries (Matthew Campbell, et al. v. Facebook Inc., et al., No. 17-16873, 9th Cir., 2020 U.S. App. LEXIS 6643).

  • March 04, 2020

    Preliminary OK Given To $32.5M Derivative Settlement Over Equifax Data Breach

    ATLANTA — A federal judge in Georgia on Feb. 24 granted preliminary approval of a $32.5 million settlement in a shareholder derivative lawsuit against several current and former officers and directors of Equifax Inc. over their handling of the credit-reporting agency’s massive 2017 data breach (In re Equifax Inc. Derivative Litigation, No. 18-317, N.D. Ga.).

  • March 03, 2020

    Final Approval Granted To $42 Million Premera Data Breach Class Action Settlement

    PORTLAND, Ore. — Seven months after an Oregon federal judge preliminarily approved a $42 million settlement between Premera Blue Cross and a class of its insureds over a 2014 data breach, the judge on March 2 granted final approval, the same day that a fairness hearing was held (In Re:  Premera Blue Cross Customer Data Security Breach Litigation, No. 3:15-md-02633, D. Ore.).

  • March 02, 2020

    Facebook, Plaintiffs Argue Over Custodians, Discovery Timeliness In Privacy Suit

    SAN FRANCISCO — In respective case management statements filed in California federal court on Feb. 27, Facebook Inc. and a putative class suing it over the Cambridge Analytica data-sharing incident blame each other for delays in the discovery process, arguing about such matters as search terms, depositions and the appropriate number of custodians (In re Facebook Inc., Consumer Privacy User Profile Litigation, No. 3:18-md-02843, N.D. Calif.).

  • March 02, 2020

    Settlements Reached With Viacom, Others In Children’s Game App Privacy Lawsuits

    SAN FRANCISCO — In a pair of notices filed in California federal court on Feb. 27, the plaintiffs in three consolidated suits brought under the Children’s Online Privacy Protection Act (COPPA) related to children’s game apps, announced that settlements had been reached between the plaintiffs, ViacomCBS Inc. and two companies involved in the games’ development (Amanda Rushing, et al. v. The Walt Disney Company, et al., No. 3:17-cv-04419, N.D. Calif.; Amanda Rushing, et al. v. ViacomCBS Inc., et al., No. 3:17-cv-04492, N.D. Calif.; Michael McDonald, et al. v. Kiloo ApS, et al., No. 3:17-cv-04344, N.D. Calif.).

  • February 27, 2020

    MGM Resorts Hit With Negligence Class Complaint Over 2019 Data Breach

    LAS VEGAS — Days after MGM Resorts International confirmed that it had experienced a data breach months earlier, a California man filed a putative class action against the resort in Nevada federal court on Feb. 21, alleging negligence and unjust enrichment for MGM’s “failure to implement adequate and reasonable cyber-security procedures and protocols necessary to protect” customers’ personally identifiable information (PII) (John Smallman v. MGM Resorts International, No. 2:20-cv-00376, D. Nev.).

  • February 27, 2020

    Biometric Data Collection Class Claims Against Medical Tech Firm Dismissed

    CHICAGO — A hospital worker failed to plead that the manufacturer of a medication-dispensing system that utilizes employees’ fingerprints for identification purposes collected or disclosed biometric data in violation of the Illinois Biometric Information Protection Act (BIPA), a Chicago federal judge ruled Feb. 24, granting the firm’s motion to dismiss the worker’s putative class claims (Corey Heard v. Becton, Dickinson & Co., No. 1:19-cv-04158, N.D. Ill., 2020 U.S. Dist. LEXIS 31249).

  • February 27, 2020

    Cryptocurrency Investor’s AT&T Phone Hack Suit Again Trimmed By Judge

    LOS ANGELES — Seven months after a California federal judge partly dismissed a well-known cryptocurrency investor’s negligence suit against AT&T Mobility LLC over phone hacking incidents that he says led to the theft of $24 million in digital currency, the same judge on Feb. 24 partly granted the cellular carrier’s renewed dismissal motion, while finding that some of the earlier pleading deficiencies had been cured (Michael Terpin v. AT&T Mobility LLC, et al., No. 2:18-cv-06975, C.D. Calif., 2020 U.S. Dist. LEXIS 31742).

Can't find the article you're looking for? Click here to search the Mealey's Data Privacy archive.