Showing posts with label In re Hannaford Bros. Co. Customer Data Security Breach Litigation. Show all posts
Showing posts with label In re Hannaford Bros. Co. Customer Data Security Breach Litigation. Show all posts

Friday, October 07, 2011





Final Approval Granted to Ameritrade Data Security Breach Settlement

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

A federal district court in San Francisco has granted final approval to a settlement of class action claims against online investment broker Ameritrade, which allegedly failed to prevent a data security breach that exposed more than six million account holders’ private information to spammers and rendered the same information vulnerable to others.

Preliminary approval was granted to the settlement in December 2010 (CCH Privacy Law in Marketing ¶60,574).

Cash Payout, Attorneys’ Fees

Ameritrade agreed to pay a minimum of $2.5 million and a maximum of $6.5 million in claims. Under the settlement, class members are eligible for a cash payout in amounts ranging from $50 to $2,500, depending on the nature of the account affected by the breach and the specific loss incurred. Attorneys’ fees for class counsel were capped at $500,000.

The settlement class was defined as “All persons who are or were accountholders or prospective accountholders of the Company and who provided physical or email addresses to the Company on or before September 14, 2007.”

The weakness of the plaintiffs’ case weighed in favor of granting approval to the settlement, the court said. Federal courts had viewed private class actions involving data breaches with skepticism, particularly where the only alleged injury was the receipt of spam, increased risk of identity theft, or loss of the benefit of the bargain.

Prosecuting the case through trial and the appellate process would involve a large amount of risk and expense. In addition, obtaining and maintaining class action status during the course of litigation would pose considerable risks to the plaintiffs.

The settlement afforded tangible benefits to the plaintiffs that were not available in prior proposed settlements, which had been rejected by the court.

Objections, Opt Outs

Notice of the settlement had been sent to the attorney general’s office of each of the 50 states, and none had objected. Of the approximately six million class members who were mailed the notice of the settlement, only 23 had submitted objections and fewer than 200 chose to opt out.

Objections to the settlement were overruled by the court. There was no evidence that class members had been misled about the terms of the settlement by the claims administrator.

Even though the settlement did not provide for a payout to every conceivable accountholder who might have been affected by the breach in some way, the settlement was a reasonable compromise that balanced the possible recovery against the risks inherent in litigating further.

The decision is In re TD Ameritrade Account Holder Litigation.

Thursday, October 07, 2010





Retail Chain’s Data Security Breach Did Not Injure Customers

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Retail grocery chain customers whose financial information was stolen during a breach of the chain's computer system did not sustain actual harm and could not pursue claims for negligence and implied contract under Maine common law, according to Maine’s highest court.

The customers asserted that they were injured by Hannaford's failure to prevent and notify them of the breach.

Dealing with Fraudulent Charges

The expenditure of time and effort to identify and remediate fraudulent charges on their credit and debit card accounts did not constitute a cognizable injury, in the absence of physical harm, economic loss, or identity theft, the court held.

The time and effort expended by the customers represented the ordinary frustrations and inconveniences confronted by everyone in daily life, the court said. The question had been certified to the court by the federal district court in Portland, Maine (CCH Privacy Law in Marketing ¶60,382).


The decision is In re Hannaford Bros. Co. Customer Data Security Breach Litigation, CCH Privacy Law in Marketing ¶60,534.

Further information about CCH Privacy Law in Marketing appears here.

Tuesday, June 16, 2009





Customers Could Sue Grocer Only if Damaged by Data Breach

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Customers of Maine-based supermarket chain Hannaford could pursue claims for breach of implied contract, negligence, and unfair trade practices under Maine law against the chain for failing to prevent a data security breach and for failing to notify them of the breach, but only if they could establish actual damages, according to the federal district court in Portland, Maine.

The alleged security breach resulted in the theft of an estimated 4.2 million debit and credit card numbers, expiration dates, PINs, and other personal information belonging to Hannaford customers.

Lawsuits over the breach from six states—Florida, Maine, New Hampshire, Massachusetts, New York, and Vermont—had been consolidated into a single case before the Maine court.

Breach of Implied Contract

The customers asserted that, at the point of a grocery sale, a merchant and customer implicitly agree that the merchant will guarantee the security of the customer's electronic data.

Although the court rejected the argument that Hannaford had made an implied commitment to prevent every intrusion under any circumstances whatsoever, the court concluded that a jury could find that there was an implied contractual term that Hannaford would use reasonable care in its custody of the customer's card data.

Negligence

Hannaford's assertion that the "economic loss" doctrine barred the customers from pursuing claims for negligence under Maine law was rejected.

Courts in some jurisdictions had applied the economic loss doctrine to prevent tort recovery for purely economic damages incurred by parties to a contractual relationship, unless there was also personal injury or property damage. Courts in Maine, however, did not apply the doctrine this broadly. The doctrine in Maine was limited to claims seeking tort recovery for a defective product's damage to itself.

Unfair Trade Practices

Failure to disclose the breach to customers could have been an unfair or deceptive practice, for purposes of Maine's Unfair Trade Practices Act (UTPA), the court said.

A jury could find that, if Hannaford had disclosed the breach immediately upon learning of it, customers would not have purchased groceries at its stores with debit and credit cards during the period between discovery of the breach (February 27, 2008) and containment of the breach (March 10, 2008). This nondisclosure would be an omission that was important to consumers and likely to affect their conduct regarding a product.

In addition, the Federal Trade Commission's pursuit of more than 20 complaints against corporations—including several retailers—for failing to use reasonable and appropriate security measures to prevent unauthorized access to personal information stored on computer networks supported accepting the customers' allegations as stating a claim under Maine's UTPA, the court reasoned.

Actual Damages

Each customer would be able to recover against Hannaford only if Hannaford's misconduct caused a direct loss to the customer's account. Consumers who did not have a fraudulent charge actually posted to their account could not recover; the only harm they could assert was the emotional distress that their accounts might be in peril, which was not actionable in the absence of monetary damages.

Consumers who had fraudulent charges posted to their accounts that were subsequently reversed and were no longer outstanding could not seek damages for alleged consequential losses, such as overdraft fees or a bank loan to cover them, a fee for insisting on changing an account when the issuing bank thought it was unnecessary, loss of accumulated reward points, time spent in convincing the issuing bank to reverse charges, or temporary lack of access to funds and inability to use a credit or debit card.

These alleged damages were too remote, not reasonably foreseeable, and speculative, in the court's view.

The decision is In re Hannaford Bros. Co. Customer Data Security Breach Litigation, CCH Privacy Law in Marketing ¶60,336.