205 F.Supp.3d 1064
N.D. Cal.2016Background
- Plaintiffs allege Yelp’s mobile app uploaded users’ Contacts address-book email addresses to Yelp’s servers without informed consent via its “Friend Finder” feature (active Jan 2010–Mar 2012 variations).
- The in-app prompts said only that the app would “find friends using your Contacts” or “look at your contacts to find friends”; earlier prompts did not say data would be uploaded to Yelp’s servers.
- Yelp’s website Terms of Service and Privacy Policy were hyperlinked during account registration; those policies referenced inviting friends and using contact info to process invites but did not clearly describe the Friend Finder matching/upload behavior.
- Apple’s internal review concluded Yelp’s older and interim prompts failed to inform users that contact data was uploaded to yelp.com; Yelp later revised the prompt to state it would upload contacts.
- Plaintiffs press a single remaining claim against Yelp: intrusion upon seclusion (invasion of privacy) under California law; Yelp moved for summary judgment arguing effective consent, lack of offensiveness, and Copyright Act preemption.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Whether users effectively consented to Yelp uploading Contacts data | Consent to “find friends” or to let Yelp “look at” Contacts did not equate to consent to upload/take data off device | Users consented by (1) agreeing to in‑app prompt and (2) agreeing to Terms/Privacy during account registration | Genuine dispute of material fact exists; summary judgment denied — jury must decide reasonable expectations and scope of consent |
| Whether upload was “highly offensive” (element of intrusion) | Uploading private address‑book data from personal phones can be a serious, offensive intrusion | Identifying social connections via address lists is commonplace/commercial and not highly offensive | Court found a triable issue of fact; offensiveness is fact‑specific and for the jury |
| Whether off‑screen Terms/Privacy gave constructive notice and obtained consent | Privacy Policy language did not clearly disclose/upload-for-matching; hyperlink-only access insufficient for constructive notice | Privacy Policy and Terms (seen at registration) put users on notice and authorized use | Court held Hyperlinked, off‑screen terms may be insufficient; ambiguity prevents summary judgment |
| Whether state privacy claim is preempted by Copyright Act | State intrusion claim alleges an extra element (highly offensive, unwarranted intrusion) distinct from mere copying | Copying/collecting contacts is reproduction potentially within Copyright Act subject matter | Court held claim not preempted because it alleges conduct beyond simple reproduction (extra element present) |
Key Cases Cited
- Shulman v. Group W Prods., 18 Cal.4th 200 (Cal. 1998) (elements and objective‑reasonableness test for intrusion upon seclusion)
- Hill v. Nat’l Collegiate Athletic Ass’n, 7 Cal.4th 1 (Cal. 1994) (consent can defeat privacy claim when explicit and voluntary)
- Sanders v. Am. Broad. Cos., 20 Cal.4th 907 (Cal. 1999) (privacy expectations vary by degree; not all intrusions eliminate privacy claims)
- Nguyen v. Barnes & Noble Inc., 763 F.3d 1171 (9th Cir. 2014) (hyperlink to terms alone may not give constructive notice of online terms)
- Perkins v. LinkedIn Corp., 53 F. Supp. 3d 1190 (N.D. Cal. 2014) (scope of consent defined by disclosures; some uses may exceed that scope)
- Folgelstrom v. Lamps Plus, Inc., 195 Cal. App.4th 986 (Cal. Ct. App. 2011) (routine commercial uses of contact info not necessarily highly offensive)
- Hernandez v. Hillsides, Inc., 47 Cal.4th 272 (Cal. 2009) (offensiveness inquiry is fact‑specific; degree and context matter)
- Feist Publ’ns, Inc. v. Rural Tel. Serv. Co., 499 U.S. 340 (U.S. 1991) (factual compilations receive thin copyright protection)
