Rand v. The Travelers Indemnity CompanyRand v. The Travelers Indemnity Company
Case Information
UNITED STATES DISTRICT COURT
SOUTHERN DISTRICT OF NEW YORK
---------------------------------------------------------------x
JENNIFER RAND, individually and on behalf of :
a class similarly situated, :
Plaintiff, : OPINION AND ORDER : v. : 21 CV 10744 (VB) : THE TRAVELERS INDEMNITY COMPANY, :
Defendant. :
---------------------------------------------------------------x
Briccetti, J.:
Plaintiff Jennifer Rand brings this putative class action against defendant The Travelers Indemnity Company (“Travelers”), arising out of Travelers’s disclosure of plaintiff’s personal identifying information (“PII”) to non-party cybercriminals. Plaintiff asserts claims under the Driver’s Privacy Protection Act (the “DPPA”) and Section 349 of the New York State General Business Law, as well as state law claims for negligence and negligence per se.
Now pending is Travelers’s motion to dismiss the amended complaint under Rules 12(b)(1) and 12(b)(6). (Doc. #23).
For the foregoing reasons, the motion is GRANTED IN PART and DENIED IN PART. BACKGROUND
For the purpose of the ruling on the motion, the Court accepts as true all well-pleaded allegations in the amended complaint and draws all reasonable inferences in plaintiff’s favor, as summarized below.
Travelers and its related entitles provide insurance, banking, investment, retirement, and mortgage services.
Plaintiff alleges Travelers designed its website to ensure agents could generate insurance quotes for consumers as seamlessly as possible through a “‘shortcut’ process.” (Doc. #20 (“Am. Compl.”) ¶¶ 44–46). Specifically, plaintiff contends an agent seeking to generate a quote for an individual consumer could do so by providing only “minimal information” about the consumer, such as a name, address, and date of birth. (Am. Compl. ¶¶ 44, 49). Plaintiff further alleges that once an agent requests a quote through the agency portal, Travelers provides a final insurance quote that auto-populates with PII regarding the individual, including the individual’s driver’s license number. This PII is allegedly drawn from the relevant state’s department of motor vehicles (“DMV”) or other third parties that receive the PII from DMVs.
Plaintiff contends needing minimal consumer information to generate a quote “is by design” as it “allows Defendant to employ less [agents] and handle less phone calls from consumers.” (Am. Compl. ¶ 45). Plaintiff further alleges Travelers’s insurance-quote application process “is easily exploitable by non-parties to obtain the PII of other individuals . . . who are not voluntary customers” of Travelers. (Am. Compl. ¶ 48).
On February 16, 2021, and again on March 30, 2021, the New York State Department of Financial Services (“NYSDFS”) issued cybersecurity fraud alerts warning regulated financial entities like Travelers that cybercriminals were targeting “websites that offer instant online automobile insurance premium quotes” to steal driver’s license numbers. (Am. Compl. ¶¶ 67, 71, 75). In light of the “serious risk of theft and consumer harm” posed by the instant quote system, NYSDFS recommended numerous data security measures, including redacting PII, “disabl[ing] prefill of redacted” PII, or “avoid[ing] displaying prefilled [PII] on public-facing websites” entirely. (Am. Compl. ¶¶ 73, 77–78).
Plaintiff alleges she received a December 10, 2021, notice from Travelers that an unauthorized party may have accessed her name, address, date of birth, and driver’s license number by improperly using the credentials of Travelers agents to access Travelers’s agency portal (the “Travelers Notice”). Plaintiff maintains she never applied for Travelers insurance on her own and is not a voluntary customer of Travelers.
As a result, Travelers allegedly offered plaintiff and the putative class members “complimentary identity theft and credit monitoring services for a period of one year.” (Am. Compl. ¶ 57).
Plaintiff claims she spent “valuable time and resources in an effort to detect and prevent any additional misuses of her PII” and protect against “the heightened risk for fraud and identity theft” for years to come. (Am. Compl. ¶¶ 39–40). Plaintiff also claims she and putative class members “face years of constant surveillance of their financial and personal records, monitoring, and loss of rights” and they “are incurring and will continue to incur such damages in addition to any fraudulent use of their PII.” (Am. Compl. ¶¶ 147–148). Plaintiff further alleges she and putative class members incurred “[c]osts associated with requested credit freezes,” “[c]osts associated with the detection and prevention of identity theft,” “[c]osts associated with purchasing credit monitoring and identity theft protection services,” and “[l]owered credit scores resulting from credit inquiries following fraudulent activities.” (Am. Compl. ¶ 173).
DISCUSSION
I. Standards of Review
A. Rule 12(b)(1)
“[F]ederal courts are courts of limited jurisdiction and lack the power to disregard such
limits as have been imposed by the Constitution or Congress.” Durant, Nichols, Houston,
Hodgson & Cortese-Costa, P.C. v. Dupont,
“When the Rule 12(b)(1) motion is facial, i.e., based solely on the allegations of the
complaint . . . , the plaintiff has no evidentiary burden,” and “[t]he task of the district court is to
determine whether the [complaint] alleges facts that affirmatively and plausibly suggest that the
plaintiff has standing to sue.” Carter v. HealthPort Techs., LLC,
In deciding a motion to dismiss under Rule 12(b)(1) at the pleading stage, the court “must
accept as true all material facts alleged in the complaint and draw all reasonable inferences in the
plaintiff’s favor.” Conyers v. Rossides,
When a defendant moves to dismiss for lack of subject matter jurisdiction and “on other
grounds, the court should consider the Rule 12(b)(1) challenge first.” Rhulen Agency, Inc. v.
Ala. Ins. Guar. Ass’n,
B. Rule 12(b)(6)
In deciding a Rule 12(b)(6) motion, the Court evaluates the sufficiency of the complaint
under the “two-pronged approach” articulated by the Supreme Court in Ashcroft v. Iqbal, 556
U.S. 662, 679 (2009). First, a plaintiff’s legal conclusions and “[t]hreadbare recitals of the
elements of a cause of action, supported by mere conclusory statements,” are not entitled to the
assumption of truth and thus are not sufficient to withstand a motion to dismiss. Id. at 678;
Hayden v. Paterson,
To survive a Rule 12(b)(6) motion, the complaint’s allegations must meet a standard of
“plausibility.” Ashcroft v. Iqbal,
II. Standing
Travelers argues plaintiff does not allege an injury-in-fact to support Article III standing. The Court disagrees.
A. Legal Standard
To satisfy the “irreducible constitutional minimum of standing . . . [t]he plaintiff must
have (1) suffered an injury in fact, (2) that is fairly traceable to the challenged conduct of the
defendant, and (3) that is likely to be redressed by a favorable judicial decision.” Spokeo, Inc. v.
Robins,
An injury-in-fact is “an invasion of a legally protected interest that is concrete and
particularized and actual or imminent, not conjectural or hypothetical.” Spokeo, Inc. v. Robins,
To be concrete, an injury “must actually exist.” Spokeo, Inc. v. Robins,
Regarding statutory harms, it is not enough to allege a defendant violated the statute;
“[o]nly those plaintiffs who have been concretely harmed by a defendant’s statutory violation”
will have standing. TransUnion LLC v. Ramirez,
“Any monetary loss suffered by the plaintiff satisfies [the injury-in-fact] element; even a
small financial loss suffices.” Carter v. HealthPort Techs., LLC,
In McMorris, the Second Circuit applied a three-factor test to determine whether a plaintiff plausibly alleges a substantial risk of identity theft as part of the injury-in-fact analysis:
(1) whether the plaintiffs’ data has been exposed as the result of a targeted attempt to obtain that data; (2) whether any portion of the dataset has already been misused, even if the plaintiffs themselves have not yet experienced identity theft or fraud; and (3) whether the type of data that has been exposed is sensitive such that there is a high risk of identity theft or fraud.
Conversely, when plaintiffs “[do] not allege[] a substantial risk of future identity theft,” based on the factors discussed above, “the time they spent protecting themselves against this speculative threat cannot create an injury.” McMorris v. Carlos Lopez & Assocs., LLC, 995 F.3d at 303.
A plaintiff seeking injunctive relief to prevent future harm may plausibly allege an
injury-in-fact if she demonstrates “the risk of [future] harm is sufficiently imminent and
substantial.” TransUnion LLC v. Ramirez,
B. Analysis
Here, plaintiff adequately pleads injuries-in-fact in the form of a loss of privacy, as well as the harm incurred by attempting to mitigate existing and future identity theft. The Court will address each theory in turn.
1. Loss of Privacy As an initial matter, plaintiff plausibly alleges injury-in-fact in the form of a loss of privacy protected under the DPPA.
The loss of privacy arising out of the data breach, against which the DPPA was intended
to protect, bears a sufficiently “close relationship” to the tort of public disclosure of private
information, recognized at common law. TransUnion LLC v. Ramirez,
Here, plaintiff plausibly alleges Travelers automatically discloses an individual’s driver’s license information to a third party seeking an insurance quote if the third party provides Travelers with “minimal and basic information” regarding that individual, and, here, Travelers disclosed plaintiff’s driver’s license number and other PII to an unauthorized third party. (Am. Compl. ¶ 49). Moreover, plaintiff alleges she received the Travelers Notice informing her of the unauthorized access, notwithstanding that she never applied for Travelers insurance on her own and is not a voluntary customer of Travelers. Accepting the allegations in the amended complaint as true and drawing all reasonable inferences in plaintiff’s favor, the Court may reasonably infer that an unauthorized third party accessed sensitive information about plaintiff on Travelers’s agency portal.
To be clear, it is debatable whether Travelers’s disclosure to even a group of
cybercriminals improperly accessing plaintiff’s PII on the agency portal is sufficiently “public”
under the tort, and whether the type of disclosure here is sufficiently “offensive,”
[3]
but the
Supreme Court is clear that the common-law analogue need not be an “exact duplicate.”
TransUnion LLC v. Ramirez,
Accordingly, the Court concludes that at this early stage in the litigation, plaintiff’s allegations sufficiently resemble the type of loss in privacy protected by the tort of public disclosure of private information such that the loss constitutes an injury-in-fact.
2. Costs Mitigating the Risk of Future Identity Theft To mitigate the risk of future identity theft, plaintiff alleges she and class members have incurred costs associated with “requested credit freezes,” “the detection and prevention of identity theft,” and “purchasing credit monitoring and identity theft protection services.” (Am. Compl. ¶¶ 142, 173).
Although plaintiff does not allege that her PII obtained from Travelers’s agency portal, or
that of other class members, was actually misused or that there was any attempted misuse after
the data breach, “misuse is not necessarily required.” Clemens v. ExecuPharm Inc., 48 F.4th
146, 154 (3d Cir. 2022) (“The Seventh Circuit has found standing despite no allegations of
misuse.”); see also In re Am. Med. Collection Agency, Inc. Consumer Data Sec. Breach Litig.,
Regarding the first factor, the amended complaint plausibly alleges Travelers discovered
suspicious activity by an unauthorized party “us[ing] the credentials of a limited number of
agents to access the portal to obtain” individuals’ PII, and plaintiff received the Travelers Notice
notwithstanding that she never voluntarily accessed Travelers’s system or requested a quote from
Travelers. Based thereon, the Court can reasonably infer plaintiff’s data was “exposed as the
result of a targeted attempt” to obtain sensitive consumer data from Travelers. McMorris v.
Carlos Lopez & Assocs., LLC,
Regarding the third factor, plaintiff plausibly alleges her PII on Travelers’s system is
sufficiently “sensitive such that there is a high risk of identity theft or fraud” upon its disclosure.
McMorris v. Carlos Lopez & Assocs., LLC,
Accordingly, although it is a close call, the Court concludes plaintiff adequately pleads an imminent risk of future identity theft, and therefore the financial costs plaintiff allegedly incurred mitigating that risk constitute an independent injury-in-fact.
III. DPPA Claim
Travelers argues plaintiff cannot state a claim under the DPPA because she does not plausibly allege Travelers “knowingly or intentionally disclosed her personal information.” (Doc. # 24 (“Def. Mem.”) at 12).
The Court disagrees.
A. Legal Standard
The DPPA prohibits state and private individuals and entities from “knowingly
disclos[ing] or otherwise mak[ing] available to any person or entity” a range of “personal
information”—including driver’s license numbers—drawn from state motor vehicle records,
unless the disclosure is made for one of fourteen enumerated “permissible uses,” including
insurance ratings.
The DPPA also regulates “the resale and redisclosure of drivers’ personal information by
private persons who have obtained that information from a state DMV.” Reno v. Condon, 528
U.S. 141, 146 (2000) (citing
The DPPA creates a civil cause of action against any “[p]erson who knowingly obtains,
discloses or uses personal information, from a motor vehicle record, for a purpose not permitted
under” the DPPA.
A “knowing disclosure” is a disclosure made voluntarily, not necessarily one made with
“knowledge of illegality or potential consequences.” Senne v. Village of Palatine,
A rediscloser like Travelers—which, as discussed above, is subject to a duty of
reasonable care before disclosing DPPA-protected information—may be liable under the DPPA
for a third-party recipient’s impermissible use of the information, but only if the rediscloser
knew or reasonably should have known of the third party’s improper purpose before it disclosed
the DPPA-protected information. See Gordon v. Softech Int’l, Inc.,
B. Analysis
Here, plaintiff adequately pleads a claim under the DPPA.
First, plaintiff plausibly alleges Travelers obtained driver’s license numbers “from the
relevant state’s department of motor vehicles . . . or other third parties, such as insurers or data
aggregators, who receive this information from state DMVs” (Am. Compl. ¶ 44), and thus were
disclosed “from a motor vehicle record.”
Second, Travelers’s voluntary decision to auto-populate its quote responses with driver’s
license numbers constitutes a “knowing disclosure” of personal information.
Third, plaintiff adequately alleges that in light of the two separate NYSDFS data-security
alerts warning Travelers of the vulnerability of its auto-populate data features, Travelers
reasonably should have known its auto-populating of driver’s license numbers would disclose
such protected information directly to cybercriminals for impermissible purposes. See Gordon v.
Softech Int’l, Inc.,
Accordingly, the DPPA claim may proceed.
IV. Negligence
Travelers argues plaintiff fails plausibly to state a negligence claim under New York law because Travelers did not owe a duty of care to plaintiff, who, in any event, does not allege cognizable damages.
The Court disagrees as to Travelers’s duty of care.
The Court also disagrees as to plaintiff’s damages based on monetary harm. However, the Court agrees plaintiff’s remaining theories of damages are not cognizable under New York law.
A. Legal Standard
To plead a negligence claim under New York law, a plaintiff must plausibly allege
“(1) the defendant owed the plaintiff a cognizable duty of care; (2) the defendant breached that
duty; and (3) the plaintiff suffered damage as a proximate result of that breach.” Stagl v. Delta
Airlines, Inc.,
1. Duty of Care
At common law, New York courts evaluate the duty of care by balancing several factors,
including “the reasonable expectations of parties and society generally, the proliferation of
claims, the likelihood of unlimited or insurer-like liability, disproportionate risk and reparation
allocation, and public policies affecting the expansion or limitation of new channels of liability.”
Hamilton v. Beretta U.S.A. Corp.,
Although appellate courts in New York have yet to address the duty of care owed by
custodians or disclosers of PII in this context, district courts applying New York law have
determined a duty of care existed when the custodian was “in the best position to protect
information on its own servers from data breach,” “understood the importance of data security to
its business, knew it was the target of cyber-attacks, and touted its data security to current and
potential customers,” and would not be subject to limitless liability, because liability would have
been “limited to the individuals whose personal information it obtained while providing its
services.” See, e.g., Toretto v. Donnelley Fin. Sols., Inc.,
2. Damages
It is well established that even when a plaintiff’s allegations are sufficient to support
standing, the plaintiff must also plead cognizable damages to survive a defendant’s motion to
dismiss under Rule 12(b)(6). See Doe v. Chao,
“Under New York’s doctrine of avoidable consequences, a plaintiff must minimize damages caused by a defendant’s tortious conduct, and can recover mitigation costs for any action reasonable under the circumstances.” Sackin v. TransPerfect Glob., Inc., 278 F. Supp. 3d 739, 749 (S.D.N.Y. 2017) (citing applicable New York law).
However, a plaintiff may only recover damages for a risk of future harm, standing alone,
if he or she alleges an expense is “reasonably certain to be incurred” by virtue of the risk.
Caudle v. Towers, Perrin, Forster & Crosby, Inc.,
Moreover, time and effort alone, without ties to lost wages, or otherwise unaccompanied
by monetary loss, are not cognizable damages in common law claims for negligence. See, e.g.,
In re Gen. Motors LLC Ignition Switch Litig.,
Finally, a plaintiff may only recover damages for the lost value of private information if
the plaintiff plausibly alleges the existence of a market for the information and how the value of
such information could have decreased due to its disclosure. See Rudolph v. Hudson’s Bay Co.,
B. Analysis
1.
Duty of Care
Here, plaintiff plausibly alleges facts that, taken together, support the inference that
Travelers owed plaintiff a duty of reasonable care under New York law. First, plaintiff plausibly
alleges Travelers obtained and then redisclosed her PII—without her knowledge or consent—as
part of its ordinary course of business, and was thus “in the best position” as between Travelers
and plaintiff to protect the information. Toretto v. Donnelley Fin. Sols., Inc.,
Thus, holding a discloser of personal information liable for its own negligence under
these circumstances fits comfortably into the “duty equation” articulated by the New York Court
of Appeals. See Hamilton v. Beretta U.S.A. Corp.,
2. Damages Generally, fees paid to freeze credit reports and costs incurred in purchasing credit monitoring and identity theft services are cognizable expenses incurred for the purpose of avoiding further data-breach-related damages. See Sackin v. TransPerfect Glob., Inc., 278 F. Supp. 3d at 749 (discussing the “doctrine of avoidable consequences”).
However, the mere time and effort plaintiff allegedly expended addressing the
consequences of the data breach, standing alone, are not cognizable. See In re Gen. Motors LLC
Ignition Switch Litig.,
In addition, even if plaintiff plausibly alleges a substantial risk of identity fraud for the
purpose of pleading injury-in-fact, she does not plausibly allege she is “reasonably certain” to
incur expenses as a result of her greater exposure to the fraud. See, e.g., Caronia v. Philip Morris
USA, Inc.,
Finally, plaintiff offers only general allegations regarding the value of her PII, and she
does not allege she could have monetized her PII or that her PII was actually monetized.
Plaintiff thus does not plausibly allege damages based on her PII’s lost value. Cf. In re Yahoo!
Inc. Customer Data Sec. Breach Litig.,
In short, plaintiff’s negligence claim may proceed, but only to the extent it is based on monetary costs incurred to mitigate the harm caused by the data breach. To the extent the negligence claim is based on the other alleged theories of damages, it must be dismissed. V. Negligence Per Se
Travelers argues plaintiff does not state a claim for negligence per se because she does not identify an applicable statutory duty under New York law and does not allege cognizable damages.
The Court disagrees as to Travelers’s duty.
For the reasons discussed above regarding plaintiff’s negligence claim, the Court also disagrees as to plaintiff’s damages based on monetary harm, but agrees plaintiff’s remaining theories of damages are not cognizable under New York law.
A duty of care established by statute implicates the rule of negligence per se. Under the rule of negligence per se, if a statute is designed to protect a class of persons, in which the plaintiff is included, from the type of harm which in fact occurred as a result of its violation, the issues of the defendant's duty of care to the plaintiff and the defendant’s breach of that duty are conclusively established upon proof that the statute was violated.
German by German v. Fed. Home Loan Mortg. Corp.,
Here, in light of the fact that (i) the DPPA “was designed to protect a class of persons”
comprising individuals whose PII has been disclosed for an impermissible purpose; (ii) plaintiff
plausibly alleges she became a part of that class as a result of Travelers’s data breach; and (iii)
the improper disclosure of plaintiff’s PII to cybercriminals is the “type of harm [that] in fact
occurred as a result of [the DPPA’s] violation,” Travelers’s duty of care to plaintiff and its
breach of that duty are conclusively established upon proof that it violated the statute. German
by German v. Fed. Home Loan Mortg. Corp.,
Accordingly, plaintiff’s negligence per se claim may proceed, but only to the extent it is based on monetary costs incurred to mitigate the harm caused by the data breach. Plaintiff’s negligence per se claim based on the other alleged theories of damages must be dismissed. VI. General Business Law Section 349
Travelers argues plaintiff does not state a claim under Section 349 because she does not plausibly allege any deceptive conduct “caused” her injuries.
The Court agrees.
Section 349 prohibits “[d]eceptive acts or practices in the conduct of any business, trade
or commerce or in the furnishing of any service.” To assert a claim under Section 349 a
“plaintiff must allege that a defendant has engaged in (1) consumer-oriented conduct that is
(2) materially misleading and that (3) plaintiff suffered injury as a result of the allegedly
deceptive act or practice.” Orlander v. Staples, Inc.,
Although justifiable reliance on the alleged misrepresentation or omission is not a requisite element under Section 349, a plaintiff must plausibly allege she was exposed to the deceptive conduct in the first instance. See Fero v. Excellus Health Plan, Inc., 502 F. Supp. 3d 724, 740 (W.D.N.Y. 2020) (applying New York law and denying class certification in data- breach action because named plaintiff, whose PII was housed on defendant’s network, failed to show sufficient evidence that he had any direct dealings with defendant at all). Put another way, “in order to have been injured by the defendant’s deceptive act, a plaintiff must have been personally misled or deceived.” Id.
817, 827 (Sup. Ct. Westchester Cty. 2020). Accordingly, the negligence per se claim allegedly arising out of either statute must be dismissed. Here, plaintiff does not plausibly allege she was ever exposed to any purportedly deceptive misrepresentation or omission by Travelers. To the contrary, the well-pleaded allegations that plaintiff never applied for Travelers insurance and was not a voluntary customer of Travelers support the inference that she was not exposed to Travelers before the data breach at all. Plaintiff thus fails plausibly to allege her injuries were “caused” by any deceptive conduct on the part of Travelers.
Accordingly, plaintiff’s Section 349 claim must be dismissed.
VII. Declaratory Relief
Travelers argues plaintiff’s separate claim for declaratory relief must be dismissed because it is not an independent cause of action.
Travelers is correct there is no independent cause of action for a declaratory judgment, but plaintiff may nevertheless pursue declaratory relief to the extent her substantive claims survive.
The Declaratory Judgment Act,
Thus, although plaintiff styled her claim for declaratory relief as a separate count, that is not fatal to her claim. In Count V, plaintiff incorporates by reference her earlier allegations and refers to the specific substantive provisions under which she is allegedly entitled to declaratory relief. Specifically, plaintiff claims pursuant to the Court’s “authority under the Declaratory Judgment Act,” it should enter a judgment declaring Travelers “owes a legal duty to secure consumers’ PII and to timely notify consumers of a data breach under the common law, Section 5 of the FTC Act, the NY Shield Act, and the DPPA.” (Am. Compl. ¶ 243(a) (emphasis added)). Plaintiff’s claim for declaratory relief is thus derivative of her substantive claims and dependent on whether her underlying claims proceed.
As the Court dismissed plaintiff’s claims under Section 5 of the FTCA and the NY Shield Act, plaintiff has no right to declaratory relief related to those statutes. Any request for declaratory relief related to those statutes is dismissed.
Plaintiff may seek declaratory relief with respect to her DPPA, negligence, and negligence per se claims.
VIII. Injunctive Relief
Travelers also argues plaintiff’s separate claim for injunctive relief must be dismissed because it is not an independent cause of action.
The Court agrees a request for injunctive relief is not a separate cause of action; however, the Court disagrees that plaintiff’s request for injunctive relief must be dismissed.
A plaintiff seeking injunctive relief must plausibly allege “(1) that it has suffered an
irreparable injury; (2) that remedies available at law, such as monetary damages, are inadequate
to compensate for that injury; (3) that, considering the balance of hardships between the plaintiff
and defendant, a remedy in equity is warranted; and (4) that the public interest would not be
disserved by a permanent injunction.” eBay Inc. v. MercExchange, L.L.C.,
Here, plaintiff plausibly alleges entitlement to the injunctive relief she seeks. That is, plaintiff seeks injunctive relief in the form of requiring Travelers to implement certain specific security protocols, including engaging third-party auditors to test its systems for weaknesses and regularly testing its systems for security vulnerabilities. Plaintiff alleges she “will likely be subjected to substantial identity theft and other damage” if Travelers does not implement these measures. (Am. Compl. ¶ 245). She also alleges “the cost to Defendant of complying with an injunction by employing” these measures “is relatively minimal,” and that an injunction will serve the public interest “by preventing another data breach at” Travelers. (Am. Compl. ¶¶ 246–247).
Thus, at this early stage of the case, plaintiff adequately alleges entitlement to the injunctive relief she seeks, and her request for injunctive relief may proceed.
CONCLUSION
The motion to dismiss under Rule 12(b)(1) is DENIED.
The motion to dismiss under Rule 12(b)(6) is GRANTED IN PART and DENIED IN PART.
Plaintiff’s claim under Section 349 of the New York General Business Law is dismissed. Plaintiff’s request for declaratory relief is also dismissed to the extent it is based on Section 5 of the FTCA or the NY Shield Act.
Plaintiff’s other claims may proceed.
Defendant shall file an answer by November 9, 2022.
By separate order, the Court will schedule an initial pretrial conference.
The Clerk is instructed to terminate the motion. (Doc. #23).
Dated: October 26, 2022
White Plains, NY
SO ORDERED:
____________________________ Vincent L. Briccetti United States District Judge
Notes
[1] Unless otherwise indicated, case quotations omit all internal citations, quotation marks, footnotes, and alterations.
[2] McMorris, decided before TransUnion, suggested that a sufficiently imminent risk of
identity theft, standing alone, could constitute injury-in-fact, even in a suit for damages. See In
re Practicefirst Data Breach Litig.,
[3] Indeed, the Restatement of Torts cautions it is not enough “to communicate a fact concerning the plaintiff's private life to a single person or even to a small group of persons.” Restatement (Second) of Torts § 652D.
[4] The Court agrees with the weight of authority applying New York law and concluding
the economic loss doctrine—which prevents recovery for “purely economic losses” absent a
“special relationship”—does not apply to data-breach cases. See Toretto v. Donnelley Fin. Sols.,
Inc.,
[5] Plaintiff also alleges breaches of statutory duties purportedly created by Section 5 of the
Federal Trade Commission Act, 15 U.S.C § 45 (the “FTCA”), and New York’s Shield Act,