There has been another ruling that makes it harder for plaintiffs in data breach litigation to prove standing. As seen on JDSupra:
Helpful guidance for businesses, and for Massachusetts state courts.
In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that in a suit for damages, “the mere risk of future harm, without more, cannot qualify as a concrete harm” sufficient to establish standing under Article III of the Constitution. (Emphasis added).
Since then, federal district courts and courts of appeal have reached different conclusions about how that principle applies to claims brought by individuals whose personal information was exposed as part of a data breach but who have not suffered a clear injury, such as identity theft or fraudulent charges.
The states have been no less confused, reaching different decisions as to whether data breach plaintiffs have alleged enough of an injury to have standing under the states’ own laws. In some states, the issue has been resolved by decisions from the states’ highest or mid-level appellate courts.
Until very recently, Massachusetts was one jurisdiction where this issue was still up in the air. That changed in June in the case of Cruceta v. J.C. Cannistraro LLC, in which the Appeals Court of Massachusetts held that plaintiffs do not have standing in data breach cases unless they allegedly suffered “cognizable damage” from the breach.
Read more at JDSupra.
