Cybersecurity, Privacy, & AI

Trending Now
Anthropic’s Reported $30B Funding Talks Spotlight AI’s Growing Role in Cybersecurity, Defense • DC3 Seeks New Contractors for DCISE Voluntary Cyber Information-Sharing Program • Pentagon Cyber Official Calls Advanced AI ‘Revolutionary Warfare’ • NIST Aims for Summer Release of AI Cyber Guidelines • President Trump’s Cyber Strategy: Cross-Sector Implications for U.S. and UK Businesses

Considering Standing Law and Future Risk of Harm in Data Breach Litigation

Two cases decided within the space of a few weeks show the difficulty courts have in evaluating whether plaintiffs in data breach class actions have standing to pursue their claims.

The Eighth Circuit joined the First, Second, Third, and Fourth Circuits in finding that alleged increased risk of future fraud and identity theft was insufficient to establish Article III standing at the pleading stage. But the D.C. Circuit joined the Sixth, Seventh, and Ninth Circuits in holding that this can be sufficient. And the Supreme Court recently denied a certiorari petition filed by a defendant, thereby letting lower courts sort out the question.

Adam Cooke of Hogan Lovells analyzes the core allegation in these suits: that plaintiffs have suffered a cognizable injury based on the threat of future harm. He presents several arguments that the courts have accepted and thus denied standing, including breaches in which motives other than fraud were apparent or plausible, or where the threat of harm was successfully mitigated.

More at Bloomberg Law

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.