Citations
- 362 F. Supp. 3d 1295
Full opinion text
THOMAS W. THRASH, JR., United States District Judge
This is a data breach case. It is before the Court on the Defendants' Motion to Dismiss the Consolidated Consumer Class Action Complaint [Doc. 425]. For the reasons set forth below, the Defendants' Motion to Dismiss the Consolidated Consumer Class Action Complaint [Doc. 425] is GRANTED in part and DENIED in part.
I. Background
On September 7, 2017, the Defendant Equifax Inc. announced that it was the subject of one of the largest data breaches in history. From mid-May through the end of July 2017, hackers stole the personal and financial information of nearly 150 million Americans. During this time period, Equifax failed to detect the hackers' presence in its systems, allowing the hackers to exfiltrate massive amounts of sensitive personal data that was in the company's custody. This data breach ("Data Breach") is unprecedented - it affected almost half of the entire American population. The Data Breach was also severe in terms of the type of information that the hackers were able to obtain. The hackers stole at least 146.6 million names, 146.6 million dates of birth, 145.5 million Social Security numbers, 99 million addresses, 17.6 million driver's license numbers, 209,000 credit card numbers, and 97,500 tax identification numbers. This is extremely sensitive personal information. Using this information, identity thieves can create fake identities, fraudulently obtain loans and tax refunds, and destroy a consumer's credit-worthiness.
Equifax Inc. is a Georgia corporation with its principal place of business in Atlanta, Georgia. Equifax is the parent company of the Defendants Equifax Information Services LLC and Equifax Consumer Services LLC. Both of those subsidiary companies are Georgia limited liability companies, with their principal places of business in Atlanta, Georgia. The Defendants operate together as an integrated consumer reporting agency. The Plaintiffs are 96 consumers who allege that they have been injured by the Data Breach. They allege that they are suffering a "present, immediate, imminent, and continuing increased risk of harm" due to the compromise of their personally identifiable information in the Data Breach. The Plaintiffs seek to represent a class of those similarly situated consumers in the United States who were injured by the Data Breach.
Equifax's business model entails aggregating data relating to consumers from various sources, compiling that data into credit reports, and selling those reports to lenders, financial companies, employers, and others. Credit reporting agencies are "linchpins" of the nation's financial system due to the importance of credit reports in decisions to extend credit. Equifax also sells this information directly to consumers, allowing consumers to purchase their credit files and credit scores. In recent years, Equifax has worked to rapidly grow its business. Recognizing the value in obtaining massive troves of consumer data, Equifax has aggressively acquired companies with the goal of expanding into new markets and acquiring new sources of data. Equifax now maintains information on over 820 million individuals and 91 million businesses worldwide.
Equifax recognized the importance of data security, and the value of the data in its custody to cybercriminals. Equifax observed other major, well-publicized data breaches, including those at Target, Home Depot, Anthem, and its competitor Experian. Equifax held itself out as a leader in confronting such threats, offering "data breach solutions" to businesses. It also acquired two identity theft protection companies, Trusted ID and ID Watchdog. Equifax was also the subject of several prior data breaches. From 2010 on, Equifax suffered several different data breach incidents highlighting deficiencies in its cybersecurity protocol. Given these prior breaches, cybersecurity experts concluded that Equifax was susceptible to a major data breach. Analyses of Equifax's cybersecurity demonstrated that it lacked basic maintenance techniques that are highly relevant to potential data breaches. However, despite these risks, Equifax did little to improve its cybersecurity practices. Equifax's leaders afforded low priority to cybersecurity, spending a small fraction of the company's budget on cybersecurity.
The story of the Data Breach begins on March 6, 2017. On that date, a serious vulnerability in the Apache Struts software was discovered and reported. This software, a popular open-source program, was used by Equifax in its consumer dispute portal website. The next day, the Apache Software Foundation issued a free patch and urged all users to immediately implement the patch. The Department of Homeland Security also issued warnings concerning this vulnerability. Equifax internally disseminated the warning, but never implemented the patch. Then, beginning on May 13, 2017, hackers were able to manipulate the Apache Struts vulnerability to access Equifax's systems, and using simple commands determined the credentials of network accounts that allowed them to access the confidential information of millions of American consumers. From May 13 to July 30, 2017, the hackers remained undetected in Equifax's systems. During this time, the hackers were able to steal the sensitive personally identifiable information of approximately 147.9 million American consumers. The personally identifiable information that hackers obtained in the Data Breach includes names, addresses, birth dates, Social Security numbers, driver's license information, telephone numbers, email addresses, tax identification numbers, credit card numbers, credit report dispute documents, and more.
On July 29, 2017, Equifax's security team noticed "suspicious network traffic" in the dispute portal. The next day, the consumer dispute portal was deactivated and taken offline. On July 31, 2017, Equifax's CEO Richard Smith was informed of the breach. On August 2, 2017, Equifax informed the Federal Bureau of Investigation about the Data Breach, and retained legal counsel to guide its investigation. Equifax also hired cybersecurity firm Mandiant to investigate the suspicious activity. On September 7, 2017, seven weeks after discovering suspicious activity, Equifax publicly disclosed the Data Breach in a press release. Experts have since opined that the Data Breach was the result of weak cybersecurity measures and Equifax's low priority for data security.
The Plaintiffs here are a putative class of consumers whose personal information was stolen during the Data Breach. The class alleges that it has been harmed by having to take measures to combat the risk of identity theft, by identity theft that has already occurred to some members of the class, by expending time and effort to monitor their credit and identity, and that they all face a serious and imminent risk of fraud and identity theft due to the Data Breach. The putative class brings a number of nationwide claims, along with a number of state claims. The class also seeks declaratory and injunctive relief. The Defendants now move to dismiss.
II. Legal Standard
A complaint should be dismissed under Rule 12(b)(6) only where it appears that the facts alleged fail to state a "plausible" claim for relief. A complaint may survive a motion to dismiss for failure to state a claim, however, even if it is "improbable" that a plaintiff would be able to prove those facts; even if the possibility of recovery is extremely "remote and unlikely." In ruling on a motion to dismiss, the court must accept the facts pleaded in the complaint as true and construe them in the light most favorable to the plaintiff. Generally, notice pleading is all that is required for a valid complaint. Under notice pleading, the plaintiff need only give the defendant fair notice of the plaintiff's claim and the grounds upon which it rests.
III. Discussion
A. Choice of Law
First, the Court concludes that Georgia law governs this case. This case is before the Court based on diversity jurisdiction. The Court therefore looks to Georgia's choice of law rules to determine the appropriate rules of decision. Georgia follows the traditional approach of lex loci delecti in tort cases, which generally applies the substantive law of the state where the last event occurred necessary to make an actor liable for the alleged tort. Usually, this means that the "law of the place of the injury governs rather than the law of the place of the tortious acts allegedly causing the injury." However, there is an exception when the law of the foreign state is the common law. "[T]he application of another jurisdiction's laws is limited to statutes and decisions construing those statutes. When no statute is involved, Georgia courts apply the common law as developed in Georgia rather than foreign case law." The Plaintiffs identify no foreign statutes that govern their common law claims. Therefore, the Court will apply Georgia law to the common law claims.
B. Fair Credit Reporting Act
The Defendants first move to dismiss the Consumer Plaintiffs' claims under the Fair Credit Reporting Act ("FCRA"). Under the FCRA, a "consumer reporting agency may furnish a consumer report" only under limited circumstances provided for in the statute. In Count 1 of the Complaint, the Consumer Plaintiffs allege that the Defendants "furnished Class members' consumer reports" in violation of section 1681b of the FCRA and "failed to maintain reasonable procedures designed to limit the furnishing of Class members' consumer reports to permitted purposes, and/or failed to take adequate security measures that would prevent disclosure of Class members' consumer reports to unauthorized entities or computer hackers" in violation of section 1681e of the FRCA. The Defendants move to dismiss, arguing that Equifax did not "furnish" any consumer information within the meaning of the statute, and that the stolen personally identifying information is not a "consumer report" within the meaning of the statute. They also argue that since the Consumer Plaintiffs' section 1681b claim fails to state a claim, their section 1681e also necessarily fails. The Court agrees that the Consumer Plaintiffs fail to state a claim under the FCRA.
First, the Defendants argue that Equifax did not "furnish" the Plaintiffs' personal information within the meaning of the FCRA. The FCRA provides that a consumer reporting agency may only "furnish" a consumer report under limited circumstances. However, the statute does not further define "furnish." Generally, courts have held that information that is stolen from a credit reporting agency is not "furnished" within the meaning of the FCRA. For example, in In re Experian Data Breach Litigation , the court explained that "[a]lthough 'furnish' is not defined in the FCRA, courts generally use the term to describe the active transmission of information to a third-party rather than a failure to safeguard the data." In such a case, the data is stolen by a third party, and not furnished to the third party. Other courts have come to the same conclusion. The Plaintiffs acknowledge that the caselaw supports Equifax's argument, but contend nonetheless that Equifax's conduct was "so egregious" that it should be considered akin to furnishing. The Plaintiffs fail to offer a discernable criteria by which to determine when conduct becomes so egregious that it becomes akin to furnishing. Even assuming Equifax's conduct was egregious, the Court concludes that the Plaintiffs have not alleged facts showing that Equifax "furnished" the Plaintiffs' consumer reports to the hackers.
Next, the Defendants argue that the personally identifying information stolen during the Data Breach is not a "consumer report" within the meaning of the FCRA. The Court agrees. Section 1681b of the FCRA prohibits the furnishing of "consumer reports," except under limited circumstances. The FCRA defines "consumer report," in general, to mean:
[A]ny written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor in establishing the consumer's eligibility for--(A) credit or insurance to be used primarily for personal, family, or household purposes; (B) employment purposes; or (C) any other purpose authorized under section 1681b of this title.
Equifax argues - and the Plaintiffs do not dispute this - that the hackers did not obtain access to the active credit files maintained by one of the Equifax subsidiaries. The hackers got only "legacy" data. Courts, facing similar factual circumstances, have concluded that information such as that taken in the Data Breach does not constitute a "consumer report," but instead is "header information." Such information is not a "consumer report" because it does not bear on an individual's credit worthiness. Information, such as a consumer's "name, phone number, social security number, date of birth, driver's license, current address, and time spent at that address" does not, itself, constitute such a credit report. The Plaintiffs' argument that the information stolen in the Data Breach could bear on their credit worthiness is not persuasive. Therefore, the Court concludes that the Plaintiffs fail to allege facts showing that the information stolen was a "credit report."
Finally, since the Consumer Plaintiffs' section 1681b claim fails, their section 1681e claim must also necessarily fail. Section 1681e requires consumer reporting agencies to "maintain reasonable procedures designed to avoid violations of section 1681c of this title and to limit the furnishing of consumer reports to the purposes listed under section 1681b of this title." However, a plaintiff bringing a claim that a reporting agency violated the "reasonable procedures" requirement of section 1681e must first show that the reporting agency released the report in violation of section 1681b. Therefore, since the Plaintiffs' claims under section 1681b fail, their claims under section 1681e also fail.
Next, two Plaintiffs, Grace Cho and Debra Lee, bring claims under 15 U.S.C. § 1681g(a). These Plaintiffs, referred to as the "FCRA Disclosure Subclass" in the Complaint, allege that the Defendants violated sections 1681(a)(1) and 1681(a)(3) of the FCRA by failing to clearly and accurately disclose all of the information in their consumer files after requesting Equifax to do so. According to these Plaintiffs, the Defendants violated this statute by failing to identify the Data Breach and the individuals who procured their information, namely the hackers. However, as explained above, the hackers did not obtain a "consumer report" within the meaning of the FCRA. And Equifax could not be expected to disclose the identity of the unknown hackers. Therefore, this claim should be dismissed.
C. Legally Cognizable Injury
The Defendants next argue that all of the Plaintiffs' tort claims, including their negligence, negligence per se, and state consumer protection act violations, fail because they have not sufficiently alleged injury and proximate causation. According to the Defendants, the Plaintiffs' injuries are not legally cognizable harms, and even if they were, the Plaintiffs have failed to adequately allege that the Defendants proximately caused their harms. Finally, the Defendants argue that the Plaintiffs' tort claims are all barred by the economic loss doctrine.
1. Non-Harms and Speculative Future Harms
First, the Defendants contend that the Plaintiffs have not pleaded legally cognizable harms because their purported injuries only include "non-harms" and "speculative future harms." "It is well-established Georgia law that before an action for a tort will lie, the plaintiff must show he sustained injury or damage as a result of the negligent act or omission to act in some duty owed to him." "Although nominal damages can be awarded where there has been an injury but the injury is small, ... where there is no evidence of injury accompanying the tort, an essential element of the tort is lacking, thereby entitling the defendant to judgment in his favor."
The Defendants first contend that the compromise of personally identifiable information itself is not an injury. Each of the Plaintiffs alleges that his or her personally identifiable information was compromised in the Data Breach. Such an injury is legally cognizable under Georgia law. The cases relied upon by the Defendants are distinguishable. The Defendants cite Rite Aid of Georgia, Inc. v. Peacock for the proposition that a plaintiff suffers no injury from the illegal sale of personally identifiable information. However, as the Plaintiffs point out, the plaintiff in that case did not allege that this information was misused, or likely to be misused. In Rite Aid , the plaintiff's pharmacy records were sold from Rite Aid to Walgreens when a Rite Aid store was closing. The plaintiff sought certification of a class of all individuals whose information had been sold to Walgreens. The court concluded that class certification was not proper, in part, because the plaintiff had not alleged an injury from the sale of his information from one pharmacy to the other, and instead only alleged a violation of law. In contrast, the Plaintiffs here have alleged that they have been harmed by having to take measures to combat the risk of identity theft, by identity theft that has already occurred to some members of the class, by expending time and effort to monitor their credit and identity, and that they all face a serious and imminent risk of fraud and identity theft due to the Data Breach. These allegations of actual injury are sufficient to support a claim for relief.
The Defendants also cite Finnerty v. State Bank & Trust Company for the proposition that fear of future damages from identity theft is too speculative to form a basis of recovery. However, as the Plaintiffs emphasize, that case involved an invasion of privacy claim by an individual whose Social Security number was included in a public court filing. The court concluded that this claim failed because, to state a claim for invasion of privacy, a plaintiff must show that there was a public disclosure in which information is distributed to the public at large. There, the claimant failed to allege that anyone actually saw his Social Security number, and thus did not prove that there was a public disclosure. Thus, the court there did not hold that the disclosure of personal information is, as a matter of law, not a legally cognizable injury. Instead, it concluded that one of the elements of an invasion of privacy claim was not met, making it distinguishable from this case. And, in contrast to the inadvertent disclosure of a Social Security number in a single public court filing, the compromise of a huge amount of personally identifying information by criminal hackers presents a much more significant risk of identity fraud.
The Defendants also cite Randolph v. ING Life Insurance and Annuity Company . There, the plaintiffs sued after a laptop computer containing their personal information was stolen from the home of one of the defendant's employees, alleging that there was a substantial risk of identity theft and other dangers due to the possible unauthorized use of their personal information. In that case, there was no evidence that the theft occurred for the specific purpose of obtaining the information on the laptop as opposed to the computer itself. Here, by contrast, the Plaintiffs allege that their information was specifically targeted and has already been misused. The Plaintiffs have adequately alleged facts showing actual cognizable injury.
The Defendants also cite Collins v. Athens Orthopedic Clinic in their reply brief. There, the defendant's patients sued after a cyberhacker stole their personal information from the defendant's systems. The court concluded that the plaintiffs did not allege a legally cognizable harm. It explained that:
Plaintiffs allege that their information has been compromised and that they have spent time placing fraud or credit alerts on their accounts and "anticipate" spending more time on these activities. Plaintiffs claim damages, specifying only the cost of identity theft protection, credit monitoring, and credit freezes to be maintained "over the course of a lifetime." While credit monitoring and other precautionary measures are undoubtedly prudent, we find that they are not recoverable damages on the facts before us because Plaintiffs seek only to recover for an increased risk of harm.
Thus, according to the Defendants, the Plaintiffs' claims must fail, since costs associated with protecting the plaintiffs' personal information in Collins failed to establish a sufficient injury.
However, Collins is distinguishable. There, the plaintiffs alleged only an "increased risk of harm" associated with taking precautionary measures. The mere risk of harm, and not the type of injuries alleged, led the court to conclude that the plaintiffs' allegations as to injuries failed. In contrast, the Plaintiffs here have not pleaded merely an increased risk of harm. Instead, they have alleged that they have already incurred significant costs in response to the Data Breach. Many of the Plaintiffs have also already suffered forms of identity theft. Moreover, the Plaintiffs here have sufficiently alleged a substantial and imminent risk of impending identity fraud due to the vast amount of information that was obtained in the Data Breach. The Court concludes that these allegations are sufficient.
The Defendants also argue that the Plaintiffs that allege payment card fraud have failed to allege a sufficient injury. Plaintiffs Alvin Alfred Kleveno Jr., Maria Martucci, and Robert J. Etten allege that they experienced unauthorized charges on their payment cards as a result of the Data Breach. The Defendants contend that these allegations are insufficient because these Plaintiffs have not alleged the date on which these fraudulent charges were made, and because they failed to allege that they were not reimbursed for those charges. However, under Rule 8's requirement of a plain and simple statement, these Plaintiffs need not allege the specific date on which these fraudulent charges occurred. The Plaintiffs' allegations that such charges occurred are sufficient, and the Defendants cite no authority holding otherwise. Furthermore, contrary to the Defendants' assertions, these Plaintiffs also need not allege that they were not reimbursed for these fraudulent charges to adequately allege an injury. The Plaintiffs' allegations that they suffered unauthorized charges on their payment cards as a result of the Data Breach are actual, concrete injuries that are legally cognizable under Georgia law.
2. Proximate Causation
The Defendants next contend that the Plaintiffs have failed to adequately allege that Equifax proximately caused their injuries. "[B]efore any negligence, even if proven, can be actionable, that negligence must be the proximate cause of the injuries sued upon." "To establish proximate cause, a plaintiff must show a legally attributable causal connection between the defendant's conduct and the alleged injury." A plaintiff must establish "that it is more likely than not that the conduct of the defendant was a cause in fact of the result." "A mere possibility of such causation is not enough; and when the matter remains one of pure speculation or conjecture, or the probabilities are at best evenly balanced, it becomes the duty of the court to grant summary judgment for the defendant."
First, the Defendants argue that the Plaintiffs fail to allege that any injuries resulting from identity theft, payment-card fraud, or other similar theories resulted specifically from the Equifax Data Breach, and not some other data breach or fraudulent conduct. According to the Defendants, the Plaintiffs highlight dozens of other security breaches dating to 2013 in the Complaint, and the Defendants assert that over 1,500 data breaches occurred in 2017 alone. Thus, since the Plaintiffs have failed to allege that their injuries resulted directly from their personal information being obtained in this specific Data Breach, their theory of causation is "guesswork at best."
However, the Court finds this argument unpersuasive. Many of the Plaintiffs have alleged in the Complaint that they suffered some form of identity theft or other fraudulent activity as a result of the Data Breach. Such an allegation is sufficient at the pleading stage to establish that the Data Breach was the proximate cause of this harm. The Plaintiffs need not explicitly state that other breaches did not cause these alleged injuries, since their allegations that this Data Breach did cause their injuries implies such an allegation. Furthermore, allowing the Defendants "to rely on other data breaches to defeat a causal connection would 'create a perverse incentive for companies: so long as enough data breaches take place, individual companies will never be found liable.' " The Court declines to create such a perverse incentive.
Many of the Plaintiffs also allege in the Complaint that they purchased credit monitoring and incurred other costs in direct response to the Data Breach. Thus, even assuming their identity theft injuries resulted from previous breaches, these separate injuries resulted only from the occurrence of the Data Breach. Finally, even assuming that such an argument could disprove proximate causation, it presents a factual dispute most appropriate for a jury to consider. The Plaintiffs have alleged that the Data Breach caused their identities to be stolen, while the Defendants contend prior breaches caused these injuries. This is purely a dispute of fact that is not appropriate for resolution at this stage of the litigation. Therefore, the Court concludes that the Plaintiffs have adequately alleged that the Data Breach proximately caused their injuries. The Plaintiffs plausibly allege that Equifax had custody of their personally identifiable information, that Equifax's systems were hacked, that these hackers obtained this personal information, and that as a result of this breach, they have become the victims of identity theft and other fraudulent activity. This is sufficient.
Next, the Defendants contend that the Plaintiffs' injuries were proximately caused by an "unidentified third party's criminal acts," and not Equifax itself. According to the Defendants, the unforeseeable criminal acts of third parties "insulate" defendants from liability. "Generally, there is no duty to prevent the unforeseeable 'intervening criminal act of a third person.' " Under Georgia law, "when a defendant claims that its negligence is not the proximate cause of the plaintiff's injuries, but that an act of a third party intervened to cause those injuries, the rule is 'that an intervening and independent wrongful act of a third person producing the injury, and without which it would not have occurred, should be treated as the proximate cause, insulating and excluding the negligence of the defendant.' "
However, "this rule does not insulate the defendant 'if the defendant had reasonable grounds for apprehending that such wrongful act would be committed.' " "[I]f the character of the intervening act claimed to break the connection between the original wrongful act and the subsequent injury was such that its probable or natural consequences could reasonably have been anticipated, apprehended, or foreseen by the original wrong-doer, the causal connection is not broken, and the original wrong-doer is responsible for all of the consequences resulting from the intervening act." Thus, if the Defendants had reasonable grounds to anticipate the criminal act, then they are not insulated from liability. "In determining whether a third party criminal act is foreseeable, Georgia courts have held that 'the incident causing the injury must be substantially similar in type to the previous criminal activities ... so that a reasonable person would take ordinary precautions to protect his or her customers or tenants against the risk posed by that type of activity.' " The question of reasonable foreseeability of a criminal attack is generally for a jury to determine. However, it may not be in this case because of the many public statements by Equifax that it knew how valuable its information was to cyber criminals and its susceptibility to hacking attempts.
In Home Depot , this Court allowed a negligence claim premised upon a data breach to continue, noting that the defendant "knew about a substantial data security risk dating back to 2008 but failed to implement reasonable security measures to combat it." Similarly, in Arby's , the court noted that the defendant knew about potential data breach threats but failed to implement reasonable security measures. Thus, according to the court, the criminal acts of the cyberhackers were reasonably foreseeable, and thus the plaintiffs' negligence claims could proceed. In Arby's , the court compared criminal data breaches to the "peculiarly similar context of premises liability," where the Georgia Supreme Court has held that if a proprietor "has reason to anticipate a criminal act," then he or she has a duty to "exercise ordinary care to guard against injury from dangerous characters."
The Court concludes that, as in Arby's and Home Depot , the criminal acts of the hackers were reasonably foreseeable to the Defendants, and thus do not insulate them from liability. In the Complaint, the Plaintiffs allege that the Defendants observed major data breaches at other corporations, such as Target, Anthem, and Experian. Equifax itself even experienced prior data breaches. Furthermore, Equifax ignored warnings from cybersecurity experts that its data systems were dangerously deficient, and that there was a substantial risk of an imminent breach. These allegations are sufficient to establish that the acts of the third party cyberhackers were reasonably foreseeable. Thus, the causal chain is not broken.
The Defendants also assert that future identity theft and fraud is a second intervening cause that insulates them from liability. According to the Defendants, the Plaintiffs have not pleaded that this fraudulent conduct is the probable consequence of a data breach, and thus was not foreseeable. However, the Court concludes that the Plaintiffs have adequately alleged that such conduct was reasonably foreseeable. In the Complaint, the Plaintiffs allege that the Defendants knew the "likelihood and repercussions" of cybersecurity threats, and had stayed informed as to other well-publicized breaches. The Complaint details the Defendants' alleged awareness of the risks that data breaches pose, including the risks that the compromise of personal information entails. Equifax knew that fraudulent activity had resulted from other, well-publicized data breaches. Thus, the Plaintiffs have adequately alleged that this criminal conduct was reasonably foreseeable.
3. Economic Loss Doctrine
The Defendants next argue that the economic loss doctrine bars the Plaintiffs' tort claims. "The 'economic loss rule' generally provides that a contracting party who suffers purely economic losses must seek his remedy in contract and not in tort." In other words, "a plaintiff may not recover in tort for purely economic damages arising from a breach of contract." Where, however, "an independent duty exists under the law, the economic loss rule does not bar a tort claim because the claim is based on a recognized independent duty of care and thus does not fall within the scope of the rule." Here, the independent duty exception would bar application of the economic loss rule. "It is well-established that entities that collect sensitive, private data from consumers and store that data on their networks have a duty to protect that information[.]" As discussed below, the Defendants owed the Plaintiffs a duty of care to safeguard their personal information. Therefore, since an independent duty existed, the economic loss rule does not apply.
D. Negligence
Next, the Defendants move to dismiss the Plaintiffs' negligence claim. In Count 2 of the Complaint, the Plaintiffs allege that Equifax owed a duty to the Plaintiffs to "exercise reasonable care in obtaining, retaining, securing, safeguarding, deleting and protecting their Personal Information in its possession from being compromised, lost, stolen, accessed and misused by unauthorized persons." The Plaintiffs also allege that Equifax had a duty of care that arose from Section 5 of the Federal Trade Commission Act (the "FTC Act"), and the FCRA. The Defendants contend that they were under no duty of care toward the Plaintiffs.
In Georgia, "[a] cause of action for negligence requires (1) [a] legal duty to conform to a standard of conduct raised by the law for the protection of others against unreasonable risks of harm; (2) a breach of this standard; (3) a legally attributable causal connection between the conduct and the resulting injury; and, (4) some loss or damage flowing to the plaintiff's legally protected interest as a result of the alleged breach of the legal duty." "The threshold issue in any cause of action for negligence is whether, and to what extent, the defendant owes the plaintiff a duty of care." Whether such a duty exists is a question of law. Georgia recognizes a general duty "to all the world not to subject them to an unreasonable risk of harm."
The Defendants contend that Georgia law does not impose a duty of care to safeguard personal information. The Defendants rely primarily upon a recent Georgia Court of Appeals case, McConnell v. Georgia Department of Labor . In McConnell , the plaintiff filed a class action against the Georgia Department of Labor after one of its employees sent an email to 1,000 Georgians who had applied for unemployment benefits. This email included a spreadsheet with the name, Social Security number, phone number, email address, and age of 4,000 Georgians who had registered for services with the agency. The plaintiff, whose information was disclosed, filed a class action, asserting, among other claims, a claim for negligence.
A brief overview of McConnell's procedural history is helpful in understanding the court's decision in that case. In June 2016, the Georgia Court of Appeals initially rejected the plaintiff's claims. In McConnell I , the plaintiff, recognizing that such a duty had not been expressly recognized in Georgia caselaw, contended that such a duty arose from two statutory sources. The court concluded that neither of these statutory sources gave rise to a duty to safeguard personal information. The court explained that "McConnell's complaint is premised on a duty of care to safeguard personal information that has no source in Georgia statutory law or caselaw and that his complaint therefore failed to state a claim of negligence." However, in doing so, the court expressly distinguished this Court's prior holding in Home Depot , noting that this Court "found a duty to protect the personal information of the defendant's customers in the context of allegations that the defendant failed to implement reasonable security measures to combat a substantial data security risk of which it had received multiple warnings dating back several years and even took affirmative steps to stop its employees from fixing known security deficiencies" and explaining that "[t]here are no such allegations in this case."
Then, the Georgia Supreme Court vacated McConnell I , holding that the Court of Appeals could not decide whether the plaintiff failed to state a claim without first considering whether the doctrine of sovereign immunity barred his claims. On remand, the Georgia Court of Appeals, after deciding that sovereign immunity did not bar the plaintiff's claims, once again concluded that the plaintiff's negligence claim failed because "McConnell's complaint is premised on a duty of care to safeguard personal information that has no source in Georgia statutory law or caselaw and that his complaint therefore failed to state a claim of negligence." Examining both the Georgia Personal Identity Protection Act and the Georgia Fair Business Practices Act, the court concluded that neither gave rise to a duty to safeguard personal information. Although the legislature showed a "concern about the cost of identity theft to the marketplace" through these statutes, it did not act to "establish a standard of conduct intended to protect the security of personal information, as some other jurisdictions have done in connection with data protection and data breach notification laws."
The Defendants contend that McConnell III confirms that there is no duty under Georgia law, common law or statutory, to safeguard personally identifiable information. The Georgia Supreme Court has granted certiorari in the case. The Defendants, at oral argument, asked the Court to delay ruling upon the Motion to Dismiss until a ruling by the Georgia Supreme Court. However, it seems very unlikely to me that the Georgia Supreme Court will adopt a rule of law that tells hundreds of millions of consumers in the United States that a national credit reporting agency headquartered in Georgia has no obligation to protect their confidential personal identifying data. Unlike the Georgia Department of Labor, Equifax and the other national credit reporting agencies are heavily regulated by federal law. As noted previously, the Fair Credit Reporting Act strictly limits the circumstances under which a credit reporting agency may disclose consumer credit information. The failure to maintain reasonable and appropriate data security for consumers' sensitive personal information can constitute an unfair method of competition in commerce in violation of the Federal Trade Commission Act. The Gramm-Leach-Bliley Act required the FTC to establish standards for financial institutions to protect consumers' personal information. The FTC has done that.
The Plaintiffs contend that, under Georgia law, allegations that a company knew of a foreseeable risk to its data security systems are sufficient to establish a duty of care. The Plaintiffs rely primarily upon Home Depot and Arby's for this proposition. In Home Depot , this Court denied the defendant's motion to dismiss a negligence claim arising out of a data breach. The Court concluded that Home Depot had a duty to safeguard customer information because it "knew about a substantial data security risk dating back to 2008 but failed to implement reasonable security measures to combat it." The Court, citing the Georgia Supreme Court's decision in Bradley Center, Inc. v. Wessner , came to this conclusion by expounding upon the general duty to "all the world not to subject them to an unreasonable risk of harm." The Court noted that "to hold that no such duty existed would allow retailers to use outdated security measures and turn a blind eye to the ever-increasing risk of cyber attacks, leaving consumers with no recourse to recover damages even though the retailer was in a superior position to safeguard the public from such a risk."
Then, in Arby's , the court declined to dismiss a plaintiff's negligence claim arising out of a data breach. The court explained that "[u]nder Georgia law and the standard articulated in Home Depot , allegations that a company knew of a foreseeable risk to its data security systems are sufficient to establish the existence of a plausible legal duty and survive a motion to dismiss." The court held that Arby's was under a duty to safeguard its customers' personal data due to allegations that it knew about potential problems and failed to implement reasonable security measures, knew about other highly-publicized data breaches, and was aware that its parent company had suffered a significant breach using the same computer system. The Arby's court also distinguished McConnell I , explaining that it was not "expressly inconsistent" with Home Depot because Home Depot found a duty to protect personal information in the context of the defendant's failure to implement reasonable security measures to combat a foreseeable risk, while there were no such allegations in McConnell I . The court also explained that the McConnell I court's characterization of Wessner as a narrow holding did not change its conclusion since McConnell I did not change the general duty that arises from foreseeable criminal acts.
The parties' interpretations of this caselaw diverge greatly. The Defendants contend that McConnell III , the latest decision of all of these cases, clarified this caselaw and affirmatively stated that there is no duty to safeguard personal information. Thus, according to the Defendants, Home Depot and Arby's are no longer good law. The Plaintiffs, in turn, argue that due to the factual differences between McConnell III , on the one hand, and Arby's and Home Depot , on the other hand, McConnell III does not conflict with these two cases. According to the Plaintiffs, there were no allegations in McConnell III that the state agency should have known that its employee would inadvertently disclose this personal information. In contrast, Home Depot and Arby's premised their holdings on the detailed allegations that the data breaches were foreseeable. Finally, the Plaintiffs argue that, despite the Defendants' characterizations, they are not asking this Court to recognize a new duty under Georgia law, but instead are asking it to apply traditional tort and negligence principles to the facts of this case.
The Court concludes that, under the facts alleged in the Complaint, Equifax owed the Plaintiffs a duty of care to safeguard the personal information in its custody. This duty of care arises from the allegations that the Defendants knew of a foreseeable risk to its data security systems but failed to implement reasonable security measures. McConnell III does not alter this conclusion. As the court in McConnell I noted, a critical distinction between these cases is that the duty in Home Depot arose from allegations that the defendant failed to implement reasonable security measures in the face of a known security risk. Such allegations did not exist in the McConnell line of cases. The McConnell III court came to the same conclusion as the McConnell I court, and did nothing to dispel this distinction made in McConnell III . Furthermore, given this mention of Home Depot in McConnell I , and the court's subsequent holding in Arby's , the McConnell III court's silence on this issue suggests a tacit approval of this distinction. And, as this Court noted in Home Depot , to hold otherwise would create perverse incentives for businesses who profit off of the use of consumers' personal data to turn a blind eye and ignore known security risks.
The Defendants go to great lengths to distinguish the Georgia Supreme Court's decision in Bradley Center, Inc. v. Wessner . Both Home Depot and Arby's relied, in part, upon Wessner to conclude that the defendants were under a duty to take reasonable measures to avoid a foreseeable risk of harm from a data breach incident. In Wessner , a man who voluntarily committed himself to a psychiatric hospital made statements to the hospital's staff that he desired to harm his wife. Despite these statements, the man was issued a weekend pass by the staff, and he subsequently obtained a gun, confronted his wife and another man, and killed them both. The Georgia Supreme Court concluded that the hospital owed a duty of care to the man's wife. The court explained that "[t]he legal duty in this case arises out of the general duty one owes to all the world not to subject them to an unreasonable risk of harm."
The Defendants argue that the holding in Wessner is much narrower than this. According to them, Wessner merely stands for the narrow proposition that a physician owes a legal duty when, in the course of treating a mental health patient, that physician exercises control over the patient and knows or should know that the patient is likely to cause harm to others. The Defendants further assert that the Wessner court's references to general negligence principles were done in an effort to explain why the case was a negligence case, and not a medical malpractice case. However, despite the Defendants' efforts to minimize the importance of Wessner , the Court finds that Wessner supports the conclusion that the Defendants owed a legal duty to take reasonable measures to prevent a reasonably foreseeable risk of harm due to a data breach incident. Nowhere in the Wessner decision does the Georgia Supreme Court limit its holding to the narrow proposition that the Defendants assert. In fact, in Wessner , the court explained that it was not creating a "new tort," but instead that it was applying "our traditional tort principles of negligence to the facts of this case." Other Georgia cases have similarly applied these same general principles. Likewise, this Court concludes that, under traditional negligence principles, the Defendants owed a legal duty to the Plaintiffs to take reasonable precautions due to the reasonably foreseeable risk of danger of a data breach incident.
The Defendants then argue that they did not "voluntarily" undertake a duty. In the Complaint, the Plaintiffs allege that Equifax's duty also arose from its "unique position as one of three nationwide credit-reporting companies that serve as linchpins of the financial system" and that Equifax "undertakes its collection of highly sensitive information generally without the knowledge or consent of consumers." The Defendants contend that this claim fails because under Georgia's "good Samaritan" provision, an undertaken duty extends only to preventing physical harm to another's person or property. The Plaintiffs do not respond to this argument. Therefore, to the extent that the Plaintiffs assert a duty premised upon the Defendants' voluntary undertaking such a responsibility, that claim should be dismissed.
E. Negligence Per Se
Next, the Defendants move to dismiss the Plaintiffs' negligence per se claim. In Count 3 of the Complaint, the Plaintiffs allege that Equifax violated Section 5 of the FTC Act, and similar state statutes, by "failing to use reasonable measures to protect Personal Information and not complying with industry standards," and that such violation constitutes negligence per se. "Georgia law allows the adoption of a statute or regulation as a standard of conduct so that its violation becomes negligence per se." In order to make a negligence per se claim, however, the plaintiff must show that it is within the class of persons intended to be protected by the statute and that the statute was meant to protect against the harm suffered.
The Defendants argue that the Plaintiffs fail to identify statutory text that imposes a duty with specificity upon the Defendants. Here, the Plaintiffs allege that Equifax violated Section 5 of the FTC Act. The Defendants argue that Section 5 cannot form the basis of a negligence per se claim. The failure to maintain reasonable and appropriate data security for consumers' sensitive personal information can constitute an unfair method of competition in commerce in violation of the Federal Trade Commission Act. The Consolidated Class Action Complaint here adequately pleads a violation of Section 5 of the FTC Act, that the Plaintiffs are within the class of persons intended to be protected by the statute, and that the harm suffered is the kind the statute meant to protect. Additionally, one Georgia case and one case applying Georgia law both suggest that the FTC Act can serve as the basis of a negligence per se claim. The Defendants' motion to dismiss the negligence per se claim should be denied.
Second, the Defendants argue that LabMD, Inc. v. Fed. Trade Comm'n , should lead this Court to a different conclusion. That was a direct enforcement action. There, the Eleventh Circuit noted that "standards of unfairness" must be found "in 'clear and well-established' policies that are expressed in the Constitution, statutes, or the common law." The court explained that the FTC in that case did "not explicitly cite the source of the standard of unfairness" it used in holding that LabMD's failure to implement a reasonable data security program was an unfair act or practice, but concluded that it was "apparent" that "the source is the common law of negligence." The court then vacated the FTC's order because the order was too vague to be enforced. It did not hold that inadequate data security cannot be regulated under Section 5.
Next, the Defendants argue that the Plaintiffs have not sufficiently alleged injury or proximate causation. Under Georgia law, negligence per se is "not liability per se." Even if negligence per se is shown, a plaintiff must still prove proximate causation and actual damage to recover. As discussed above, the Court concludes that the Plaintiffs have sufficiently alleged both a legally cognizable injury and proximate causation. Therefore, this argument is unavailing.
F. Georgia Fair Business Practices Act
Next, the Defendants move to dismiss the Plaintiffs' claims under the Georgia Fair Business Practices Act. The Georgia Fair Business Practices Act prohibits, generally, "unfair or deceptive acts or practices in the conduct of consumer transactions and consumer acts or practices in trade or commerce." In Count 4 of the Complaint, the Plaintiffs allege that the Defendants violated multiple provisions of the Georgia Fair Business Practices Act, including O.C.G.A. §§ 10-1-393(a), 10-1-393(b)(5), 10-1-393(b)(7), 10-1-393(b)(9). The Defendants make multiple arguments in favor of dismissal.
The Defendants first argue that the Georgia Fair Business Practices Act does not require the safeguarding of personally identifiable information. According to the Defendants, McConnell III would have been decided differently if the Georgia Fair Business Practices Act contained such a requirement. In McConnell III , the court concluded that part of the Georgia Fair Business Practices Act, O.C.G.A. § 10-1-393.8, "can not serve as the source of such a general duty to safeguard and protect the personal information of another." That provision prohibited "intentionally communicating a person's social security number." The court rejected the plaintiff's claim, noting that he had alleged that the defendant negligently disseminated his social security number.
The Plaintiffs make multiple arguments in response. However, the Court finds these arguments unpersuasive. First, they argue that Arby's II , decided after McConnell III , held that data breach victims can pursue a claim under the Georgia Fair Business Practices Act. However, that decision only considered whether the plaintiffs had adequately alleged reliance. Thus, the court's reasoning does not bear on whether McConnell III precluded recovery under the Georgia Fair Business Practices Act. Second, the Plaintiffs contend that McConnell III only stands for the proposition that the Georgia Fair Business Practices Act is not the basis of a general tort duty. However, McConnell III 's holding was broader than that. In McConnell III , the court, after examining parts of the Georgia Fair Business Practices Act, along with the Georgia Personal Identity Protection Act, concluded that there is no statutory basis for a duty to safeguard personal information in Georgia. It further explained that the Georgia legislature has not acted to establish a standard of conduct to protect the security of personal information, unlike other jurisdictions with data protection and data breach laws. Even though McConnell III examined the Georgia Fair Business Practices Act in the context of its provisions dealing with Social Security numbers specifically, it concluded that the entire Act, along with the rest of Georgia statutory law, did not require the safeguarding of personal information. Therefore, the Court concludes that the Georgia Fair Business Practices Act does not require businesses to safeguard personally identifiable information. This issue may be revisited depending upon the ruling of the Georgia Supreme Court in McConnell III .
G. Unjust Enrichment
The Defendants next move to dismiss the Plaintiffs' unjust enrichment claim. In Count 5 of the Complaint, the Plaintiffs allege that Equifax has been unjustly enriched by benefitting from and profiting off of the sale of the Plaintiffs' personally identifiable information, all at the Plaintiffs' expense. Unjust enrichment is an equitable doctrine that "applies when as a matter of fact there is no legal contract, but where the party sought to be charged has been conferred a benefit by the party contending an unjust enrichment which the benefitted party equitably ought to return or compensate for." Thus, in order to state a claim for unjust enrichment, the Plaintiffs must show that "(1) a benefit has been conferred, (2) compensation has not been given for receipt of the benefit, and (3) the failure to so compensate would be unjust."
The Defendants argue that, with regard to most of the Plaintiffs, personally identifiable information was conferred on Equifax by third parties, and not by the Plaintiffs themselves. Instead, only the Contract Plaintiffs gave their information to Equifax. Thus, according to the Defendants, the unjust enrichment claims of these non-Contract Plaintiffs fail because they do not allege that they conferred anything of value on Equifax.
The Plaintiffs first cite Arby's , contending that the court in that case "sustain[ed]" the plaintiffs' claim for unjust enrichment. However, the court in Arby's did not consider the merits of the plaintiffs' unjust enrichment claim. Instead, it merely decided that the plaintiffs could assert a claim for unjust enrichment in the alternative to their contract claims. Therefore, this case does not provide guidance as to whether the Plaintiffs have made allegations that satisfy each element of an unjust enrichment claim. The Plaintiffs also cite Sackin v. TransPerfect Global, Inc. However, the plaintiffs in that case asserted an unjust enrichment claim under New York law, which contains different elements than such a claim under Georgia law.
The Court concludes that the non-Contract Plaintiffs fail to establish the necessary elements of an unjust enrichment claim. The Georgia Court of Appeals has explained that "for unjust enrichment to apply, the party conferring the labor and things of value must act with the expectation that the other will be responsible for the cost. Otherwise, that party, like one who volunteers to pay the debt of another, has no right to an equitable recovery." For example, in Sitterli v. Csachi , the court concluded that for unjust enrichment to apply, the party conferring things of value must act with the expectation that the other will be responsible for the cost. The Plaintiffs have failed to show that they conferred a thing of value, namely their personally identifiable information, upon the Defendants with the expectation that Equifax would be responsible for the cost. The non-Contract Plaintiffs have failed to allege that they had any such expectation.
The Defendants also argue that the Contract Plaintiffs' unjust enrichment claims must be dismissed because those Plaintiffs have also pleaded breach of contract claims. Under Georgia law, "[a] party can only recover for a claim of unjust enrichment if there is not an express contract that governs the dispute." However, "[w]hile a party, indeed, cannot recover under both a breach of contract and unjust enrichment theory, a plaintiff may plead these claims in the alternative." Thus, the Contract Plaintiffs may assert inconsistent contract and unjust enrichment theories at this stage of the proceedings.
H. Breach of Contract
Next, the Defendants move to dismiss the Contract Plaintiffs' breach of contract claims. Nineteen Plaintiffs allege that they formed a contract with Equifax, either express or implied, when they obtained credit monitoring or identity theft protection services from the company. According to these Contract Plaintiffs, Equifax's Privacy Policy constituted an agreement between Equifax and those individuals who provided personal information to it, including the Contract Plaintiffs. Equifax's Privacy Policy states that Equifax "restrict[s] access to personally identifiable information ... that is collected about you to only those who have a need to know that information in connection with the purpose for which it is collected and used." Equifax allegedly breached this contract by failing to take steps to protect the Contract Plaintiffs' personal information.
The Defendants argue that the Privacy Policy is not a contract, and even if it is, it did not impose the obligations that the Plaintiffs assert. They argue that the Contract Plaintiffs' purchases were governed by an express contract, with a merger clause, that does not incorporate the Privacy Policy. Under Georgia law, "a merger clause operates as a disclaimer of all representations not made on the face of the contract." The Equifax Product Agreement and Terms of Use, which the Defendants contend was the sole contract entered into between Equifax and the Contract Plaintiffs, provides that "[t]his Agreement constitutes the entire agreement between You and Us regarding the Products and information contained on or acquired through this Site or provided by Us." However, even if this is a valid merger clause, the Equifax Terms of Use go on to provide that these terms are "[s]ubject to the conditions described on the privacy page of this Web Site." Therefore, the Court concludes that the merger clause in the Terms of Use does not preclude the Contract Plaintiffs' claims.
The Contract Plaintiffs argue that they adequately pleaded that the Privacy Policy constituted a contract when they purchased services from Equifax, obtained their credit files, disputed their entries, or more. Courts have concluded that a business's privacy policy can constitute a stand-alone contract. However, the Contract Plaintiffs have not explicitly alleged that they read the Privacy Policy, or otherwise relied upon or were aware of the representations and assurances made in the Privacy Policy when choosing to use the Defendants' services. Without such a showing, the Plaintiffs have failed to establish the essential element of mutual assent. The Plaintiffs also assert that the Product Agreement and Terms of Use incorporated the Privacy Policy. However, even if the Plaintiffs establish that the Privacy Policy was part of this express contract, the terms of the agreement provide that Equifax will not "be liable to any party for any direct, indirect, special or other consequential damages for any use of or reliance upon the information found at this web site." Thus, even assuming the Privacy Policy was incorporated by reference, under the terms of this agreement the Plaintiffs cannot seek damages relating to the information in Equifax's custody.
The Plaintiffs alternatively assert an implied contract claim. However, this claim fails. As discussed above, the Equifax Terms of Use contained a valid merger clause. Such a clause precludes the assertion of an implied contract claim. Furthermore, the Plaintiffs have failed to allege facts establishing the necessary elements of an implied contract claim. The Georgia Court of Appeals has explained that, for both express and implied contract claims, "[t]he concept of a contract requires that the minds of the parties shall meet and accord at the same time, upon the same subject matter, and in the same sense