Mealey's Data Privacy

  • August 19, 2024

    After Jarkesy, FTC Seeks Dismissal Of Meta Claims Over Consent Order Changes

    WASHINGTON, D.C. — The Federal Trade Commission and its three commissioners in their official capacities (FTC, collectively) filed in a federal court in the District of Columbia a renewed motion to dismiss due process, Article II of the U.S. Constitution and nondelegation claims by Meta Platforms Inc. (formerly Facebook Inc.), following the U.S. Supreme Court ruling in SEC v. Jarkesy and arguing that that opinion “has no bearing on” the claims in which Meta challenges the FTC’s revision of a 2020 $5 billion consent order that settled a privacy investigation.

  • August 16, 2024

    Enzo Biochem Pays $4.5M To 3 States After Testing Lab Ransomware Attack

    Enzo Biochem Inc. and subsidiary Enzo Clinical Labs Inc. (collectively, Enzo) have agreed to pay $4.5 million to New York, New Jersey and Connecticut to settle attorney general investigations into an April 2023 ransomware attack, according to a company regulatory filing and the state prosecutors’ offices.

  • August 16, 2024

    Class Action Under Utah Data Privacy Law Survives Retailer’s Dismissal Bid

    SALT LAKE CITY — Finding that consumer plaintiffs have standing and have adequately alleged that a retailer violated Utah’s Notice of Intent to Sell Nonpublic Personal Information Act (NISNPIA) by disclosing their private purchase information to third parties, a federal judge in Utah denied the retailer’s motion to dismiss.

  • August 15, 2024

    Magistrate Approves Fees In Data Breach Case Despite Initial, Inflated Calculation

    BROOKLYN, N.Y. — A federal magistrate judge in New York has granted a plaintiffs’ motion for attorney fees and costs following a $626,985.58 settlement in litigation over a data breach, ruling that although the plaintiffs’ initial calculation was “inflated,” the fees sought were “reasonable” based on other factors including the value of the multiplier applied to a recalculated amount of hours and billing rates, often referred as a “lodestar.”

  • August 14, 2024

    Data Breach Class Complaint Against Restaurant Group Sent Back To State Court

    LOS ANGELES — A putative class complaint accusing Panda Restaurant Group Inc. of failing to have sufficient measures in place to protect customers’ personal data belongs in state court, a federal judge in California ruled, opining that even though the data breach affected the operator of more than 2,000 restaurants in 30 states, the plaintiff is free to limited his proposed class to California customers.

  • August 13, 2024

    Planned Parenthood’s $6M Data Breach Class Settlement Granted Conditional Approval

    LOS ANGELES — A California judge conditionally granted final approval of a $6 million settlement to be paid by Planned Parenthood Los Angeles (PPLA) to end a consolidated class complaint accusing the reproductive health care provider of failing to protect patients’ personally identifiable information and protected health information from being accessed and stolen.

  • August 13, 2024

    Federal Judge Dismisses 1 CGL Insurer From Coverage Suit Over BIPA Violation Claim

    CHICAGO — Per the parties’ stipulation, a federal judge in Illinois on Aug. 12 dismissed without prejudice the claims and counterclaims between an insured and one of its commercial general liability insurers in the insured’s lawsuit seeking a declaration as to coverage for an underlying putative class lawsuit alleging that it violated the Illinois Biometric Privacy Act (BIPA) by using biometric time clocks to track employee working hours.

  • August 12, 2024

    Facebook To High Court: Risk Disclosure Statements Weren’t Misleading

    WASHINGTON, D.C. — The social media giant formerly known as Facebook Inc. told the U.S. Supreme Court in an Aug. 9 brief that the Ninth Circuit U.S. Court of Appeals erred when it held that the company issued misleading statements about the risk of potential misuse of user data because the company was aware that it had already occurred; Facebook argues that it disclosed all information required under federal securities laws.

  • August 09, 2024

    Judge: Retailer Doesn’t Show Software Company’s Negligence For Data Breach

    NEWARK, N.J. — A federal judge in New Jersey said an online retailer’s breach of contract claims against an e-commerce software company stemming from a data breach survive the software company’s motion to dismiss, but the judge said the retailer failed to substantiate its negligence claims because it did not show it was owed a duty of reasonable care beyond what was included in the contract.

  • August 09, 2024

    Judge: Biometric Data Claims Lacking In Illinois Suit Over AI Image Creation App

    CHICAGO — A man’s mere belief that his photographs and other biometric information are included in datasets used to train a third-party artificial intelligence that powers an imaging rendering application does not state a claim, and the court lacks personal jurisdiction, a federal judge in Illinois said in dismissing the case.

  • August 09, 2024

    TikTok Data Collection Claims Will Move Forward In California Federal Court

    LOS ANGELES — A man who accessed an educational website that allegedly collected his personal information through software created by TikTok properly stated his data privacy claims against the website’s owner under California law, a California federal judge found in denying the owner’s motion to dismiss.

  • August 09, 2024

    California Appeals Court: Minor Established Privacy Claims In Data Breach Suit

    VENTURA, Calif. — A California appeals panel reversed a lower court’s decision to sustain a demurrer without leave to amend a putative class complaint brought by an 11-year-old who said an educational consulting company did not do enough to prevent his medical information from being accessed in a data breach, with the panel holding that the company is subject to two state data privacy acts.

  • August 07, 2024

    $9.39M White Castle Finger Scan Class Settlement Granted Final Approval

    CHICAGO — A federal judge in Illinois granted final approval to a $9,394,440 settlement to be paid by White Castle System Inc. to end a class complaint by an employee who alleged that the fast food company’s finger scan policy violated the  Illinois’ Biometric Information Privacy Act (BIPA).

  • August 07, 2024

    Memo On Student-Workers’ Rights Under NLRA, Privacy Rights Issued By NLRB

    WASHINGTON, D.C. — The National Labor Relations Board general counsel issued a memo on Aug. 6 clarifying the obligations of colleges and universities under the National Labor Relations Act (NLRA) and the Family Educational Rights and Privacy Act of 1974 (FERPA) regarding the disclosure of student-worker information to labor unions and students’ privacy rights.

  • August 06, 2024

    Officials: High Court Case Claiming Texas Drone Law Is Unconstitutional Fails

    WASHINGTON, D.C. — Officials in a Texas municipality have filed an opposition brief in the U.S. Supreme Court arguing that a petition for certiorari filed by a journalist and a photographer association, claiming that a Texas law that curbs the use of drones for aerial photography violates the First Amendment to the U.S. Constitution, should be denied because a lower court’s judgment, “although its reasoning is imperfect,” does not merit the Supreme Court’s attention.

  • August 05, 2024

    DOJ Complaint Accuses ByteDance, TikTok Of Violating Children’s Privacy Laws

    LOS ANGELES — The United States filed a complaint Aug. 2 in a federal court in California accusing TikTok Inc., ByteDance Ltd. and their affiliates of violating the Children’s Online Privacy Protection Act (COPPA) and its implementing regulations as well as a 2019 court order by knowingly permitting children to create regular rather than “Kids Mode” TikTok accounts and to create, view and share videos and messages with adults.

  • August 05, 2024

    Former Employees Say Philadelphia Inquirer Liable For Breach Of Records

    PHILADELPHIA — In a consolidated putative class complaint filed in a Pennsylvania federal court, three employees or former employees of the Philadelphia Inquirer LLC bring claims against the newspaper, saying it is liable for damages caused by a data breach the newspaper did not disclose to subscribers and employees for nearly a year.

  • August 02, 2024

    Data Breach Class Suits Against Health Care Provider, IT Vendor Consolidated

    SCRANTON, Pa. — A federal judge in Pennsylvania has consolidated nine putative class actions against Geisinger Health and its third-party information technology services vendor stemming from the Nov. 29 discovery that a former employee of the vendor had accessed and acquired the personally identifiable information (PII) and personal health information (PHI) of individuals who received health care from the provider.

  • August 01, 2024

    Ohio Panel Affirms Discovery Ruling For Estate Administrator In Wrongful Death Case

    CLEVELAND — Finding that the operators of a group residential facility for children failed to establish that information and documents sought by the administrator of the estate of a boy who died while under their care falls under the Health Insurance Portability and Accountability Act (HIPAA) or “is subject to any privilege such that they would be protected from discovery,” an Ohio appellate court affirmed a lower court’s ruling granting the administrator’s motion to compel.

  • July 31, 2024

    Judge Nixes Claim That Facial Recognition In Samsung App Violates Data Privacy Law

    CHICAGO — A federal judge in Illinois has granted a motion to dismiss a class action lawsuit against Samsung Electronics America Inc. brought by individuals who allege that facial recognition technology in Samsung’s Gallery photo application violates the Illinois Biometric Information Privacy Act (BIPA), ruling that the allegations are “insufficient” to show that the data constitute a biometric identifier or biometric information.

  • July 31, 2024

    8th Circuit Reverses Attorney Fees Awarded In T-Mobile Data Breach Settlement

    ST. LOUIS — A trial court abused its discretion in striking one of two objections to the $78.75 million attorney fees portion of a $350 million data breach class settlement between customers and T-Mobile US Inc., an Eighth Circuit U.S. Court of Appeals panel ruled, opining that the fees awarded were “unreasonable.”

  • July 30, 2024

    Meta Will Pay $1.4 Billion To Settle Texas’ Biometric Data Privacy Lawsuit

    MARSHALL, Texas — Meta Platforms Inc., formerly known as Facebook Inc., will pay $1.4 billion to end claims by Texas that it captured and used the personal biometric data of millions of state residents, according to an agreed final judgment filed in a Texas court on July 30.

  • July 29, 2024

    Health Care Providers Sue, Allege Health Care Industry ‘Immobilized’ By Data Breach

    MINNEAPOLIS — Health care providers in 21 states filed a class complaint in a federal court in Minnesota against a health insurer subsidiary that they say touches “one-in-three U.S. patient records” after a data breach allegedly carried out by hackers known as “ALPHV/Blackcat” accessed an unprotected network using an employee’s credentials and “wreaked havoc on the healthcare industry.”

  • July 25, 2024

    California Woman Says Retailer Used AI Company To Illegally Analyze Calls

    VENTURA, Calif. — A clothing retailer uses a third-party artificial intelligence company to intercept and analyze customer calls in violation of California law, a woman alleges in a class action filed in California state court.

  • July 24, 2024

    Converse Granted Summary Judgment In Class Suit Over Privacy Of Chat Feature

    LOS ANGELES — A Converse Inc. website user who sued the footwear and clothing company alleging that its website’s chat features recorded users’ messages without consent failed to establish any violation of California’s Invasion of Privacy Act (CIPA), including allegations that Converse aided and abetted third-party vendor Salesforce Inc., a federal judge in California ruled granting the retailer’s motion for summary judgment.

Can't find the article you're looking for? Click here to search the Mealey's Data Privacy archive.