Memorandum. Connecticut State Courts Address the Definition of Injury in the Data Breach Context. Introduction. June 22, 2015



Similar documents
Increased Regulatory Focus on Cybersecurity Underscores Need for Public Companies to Review Cybersecurity-Related Disclosures

Memorandum. SEC Charges Former CEO With Using Corporate Funds for Personal Perks Without Disclosure to Investors. Introduction

SEC Institutes Administrative Proceedings Against KPMG For Auditor Independence Violations

SEC Announces Final Rules Implementing The Dodd- Frank Whistleblower Program

Three Federal Courts Dismiss Lawsuits Against Chevedden, Citing Lack of Subject Matter Jurisdiction

April 12, 2013 CFTC SWAP REPORTING RULES

Federal Reserve Issues Regulations for Savings and Loan Holding Companies

FINAL REGULATIONS RELATING TO OPTIONS GRANTED UNDER EMPLOYEE STOCK PURCHASE PLANS

The SEC s New Large Trader Reporting Rule

July 12, See CFTC Fact Sheet available at:

Federal Reserve Proposes Changes to Regulation Z to Implement New Ability-to-Repay Requirement for Residential Mortgage Loans

Global Accounting Firms Caught in the Crossfire as SEC Fails to Reach Agreement with Chinese Regulators on Document Sharing

How To Find Out If The Loss Of The Tapes Is A Personal Injury In A Personal Liability Insurance Policy

Bank Liquidity Requirements: Basel Oversight Committee Endorses Revised Liquidity Standards and Extends Fully Phased-In Compliance to 2019

INTRODUCTION BACKGROUND. September 27, 2010

Reports or Connecticut Appellate Reports, the

California Supreme Court Issues Ruling in Brinker Clarifying Employers Duty to Provide Meal and Rest Breaks to Hourly Employees

June 22, Gerald S. Sachs, Of Counsel Paul Hastings LLP. (202)

Federal Deposit Insurance Corporation Temporary Liquidity Guarantee Program

Mortgage Reform Update: CFPB Issues Final Rule on Residential Mortgage Lending Requirements

Supreme Court Decision Affirming Judicial Right to Review EEOC Actions

This Alert discusses recent decisions relating to the timeliness of a late notice

IN THE SUPREME COURT OF THE STATE OF DELAWARE

OIL AND GAS PRACTICE

c l i e n t m e m o r a n d u m

IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF PENNSYLVANIA. Memorandum and Order

Insurance Law Alert. In This Issue. Delaware Supreme Court Certifies Allocation and Exhaustion Questions to New York Court of Appeals

This Alert discusses recent decisions relating to the consequences of an insurer s

Case 0:05-cv DSD-RLE Document 51 Filed 03/16/2006 Page 1 of 6. UNITED STATES DISTRICT COURT DISTRICT OF MINNESOTA Civil No.

Insurance Coverage In Consumer Class Actions

Reports or Connecticut Appellate Reports, the

Reports or Connecticut Appellate Reports, the

No Filed: IN THE APPELLATE COURT OF ILLINOIS SECOND DISTRICT

IN THE COURT OF COMMON PLEAS FIRST JUDICIAL DISTRICT OF PENNSYLVANIA TRIAL DIVISION CIVIL SECTION

No THIRD DISTRICT A.D., 2009

NOT TO BE PUBLISHED IN THE OFFICIAL REPORTS IN THE COURT OF APPEAL OF THE STATE OF CALIFORNIA SECOND APPELLATE DISTRICT DIVISION TWO

FORC QUARTERLY JOURNAL OF INSURANCE LAW AND REGULATION

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF ARIZONA

States and the federal government have laws, known generically as a

September Edition of Notable Cases and Events in E-Discovery

IN THE CIRCUIT COURT OF THE NINTH JUDICIAL CIRCUIT, IN AND FOR ORANGE COUNTY, FLORIDA

CLASS ACTION. Westlaw Journal. Expert Analysis The State of Coverage Disputes Concerning Advertising And Privacy Claims

Dodd-Frank and Corporate Whistleblower Grants

Case 1:14-cv JEB Document 17 Filed 09/23/14 Page 1 of 8 UNITED STATES DISTRICT COURT FOR THE DISTRICT OF COLUMBIA UNOPPOSED MOTION TO DISMISS

IN THE COURT OF APPEALS OF TENNESSEE AT NASHVILLE December 02, 2014 Session

United States Court of Appeals

How To Defend Yourself In A Lawsuit Against A Car Insurance Policy In Illinois

Present: Carrico, C.J., Compton, Stephenson, Lacy, Keenan, Koontz, JJ., and Whiting, Senior Justice NORTHBROOK PROPERTY AND CASUALTY INSURANCE COMPANY

Second Annual Conference September 16, 2015 to September 18, 2015 Chicago, IL

United States Court of Appeals for the Federal Circuit

This Alert features decisions relating to allocation, the availability of excess coverage

IN THE UNITED STATES DISTRICT COURT FOR THE WESTERN DISTRICT OF OKLAHOMA ORDER

UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF INDIANA EVANSVILLE DIVISION ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) )

New York State Labor Law Amendments Affecting Proof in Pay Discrimination Cases and Employer Policies Concerning Wage Disclosure

IN THE SUPREME COURT OF THE STATE OF MONTANA 2007 MT 267

2:08-cv DPH-PJK Doc # 67 Filed 03/26/13 Pg 1 of 7 Pg ID 2147 UNITED STATES DISTRICT COURT EASTERN DISTRICT OF MICHIGAN SOUTHERN DIVISION

IN THE COURT OF APPEAL OF THE STATE OF CALIFORNIA SECOND APPELLATE DISTRICT DIVISION EIGHT

How To Defend A Claim Against A Client In A Personal Injury Case

Whistleblower Claims: Are You Covered?

This opinion will be unpublished and may not be cited except as provided by Minn. Stat. 480A.08, subd. 3 (2010).

Reports or Connecticut Appellate Reports, the

claiming coverage as an additional insured under an umbrella liability policy it issded tot

Case 2:10-cv JAR Document 98 Filed 05/04/11 Page 1 of 8 IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF KANSAS

Illinois Official Reports

How To Prove That A Person Is Not Responsible For A Cancer

NO IN THE APPELLATE COURT OF ILLINOIS FIFTH DISTRICT

Reverse and Render; Dismiss and Opinion Filed June 19, In The Court of Appeals Fifth District of Texas at Dallas. No.

California s False Claims Act: What it Means for Companies Doing Business with California Governmental Entities

How To Get A Summary Judgment In A Well Service Case In Texas

2015 IL App (1st) U. No IN THE APPELLATE COURT OF ILLINOIS FIRST JUDICIAL DISTRICT

NON-PRECEDENTIAL DECISION - SEE SUPERIOR COURT I.O.P Appeal of: The Buzbee Law Firm No EDA 2014

Retailers in California Face New Scrutiny of Credit Card Transactions in Light of Pineda v. Williams- Sonoma Stores, Inc., 51 Cal.

IN THE COURT OF APPEALS OF INDIANA

In The Court of Appeals Fifth District of Texas at Dallas. No CV

Case 1:09-cv MGC Document 208 Entered on FLSD Docket 06/01/2011 Page 1 of 6 UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF FLORIDA

Securities Litigation

Case 4:14-cv Document 39 Filed in TXSD on 07/08/15 Page 1 of 7 UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF TEXAS HOUSTON DIVISION ORDER

UNITED STATES DISTRICT COURT FOR THE CENTRAL DISTRICT OF CALIFORNIA ) ) ) ) ) ) ) ) ) ) ) )

United States Court of Appeals

****************************************************** The officially released date that appears near the beginning of each opinion is the date the

Summary of Key Cases: Protections Under the Patient Safety and Quality Improvement Act of 2005 (PSQIA)

O R D E R. This insurance coverage dispute came before the Supreme Court on February 2,

Liberty Surplus Ins. Corp. v Burlington Ins. Co NY Slip Op 30564(U) April 14, 2015 Sup Ct, New York County Docket Number: /2012 Judge:

PERSONAL INJURY ISSUES PRESENTED TO THE TRIAL COURT IN PARR V. ARUBA PETROLEUM i. Charles W. Sartain and Maryann Zaki Gray Reed & McGraw PC

COURT OF APPEAL OF THE STATE OF CALIFORNIA FIFTH APPELLATE DISTRICT. Plaintiff and Respondent, v. Kern County Superior Court

You ve Been Sued, Now What? A Roadmap Through An Employment Lawsuit

DELAWARE SUPREME COURT RULES DIRECTORS OF A CORPORATION IN THE ZONE OF INSOLVENCY OWE NO FIDUCIARY DUTIES TO CREDITORS

****************************************************** The officially released date that appears near the beginning of each opinion is the date the

STEPHEN S. EDWARDS, individually and as Trustee of the Super Trust Fund, u/t/d June 15, 2001, Plaintiff/Appellant,

IN THE UNITED STATES COURT OF APPEALS FOR THE ELEVENTH CIRCUIT. No Non-Argument Calendar. D.C. Docket No. 1:13-cv JRH-BKE

Federal Banking Agencies Revamp Guidance on Leveraged Lending

IN THE COURT OF APPEALS OF INDIANA

Reports or Connecticut Appellate Reports, the

Case 1:10-cv NMG Document 38 Filed 06/15/11 Page 1 of 9. United States District Court District of Massachusetts MEMORANDUM & ORDER

A&E Briefings. Indemnification Clauses: Uninsurable Contractual Liability. Structuring risk management solutions

Illinois Official Reports

But For Causation in Defective Drug and Toxic Exposure Cases: California s Form Jury Instruction CACI 430

IN THE APPELLATE COURT OF ILLINOIS FIRST DISTRICT

2014 IL App (5th) U NO IN THE APPELLATE COURT OF ILLINOIS FIFTH DISTRICT

UNITED STATES COURT OF APPEALS FIFTH CIRCUIT. No (Summary Calendar) GLEN R. GURLEY and JEAN E. GURLEY, AMERICAN STATES INSURANCE COMPANY,

Transcription:

Memorandum Connecticut State Courts Address the Definition of Injury in the Data Breach Context June 22, 2015 Introduction Quantifying the degree of harm resulting from a data breach can be an inherently difficult task. Access to sensitive information can be appropriated but not exploited, data can be stolen but not distributed, and sometimes the digital trail goes cold before the fact of a breach can even be confirmed at all. Establishing an evidentiary threshold for harm at which notification requirements are triggered, therefore, can prove unwieldy. As a result, legislative and regulatory regimes generally require companies to mitigate against the possibility of harm by notifying potential victims before any harm is evidenced. 1 The Connecticut courts were recently called upon to address whether a data breach constituted personal injury under a general liability insurance policy where there was no evidence that the stolen data had ever been accessed by a third party. Last month, the Connecticut Supreme Court affirmed an appellate court decision holding that a breach alone is not personal injury and, additionally, that triggering a notification statute is not a substitute for a personal injury. This holding will help to inform the ever more frequent discussions over what constitutes injury in the data breach context. 1 The bulk of these requirements are contained in state statutes on the subject, the first of which is California s Notice of Security Breach Act, which was enacted in 2002 (CAL. CIV. CODE 1798.29 (2013)). Similar bills addressing notification have been proposed in Congress, most notably the Data Security and Breach Notification Act of 2015 (H.R.1770, 114 th Cong. (2015); see also, e.g., S. 1535, 112 th Cong. (2011)), and President Obama expressed support for a federal law requiring companies to notify victims of breach in his 2015 State of the Union Address (The State of the Union Address (2015)).

2 Recall Total Information Management v. Federal Insurance Company 2 A. The Facts In 2003, IBM entered into a data record storage agreement with Recall Total Information Management, Inc. ( Recall ), which subcontracted with Executive Logistics, Inc. ( Executive Logistics ) for transportation of those records. Four years into the contract, 130 data tapes fell out of one of Executive Logistics vans near a highway exit and were taken by an unknown person. The tapes contained employment-related data for over 500,000 past and present employees of IBM, including contact information, birthdates, and social security numbers. However, the tapes were not readable by a conventional computer and, though they were never recovered, there is no evidence that they were ever accessed after disappearing from the roadside. IBM promptly notified the persons whose information was contained on the tapes and provided each with one year s worth of credit monitoring services. These efforts cost IBM $6 million, which was reimbursed by Recall after a short negotiation. Executive Logistics, which had general liability and umbrella insurance policies in place with Federal Insurance Company (the Insurer ) naming Recall as an additional insured, gave Recall a promissory note for $6 million and submitted a claim to the Insurer, which was denied. Recall and Executive Logistics filed suit against the Insurer in Connecticut Superior Court for the denial of coverage alleging, among other things, breach of contract based upon obligations of the Insurer under the policies to defend Recall and Executive Logistics against suits and to reimburse them for covered personal injuries. Though these policies had no explicit cybersecurity or data breach-related provisions and though they explicitly carved out losses relating to intangible property, Recall and Executive Logistics argued that the damages suffered in the wake of the breach fit within the general liability coverage in the policies. B. The Court s Ruling The trial court had granted summary judgment for the Insurer on three issues: (1) the Insurer had no duty to defend Executive Logistics because the policy only covered suits, and the negotiations took place in the absence of such a suit, (2) the plaintiffs losses were not covered under the property damage provision because the data was intangible property, which was carved out of the policy, and (3) the plaintiffs losses were not covered under the personal injury provision of the policy because there had been no injury to a person. After filing a failed motion for rehearing, the plaintiffs appealed to the Connecticut Appellate Court (the Court ), which ultimately affirmed the trial court s grant of summary judgment. The Court s holding can be broken down into two sub-parts. 3 First, that the loss of the tapes did not constitute personal injury as 2 Recall Total Info. Mgmt., Inc. v. Fed. Ins. Co., 83 A.2d 664 (Conn. App. Ct. 2014), aff d per curiam, SC 19291, 2015 WL 2371957 (Conn. May 26, 2015). 3 With regard to the duty to defend, the Court held that, [o]n the basis of a plain reading of the policy, we cannot conclude that the term suit or phrase other dispute resolution proceeding was meant to encompass the mere negotiations that took place in this case. (Recall at 671).

3 defined in the policy, and second, that triggering the remedial provisions of various state privacy laws did not constitute personal injury per se. 1. Publication as Injury The plaintiffs argued that the loss of tapes fell within the policy s personal injury coverage because the policy s definition of personal injury included certain injury caused by the publication of material that... violates a person s right to privacy. Plaintiffs based their argument on the definition of publication imported from the defamation context roughly translating to dissemination to a third party and sought to analogize their circumstances to defamation per se (in which actual injury does not typically need to be proven). 4 The Court rejected that analogy, declaring that, [a]s the complaint and affidavits are entirely devoid of facts suggesting that the personal information actually was accessed, there has been no publication. 2. Notification Requirement as Injury The second part of the Court s holding dealt specifically with the argument that, if per se harm did not result from the sort of publication at issue in this case, then the triggering of notice provisions of certain state statutes constitutes harm instead. Once again, the Court rejected the argument and found no evidence of harm: These notification statutes simply do not address or otherwise provide for compensation from identity theft or the increased risk thereof, they merely require notification to an affected person so that he may protect himself from potential harm. Accordingly, merely triggering a notification statute is not a substitute for a personal injury. Taken with the holding on publication, the court s ruling on notification essentially closes the door on the argument that, absent evidence of actual harm or a statute explicitly foregoing such evidence, an injury has necessarily taken place as a result of a data breach alone. Recall in the Context of the Current Legal Landscape The opinion s treatment of what constitutes injury (and the concomitant requirement of access) supports the current jurisprudence on the necessity of injury in establishing standing in data breach cases. Specifically, as in other contexts, standing in a data breach case requires injury that is concrete, particularized, and actual or imminent. 5 The Court in Recall was presented with the opportunity to lighten 4 See generally Restatement (Second) of Torts 570 (2013). 5 Lujan v. Defenders of Wildlife, 504 U.S. 555, 560-61 (1992).

4 the burden on plaintiffs to show such injury by allowing them to use publication or the triggering of notification statutes as per se injury. By focusing on access in this particular factual circumstance, the Court rejects that opportunity in favor of consistency with existing case law addressing harm. Indeed, this approach is the one used in the largest data breach cases of recent memory, both to confirm standing where identifiable harms exist 6 and to deny it where the harms are merely theoretical. 7 Without citing any of these cases or explicitly invoking the law of standing, the Court in Recall has required a showing of harm consistent with the existing case law that addresses data breaches in contexts other than insurance disputes. Given that cybersecurity law is in its infancy, the landscape may shift. Companies should review their cybersecurity-related policies (insurance and otherwise) and engage counsel early in the event of any breach to ensure compliance with and utilization of the latest case law on the subject. If you have any questions or would like additional information, please do not hesitate to contact any member of the Firm s Privacy and Cybersecurity Practice. The contents of this publication are for informational purposes only. Neither this publication nor the lawyers who authored it are rendering legal or other professional advice or opinions on specific facts or matters, nor does the distribution of this publication to any person constitute the establishment of an attorney-client relationship. assumes no liability in connection with the use of this publication. Please contact your relationship partner if we can be of assistance regarding these important developments. The names and office locations of all of our partners, as well as our recent memoranda, can be obtained from our website, www.simpsonthacher.com.. 6 In re Target Corp. Customer Data Security Breach Litig., 2014 WL 7192478 (D. Minn. December 18, 2014). 7 In re Barnes & Noble Pin Pad Litig., 2013 WL 4759588 (N.D. Ill. Sept. 3, 2013).

Memorandum November 21, 2014 5 UNITED STATES New York 425 Lexington Avenue New York, NY 10017 +1-212-455-2000 Houston 600 Travis Street, Suite 5400 Houston, TX 77002 +1-713-821-5650 Los Angeles 1999 Avenue of the Stars Los Angeles, CA 90067 +1-310-407-7500 Palo Alto 2475 Hanover Street Palo Alto, CA 94304 +1-650-251-5000 Washington, D.C. 1155 F Street, N.W. Washington, D.C. 20004 +1-202-636-5500 EUROPE London CityPoint One Ropemaker Street London EC2Y 9HU England +44-(0)20-7275-6500 ASIA Beijing 3919 China World Tower 1 Jian Guo Men Wai Avenue Beijing 100004 China +86-10-5965-2999 Hong Kong ICBC Tower 3 Garden Road, Central Hong Kong +852-2514-7600 Seoul West Tower, Mirae Asset Center 1 26 Eulji-ro 5-gil, Jung-gu Seoul 100-210 Korea +82-2-6030-3800 Tokyo Ark Hills Sengokuyama Mori Tower 9-10, Roppongi 1-Chome Minato-Ku, Tokyo 106-0032 Japan +81-3-5562-6200 SOUTH AMERICA São Paulo Av. Presidente Juscelino Kubitschek, 1455 São Paulo, SP 04543-011 Brazil +55-11-3546-1000