Do you collect, store and use client and prospect data as part of your business? If so, you must know and follow the rules to keep your business safe from an expensive, unnecessary lawsuit.

Data breaches involving retailers and Internet services are common these days. Naturally, litigation has followed. Breaches involving such notable companies as Target, J.P. Morgan, Home Depot, and Sony have resulted in federal lawsuits claiming that the theft or exposure of private information caused harm to those whose information was compromised.

Federal courts dismissed early data breach cases, finding a lack of standing. This means that the courts found that the plaintiffs who filed suit had suffered no injury to warrant a lawsuit, as required by Article III of the U.S. Constitution.

In later years, however, the tide started to turn in the other direction when, in 2007, the Seventh Circuit Court of Appeals found that a threat of future harm could meet the injury requirement. The Ninth Circuit followed that lead in a case against Starbucks in 2010.

In 2013, the U.S. Supreme Court clarified the standard, ruling that threatened injury must be “certainly impending” to constitute an injury sufficient to support a lawsuit.

Since the Supreme Court’s decision, federal courts have struggled to define the level of necessary injury to support a valid data breach claim. In the Seventh Circuit, cases against Barnes & Noble and Neiman Marcus were both dismissed for lack of standing. The Ninth Circuit, however, did not abandon its position that a threat of future harm could meet the injury-in-fact requirement. In a case against Sony, the U.S. District Court for the Southern District of California found that the allegations of Sony’s collection and subsequent disclosure of personal information was sufficient to establish standing.

Most recently, in July 2015, the Seventh Circuit came full circle when it reinstated the previously dismissed class action against Neiman Marcus. In doing so, the appeal court held that there was a non-speculative, substantial risk of future harm.

What does this mean for you and your business? It means that you must follow established industry standards relating to the collection, use, and storage of data.

We can help you protect the confidentiality, integrity, and accessibility of data you collect. Make an appointment today to discuss any questions you have about data breach avoidance, or schedule a Business Audit Session, which includes employment structuring, financial, and tax systems you need for your business.

Copyright © 2020 Jiah Kim & Associates, P.C. All rights reserved.
Unauthorized reproduction is illegal.
Note: The content of this site belongs to the authors, and the content is protected by United States copyright laws. When copying part or all of the contents of this site (including reprinting on other homepages or print media, including copying in electronic files), permission of the copyright holder is required regardless of commercial purposes. Source must be specified. Unauthorized use of the content of this site without following these steps may be subject to penalties under US copyright law, and as a registered copyright holder, we can take legal action to compensate for legal damages.

Subscribe to our newsletter to receive more helpful tips on entrepreneurship and protecting your family and asset.
  • This field is for validation purposes and should be left unchanged.