Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Substantive rulingFiled Nov. 13, 2024

TrustLabs, Inc. v. An

Judge
Charles Breyer
Docket
3:21-cv-02606
Court
U.S. District Court · Northern District of California
Pages
10
Summary JudgmentCivil Procedure
In one sentence

In TrustLabs v. An, Judge Breyer partly granted TrustLabs’s summary-judgment motion, ruling on California liability but leaving federal claims and damages unresolved.

Who this affects

TrustLabs obtained a ruling establishing An’s liability under the California computer-fraud statute. An prevailed on the request for summary judgment as to the two federal claims and punitive damages only in the sense that those issues were not resolved against him at this stage; those issues remain unresolved.

What happened

TrustLabs, Inc. v. Daniel Jaiyong An concerns TrustLabs’s claims against its former CEO after he deleted the company’s Slack account. TrustLabs sued under two federal computer-communications laws and a California computer-fraud law.

An admitted deleting the account, which temporarily disrupted TrustLabs’s communications. TrustLabs argued that An lacked permission or authorization to do so, while An disputed when his authority ended and whether he had agreed to resign.

Judge Charles R. Breyer granted summary adjudication to TrustLabs on An’s liability under the California statute. He denied summary adjudication on liability under the two federal statutes and denied it on punitive damages for all claims, leaving those issues unresolved.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
TrustLabs, Inc. v. An · No. 3:21-cv-02606
Judge
Charles Breyer
Date
Nov. 13, 2024

Background

Daniel Jaiyong An was TrustLabs, Inc.’s cofounder and former chief executive officer. Shortly before TrustLabs removed him, An deleted the company’s Slack account. TrustLabs employees frequently used Slack to communicate, and the company described it as critical infrastructure. TrustLabs regained access approximately 12 hours later, after business activity had substantially slowed.

TrustLabs sued An under the federal Computer Fraud and Abuse Act, the federal Stored Communications Act, and California’s Comprehensive Computer Data Access and Fraud Act. It also sought punitive damages. TrustLabs moved for summary judgment, which asks whether the evidence shows that no important factual dispute requires a trial and that the moving party is entitled to judgment under the law.

Court’s Analysis

The court found that TrustLabs established more than $6,000 in damages from deleting the Slack account. That amount satisfied the Computer Fraud and Abuse Act’s damages threshold, and An did not provide evidence creating a meaningful dispute about the amount.

An conceded that he deleted the Slack account, and the court concluded that the conduct potentially fell within all three statutes. The central dispute for the federal claims was whether An acted without authorization or beyond his authorization. TrustLabs relied mainly on an email stating that An had to resign by 4 p.m. or the company would take steps to replace the board and hire a new chief executive. The court found that the email did not conclusively establish that An’s authority ended at 4 p.m. It could have meant that the company would begin another process to terminate him, and An was not formally removed until after he deleted the account. An also denied agreeing to resign, creating a credibility dispute that could not be resolved on summary judgment.

The California statute uses a broader “without permission” standard and includes a defense for conduct within the scope of lawful employment when reasonably necessary to perform the employee’s work assignment. The court found that deleting Slack denied access to the company and its legitimate users. It also found that An identified no evidence showing that deleting Slack was reasonably necessary for his work. The court therefore granted summary adjudication against An on liability under the California statute.

As to punitive damages, TrustLabs argued that An acted intentionally and maliciously, relying in part on alleged post-termination attempts to access company accounts and communications with a client. An disputed that he acted maliciously. The court found a genuine dispute of material fact about whether punitive damages were appropriate and denied TrustLabs’s motion on punitive damages for all three claims.

Ruling

The court vacated the scheduled hearing. It granted summary adjudication in favor of TrustLabs and against An on liability under California’s Comprehensive Computer Data Access and Fraud Act. It denied summary adjudication on liability under the Computer Fraud and Abuse Act and the Stored Communications Act, and denied summary adjudication as to damages on all claims. The court also denied An’s motion to file supplemental authority.

The authoritative version

Read the full 10-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.