Kapil v. Apple Inc.
- Virginia Demarchi
- 5:24-cv-09304
- U.S. District Court · Northern District of California
- 4
Counsel of record per CourtListener. Firm names are approximate and have been consolidated across spelling variants.
In Kapil v. Apple, Judge DeMarchi adopted plaintiffs’ data-security proposal with one modification and Apple’s Highly Confidential access provision.
Sandeep Kapil and the other plaintiffs, Apple Inc., and the parties’ counsel and receiving parties handling protected discovery materials.
What happened
In Sandeep Kapil, et al. v. Apple Inc., the parties asked the court to resolve two disagreements over a proposed protective order for discovery. The plaintiffs seek damages from Apple over cryptocurrency scams they say followed their use of cryptocurrency applications from Apple’s App Store.
The first dispute concerned what security standards a party receiving protected information must follow. Apple wanted compliance with at least one listed cybersecurity standard, while the plaintiffs proposed different security requirements. The second dispute concerned whether the named plaintiffs could receive all discovery labeled “Highly Confidential.”
Judge Virginia K. DeMarchi adopted the plaintiffs’ data-security provisions with one modification and adopted Apple’s provision limiting access to Highly Confidential material. The parties must file a proposed protective order that follows the court’s decision.
The detailed version
- Kapil v. Apple Inc. · No. 5:24-cv-09304
- Virginia Demarchi
- Aug. 13, 2026
Background
The plaintiffs and Apple asked the court to resolve a discovery dispute involving two provisions of a proposed protective order. The court held a hearing on August 11, 2026.
The case concerns cryptocurrency scams to which the plaintiffs say they fell victim after downloading and using cryptocurrency applications from Apple’s App Store. The opinion states that the plaintiffs seek monetary damages for negligent misrepresentation and violation of the California Consumer Legal Remedies Act.
Data Security Provision
The parties agreed that a receiving party must maintain an information security management system to protect discovery materials. They disagreed about whether the receiving party also had to comply with at least one of several specified security standards, including ISO 27001, NIST 800-53, or the Center for Internet Security Critical Security Controls.
The court was not persuaded that Apple’s requested standards were necessary for the blanket protective order. It relied in part on plaintiffs’ counsel’s representation that the counsel’s law firm already had security measures meeting the plaintiffs’ proposed provision. The court adopted the plaintiffs’ proposed section 11(a), with one modification. The adopted language addresses security safeguards, multi-factor authentication, encryption, court filings, and possible additional measures if source-code production becomes necessary. The court also adopted the plaintiffs’ proposal for section 11(b).
The court stated that its decision on section 11(a) did not prevent either party from later seeking additional or different protections for particular protected material.
Access to Highly Confidential Material
The court rejected the proposal that named plaintiffs have access to all discovery Apple designated “Highly Confidential.” It also rejected allowing plaintiffs’ counsel to decide alone whether disclosure to named plaintiffs was reasonably necessary. The court adopted Apple’s proposal for section 9, while allowing plaintiffs to later seek permission to disclose specific Highly Confidential Apple material to the named plaintiffs.
Disposition
The court ordered the parties to file a proposed protective order conforming to its decisions. The order also states that future discovery disputes, including challenges to protected-material designations, are subject to the discovery procedures in Judge DeMarchi’s standing order for civil cases.
Read the full 4-page opinion on CourtListener, the free public archive maintained by the Free Law Project.