Damner v. Facebook Incorporated
- Joseph Spero
- 3:20-cv-05177
- U.S. District Court · Northern District of California
- 15
In Damner v. Facebook Inc., Judge Spero granted Facebook’s motion to dismiss claims over a hacked account, allowing amendment.
Leland Damner’s claims against Facebook Inc. were dismissed, with permission to file a second amended complaint addressing the identified pleading deficiencies.
What happened
Leland Damner, representing himself, sued Facebook Inc. after an unknown person allegedly hacked his Facebook account, changed his credentials, and used the account to send messages demanding money. Damner alleged that Facebook failed to restore his access and brought claims under the Stored Communications Act, California law, contract law, negligence, and misrepresentation theories.
Facebook asked the court to dismiss all claims for failure to state a legally sufficient claim. The court concluded that Damner did not allege unauthorized access by Facebook or that Facebook knowingly disclosed his communications. It also found that the Facebook terms did not promise to safeguard his information, released Facebook from responsibility for third-party actions, and defeated or failed to support his state-law claims.
In Damner v. Facebook Inc., Chief Magistrate Judge Joseph C. Spero granted Facebook’s motion and dismissed Damner’s claims, but allowed him to amend his complaint to address the pleading deficiencies. The court required the second amended complaint to be filed by February 1, 2021.
The detailed version
- Damner v. Facebook Incorporated · No. 3:20-cv-05177
- Joseph Spero
- Dec. 31, 2020
Background
Leland Damner, proceeding without a lawyer, alleged that an unknown person hacked his Facebook account on April 20, 2020. According to the first amended complaint, the hacker changed Damner’s password and other credentials, preventing him from accessing or controlling the account, and sent messages to other users demanding money. Damner alleged that he contacted Facebook for help but received no response.
The first amended complaint asserted eight claims: two under the Stored Communications Act, intrusion upon seclusion, negligence, breach of contract, breach of the implied covenant of good faith and fair dealing, violation of California Civil Code section 1798.29, and fraudulent and negligent misrepresentation. Damner alleged that Facebook’s privacy settings and public statements led him to expect that his information would be protected. He also alleged that he had agreed to Facebook’s Statement of Rights and Responsibilities and Privacy Policy.
Rule 12(b)(6) standard
Facebook moved to dismiss under Rule 12(b)(6), which allows dismissal when a complaint does not state a legally sufficient claim. The court considered Facebook’s Statement of Rights and Responsibilities because Damner repeatedly relied on it in his complaint and its authenticity was not disputed. The court accepted factual allegations as true for purposes of the motion but did not accept unsupported legal conclusions.
Stored Communications Act claims
The court dismissed Damner’s claim under 18 U.S.C. § 2701(a). That provision concerns intentional, unauthorized access to a facility through which electronic communications services are provided. Damner alleged that Facebook refused to take steps to restore his account, but he did not allege that Facebook itself accessed the account without authorization. The court also concluded that the statutory exception for conduct authorized by the communications-service provider applied to Facebook’s alleged actions or inaction concerning the account.
The court also dismissed the claim under 18 U.S.C. § 2702(a), which prohibits certain knowing disclosures of stored communications or subscriber information. The court concluded that Damner had not alleged facts showing that Facebook knew with substantial certainty that its alleged failure to protect the account or restore access would result in a third-party hacker disclosing his communications. The court stated that failing to prevent a data breach, without more, does not establish a knowing disclosure under that provision.
State-law claims
The intrusion-on-seclusion claim failed because Damner did not allege that Facebook itself intentionally intruded into a private place, conversation, or matter. The court also concluded that Damner could not base the claim on the hacker’s conduct because the Statement of Rights and Responsibilities released Facebook from claims connected to third-party actions.
The negligence claim failed because the Statement of Rights and Responsibilities contradicted Damner’s allegation that Facebook owed him a duty to keep his information safe. The court found that the document expressly disclaimed such a duty.
The breach-of-contract claim failed because Damner did not identify a specific contractual provision that Facebook breached. The court explained that the provisions Damner quoted said Facebook would do its best to keep the service safe but could not guarantee safety, provided the service as is, and disclaimed responsibility for third-party actions. Read in full, those provisions did not promise to safeguard Damner’s private information.
The claim for breach of the implied covenant of good faith and fair dealing also failed. The court explained that this implied duty cannot create substantive obligations beyond the contract’s specific terms. Because Damner did not identify a contractual obligation requiring Facebook to keep the service safe or help recover his account, the claim was insufficient.
The claim under California Civil Code section 1798.29 failed as a matter of law because the provision applies to state agencies, and Facebook is not a state agency.
The fraudulent and negligent misrepresentation claims failed because Damner did not plausibly allege a misleading statement that his privacy would be protected. The only specific statement he identified was attributed to Facebook CEO Mark Zuckerberg, who allegedly said that users share content because they know their privacy will be protected. The court found that statement too vague to constitute a representation of material fact. The court also concluded that Damner had not alleged reasonable reliance in light of the warnings in the Statement of Rights and Responsibilities, including its statements that Facebook did not guarantee safety and was not responsible for third-party actions. The court noted that fraudulent misrepresentation claims are subject to a heightened requirement to plead the circumstances of fraud with particularity.
Disposition
Chief Magistrate Judge Joseph C. Spero granted Facebook’s motion to dismiss and dismissed Damner’s claims. In light of Damner’s status as a self-represented litigant, the court allowed him to amend his complaint to address the pleading deficiencies in his existing claims. The court ordered that a second amended complaint be filed no later than February 1, 2021.
Read the full 15-page opinion on CourtListener, the free public archive maintained by the Free Law Project.