Baton v. Ledger SAS
- Edward Chen
- 3:21-cv-02470
- U.S. District Court · Northern District of California
- 23
In Baton v. Ledger SAS, Judge Chen dismissed the data-breach case with prejudice for lack of personal jurisdiction and denied jurisdictional discovery.
The plaintiffs’ data-breach claims against Shopify USA, Shopify, Inc., and Ledger SAS were dismissed with prejudice; the court denied the plaintiffs’ request for jurisdictional discovery and closed the case.
What happened
Baton v. Ledger SAS was a proposed class action by customers who alleged that data breaches exposed their personal information and led to phishing scams, cyberattacks, ransom demands, and threats.
The court ruled that it lacked authority over Shopify USA, Shopify, Inc., and Ledger SAS because the defendants did not have the required connections to California. It granted each defendant’s motion to dismiss, denied the plaintiffs’ request for jurisdictional discovery, and dismissed the case with prejudice.
Judge Edward Chen concluded that further discovery would be speculative and that changing the complaint would be futile. He directed the clerk to enter judgment and close the case.
The detailed version
- Baton v. Ledger SAS · No. 3:21-cv-02470
- Edward Chen
- Nov. 9, 2021
Background
The plaintiffs were customers who bought Ledger hardware wallets through Ledger SAS’s online store, which operated on Shopify, Inc.’s platform. They brought a proposed class action after alleging that two security incidents exposed customer contact information. The alleged data included names, email addresses, postal addresses, and telephone numbers. The plaintiffs alleged that the breaches led to phishing scams, cyberattacks, ransom demands, and threats.
The plaintiffs asserted claims including negligence, negligence per se, requests for injunctive relief, and claims under California, Georgia, and New York consumer-protection laws. The remaining defendants were Shopify USA, Shopify, Inc., and Ledger SAS. Ledger Technologies had previously been voluntarily dismissed from the case.
Personal jurisdiction
The defendants moved to dismiss under Federal Rule of Civil Procedure 12(b)(2), which allows dismissal when a court lacks personal jurisdiction over a defendant. The court explained that the plaintiffs had to make a preliminary showing that jurisdiction was proper and that California’s jurisdictional law reaches as far as federal due-process requirements allow.
The court rejected general jurisdiction over Shopify USA. General jurisdiction allows a defendant to be sued in the forum for any claim and generally requires contacts so continuous and systematic that the company is essentially at home there. The court noted that Shopify USA was incorporated in Delaware and had its principal place of business in Ottawa, Canada, when the case was filed. The plaintiffs’ evidence that Shopify USA had previously listed San Francisco as its principal place of business did not establish general jurisdiction at the time of filing. The court also found that the plaintiffs had not shown that Shopify USA’s California contacts made this an exceptional case for general jurisdiction.
The court also rejected specific jurisdiction over Shopify USA and Shopify, Inc. Specific jurisdiction requires the defendant to purposefully direct conduct toward California, requires the claims to arise from that conduct, and requires exercising jurisdiction to be reasonable. The court found that Shopify, Inc.’s nationwide services and its role in providing software to Ledger did not show that Shopify, Inc. itself purposefully directed conduct toward California. Ledger’s California-related conduct could not be attributed to Shopify, Inc. merely because Ledger used Shopify’s services.
The court further found that the evidence did not show that Shopify, Inc. carried out the breach in California or provided access to the data there. The alleged contractors involved in the breach were located in the Philippines, and the court found no evidence that Shopify, Inc. made its notification decisions in California or specifically targeted California by failing to notify affected people.
As to Ledger SAS, the court found that selling hardware wallets through an internationally accessible website, including to California customers, was not enough to show that Ledger expressly aimed its conduct at California. The plaintiffs did not show that Ledger’s website, advertising, or sales activity had a California-specific focus. The court also found that the alleged injury arose from the data breach, not from the sales themselves, and that the plaintiffs had not connected the breach or Ledger’s later conduct to California in the manner required for specific jurisdiction.
Jurisdictional discovery and disposition
The plaintiffs asked for discovery about the defendants’ employees, contractors, data practices, advertising, sales, and business activities. The court denied that request because it was based on speculation and the evidence already before the court contradicted or did not support the proposed jurisdictional theories. The court concluded that further discovery would be unwarranted and that amending the complaint to assert personal jurisdiction would be futile.
The court granted each of Shopify USA’s, Shopify, Inc.’s, and Ledger SAS’s motions to dismiss. It denied the plaintiffs’ request for jurisdictional discovery and dismissed the case with prejudice. The court directed the clerk to enter judgment and close the case.
Read the full 23-page opinion on CourtListener, the free public archive maintained by the Free Law Project.