Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Nov. 8, 2021

Baton v. Ledger SAS

Judge
Edward Chen
Docket
3:21-cv-02470
Court
U.S. District Court · Northern District of California
Pages
22
Civil ProcedureMotion to DismissDiscovery
In one sentence

Baton v. Ledger SAS: Judge Chen dismissed the case with prejudice after finding no personal jurisdiction over defendants and denying jurisdictional discovery.

Who this affects

The plaintiffs and proposed class members whose claims against Shopify USA, Shopify, Inc., and Ledger SAS were dismissed with prejudice; the defendants were no longer required to defend the case in this court.

What happened

In Baton v. Ledger SAS, customers who bought hardware wallets sued Ledger and Shopify after data breaches allegedly exposed their personal information and led to phishing, cyberattacks, ransom demands, and threats.

The court considered whether California could exercise personal jurisdiction over Shopify USA, Shopify, Inc., and Ledger. It concluded that the defendants’ contacts with California did not meet the legal requirements for general or specific jurisdiction. The court also found that the requested jurisdictional discovery was based on speculation.

Judge Edward M. Chen granted each defendant’s motion to dismiss, denied the plaintiffs’ request for jurisdictional discovery, and dismissed the case with prejudice because amending the complaint to establish jurisdiction would be futile.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Baton v. Ledger SAS · No. 3:21-cv-02470
Judge
Edward Chen
Date
Nov. 8, 2021

Background

The plaintiffs were customers who purchased Ledger hardware wallets through Ledger’s e-commerce website, which operated on Shopify, Inc.’s platform. They alleged that two security incidents exposed customer information, including names, email addresses, postal addresses, and telephone numbers. The alleged disclosures involved approximately 272,000 people in one incident and larger numbers of email and physical contact records in another. The plaintiffs alleged that the breaches and Ledger’s and Shopify’s responses led to phishing scams, cyberattacks, ransom demands, and threats.

The plaintiffs brought a proposed class action asserting claims including negligence, negligence per se, injunctive relief, and claims under California, Georgia, and New York statutes. The remaining defendants were Shopify USA, Shopify, Inc., and Ledger SAS. Ledger Technologies had previously been voluntarily dismissed from the case.

Personal jurisdiction

The defendants moved to dismiss under Federal Rule of Civil Procedure 12(b)(2), which permits dismissal for lack of personal jurisdiction—the court’s power to exercise authority over a defendant. Because the motions relied on written materials rather than an evidentiary hearing, the plaintiffs needed to make a preliminary showing of jurisdictional facts.

The plaintiffs argued that the court had general jurisdiction over Shopify USA and specific jurisdiction over all three remaining defendants. General jurisdiction allows a defendant to be sued in the forum on any claim when the defendant’s contacts are so continuous and systematic that the defendant is essentially at home there. Specific jurisdiction concerns claims connected to the defendant’s forum-related conduct.

The court found that it lacked general jurisdiction over Shopify USA. Although the plaintiffs pointed to earlier business filings and litigation stating that Shopify USA had a San Francisco principal place of business, the court held that general jurisdiction is determined no earlier than when the complaint is filed. At that time, Shopify USA’s principal place of business was in Ottawa, Canada, and the plaintiffs did not show that California was an exceptional forum in which Shopify USA was essentially at home.

The court also found no specific jurisdiction over Shopify, Inc. or Shopify USA. For tort-based claims, the plaintiffs had to show that the defendants purposefully directed conduct toward California and that the claims arose from that conduct. The court held that nationwide services, the use of Ledger’s sales activity, and the operation of a generally accessible website did not establish that Shopify, Inc. deliberately targeted California. The court also found no evidence that Shopify, Inc. or its contractors handled the relevant data or carried out the breach in California. The fact that a California resident allegedly paid a Philippines-based contractor’s employee to obtain data did not show that Shopify, Inc. purposefully directed conduct toward California.

The court likewise found no specific jurisdiction over Ledger. Ledger conceded that it intentionally offered its products for sale on an internationally accessible website, including to California customers. But the court held that the plaintiffs did not show that Ledger expressly aimed its activities at California or that the sales caused harm Ledger knew was likely to occur there. The court also found no sufficient connection between Ledger’s California sales and the alleged data-breach injuries. Ledger submitted evidence that it had no California or other United States offices or employees and did not specifically direct its business or advertising toward California.

Jurisdictional discovery and disposition

The plaintiffs requested discovery about the defendants’ employees, contractors, data-security practices, advertising, sales, and handling of California customers’ information. The court denied the request because it was based on speculation, and the existing evidence showed that the alleged data-related activities did not occur in California. The court also concluded that amendment would be futile because the plaintiffs could not establish personal jurisdiction through an amended complaint.

Judge Edward M. Chen granted each of the defendants’ motions to dismiss, denied the plaintiffs’ request for jurisdictional discovery, and dismissed the case with prejudice. The clerk was directed to enter judgment and close the case. Because the ruling rested on the court’s lack of personal jurisdiction rather than the merits of the alleged data-breach claims, the opinion is classified as a procedural order.

The authoritative version

Read the full 22-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.