Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Nov. 12, 2021

Schmitt v. SN Servicing Corporation, an Alaska Corporation

Judge
William Orrick
Docket
3:21-cv-03355
Court
U.S. District Court · Northern District of California
Pages
17
Civil ProcedureMotion to DismissTort
In one sentence

In Schmitt v. SN Servicing, Judge Orrick granted in part and denied in part the dismissal motion: privacy was dismissed with prejudice; amendment was allowed on unlawful competition; unfair competition and negligence survived.

Who this affects

Desiree Schmitt and the proposed nationwide class of borrowers affected by the alleged SNSC data breach; SNSC must continue defending the unfair-prong and negligence claims, while Schmitt may amend the unlawful-prong claim.

What happened

In Schmitt v. SN Servicing Corporation, Desiree Schmitt sued over an alleged ransomware attack that obtained files containing borrowers’ personal and financial information. She alleged that the company waited three months to notify customers and that she spent money and time monitoring her credit and protecting her accounts.

SN Servicing Corporation asked the court to dismiss Schmitt’s amended claims, arguing that she had not adequately alleged a serious privacy invasion, violations supporting her unlawful business-practices claim, or the elements of negligence. Schmitt argued that the allegations supported her claims, including because the company possessed sensitive information and recommended that customers monitor their credit.

Judge William Orrick granted the motion in part and denied it in part. He dismissed the invasion-of-privacy claim with prejudice, allowed amendment of the unlawful business-practices claim, and denied dismissal of the unfair business-practices and negligence claims. The order allowed amendment in twenty days.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Schmitt v. SN Servicing Corporation, an Alaska Corporation · No. 3:21-cv-03355
Judge
William Orrick
Date
Nov. 12, 2021

Background

Desiree Schmitt sued SN Servicing Corporation (SNSC) on behalf of a proposed nationwide class of borrowers affected by an alleged data breach. According to the amended complaint, an unauthorized party used ransomware to obtain digital files from SNSC’s system in late 2020. Schmitt alleged that information belonging to at least 170,426 people was stolen and that SNSC did not notify customers until January 14, 2021, about three months after learning of the breach.

SNSC’s notice said the stolen information might include names, addresses, loan numbers, balances, and billing information. A later supplemental disclosure to some class members said that names, contact information, birthdates, Social Security numbers, and loan or borrower information may also have been accessible. Schmitt alleged that she spent more than $200 per year on credit monitoring, along with additional amounts for a password manager and password protection. She also alleged that she spent time reviewing accounts and changing passwords and experienced increased spam, phishing attempts, and social-engineering efforts.

Schmitt asserted claims for negligence, invasion of privacy, and violations of the unlawful and unfair prongs of California’s Unfair Competition Law. SNSC moved under Federal Rule of Civil Procedure 12(b)(6), which requires dismissal when a complaint does not state a legally sufficient claim. At this stage, the court accepts well-supported allegations as true and draws reasonable inferences for the plaintiff, but does not accept conclusions or unreasonable inferences as facts.

Invasion of Privacy

California invasion-of-privacy claims require a legally protected privacy interest, a reasonable expectation of privacy, and a serious invasion of that interest. The court described the standard for a serious invasion as a high bar requiring conduct sufficiently serious and egregious to violate the social norms underlying the privacy right.

The court held that Schmitt had not met that standard. It distinguished cases involving alleged intentional sharing of personal information from Schmitt’s allegations that SNSC’s inadequate security allowed hackers to obtain the information. The court concluded that the alleged conduct was, at most, negligent rather than intentional or egregious. It therefore granted SNSC’s motion to dismiss the invasion-of-privacy claim with prejudice.

California Unfair Competition Law

The Unfair Competition Law prohibits unlawful, unfair, or fraudulent business practices. Schmitt relied on the unlawful and unfair prongs.

For the unlawful prong, Schmitt sought to use alleged violations of the Federal Trade Commission Act and Federal Trade Commission guidance as the underlying violations. The court ruled that those sources could serve as the basis for an unlawful claim under the Unfair Competition Law. But Schmitt did not identify a specific provision that SNSC allegedly violated or explain with sufficient detail how SNSC violated it. The court also found that a Federal Trade Commission business brochure cited in Schmitt’s opposition did not appear to be a law or federal regulation and could not serve as the predicate for the claim on the allegations presented. The court granted the motion on the unlawful-prong claim, with leave to amend.

For the unfair prong, the court considered whether Schmitt plausibly alleged conduct that was immoral, unethical, oppressive, unscrupulous, or substantially injurious. The court found sufficient allegations at the pleading stage, including Schmitt’s claims that SNSC represented it would protect personal information while allegedly maintaining inadequate safeguards and that it failed to provide timely notice of the breach. The court therefore denied the motion to dismiss the unfair-prong claim.

Negligence

A California negligence claim requires a duty, breach, causation, and damages. The court found that Schmitt adequately alleged that personally identifying information was compromised. Her allegations about the kinds of information SNSC possessed, SNSC’s privacy policy, and the supplemental disclosure supported a reasonable inference that Social Security numbers were among the information exposed.

The court also concluded that Schmitt adequately alleged a duty of care. In applying California’s duty factors, the court relied in part on the foreseeability of harm from a data breach, SNSC’s recommendations that customers monitor their credit, the connection between SNSC’s alleged security failures and Schmitt’s claimed expenses, and the policy of preventing identity fraud and related harms. Because Schmitt adequately alleged a duty, the court found no pleading issue concerning breach, which SNSC did not challenge in its motion.

The court further held that the time and money Schmitt allegedly spent on credit monitoring constituted legally recognizable harm supporting the negligence claim. It therefore denied SNSC’s motion to dismiss the negligence claim.

Disposition

Judge William Orrick ordered that SNSC’s motion to dismiss the amended complaint was granted in part and denied in part, with leave to amend in twenty days. Specifically, dismissal of the invasion-of-privacy claim was granted with prejudice; dismissal of the unlawful-prong claim was granted with leave to amend; and dismissal was denied as to the unfair-prong and negligence claims. The order addressed whether the claims were adequately pleaded and did not determine SNSC’s ultimate liability for the alleged data breach.

The authoritative version

Read the full 17-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.