Thomas v. Kimpton Hotel & Restaurant Group, LLC
- Maxine Chesney
- 3:19-cv-01860-MMC
- U.S. District Court · Northern District of California
- 10
In Thomas v. Kimpton Hotel & Restaurant Group, LLC, Judge Chesney denied class certification because individualized reliance issues predominated and denied Kimpton’s expert motion as moot.
Jake Thomas, Salvatore Galati, Jonathan Martin, the proposed class members, and Kimpton Hotel & Restaurant Group, LLC. The plaintiffs could not proceed with the identified claims as a certified class, and Kimpton’s motion to exclude the classwide damages expert was denied as moot.
What happened
In Thomas v. Kimpton Hotel & Restaurant Group, LLC, Jake Thomas, Salvatore Galati, and Jonathan Martin sought to represent a class of people whose personal information was allegedly accessed after hackers entered Sabre Corporation’s hotel-reservation system. They pursued state-law claims against Kimpton Hotel & Restaurant Group, LLC, including breach of contract, a California data-security claim, and a Texas consumer-protection claim.
The court concluded that class certification was not appropriate. For the contract and California data-security claims, deciding whether Sabre was acting as Kimpton’s apparent agent would require examining each person’s individual experience and whether that person reasonably believed they were providing information to Kimpton rather than Sabre. The Texas claim likewise required individualized proof of whether each person relied on Kimpton’s statements. Those individual issues predominated over common questions.
The court denied the plaintiffs’ motion for class certification. It denied as moot Kimpton’s motion to exclude the plaintiffs’ damages expert because the expert’s opinions concerned calculating damages for a class. Judge Elaine M. Chesney issued the order.
The detailed version
- Thomas v. Kimpton Hotel & Restaurant Group, LLC · No. 3:19-cv-01860-MMC
- Maxine Chesney
- Apr. 20, 2022
Background
The plaintiffs alleged that Kimpton contracted with Sabre Corporation to provide a hotel-reservation system. They alleged that customers booked rooms at Kimpton hotels and supplied personally identifiable information, which hackers later accessed through Sabre’s Central Reservations system. According to the plaintiffs, the hackers obtained credentials and entered the system because it used single-factor authorization rather than multiple levels of authentication. The plaintiffs also alleged that Sabre was Kimpton’s agent, making Kimpton responsible for Sabre’s conduct.
The plaintiffs sought certification of a class for three claims that remained after an earlier order partially granted Kimpton’s motion to dismiss: a breach-of-contract claim, a claim under California Civil Code § 1798.81.5, and part of a claim under the Texas Deceptive Trade Practices–Consumer Protection Act. They relied on statements in Kimpton’s privacy policy and on its payment page concerning the protection and security of customers’ personal information.
Class-Certification Standard
Under Federal Rule of Civil Procedure 23, plaintiffs seeking class certification must establish four requirements: sufficiently numerous class members, common legal or factual questions, representative claims typical of the class, and representatives who will fairly and adequately protect the class’s interests. They must also satisfy at least one additional Rule 23(b) requirement. The plaintiffs relied on Rule 23(b)(3), which requires common questions to predominate over individual questions and a class action to be superior to other available methods of resolving the dispute.
Breach-of-Contract Claim
The plaintiffs argued that Kimpton’s privacy policy and payment-page statements were contractual promises to safeguard customers’ personal information. They acknowledged that the alleged hackers accessed information in Sabre’s system rather than Kimpton’s system, but argued that Kimpton could be responsible under an ostensible-agency theory.
Ostensible agency is a legal theory under which a principal may be responsible for another entity’s conduct when the principal’s acts or lack of ordinary care reasonably cause a third person to believe that the other entity is the principal’s agent, and the person relies on that belief to their detriment. The court held that whether each class member reasonably believed they were providing information to Kimpton, rather than Sabre, would require an individualized inquiry.
The court relied in part on Kimpton’s privacy policy, which warned users to check the browser’s location bar to determine whether they had been directed to a different website and stated that Kimpton was not responsible for the information practices of third-party websites or service providers. Kimpton also submitted undisputed evidence that clicking the “Book Now” link took users to a Sabre-operated website whose address displayed “synxis.com.” The court therefore found that individual issues about each person’s knowledge, expectations, and reliance predominated over common issues. The court denied certification for the breach-of-contract claim.
California Data-Security Claim
The plaintiffs’ allegations under California Civil Code § 1798.81.5(b) asserted that Kimpton failed to maintain reasonable security procedures because it used, or allowed its contractor to use, single-factor authorization. The plaintiffs appeared to seek class certification under subsection (c), which concerns a business’s contractual disclosure of personal information to a nonaffiliated third party and requires the business to require appropriate security practices by contract.
The court concluded that subsection (c) did not apply to the allegations in the operative complaint because the plaintiffs alleged that they themselves provided their information to Sabre. They did not allege that Kimpton disclosed the information to Sabre under the circumstances described in subsection (c), or that Sabre disclosed it under a contract with another nonaffiliated third party. To the extent the plaintiffs sought certification under subsection (b), the court found that the claim again depended on individualized questions about ostensible agency. The court denied certification for the California data-security claim.
Texas Consumer-Protection Claim
The plaintiffs based their Texas Deceptive Trade Practices–Consumer Protection Act claim on the same privacy and security statements used for their contract claim. They argued that the statements were misleading or deceptive because Sabre’s actual security measures did not use multiple layers of authentication.
The court explained that the relevant Texas claim requires a consumer to rely on a misleading or deceptive act to the consumer’s detriment. Uniform receipt of the same statement does not establish classwide reliance because individual consumers may interpret or rely on the statement differently. The court found that determining whether each person believed they were providing information to Kimpton or Sabre, and whether each person relied on Kimpton’s statements, could not be resolved on a classwide basis. The court denied certification for the Texas claim.
Disposition
The court denied the plaintiffs’ motion for class certification. It denied as moot Kimpton’s motion to exclude the opinions of the plaintiffs’ damages expert because those opinions concerned exclusively classwide damages calculations. The order addressed whether the claims could proceed as a class action; it did not decide the ultimate merits of the underlying claims.
Read the full 10-page opinion on CourtListener, the free public archive maintained by the Free Law Project.