Greenstein v. Noblr Reciprocal Exchange
- Jeffrey White
- 4:21-cv-04537
- U.S. District Court · Northern District of California
- 10
In Greenstein v. Noblr, Judge White dismissed the data-breach class action with prejudice because plaintiffs did not establish standing.
The dismissal affected Michael Greenstein, Nelson, Au, and the proposed class members whose claims were asserted against Noblr Reciprocal Exchange.
What happened
Greenstein v. Noblr Reciprocal Exchange involved claims that Noblr exposed plaintiffs’ names, addresses, and driver’s-license numbers and notified them about the disclosure after a delay. The plaintiffs alleged risks of identity theft, time and effort spent monitoring their credit, and other injuries, and asserted claims under the Drivers’ Privacy Protection Act, negligence law, California’s Unfair Competition Law, and requests for court-ordered relief.
The court decided that the plaintiffs still had not shown a real and immediate risk of identity theft from the limited information disclosed. It also found that their credit-monitoring efforts, alleged loss in the value of their information, and one plaintiff’s attempted unemployment-benefits application did not establish a legally sufficient injury. The plaintiffs also failed to show that their alleged injuries were caused by Noblr’s disclosure or delay, or that a favorable court decision would likely remedy them.
Judge White granted Noblr’s motion to dismiss. The conclusion states that the case was dismissed with prejudice because the plaintiffs had already been given an opportunity to amend, and the court directed the clerk to close the file. Earlier in the order, however, the court stated that the motion was granted with leave to amend.
The detailed version
- Greenstein v. Noblr Reciprocal Exchange · No. 4:21-cv-04537
- Jeffrey White
- Dec. 5, 2022
Background
Plaintiffs alleged that Noblr sent them a May 14, 2021 letter stating that their personal information may have been compromised. The information allegedly included their names, addresses, and driver’s-license numbers. They claimed that they and other proposed class members faced an imminent risk of identity theft and fraud, and that named plaintiffs incurred injury by spending time and effort monitoring their credit reports. Plaintiff Au also alleged that someone fraudulently attempted to apply for unemployment benefits using her information.
The second amended complaint asserted four causes of action: violation of the Drivers’ Privacy Protection Act, negligence, violation of California’s Unfair Competition Law, and requests for declaratory and injunctive relief.
Legal standard
The court evaluated Noblr’s challenge to subject-matter jurisdiction under Federal Rule of Civil Procedure 12(b)(1). Because Noblr made a facial challenge, the court treated the complaint’s factual allegations as true and viewed them in the plaintiffs’ favor. The plaintiffs nevertheless had to establish Article III standing, meaning an injury in fact, a causal connection between that injury and Noblr’s conduct, and a likelihood that a favorable decision would remedy the injury. In a class action, at least one named plaintiff must have standing for each claim asserted for the class.
Analysis
The court held that the plaintiffs had not corrected the deficiencies identified in the earlier complaint.
First, the court found no cognizable threat of future harm. Although it described the issue as a close call, it continued to hold that driver’s-license numbers were not as sensitive as Social Security numbers and that names, addresses, and driver’s-license numbers alone did not create a credible and imminent threat of identity theft. The court also found that the plaintiffs had not shown that their personal information lost value because they did not establish both a market for the information and an impairment of their ability to participate in that market.
The court further held that the plaintiffs’ mitigation efforts did not establish injury in fact. Credit-monitoring costs can qualify as an injury when future harm is real and imminent and the monitoring is reasonable and necessary. Here, the court found no real and imminent risk of identity theft, and it found that the plaintiffs had not adequately supported their monitoring allegations or shown that the services were reasonable and necessary. The court also found that Au did not allege a cognizable injury from the attempted unemployment-benefits application, which was not alleged to have succeeded or caused her injury.
Second, the court found that the plaintiffs had not shown causation. It held that any future identity theft or fraud would be difficult to trace to Noblr’s disclosure because the information could have been obtained from other sources, combined with other stolen information, or acquired through another breach. The court also found that Au had not shown that the information used in the attempted application came from Noblr’s disclosure. The alleged four-month delay in notifying plaintiffs likewise did not establish a specific additional injury caused by Noblr.
Third, the court held that the alleged harm was not likely to be redressed by a favorable decision. Declaratory or injunctive relief could not force hackers or Noblr to return information that had already been disclosed, and the court noted that Noblr had already changed its policies and masked driver’s-license numbers in its page-source code.
Disposition
The court’s conclusion states: “Defendant’s motion to dismiss is GRANTED.” It further states that dismissal with prejudice was appropriate because the court had previously given plaintiffs leave to amend, ordered that a separate judgment issue, and directed the clerk to close the file. The order earlier stated that the motion was granted with leave to amend, creating an apparent inconsistency within the opinion about whether amendment remained available.
Read the full 10-page opinion on CourtListener, the free public archive maintained by the Free Law Project.