In re Robinhood Data Security Litigation
- James Donato
- 3:21-cv-08906
- U.S. District Court · Northern District of California
- 3
In re Robinhood Data Security Litigation: Judge Donato dismissed the complaint as unclear, allowing plaintiffs to file a second amended complaint by March 20, 2023.
The 25 named Robinhood customers and the proposed nationwide and state classes were affected. Robinhood Markets, Inc. was also affected by the dismissal and the requirement that any future briefing comply with the court’s standing order.
What happened
In In re Robinhood Data Security Litigation, 25 Robinhood customers alleged that a November 2021 data breach exposed personal information belonging to more than seven million customers. They asserted 24 claims, including negligence, breach of contract, and violations of state consumer-protection and data-security laws, on behalf of proposed nationwide and state classes.
The court found that the complaint did not clearly identify which state’s law governed its common-law claims and did not provide enough concrete facts about Robinhood’s alleged security failures. The court also criticized the parties’ briefing for failing to adequately explain their legal arguments.
Judge Donato dismissed the complaint under the requirement that pleadings provide a short and clear statement of the claim. He allowed the plaintiffs to file a second amended complaint by March 20, 2023, barred new claims or parties without permission, and warned that missing the deadline would result in dismissal of the case under Rule 41(b).
The detailed version
- In re Robinhood Data Security Litigation · No. 3:21-cv-08906
- James Donato
- Mar. 6, 2023
Background
This proposed class action arose from a November 2021 data breach that allegedly exposed the full names, email addresses, dates of birth, ZIP codes, and other personally identifiable information of more than seven million Robinhood customers. Twenty-five customers from 13 states brought 24 claims against Robinhood Markets, Inc., including negligence, negligence per se, breach of contract, breach of implied contract, unjust enrichment, declaratory judgment, and alleged violations of several state consumer-protection and data-security laws. They sued for themselves, a proposed nationwide class, and 11 proposed state subclasses.
Robinhood asked the court to dismiss the consolidated amended complaint under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). The court said dismissal was warranted on grounds different from those Robinhood proposed.
Reasons for the ruling
The court found that the complaint was not a workable pleading under Rule 8. Rule 8(a)(2) requires a complaint to provide a short and plain statement showing that the plaintiff is entitled to relief.
First, the complaint did not identify the state law intended to govern the nationwide class’s common-law claims. The court noted that the case invoked the Class Action Fairness Act, which provides a form of diversity jurisdiction, and that state substantive law would therefore govern the claims. Because the named plaintiffs came from 13 states and Robinhood was alleged to be a Delaware business entity with its principal place of business in California, the court viewed the choice-of-law issue as significant. The parties’ briefing cited laws from multiple states without providing a clear choice-of-law analysis, including on the possible application of the economic loss rule.
Second, the court found that the complaint was thin on facts concerning Robinhood’s alleged failure to protect user data. Although the breach itself was supported by Robinhood’s public and user communications, and some plaintiffs alleged concrete and particularized injuries, the complaint generally asserted that Robinhood apparently lacked adequate security measures and, on information and belief, failed to follow Federal Trade Commission data-security guidelines. The court said the complaint’s descriptions of security safeguards were not tied to facts showing how Robinhood’s conduct fell short, while also noting that this lack of detail did not necessarily doom the plaintiffs’ case.
The court also criticized Robinhood’s dismissal brief for presenting new theories with little meaningful discussion or analysis. It said that the brief’s bullet points and footnotes fell below the professionalism standards expected in the district and violated the court’s Standing Order for Civil Cases, which states that inadequately supported arguments will be disregarded. The court warned that future briefs and arguments not complying with that order would be summarily denied.
Disposition
The court dismissed the consolidated amended complaint because it did not satisfy Rule 8. The plaintiffs were permitted to file a second amended complaint by March 20, 2023, that complied with the order. They could not add new claims or parties without the court’s prior consent. The court stated that failure to meet the deadline would result in dismissal of the case under Rule 41(b). The order did not decide whether Robinhood was ultimately liable for the alleged data breach.
Classification
This is a procedural order because the court dismissed the complaint for inadequate pleading without deciding the underlying liability claims.
Read the full 3-page opinion on CourtListener, the free public archive maintained by the Free Law Project.