Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Mar. 29, 2024

Affinity Credit Union v. Apple Inc.

Judge
Jeffrey White
Docket
4:22-cv-04174
Court
U.S. District Court · Northern District of California
Pages
7
DiscoveryCivil ProcedureClass Action
In one sentence

In Affinity Credit Union v. Apple Inc., Judge White resolved discovery disputes by adopting plaintiffs’ ESI protocol and parts of both proposed protective orders.

Who this affects

The order affects Affinity Credit Union, Greenstate Credit Union, Consumers Co-Op Credit Union, Apple Inc., and the parties’ handling of confidential information and electronic discovery in the putative class action.

What happened

In Affinity Credit Union v. Apple Inc., the plaintiffs and Apple disagreed about confidentiality, data security, data-breach discovery, sealing documents, and logging communications involving Apple’s in-house lawyers. The dispute concerned proposed rules for handling evidence in the putative class action.

The court approved Apple’s proposal to limit “Highly Confidential” materials to attorneys’ eyes only, while allowing plaintiffs to challenge designations later in appropriate circumstances. It approved plaintiffs’ less restrictive data-security and multi-factor-authentication language, declined to add Apple’s proposed automatic data-breach discovery requirement, required court authorization before filing documents under seal, and adopted plaintiffs’ electronic-discovery protocol in full.

Judge Jeffrey S. White entered the order resolving the discovery disputes. Apple may seek an amended electronic-discovery protocol if the parties reach a compromise about privilege logs for certain in-house litigation counsel communications.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Affinity Credit Union v. Apple Inc. · No. 4:22-cv-04174
Judge
Jeffrey White
Date
Mar. 29, 2024

Background

The plaintiffs—Affinity Credit Union, Greenstate Credit Union, and Consumers Co-Op Credit Union—and Apple submitted competing proposed protective orders and protocols for electronically stored information. The proposals were substantially identical, but the plaintiffs argued that Apple’s requested security and confidentiality measures were too restrictive. Apple argued that stricter measures were necessary because law firms are increasingly targeted by hackers and because documents could be used to gain a commercial advantage in future negotiations.

Protective-Order Provisions

The court adopted language from both proposals.

Highly Confidential material. The parties agreed that some information could be designated “Highly Confidential” when it was extremely sensitive and could cause economic harm or significant competitive disadvantage or reveal personally identifiable information. Apple proposed that these materials be limited to attorneys’ eyes only, while the plaintiffs proposed allowing up to three client representatives and their immediate staff to view them. The court adopted Apple’s attorneys’-eyes-only language. It noted that the designation should be used sparingly and stated that the plaintiffs could later challenge some or all of the designations if they had a good-faith basis.

Data security and authentication. Apple sought strict security protocols and language requiring multi-factor authentication “for any access” to confidential materials. The court found the plaintiffs’ proposed security language more than sufficient. That language required an information security management system with appropriate administrative, physical, and technical safeguards, network security, encryption technologies, and written policies and procedures. The court also found the plaintiffs’ multi-factor-authentication language—requiring measures “to prevent unauthorized access”—sufficient and found Apple’s proposed “for any access” wording vague.

Data-breach discovery. Apple sought a provision requiring the receiving party to provide reasonable discovery concerning a data breach. The court did not adopt that additional requirement. It found that the provision could create disputes unrelated to resolving the case. The court noted that the proposed order already required reasonable requests for information related to investigating, remedying, and reducing the effects of a data breach. If that informal exchange proved insufficient, the producing party could seek permission from the court to conduct formal discovery.

Sealing. The court modified the proposed protective order to require prior court authorization before any document could be filed under seal, consistent with the court’s local rules.

Electronic-Discovery Protocol

Apple sought to add language excusing parties from listing certain communications and work product involving in-house or outside litigation counsel in privilege logs when the material was generated after the complaint was filed. A privilege log is a description of withheld documents that allows the opposing party and the court to evaluate a claim of attorney-client privilege or work-product protection.

The court explained that attorney-client privilege protects confidential communications made to obtain legal advice and the lawyer’s response. Communications with in-house counsel about ordinary business operations are not automatically privileged; the company claiming privilege must clearly show that the advice was given in a legal, rather than business, capacity. The party claiming privilege also bears the burden of establishing the privilege and separating privileged from nonprivileged information.

The court held that Apple had not made the required initial showing that its in-house counsel communications were made in a legal-adviser capacity and related to obtaining legal advice. Requiring a privilege log would allow the plaintiffs to evaluate whether the communications concerned legal advice or ordinary business practices. The court also agreed that a compromise might be possible if Apple identified specific in-house litigation counsel. Accordingly, it adopted the plaintiffs’ electronic-discovery protocol in full. Apple may move for an amended protocol if the parties reach a compromise concerning the privilege log.

Disposition

The court resolved the joint discovery-dispute letter without further briefing or a telephone conference. It adopted Apple’s attorneys’-eyes-only language for Highly Confidential materials, adopted the plaintiffs’ data-security and data-breach provisions, modified the sealing provisions to require prior court authorization, and approved the plaintiffs’ electronic-discovery protocol in full. Judge Jeffrey S. White entered the order.

The authoritative version

Read the full 7-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.