Rodriguez v. Google LLC
- Richard Seeborg
- 3:20-cv-04688
- U.S. District Court · Northern District of California
- 11
In Rodriguez v. Google, Judge Seeborg granted in part Google’s motion, excluding some accounts from damages classes while retaining them for other claims and relief.
The ruling affects people with Enterprise Dasher or Supervised Unicorn Google accounts who may fall within the certified classes, Google, the named Plaintiffs, and the administration of class notice. Dasher and Unicorn users remain included for the California data-access claim and for declaratory or injunctive relief, but are excluded from the damages classes for intrusion upon seclusion and invasion of privacy.
What happened
In Rodriguez v. Google LLC, the court considered whether business-managed Enterprise Dasher accounts and parent-managed Supervised Unicorn accounts belonged in two certified privacy classes. Google argued that including them created individualized questions about who turned off Google’s privacy settings and who saw Google’s disclosures.
The court ruled that those accounts could remain in the classes for the California Computer Data Access and Fraud Act claim and for classes seeking declaratory or injunctive relief. But it modified the damages classes for intrusion upon seclusion and invasion of privacy to exclude Enterprise and Supervised accounts because individual questions would defeat the requirement that common issues predominate.
Judge Seeborg granted in part Google’s motion to modify the class certification order. He also granted Plaintiffs’ motion to seal specified exhibits, required public redacted versions, and directed the parties to address a revised class-notice plan and tolling arrangements.
The detailed version
- Rodriguez v. Google LLC · No. 3:20-cv-04688
- Richard Seeborg
- Apr. 5, 2024
Background
This privacy class action includes claims for intrusion upon seclusion, invasion of privacy, and violation of California’s Comprehensive Computer Data Access and Fraud Act. The certified classes cover people whose Google Web & App Activity or supplemental Web & App Activity settings were turned off, but whose activity on non-Google mobile apps was transmitted to Google through specified software development kits.
The parties disputed whether two types of accounts were included: Enterprise Dasher accounts, created and managed by businesses or organizations for employees or other members, and Supervised Unicorn accounts, created and managed by parents or guardians for children under thirteen. Google moved to modify, although it called the request a clarification of, the class definition before class notice was sent.
Rule 23 Analysis
The court held that the certified class language covered “all individuals” whose settings were turned off and was not limited to people who personally changed the settings. The court also found that Google had notice before class certification that Plaintiffs were considering including Dasher and Unicorn accounts.
The court determined that commonality, typicality, and adequacy under Federal Rule of Civil Procedure 23(a) remained satisfied even if those accounts were included. However, Rule 23(b)(3) also requires common questions to predominate over individual questions. For the intrusion upon seclusion and invasion of privacy claims, the court found individualized questions about whether an enterprise administrator, parent, guardian, employee, or child changed the settings; who saw Google’s disclosures; and whether the relevant user had a reasonable expectation of privacy or consented to the data collection. Those questions defeated predominance for those claims.
The court reached a different conclusion for the California data-access claim. It stated that whether Google had permission to collect the data turned on the status of the Web & App Activity or supplemental setting, which could be shown through common proof. The court further stated that the other elements identified in the opinion were also subject to common proof of Google’s conduct. Dasher and Unicorn accounts therefore remained included for that claim.
Disposition
The court granted in part Google’s motion to modify the class certification order. For the Rule 23(b)(3) classes covering intrusion upon seclusion and invasion of privacy, the court modified the definitions to include only “non-Enterprise” and “non-Unicorn” individuals. The Rule 23(b)(3) classes for the data-access claim remained unchanged and continued to include Dasher and Unicorn users.
The Rule 23(b)(2) classes, which seek declaratory or injunctive relief, also continued to include Dasher and Unicorn users. The court found that any such relief concerning Google’s settings would affect users regardless of account type and that Google had not shown a deficiency in the Rule 23(a) requirements.
The court vacated the April 11, 2024 hearing and directed the parties to report whether they would withdraw and resubmit a modified class-notice plan. Plaintiffs were also directed to file a stipulated tolling agreement or a proposed tolling order within two weeks. Separately, the court granted Plaintiffs’ motion to seal exhibits containing Google employee email addresses, internal code names, and commercially sensitive business information, and required public redacted versions within two weeks.
Read the full 11-page opinion on CourtListener, the free public archive maintained by the Free Law Project.