Court, Explained
U.S. Federal District Courts
Back to docket
D. Minn.Procedural orderFiled Jan. 12, 2023

Perry v. Bay & Bay Transportation Services, Inc.

Judge
John Tunheim
Docket
0:22-cv-00973
Court
U.S. District Court · District of Minnesota
Pages
23
Civil ProcedureMotion to DismissTortContract
In one sentence

In Perry v. Bay & Bay, Judge Tunheim denied dismissal, finding standing and plausible negligence and implied-contract claims after a data breach.

Who this affects

Billy Perry’s individual claims and the proposed nationwide class claims may proceed against Bay & Bay Transportation Services, Inc.; the court’s order did not decide whether the proposed class would be certified or whether Perry would ultimately prevail.

What happened

In Perry v. Bay & Bay Transportation Services, Inc., Billy Perry alleged that a ransomware attack exposed personal information Bay & Bay collected from him and others. He sued for negligence, negligence based on a federal consumer-protection law, and breach of an implied contract, seeking damages and improved data security for a proposed nationwide class.

Bay & Bay argued that Perry lacked a real injury connected to the breach and that the company’s credit-monitoring and insurance program addressed his injuries. It also argued that Perry had not alleged enough facts to support damages, causation, or an implied contract. The court rejected those arguments at this stage, relying on allegations that Perry’s information was published online, used in a bank scam that cost him $500, and required time spent monitoring and responding to the breach.

Judge John R. Tunheim denied Bay & Bay’s motion to dismiss in all respects. The ruling allows Perry’s claims to continue, but it did not decide whether he will ultimately prove them.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Perry v. Bay & Bay Transportation Services, Inc. · No. 0:22-cv-00973
Judge
John Tunheim
Date
Jan. 12, 2023

Background

Billy Perry sued Bay & Bay Transportation Services, Inc. individually and on behalf of a proposed nationwide class of employees and consumers affected by a data breach. Perry alleged that he applied for employment with Bay & Bay and provided private information, including information the company required from prospective, current, and former employees and customers. The information allegedly included names, addresses, Social Security numbers, birth dates, driver’s-license information, and direct-deposit information.

Perry alleged that Bay & Bay stored this information and promised to keep it confidential and secure. According to the complaint, unauthorized parties accessed Bay & Bay’s systems during a ransomware attack in November 2021, and private information was published on the dark web. Bay & Bay notified Perry in February 2022 that his information had been compromised. Perry alleged that he spent about three to four hours each week monitoring accounts and dealing with the consequences of the breach. He also alleged that cyberthieves used his information to impersonate his bank and scam him out of $500. Bay & Bay disputed some of these allegations, including whether criminals obtained Perry’s information and whether he provided direct-deposit information.

Perry asserted claims for negligence, negligence per se based on Section 5 of the Federal Trade Commission Act, and breach of implied contract. He sought damages, costs, attorney fees, and injunctive relief requiring Bay & Bay to adopt specified data-security measures.

Bay & Bay’s motion

Bay & Bay moved to dismiss under two Federal Rules of Civil Procedure. Under Rule 12(b)(1), it argued that Perry lacked Article III standing—the constitutional requirement that a plaintiff show a concrete injury connected to the defendant’s conduct and likely to be addressed by a court ruling. Under Rule 12(b)(6), it argued that Perry had not alleged enough facts to state claims for negligence, negligence per se, or breach of implied contract.

Bay & Bay argued that Perry had not shown an actual injury or a sufficiently likely future injury and that the company’s credit-monitoring and identity-theft-insurance program had fully addressed any harm. It also argued that Perry had not adequately pleaded damages or causation and that its privacy policy did not create an implied contract with a job applicant.

Standing

The court held that Perry adequately alleged standing for both injunctive relief and monetary relief at the motion-to-dismiss stage. For forward-looking relief, Perry sought improvements to Bay & Bay’s data-security systems, future audits, and company-funded credit monitoring. The court found a sufficiently imminent and substantial risk of future harm because Perry alleged that unauthorized parties accessed his private information, published it on the dark web, and used it in a bank scam.

For monetary relief, the court found that Perry alleged concrete injuries, including disclosure of private information, misuse of that information, time and resources spent monitoring and responding to the breach, and the $500 bank-scam loss. The court concluded that the alleged $500 loss was not covered by Bay & Bay’s credit-monitoring services. It also concluded that, at this stage, Perry had adequately connected the alleged loss to the data breach because he alleged that cyberthieves used information obtained through the breach.

Negligence and negligence per se

The court held that Perry adequately alleged damages and causation for his negligence and negligence-per-se claims. Under Minnesota law, negligence generally requires a duty of care, a breach, an injury, and a causal connection between the breach and the injury. Negligence per se uses a legal rule or statute as the required standard of conduct, but the plaintiff must still show injury and causation.

The court concluded that Section 5 of the Federal Trade Commission Act was not too vague to serve as the basis for a negligence-per-se claim under Minnesota law. It also concluded that Minnesota law could allow such a claim even though the Act does not itself provide a private right to sue, if the statute’s protected people and intended harms requirements are met. Perry plausibly alleged that Bay & Bay’s failure to protect private information caused the type of harm the statute was intended to prevent.

The court recognized that Perry would later need to prove that Bay & Bay’s conduct was the proximate cause of his injury. It noted possible factual questions, including when the bank scam occurred and whether other causes could explain it. But the court held that Perry’s allegations were sufficient to proceed beyond the motion-to-dismiss stage.

Implied contract

The court described the implied-contract claim as a close question but held that Perry had alleged enough facts to continue. It reasoned that Perry plausibly alleged an exchange in which he provided valuable private information while Bay & Bay considered him for employment. The court found it plausible that Bay & Bay thereby made an implied promise to keep the information secure.

The court also found that Perry had plausibly alleged the other contract elements: his performance, Bay & Bay’s breach when a data breach occurred, and damages including loss of the benefit of the bargain, monetary loss, and reduced value of the private information.

Disposition

The court denied Bay & Bay’s motion to dismiss in all respects. The order did not determine whether Perry will ultimately prove his claims; it determined only that his allegations were sufficient to continue the case at this stage.

The authoritative version

Read the full 23-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.