Rand v. The Travelers Indemnity Company
- Vincent Briccetti
- 7:21-cv-10744
- U.S. District Court · Southern District of New York
- 22
In Rand v. Travelers, Judge Briccetti denied the jurisdiction motion and granted in part and denied in part Travelers’s complaint-dismissal motion.
Jennifer Rand and the proposed class members may continue pursuing the DPPA claim, limited negligence and negligence-per-se claims, related declaratory relief, and injunctive relief. Travelers obtained dismissal of the Section 349 claim, certain damages theories, and declaratory relief based on the Federal Trade Commission Act and New York’s Shield Act.
What happened
Jennifer Rand brought a proposed class action against The Travelers Indemnity Company after an unauthorized party allegedly obtained her personal information, including her driver’s license number, through Travelers’s insurance-quote system. She asserted claims under the Driver’s Privacy Protection Act, New York General Business Law Section 349, negligence, and negligence per se.
The court denied Travelers’s challenge to Rand’s standing to sue. It dismissed the Section 349 claim, dismissed declaratory relief based on the Federal Trade Commission Act and New York’s Shield Act, and dismissed parts of the negligence and negligence-per-se claims that relied on nonmonetary damages or certain future risks. The Driver’s Privacy Protection Act claim, the negligence claims based on monetary costs to reduce data-breach harm, related declaratory relief, and the request for an injunction may proceed.
Judge Vincent L. Briccetti ruled that the amended complaint plausibly alleged privacy harm, costs incurred to reduce identity-theft risks, Travelers’s duty of care, and a knowing disclosure under the Driver’s Privacy Protection Act. The court ordered Travelers to answer by November 9, 2022.
The detailed version
- Rand v. The Travelers Indemnity Company · No. 7:21-cv-10744
- Vincent Briccetti
- Oct. 27, 2022
Background
Jennifer Rand filed a proposed class action against The Travelers Indemnity Company ("Travelers") concerning the alleged disclosure of her personal identifying information to unauthorized cybercriminals. She asserted claims under the Driver’s Privacy Protection Act ("DPPA"), New York General Business Law Section 349, negligence, negligence per se, and requests for declaratory and injunctive relief.
Rand alleged that Travelers’s agency portal allowed an insurance quote to be generated using minimal information, such as a person’s name, address, and date of birth. The resulting quote allegedly auto-populated additional personal information, including a driver’s license number, obtained from state motor-vehicle records or other sources that received information from state motor-vehicle departments. Rand alleged that New York’s Department of Financial Services had warned Travelers about cybercriminals targeting instant online automobile-insurance quote systems to obtain driver’s license numbers.
Rand alleged that Travelers later notified her that an unauthorized party may have accessed her name, address, date of birth, and driver’s license number by improperly using Travelers agents’ credentials. She alleged that she never applied for Travelers insurance and was not a voluntary Travelers customer. She also alleged costs and other harm associated with monitoring and protecting against identity theft.
Travelers moved to dismiss the amended complaint for lack of subject-matter jurisdiction under Rule 12(b)(1) and for failure to state a claim under Rule 12(b)(6). At this stage, the court treated the amended complaint’s well-pleaded factual allegations as true and drew reasonable inferences for Rand.
Standing
The court denied the Rule 12(b)(1) motion. It held that Rand plausibly alleged an injury sufficient to give her standing to sue. First, the alleged disclosure of her driver’s license information and other personal information plausibly involved a loss of privacy similar to the traditional harm of publicly disclosing private information. The court noted that it was debatable whether the alleged disclosure to a group of cybercriminals was sufficiently public or offensive under the traditional privacy tort, but concluded that an exact match to the traditional tort was not required at this stage.
Second, the court held that Rand plausibly alleged an imminent and substantial risk of future identity theft. The allegations described a targeted attempt to obtain consumer information, involved sensitive information such as a driver’s license number, and stated that the information could be used for fraudulent unemployment claims, new accounts, loans, or tax-refund fraud. The court therefore held that the alleged costs of credit freezes, identity-theft detection, and credit-monitoring or identity-theft-protection services could constitute an independent injury.
DPPA Claim
The court held that Rand adequately pleaded a DPPA claim, so that claim may proceed. The DPPA generally restricts the knowing disclosure of personal information obtained from motor-vehicle records, subject to listed permissible uses. The court concluded that Rand plausibly alleged that Travelers obtained driver’s license numbers from motor-vehicle records or related sources.
The court also held that Travelers’s voluntary configuration of its portal to auto-populate driver’s license numbers in insurance quotes could constitute a knowing disclosure. The court further concluded that Rand plausibly alleged Travelers knew or reasonably should have known that the system’s design could disclose protected information to cybercriminals for impermissible purposes, particularly in light of the two cybersecurity alerts.
Negligence
The court rejected Travelers’s argument that it owed Rand no duty of care under New York law. It held that Rand plausibly alleged that Travelers obtained and redisclosed her information without her knowledge or consent, was in the best position to protect it, marketed its cybersecurity, and knew it was being targeted by cyberattacks. The court concluded that recognizing a duty in these circumstances would not impose unlimited liability.
The negligence claim may proceed only to the extent it is based on monetary costs incurred to mitigate harm from the data breach. The court treated fees for credit freezes and costs for credit-monitoring and identity-theft services as potentially recoverable mitigation expenses. It held that time and effort alone were not cognizable damages, that a lowered credit score was insufficient without allegations of its actual financial effect, that future expenses were not alleged to be reasonably certain to occur, and that Rand had not adequately alleged a lost economic value for her personal information.
Negligence Per Se
Negligence per se is a rule under which violation of a statute designed to protect a class of people from the type of harm that occurred can establish the defendant’s duty and breach. The court held that the DPPA could supply the relevant duty because it protects people whose personal information is improperly disclosed and Rand plausibly alleged that she was within that protected group.
The negligence-per-se claim may proceed only insofar as it seeks monetary costs incurred to mitigate the data-breach harm. The remaining damages theories were dismissed for the same reasons given for the negligence claim. The opinion also states that the Federal Trade Commission Act and New York’s Shield Act do not create a private right of action, so negligence-per-se claims based on those statutes must be dismissed.
New York General Business Law Section 349
The court dismissed Rand’s Section 349 claim. That statute prohibits deceptive acts or practices in business and requires consumer-oriented conduct that was materially misleading and caused the plaintiff’s injury. The court held that Rand did not plausibly allege that she was exposed to any deceptive representation or omission by Travelers. Her allegations that she never applied for Travelers insurance and was not a voluntary customer supported the conclusion that she had no contact with Travelers before the alleged data breach.
Declaratory and Injunctive Relief
The court held that the Declaratory Judgment Act does not create an independent cause of action. However, Rand could seek declaratory relief based on substantive claims that survived. Her request for declaratory relief was dismissed to the extent it was based on the Federal Trade Commission Act or the New York Shield Act, but it may proceed as related to the DPPA, negligence, and negligence-per-se claims.
The court also held that injunctive relief is a remedy rather than a separate cause of action, but it allowed Rand’s request to proceed. Rand plausibly alleged that Travelers should implement security measures, including third-party audits and regular testing for security weaknesses, and that failing to do so could expose her to substantial identity theft and other harm.
Disposition
The Rule 12(b)(1) motion to dismiss was DENIED. The Rule 12(b)(6) motion to dismiss was GRANTED IN PART and DENIED IN PART. The Section 349 claim was dismissed. The request for declaratory relief was dismissed insofar as it was based on the Federal Trade Commission Act or the New York Shield Act. The other claims, subject to the limitations described above, may proceed. Travelers was ordered to file an answer by November 9, 2022.
Read the full 22-page opinion on CourtListener, the free public archive maintained by the Free Law Project.