It seems that in such a technologically dependent society, where digital information is everywhere, unauthorized access to computer databases (commonly referred to as “hacking”) is an all too common occurrence. However, as the recent Third Circuit decision in Reilly v. Ceridian Corp. illustrates, a company’s security breach that results in the exposure of hundreds of individuals’ personal information does not necessarily result in an automatic “harm” worthy of compensation.
In Reilly v. Ceridian Corp., Ceridian Corporation was a payroll processing firm. In order to process its customers’ payrolls, Ceridian collected personal information of its customers’ employees, which in some instances included an employee’s name, address, social security number, date of birth, and bank account information. One of Ceridian’s customers was the Brach Eichler law firm, where the plaintiffs, Kathy Reilly and Patricia Pluemacher, were both employed. On December 22, 2009, disaster struck when an unknown hacker infiltrated Ceridian’s records systems. While it is unknown whether the hacker read, copied, or understood the data he or she had access to, it was clear that the hacker potentially gained access to the personal and financial information of approximately 27,000 employees, including Reilly and Pluemacher. Ceridian contacted the potential victims to inform them of the situation, but for Reilly and Pluemacher, contact from Ceridian was simply not enough. Reilly and Pluemacher filed a claim in the United States District Court for the District of New Jersey on behalf of all of Ceridian’s potential victims. Reilly and Pluemacher claimed that the security breach made them susceptible to an increased risk of identity theft, and required their additional time and money to monitor their credit activity. The District Court, however, granted Ceridian’s motion to dismiss, stating that Reilly, Pluemacher, and the other potential victims’ claims did not have standing for failing to address a “case of controversy.” The Court of Appeals for the Third Circuit affirmed.
The Third Circuit agreed that the potential victims failed to establish adequate standing under Article III of the Constitution to bring their claim to federal court. Article III limits federal courts to only hear actual “cases or controversies” that might arise. Part of that requirement is a showing of “injury-in-fact,” or what the Supreme Court described in Danvers Motor Co. v. Ford Motor Co. as an invasion of a legally protected interest that is (1) concrete and particularized, and (2) actual or imminent, not conjectural or hypothetical. The Third Circuit felt that the potential victims’ allegations were too speculative. In order for the potential victims’ claim to adequately have standing, the court would have to assume that the hacker had actually read, copied or understood the personal information, had intended to commit future criminal acts by misusing the information, and had the capabilities of making unauthorized transactions with that information. Without these facts, no harm was suffered and, thus, no claim existed.