On December 21, 2017, the Illinois Second District Appellate Court dealt a significant blow to the recent wave of Illinois Biometric Information Privacy Act (BIPA) class actions, holding in Rosenbach v. Six Flags Entertainment Corp. that plaintiffs alleging mere procedural violations of BIPA, without “any injury or adverse effect,” are not “aggrieved” persons entitled to any relief—monetary or otherwise—under the statute.1
BIPA prohibits companies from collecting biometric information from individuals without notice and written consent.2 The Illinois legislature passed BIPA in 2008 in response to the growing use of biometric technology in the business and security screening sectors in Illinois.3 Specifically, lawmakers were concerned about companies like Pay By Touch—which, in the early 2000s, brought biometric authentication to payment systems —going bankrupt and, consequently, putting consumers’ sensitive personal information at risk.4 To that end, BIPA contains a private right of action that allows any person “aggrieved” by a violation of the act to bring a claim against the offending party for $1,000 or actual damages per negligent violation, and $5,000 or actual damages per intentional or reckless violation.5 Critically, the statute does not define “aggrieved” persons, which proved to have a decisive impact on the Rosenbach court’s ruling.Continue Reading Illinois Appellate Court Holds That BIPA Plaintiffs Must Show Actual Harm
In yet another round of Schrems versus Facebook, on January 25, 2018, the Court of Justice of the European Union (CJEU) ruled that privacy activist Max Schrems is a consumer with regard to his Facebook
Last year, the U.S. Supreme Court issued a decision in Spokeo Inc. v. Robins, holding that a plaintiff bears the burden of establishing Article III standing by alleging an injury in fact that is concrete, particularized, and actual or imminent.
On July 21, 2017, Judge John A. Ross of the U.S. District Court for the Eastern District of Missouri issued a preliminary approval of a settlement agreement between the owner of AshleyMadison.com and the class representing former users whose personal information was breached in July 2015. Under terms of the settlement, Ruby Corp, the operator of the Ashley Madison website, is scheduled to pay $11.2 million. For some, the settlement announcement is a missed opportunity: the litigation represented a chance to clarify the scope of actionable consumer harm in breach-related litigation, as unlike in other notable breaches, the mere identification of individuals who used the website (and were thus affected by the breach) likely produced unwanted consequences. Nonetheless, the settlement agreement is interesting by itself, as it offers unique solutions to address class members seeking financial remuneration but wishing to avoid further publicity regarding their connection to AshleyMadison.com.