You are viewing a free summary from Descrybe.ai. For citation checking, legal issue analysis, and other advanced tools, explore our Legal Research Toolkit — not free, but close.

In re Target Corp. Customer Data Security Breach Litigation

Citations: 64 F. Supp. 3d 1304; 2014 WL 6775314Docket: MDL No. 14-2522 (PAM/JJK)

Court: District Court, D. Minnesota; December 1, 2014; Federal District Court

Narrative Opinion Summary

The case involves a consolidated class action lawsuit arising from a data breach announced by Target Corporation in December 2013, affecting around 110 million customers. The plaintiffs, comprising a class of issuer banks, brought forth claims against Target for negligence, violation of Minnesota's Plastic Card Security Act (PCSA), negligence per se, and negligent misrepresentation by omission. In assessing Target's motion to dismiss under Rule 12(b)(6), the court considered whether the plaintiffs sufficiently alleged facts to support their claims. It found that the plaintiffs stated a plausible negligence claim by alleging that Target's inadequate data security created a foreseeable risk, thus establishing a duty of care. The court also upheld the viability of claims under the PCSA, which regulates data retention practices, and the associated negligence per se claim. However, the negligent misrepresentation claim was dismissed without prejudice due to insufficient allegations of reliance. The court partially granted and partially denied Target's motion, allowing the plaintiffs to amend their complaint regarding the negligent misrepresentation claim within 30 days.

Legal Issues Addressed

Duty of Care in Negligence

Application: The court found that Target owed a duty of care based on the foreseeability of harm from its security practices, aligning with Minnesota's policy to protect consumer information.

Reasoning: Imposing a duty on Target aligns with Minnesota's policy of penalizing companies that fail to protect consumer information, as outlined in Minn. Stat. 325E.64.

Minnesota's Plastic Card Security Act (PCSA) Application

Application: The PCSA applies to entities conducting business in Minnesota and regulates data retention practices, which supports the plaintiffs' claims against Target.

Reasoning: However, the Act applies to any entity conducting business in Minnesota, which includes Target, thus making the data retention practices subject to the Act.

Motion to Dismiss Standard under Rule 12(b)(6)

Application: The court evaluates the sufficiency of the complaint by assuming the truth of the allegations and construing them favorably towards the plaintiffs, while dismissing conclusory statements.

Reasoning: In evaluating the motion to dismiss under Rule 12(b)(6), the court assumes the truth of the complaint's facts and construes them favorably for the plaintiffs.

Negligence Claim Requirements

Application: Plaintiffs must establish duty, breach, causation, and injury to survive dismissal, which they have adequately done against Target.

Reasoning: Under Minnesota law, a negligence claim necessitates four elements: duty, breach, causation, and injury.

Negligence Per Se Related to PCSA Violation

Application: The viability of the negligence per se claim hinges on the PCSA violation, which remains undismissed due to the allegations of data retention.

Reasoning: Consequently, the court must deny Target's Motion to Dismiss, and since the dismissal of the PCSA claim is critical to Target's negligence per se argument, that claim also survives the motion.

Negligent Misrepresentation by Omission

Application: Plaintiffs must allege reliance on omissions, which they failed to do, leading to dismissal without prejudice of their negligent misrepresentation claim.

Reasoning: Thus, Plaintiffs must allege reliance on Target’s omissions to succeed in their claim, which they have failed to do, leading to the dismissal of their negligent misrepresentation claim.