Skip to content

menu

Open Legal Blog Archive logo
HomeAboutBlogsFAQsSubmit

Do Consumers Have Property Rights in Their Personal Information Collected by Website Operators?

By Daniel A. Zlatnik on June 1, 2011

When consumers sue online service providers for data breaches involving such consumers’ personally identifiable information (“PII”), courts routinely dismiss such suits based on the failure to allege an “injury in fact” as required to establish constitutional standing — see, for example, the decisions in Bell v. Acxiom Corporation and Amburgy v. Express Scripts, Inc.  In a recent ruling by the District Court for the Northern District of California in Claridge v. RockYou, Inc., however, the plaintiff survived a motion to dismiss on standing grounds by advancing a novel theory:  PII, such as login information used to access social media websites, constitutes “property” that consumers provide to website operators in exchange for products, services and the promise that such website operators will safeguard such PII.

RockYou provides applications for use with social media sites such as Facebook.  According to the plaintiff, RockYou promised in its online privacy policy to use “commercially reasonable physical, managerial, and technical safeguards to preserve the integrity and security” of the personal information of its customers.  The plaintiff alleged that, despite this promise, RockYou stored its customers’ PII in unencrypted form, and without taking any common and reasonable data protection measures, so that such PII was readily available to anyone who could access the database.  Furthermore, the defendant allegedly failed to respond immediately to a warning from an online security firm that hackers knew about and were actively exploiting a security flaw in RockYou’s database.  RockYou acknowledged that its database had not been up to date with regard to standard security protocols and that one or more hackers had gained access to its database, which contained social networking login credentials for millions of users.

The ruling may also signal a new willingness for courts to view PII as personal property having monetary value, which could give users greater ability to enforce public-facing privacy and data security policies against website operators.

The crux of the plaintiff’s theory was that RockYou’s customers “buy” products and services by providing their PII, which is valuable property and is consideration for RockYou’s promise that it would employ reasonable security methods.  Under the plaintiff’s theory, RockYou’s failure to safeguard customers’ PII breached RockYou’s obligations to its customers, and harmed the value of that PII by compromising it.  The court noted that there was no established law that clearly addressed such an argument.  Further, the court avoided a probing analysis of the fundamental issues, and even expressed doubt that the plaintiff could prove any damages, but nonetheless found the plaintiff’s allegations of harm sufficient “to allege a generalized injury in fact.” Thus, the plaintiff had standing to assert claims against RockYou for, among other things, breach of contract, negligence and violation of various statutes.

Although the plaintiff’s novel theory may not ultimately succeed as a way of establishing standing in data breach cases, commentators have observed that the RockYou case is noteworthy in its acknowledgment of the economic realities of the Internet, where creative use of PII is an increasingly important revenue source for online service providers.  The court’s ruling legitimizes, at least for now, complaints based on a website operator’s failure to protect the inherent value of PII collected from site users.  The ruling may also signal a new willingness for courts to view PII as personal property having monetary value, which could give users greater ability to enforce public-facing privacy and data security policies against website operators.  Further, in viewing a website privacy policy as a set of promises made by a website operator in exchange for valuable PI I, the RockYou decision has the potential to significantly alter the balance of risks in the gathering, storing and use of PII on the Internet.

It is unclear, however, whether other courts will follow RockYou’s novel approach.  Indeed, in an opinion issued only one month after the RockYou decision, another judge in the Northern District of California rejected the plaintiffs’ argument that PII was property for purposes of stating a claim under California’s Unfair Competition Law (“UCL”).  The plaintiffs in that case, In re Facebook Privacy Litigation, brought a number of claims against Facebook based on Facebook’s alleged transmission of PII to third party advertisers without plaintiffs’ consent.  The defendant moved to dismiss.  After dismissing the plaintiffs’ claims under the Electronic Communications Privacy Act, the court found that “personal information” was not property under the UCL.  The court distinguished one of its prior cases, Doe 1 v. AOL, LLC, and found that, because the plaintiffs had not paid fees to use Facebook, they could not be considered “consumers,” and thus could not state a claim under the California consumer protection statutes.  In a footnote, the court noted that, although the plaintiffs argued that PII was a form of property and itself constituted “currency,” the plaintiffs had offered no case law in support of those arguments.  The Facebook court had already found that the plaintiffs had standing; whether its holding on the issue of PII as property foreshadows the ultimate fate of the RockYou plaintiff remains to be seen.

A final note on the RockYou case:  While the court was required to address the cutting-edge standing issues discussed above, it also illustrated the perhaps more quotidian point that language matters when drafting privacy policies and other website terms of use.  As one commentator noted, the court’s decision depended in part on the literal meaning of certain disclaimer language in RockYou’s own privacy policy.  Specifically, RockYou’s privacy policy contained a disclaimer of liability related to unauthorized access to PII, which proved ineffective because the disclaimer only applied to “unauthorized access to or use of [RockYou’s] secure servers . . . .” (Emphasis added).  The court refused to dismiss the plaintiff’s contract claims based on this provision because the plaintiff alleged that RockYou’s servers were not “secure.” Therefore, at least with respect to its contract claims, the plaintiff survived defendant RockYou’s motion to dismiss based on the implied guarantee of security, a result that might have been avoided with a more carefully worded privacy policy.

 

 

  • Posted in:
    Employment & Labor, Intellectual Property, Privacy & Data Security
  • Blog:
    Socially Aware Blog
  • Organization:
    Morrison & Foerster LLP
  • Article: View Original Source

Open Legal Blog Archive, Inc. logo
Seattle, Washington
Copyright © 2026, Open Legal Blog Archive, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo