In Shah v. Cap. One Fin. Corp., No. 24-CV-05985-TLT, 2025 WL 714252, at *7–8 (N.D. Cal. Mar. 3, 2025), Plaintiffs alleged that after visiting Defendant’s website, they received ads for similar financial products. As a result, Plaintiffs allege that their personal information and communications were improperly disclosed to third-parties through Defendant’s website.
These communications included Plaintiffs’ and Class Members’ (1) employment information; (2) bank account information; (3) citizenship and dual citizenship status; (4) credit card preapproval and eligibility; (5) credit card approval and eligibility; (6) existing user, or Customer, status; (7) browsing activities, including viewed pages and content; (8) credit card application status; and (9) other information collected through an internet “cookie.” Id. ¶ 187.
Based on those allegations, Plaintiffs assert the usual litany of privacy violations. The District Court Judge, Trina Thompson, answered the following questions:
Is personal information property? No.
Plaintiffs state that they had a property interest in their personal information and that Plaintiffs lost money and property when Defendant disclosed their personal information with third parties. Compl. ¶¶ 273–74. However, Plaintiffs’ personal information does not constitute property. SeeLow, 900 F. Supp. 2d at 1030 (explaining that the “weight of authority” holds that a plaintiff’s personal information does not constitute property); In re iPhone Application Litig., 844 F. Supp. 2d at 1074–75 (holding that personal information is not property). Additionally, Plaintiffs do not plead that they “ever attempted or intended to participate in the market for the information” Defendant disclosed or that they derived economic value from that information. Lau v. Gen Digit. Inc., No. 22-cv-08981-JST, 2023 WL 10553772, at *7 (N.D. Cal. Sept. 13, 2023). As a result, Plaintiffs fail to allege that they had a property interest in their personal information.
Plaintiffs also cannot make an argument that the profit Defendant made as a result of disclosing Plaintiffs’ data is sufficient to demonstrate a loss. SeeIn re Facebook, Inc. v. Consumer Priv. User Profile Litig., 402 F. Supp. 3d 767, 804 (N.D. Cal. 2019) (“Facebook may have gained money through its sharing or use of the plaintiffs’ information, but that’s different from saying the plaintiffs lost money.”); Hazel v. Prudential Fin., Inc., No. 22-cv-07465-CRB, 2023 WL 3933073, at *6 (N.D. Cal. June 9, 2023) (explaining that even if a company made money off of the sharing or use of a plaintiff’s information, that company’s gain of money does not equal a plaintiff’s loss of money or property).
*8 Furthermore, even an argument that Plaintiffs experienced a diminution of the value of their private and personal information would not confer standing. SeeDoe v. Meta Platforms, Inc., 690 F. Supp. 3d 1064, 1082 (N.D. Cal. 2023) (finding that a diminution of the value of disclosed information was not a loss or damage). Plaintiffs, therefore, cannot allege lost money or property for purposes of standing under the CDAFA or the UCL.
Does the CCPA private right of action require a data breach? No.
Although the CCPA “calls for enforcement by the California Attorney General,” it allows a private right of action in the event of a security breach. Delgado v. Meta Platforms, Inc., 718 F. Supp. 3d 1146, 1155 (N.D. Cal. 2024). Courts, however, have also permitted the CCPA claims to survive a motion to dismiss in cases where the plaintiff does not allege a data breach, but instead where the “defendants disclosed plaintiff’s personal information without his consent due to the business’s failure to maintain reasonable security practices.” M.G. v. Therapymatch, Inc., No. 23-cv-04422-AMO, 2024 WL 4219992, at *7 (N.D. Cal. Sept. 16, 2024).
In this case, Plaintiffs allege that Defendant knowingly collected, used, and sold Plaintiffs’ personal information to third and fourth parties without their consent. Compl. ¶ 292. Because Plaintiffs allege that Defendant allowed third parties to embed trackers, such as Google and Microsoft, on its website and that these trackers transmitted Plaintiffs’ personal information, Plaintiffs need not allege a data breach. Id. ¶¶ 51–52; see Therapymatch, 2024 WL 4219992, at *7 (finding that the plaintiff did not need to allege a data breach where the plaintiff disclosed plaintiff’s personal information without his consent); Stasi v. Inmediata Health Grp. Corp., 501 F. Supp. 3d 898, 924 (S.D. Cal. 2020) (finding that plaintiffs alleged a sufficient CCPA claim when defendants disclosed their personal information over the internet but there was no theft). Because Plaintiffs plead that Defendant disclosed their personal information without their consent, Plaintiffs state a CCPA claim.
