Standing is the threshold problem
A federal plaintiff must show concrete injury, and courts have divided on whether the exposure of personal data qualifies before anything has been done with it. The Supreme Court has held that a risk of future harm is generally insufficient for damages in federal court, which has made standing the decisive issue in a large share of breach cases.
Claims are strongest where misuse has actually occurred: fraudulent charges, accounts opened in the plaintiff’s name, or tax fraud. Courts more readily find standing where the exposed data is sensitive — Social Security numbers, medical records or financial credentials — and where it has surfaced on criminal marketplaces.
Mitigation costs and time spent are accepted by some courts as injury and rejected by others as self-inflicted. This split is why apparently similar breach cases reach opposite outcomes in different circuits.
Keep the notice letter and any evidence of misuse
Breach notification letters establish what was exposed and when. Combined with records of fraudulent charges, credit monitoring costs or time spent resolving the problem, they are the evidence that most often decides whether a claim survives.
What breach settlements typically provide
Settlements commonly combine several components: reimbursement of documented out-of-pocket losses up to a cap, a modest flat payment for those without documented loss, compensation for time spent at a stated hourly rate, and a period of credit monitoring or identity protection.
Because claim rates in consumer breach settlements are typically low, actual per-person payments frequently exceed the nominal estimate for those who do file — and are zero for the large majority who never submit a claim. Settlements also often require security improvements, which can be the more consequential outcome.
Biometric and tracking claims
A distinct and more successful body of privacy litigation does not depend on proving harm at all, because statutes supply damages directly. Illinois’ Biometric Information Privacy Act requires informed written consent before collecting fingerprints, faceprints or voiceprints, and provides fixed statutory damages per violation — which has produced some of the largest privacy settlements on record.
A second wave concerns session replay, tracking pixels and analytics tools, brought under state wiretapping and video privacy statutes on the theory that deploying them without consent constitutes interception. These claims have had mixed results and are unsettled, but they avoid the standing problem where the statute defines the violation as the injury.
Sections in This Category
Each section below groups the cases that share a defendant, a product or a legal theory, and sets out what those cases have in common before linking to the individual coverage.
- Streaming and Telecom Lawsuits — 9 cases
- Data Breach Lawsuits — 5 cases
- Social Media Platform Lawsuits — 10 cases
Related Claims Elsewhere on the Site
These pages sit in other categories but turn on the same cause of action covered here.