
By Gerald L. Maatman, Jr.
Duane Morris Takeaways: I had the privilege and honor of presenting on September 30 at the Perfect Law Class Action Conference at New York University School of Law. Practitioners and law professors from Europe, Canada, and the United States convened at NYU to debate cutting-edge class action issues involving privacy, securities fraud, products liability, and antitrust laws. The “debate” between the plaintiffs’ bar, defense lawyers, and academics made for an engaging and enlightening day. The full agenda is here – https://perfectlaw.co.uk/
Overview
Dean Troy McKenzie of NYU School of Law gave the keynote address that identified the array of unanswered and evolving legal issues in the class action space. Along with Professor Samuel Issacharoff, Den McKenzie set the stage for discussion about the quickly and ever-evolving law in this area. At the same time, artificial intelligence is fueling change and accelerating developments on all continents. “AI” became a consensus concept during all the conference presentations in terms of its potential to transform class action litigation issues.
Comparative Jurisdictions
In a follow up panel that included jurists from Europe and the United States, Judge Robert Dow – presently chief counsel for Chief Justice John Roberts of the U.S. Supreme Court and formerly a Judge of the U.S. District Court for the Northern District of Illinois – asserted that tools to manage complex litigation are functioning well, despite their genesis some 60 years ago. Both Supreme Court decisional law and Congressional enactments – such as the Class Action Fairness Act of 2005 – created heightened pleading requirements for litigating class actions and a preference for most of such cases being docketed in federal courts. As a result, class action litigation is growing, and federal courts are increasingly encountering cutting-edge class action issues as their caseloads expand.
Justice Benjamin Glustein of the Ontario Superior Court of Ontario observed that class actions likewise are increasing in Canada, and unlike U.S. practice, claims are more apt to be certified, especially dealing with civil rights claims. Canadian class actions, as a result, are thriving.
In terms of Europe, law professor Miguel Ferror of the University of Lisbon and plaintiffs’ lawyers Marc Grossman of Milberg and Luke Streatfield of Hausfeld talked about the rise of magnet jurisdictions in Europe, especially for antitrust claims in the United Kingdom. They opined that selection of jurisdiction is a high-stakes decision point for plaintiffs’ lawyers in Europe. In this respect, certain jurisdictions are not optimal forums for collective redress lawsuits. For example, while Romania follows a regime of 20% presumed damages, they observed, in essence, that “no one litigates in Romania” because they do not trust the courts and legal outcomes there. Litigation funders, they opined, also take a close look at selections of venue and pertinent ethical rules in those jurisdictions in terms of mass or group-wide claims.
Privacy Class Actions
On a panel with three plaintiffs’ privacy lawyers, I spoke on the rise and pervasiveness of privacy violations as a new frontier of class actions. In general terms, I opined that Article III standing requirements are critically important in this space. The case law is not necessarily consistent, the legal state of play is in flux, and many decisions turn on specific factual situations. I offered three distinct takeaways using a recent case from New York as an exemplar.
First – There was an important decision from the Southern District of New York issued in August of last year that goes into great depth into the issues raised by these questions.
In Re Zeta Global Privacy Litig., No. 25 Civ. 5780, 2026 WL 2254612 (S.D.N.Y. Aug. 8, 2025) (granting motion to dismiss a putative class action under ECPA and state consumer protection laws for lack of standing under Rule 12(b)(1) for lack of injury in fact).
Zeta is a company that uses artificial intelligence to develop personalized marketing techniques aimed at helping brands acquire and retain customers. Id. at *1. The named plaintiffs alleged that when they visited storefronts of business that use Zeta for this purpose, those businesses tracked them across the Internet; and that Zeta, and its clients, profited from collecting their PII. Id. Among other things, the plaintiffs alleged “Zeta uses this AI Engine to generate ‘insights’ which its clients can use to identify consumers who “can be targeted for specific lines of business.” Id. at 2. They alleged this creates significant monetary value as measured by how much clients pay to access the dataset. Id. They sought damages under the Electronic Communications Privacy Act (“ECPA”), 18 U.S.C. § 2510, et seq., and various state consumer protection laws. Id. at 1.
In response to the motion to dismiss, the plaintiffs argued that they pled two privacy-related harms traditionally recognized as adequate to confer standing: (1) invasion of privacy – at common law referred to as public disclosure of “private facts,” and (2) “intrusion upon seclusion. Id. at 4. They also argued: (3) because defendants profited from monetizing their PII data and harmed “plaintiffs’ electronic device ‘resources,’ and caused a loss of control of their data.” Id. at *4.
On the first claim – disclosure of private information – the court explained that in the Second Circuit, the Article III standing analysis requires either “’actual injuries’” resulting from the disclosure or ‘a substantial risk of harm’”
- See FritzCo LLC v. Verizon Commc’ns Inc., No. 21 Civ. 10432, 2026 WL 734776, at *4 (S.D.N.Y. Mar. 16, 2026). Id. at 5.
A “substantial risk of harm’ is determined by “whether the type of data that has been exposed is sensitive such that there is a high risk of identity theft or fraud.”
- McMorris v. Carlos Lopez & Assocs., LLC, 995 F.3d 295, 303 (2d Cir. 2021). Id. at 5.
This turns on whether it constituted “sensitive information” – id. at 6 – which the court noted does not include data like addresses, phone numbers, email addresses, and IP addresses.
- Cooper v. Bonobos, Inc., No. 21 Civ. 854, 2022 WL 170622, at *6 (S.D.N.Y. 2022).
It also does not include “partial credit card numbers” and “password histories” (id.) because they are unlikely to cause an injury that was “certainly impending” or suggesting a “substantial risk the harm will occur” the standards set forth in the Cooper case. This was because of “the fragmented nature of the data and the age of the information (e.g. old passwords—that were captured.” (Id.)
On the other hand, a plaintiff arguably does have Article III standing for state law claims if credit card information is taken which, along with other stolen personal information, enables third parties to complete unauthorized transactions.
- FritzCo LLC v. Verizon Commc’ns Inc., No. 21 Civ. 10432, 2026 WL 734776, at *4 (S.D.N.Y. Mar. 16, 2026).
And if the content of emails is sold, that is sufficient to establish standing for federal privacy claims if it contains information such as sensitive PII.
- Cooper v. Slice Techs., Inc., No. 17 Civ. 7102, 2018 WL 2727888, at *2-3 (S.D.N.Y. June 6, 2018).
- See also In re Christie’s Data Breach Litig., 767 F. Supp. 3d 12, 16-18 (S.D.N.Y. 2025) (finding disclosure of plaintiffs’ full names, passport numbers, and driver’s license numbers sensitive).
The court concluded that the named plaintiffs in the Zeta litigation did not provide enough specificity in their pleading to establish Article III standing. They did not state the nature of the PII allegedly collected and analyzed by the AI learning model, which the court explained was fatal to their complaint:
“It does not allege that credit card information, medical information, Social Security numbers, or any other data otherwise recognized by courts as sensitive—was disclosed. It hypothesizes that Zeta might possess “2,500” pieces of information about these plaintiffs, and that “Zeta has likely stored more information than what is publicly known.” FAC ¶¶ 67, 85. But such conjecture cannot support standing.”
- In Re Zeta at *6.
Second – Other courts have held that the disclosure or capture of mere browsing activity, without more, is also not sufficient for a concrete injury.
- Bradshaw v. Lowe’s Cos., No. 25 Civ. 742, 2025 WL 3171740, at *5 (S.D. Cal. Nov. 12, 2025) (collecting cases and observing combination of browser information with other information captured by tracking pixels did not demonstrate a concrete injury to show Article III standing);
- Smidga v. Spirit Airlines, Inc., No. 22-CV-1578, 2024 WL 1485853, at *4 (W.D. Pa. Apr. 5, 2024) (“[C]ourts have held that even the collection of basic contact information by [ ] software or where the plaintiffs merely visited the website are not [ ] concrete harms.”).
- Magliocca v. United Healthcare Servs., No. 25-CV-3388, 2026 WL 878694, at *4 (E.D. Cal. Mar. 31, 2026) (“button clicks, page visits, session lengths, URLs, and IP addresses” were the kind of “non-sensitive browsing activity on a single website” that courts have repeatedly found insufficient to establish a concrete injury under the ECPA and state law).
Third – the disclosure of private information claim in the Zeta case was also dismissed because the court concluded plaintiffs inadequately pled any harm whatsoever from the profit claim and the potential to serve targeted ads to the plaintiffs and the putative class. The complaint did not allege any named plaintiff received any targeted advertising or were otherwise affected, let alone harmed, by it.
- In Re Zeta, at *7.
Conclusion
Class actions are wide and varied and are increasing in number. The stakes and risks for Corporate America have never been higher. The panel presentations at the Perfect Law Conference underscored these issues, and predicted more changes fueled by AI.
