{"id":1480,"date":"2024-06-03T22:22:22","date_gmt":"2024-06-04T02:22:22","guid":{"rendered":"https:\/\/blogs.duanemorris.com\/classactiondefense\/?p=1480"},"modified":"2024-06-03T22:35:26","modified_gmt":"2024-06-04T02:35:26","slug":"four-best-practices-for-deterring-cybersecurity-and-data-privacy-class-actions-and-mass-arbitrations","status":"publish","type":"post","link":"https:\/\/blogs.duanemorris.com\/classactiondefense\/2024\/06\/03\/four-best-practices-for-deterring-cybersecurity-and-data-privacy-class-actions-and-mass-arbitrations\/","title":{"rendered":"Four Best Practices For Deterring Cybersecurity And Data Privacy Class Actions And Mass Arbitrations"},"content":{"rendered":"<p><strong><a href=\"http:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/security-2168233_1280.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-1483\" src=\"http:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/security-2168233_1280-300x190.jpg\" alt=\"\" width=\"300\" height=\"190\" srcset=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/security-2168233_1280-300x190.jpg 300w, https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/security-2168233_1280-1024x649.jpg 1024w, https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/security-2168233_1280-768x487.jpg 768w, https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/security-2168233_1280.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>By <a href=\"https:\/\/www.duanemorris.com\/attorneys\/justindonoho.html#tab_Biography\">Justin Donoho<\/a><\/strong><\/p>\n<p><strong><em>Duane Morris Takeaway:<\/em><\/strong><em> Class action lawsuits and mass arbitrations alleging cybersecurity incidents and data privacy violations are rising exponentially.\u00a0 Corporate counsel seeking to deter such litigation and arbitration demands from being filed against their companies should keep in mind the following four best practices: (1) add or update arbitration clauses to mitigate the risks of mass arbitration; (2) use cybersecurity best practices, including continuously improving and prioritizing compliance activities; (3) audit and adjust uses of website advertising technologies; and (4) update website terms of use, data privacy policies, and vendor agreements.<\/em><\/p>\n<p><strong>Best Practices<\/strong><\/p>\n<ol>\n<li><strong> Add or update arbitration agreements to mitigate the risks of mass arbitration<\/strong><\/li>\n<\/ol>\n<p>Many organizations have long been familiar with the strategy of deterring class and collective actions by presenting arbitration clauses containing class and collective action waivers prominently for web users, consumers, and employees to accept via click wrap, browse wrap, login wrap, shrink wrap, and signatures.\u00a0 Such agreements would require all allegedly injured parties to file individual arbitrations in lieu of any class or collective action.\u00a0 Moreover, the strategy goes, filing hundreds, thousands, or more individual arbitrations would be cost-prohibitive for so many putative plaintiffs and thus deter them from taking any action against the organization in most cases.<\/p>\n<p>Over the last decade, this strategy of deterrence was effective.<a href=\"#_ftn1\" name=\"_ftnref1\"><sup>[1]<\/sup><\/a>\u00a0 Times have changed.\u00a0 Now enterprising plaintiffs\u2019 attorneys with burgeoning war chests, litigation funders, and high-dollar novel claims for statutory damages are increasingly using mass arbitration to pressure organizations into agreeing to multimillion dollar settlements, just to avoid the arbitration costs.\u00a0 In mass arbitrations filed with the American Arbitration Association (AAA) or Judicial Arbitration and Mediation Services (JAMS), for example, fees can total millions of dollars just to defend only 500 individual arbitrations.<a href=\"#_ftn2\" name=\"_ftnref2\"><sup>[2]<\/sup><\/a>\u00a0 One study found upfront fees ranging into the tens of millions of dollars for some large mass arbitrations.<a href=\"#_ftn3\" name=\"_ftnref3\"><sup>[3]<\/sup><\/a>\u00a0 Companies with old arbitration clauses have been caught off guard with mass arbitrations, have sought relief from courts to avoid having to defend these mass arbitrations, and this relief was rejected in several recent decisions where the court ordered the defendant to arbitrate and pay the required hefty mass arbitration fees.<a href=\"#_ftn4\" name=\"_ftnref4\"><sup>[4]<\/sup><\/a><\/p>\n<p>If your organization has an arbitration clause, then one of the first challenges for counsel defending many newly served class action lawsuits these days is determining whether to move to compel arbitration.\u00a0 Although it could defeat the class action, is it worth the risk of mass arbitration and the potential projected costs of mass arbitration involved?\u00a0 Sometimes not.<\/p>\n<p>Increasingly organizations are mitigating this risk by including mechanisms in their arbitration clauses such as pre-dispute resolution clauses, mass arbitration waivers, bellwether procedures, arbitration case filing requirements, and more.\u00a0 This area of the law is developing quickly.\u00a0 One case to watch will be one of the first appellate cases to address the latest trend of mass arbitrations &#8212; <em>Wallrich v. Samsung Electronics America, Inc.<\/em>, No. 23-2842 (7th Cir.) (argued February 15, 2024, at issue is whether the district court erred in ordering the BIPA defendant to pay over $4 million in mass arbitration fees).<\/p>\n<ol start=\"2\">\n<li><strong> Use cybersecurity best practices, including continuously improving and prioritizing<\/strong><\/li>\n<\/ol>\n<p>IT organizations have long been familiar with the maxim that they should continuously improve their cybersecurity measures and other IT services.\u00a0 Continuous improvement is part of many IT industry guidelines, such as ISO 27000, COBIT, ITIL, the NIST Cybersecurity Framework (CSF) and Special Publication 800, and the U.S. Department of Energy\u2019s Cybersecurity Capability Maturity Model (C2M2).\u00a0 Continuous improvement is becoming increasingly necessary in cybersecurity, as organizations\u2019 IT systems and cybercriminals\u2019 tools multiply at an increased rate.\u00a0 The volume of data breach class actions doubled three times from 2019-2023:<\/p>\n<p><a href=\"http:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/Data-breach.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1481\" src=\"http:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/Data-breach.png\" alt=\"\" width=\"425\" height=\"297\" srcset=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/Data-breach.png 425w, https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/06\/Data-breach-300x210.png 300w\" sizes=\"auto, (max-width: 425px) 100vw, 425px\" \/><\/a><\/p>\n<p>Continuous improvement of cybersecurity measures needs to accelerate accordingly.\u00a0 As always, IT organizations need to prioritize.\u00a0 Priorities typically include:<\/p>\n<ul>\n<li>improving IT governance;<\/li>\n<li>complying with industry guidelines such as ISO, COBIT, ITIL, NIST, and C2M2;<\/li>\n<li>deploying multifactor authentication, network segmentation, and other multilayered security controls;<\/li>\n<li>staying current with identifying, prioritizing, and patching security holes as new ones continuously arise;<\/li>\n<li>designing and continuously improving a cybersecurity incident response plan;<\/li>\n<li>routinely practicing handling ransomware incidents with tabletop exercises (may be covered by cyber-insurers); and<\/li>\n<li>implementing and continuously improving security information and event management (SIEM) systems and processes.<\/li>\n<\/ul>\n<p>Measures like these to continuously improve and prioritize: (a) will help prevent a cybersecurity incident from occurring in the first place; and (b) if one occurs, will help the victim organization of cybertheft defend against plaintiffs\u2019 arguments that the organization failed to use reasonable cybersecurity measures.<\/p>\n<ol start=\"3\">\n<li><strong> Audit and adjust uses of website advertising technologies<\/strong><\/li>\n<\/ol>\n<p>In 2023, plaintiffs filed over 250 class actions alleging that Meta Pixel, Google Analytics, and other similar software embedded in defendants\u2019 websites secretly captured plaintiffs\u2019 web browsing data and sent it to Meta, Google, and other online advertising agencies, respectively.\u00a0 This software, often called website advertising technologies or \u201cadtech\u201d (and often referred to by plaintiffs as \u201ctracking technologies\u201d) is a common feature on many websites in operation today \u2014 millions of companies and governmental organizations have it.<a href=\"#_ftn5\" name=\"_ftnref5\"><sup>[5]<\/sup><\/a>\u00a0 These lawsuits generally allege that the organization\u2019s use of adtech violated federal and state wiretap statutes, consumer fraud statutes, and other laws, and often seek hundreds of millions of dollars in statutory damages.\u00a0 The businesses targeted in these cases so far mostly have been healthcare providers but also span nearly every industry including retailers, consumer products, and universities.<\/p>\n<p>Several of these cases have resulted in multimillion-dollar settlements, several have been dismissed, and the vast majority remain undecided.\u00a0 The legal landscape in this area has only begun to develop under many plaintiffs\u2019 theories of liability, statutes, and common laws.\u00a0 The adtech alleged has included not only Meta Pixel and Google Analytics but also dozens of the hundreds or thousands of other types of adtech.\u00a0 All this legal uncertainty multiplied by requested statutory damages equals serious business risk to any organization with adtech on its public-facing website(s).<\/p>\n<p>An organization may not know that adtech is present on its public-facing websites.\u00a0 It could have been installed on a website by a vendor without proper authorization, for example, or as a default without any human intent by using some web publishing tools.<\/p>\n<p>Organizations should consider whether to have an audit performed before any litigation arises as to which adtech is or has been installed on which web pages when and which data types were transmitted as a result.\u00a0 Multiple experts specialize in such adtech audits and serve as expert witnesses should any litigation arise.\u00a0 An adtech audit is relatively quick and inexpensive and it might be cost-beneficial for an organization to perform an adtech audit before litigation arises because: (a) it might convince an organization to turn off some of its unneeded adtech now, thereby cutting off any potential damages relating to that adtech in a future lawsuit; (b) in the event of a future lawsuit, such an audit would not be wasted \u2014 it is one of the first things adtech defendants typically perform upon being served with an adtech lawsuit; and (c) an adtech audit could assist in presently updating and modernizing website terms of use, data privacy policies, and vendor agreements (next topic).<\/p>\n<ol start=\"4\">\n<li><strong> Update and modernize website terms of use, data privacy policies, and vendor agreements<\/strong><\/li>\n<\/ol>\n<p>Organizations should consider whether to modify their website terms of use and data privacy policies to describe the organization\u2019s use of adtech in additional detail.\u00a0 Doing so could deter or help defend a future adtech class action lawsuit similar to the many that are being filed today, alleging omission of such additional details, raising claims brought under various states\u2019 consumer fraud acts, and seeking multimillion-dollar statutory damages.<\/p>\n<p>Organizations should consider adding to contracts with website vendors and marketing vendors clauses that prohibit the vendor from incorporating any unwanted adtech into the organization\u2019s public-facing websites.\u00a0 That could help disprove the element of intent at issue in many claims brought under the recent explosion of adtech lawsuits.<\/p>\n<p><strong>Implications For Corporations:<\/strong> Implementation of these best practices is critical to mitigating risk and saving litigation dollars.\u00a0 Click to learn more about the services Duane Morris provides in the practice areas of <a href=\"https:\/\/www.duanemorris.com\/practices\/classactionlitigation.html\">Class Action Litigation<\/a>; <a href=\"https:\/\/www.duanemorris.com\/practices\/arbitration_mediation_adr.html\">Arbitration, Mediation, and Alternative Dispute Resolution<\/a>; <a href=\"https:\/\/www.duanemorris.com\/practices\/cybersecurity.html\">Cybersecurity<\/a>; <a href=\"https:\/\/www.duanemorris.com\/practices\/privacy_and_data_protection.html\">Privacy and Data Protection<\/a>; <a href=\"https:\/\/www.duanemorris.com\/practices\/healthcare_information_technology.html\">Healthcare Information Technology<\/a>; and <a href=\"https:\/\/www.duanemorris.com\/practices\/privacy_and_security_for_healthcare_providers.html\">Privacy and Security for Healthcare Providers<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> In 2015, for example, a large study found that of 33 banks that had engaged in practices relating to debit card overdrafts, 18 endured class actions and ended up paying out $1 billion to 29 million customers, whereas 15 had arbitration clauses and did not endure any class actions.\u00a0 <em>See <\/em>Consumer Protection Financial Bureau (CPFB), <em>Arbitration Study: Report to Congress, Pursuant to Dodd-Frank Wall Street Reform and Consumer Protection Act \u00a7 1028(a) <\/em>at Section 8, available at https:\/\/files.consumerfinance.gov\/f\/201503_cfpb_arbitration-study-report-to-congress-2015.pdf.\u00a0 These 15 with arbitration clauses paid almost nothing\u2014less than 30 debit card customers per year in the entire nation filed any sort of arbitration dispute regarding their cards during the relevant timeframe.\u00a0 <em>See id.<\/em> at Section 5, Table 1.\u00a0 Another study of AT&amp;T from 2003-2014 found similarly, concluding, \u201cAlthough hundreds of millions of consumers and employees are obliged to use arbitration as their remedy, almost none do.\u201d\u00a0 Judith Resnik, <em>Diffusing Disputes: The Public in the Private of Arbitration, the Private in Courts, and the Erasure of Rights<\/em>, 124 Yale L.J. 2804 (2015).<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> AAA, Consumer Mass Arbitration and Mediation Fee Schedule (amended and effective Jan. 15, 2024), available at https:\/\/www.adr.org\/sites\/default\/files\/Consumer_Mass_Arbitration_and_Mediation_Fee_Schedule.pdf; JAMS, Arbitration Schedule of Fees and Costs, available at https:\/\/www.jamsadr.com\/arbitration-fees.<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> J. Maria Glover, <em>Mass Arbitration<\/em>, 74 Stan. L. Rev. 1283, 1387 &amp; Table 2 (2022).<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>See, e.g., BuzzFeed Media Enters., Inc. v. Anderson<\/em>, 2024 WL 2187054, at *1 (Del. Ch. May 15, 2024) (dismissing action to enjoin mass arbitration of claims brought by employees); <em>Hoeg v. Samsung Elecs. Am., Inc.<\/em>, No. 23-CV-1951 (N.D. Ill. Feb. 2024) (ordering defendant of BIPA claims brought by consumers to pay over $300,000 in AAA filing fees); <em>Wallrich v. Samsung Elecs. Am., Inc.<\/em>, 2023 WL 5935024 (N.D. Ill. Sept. 12, 2023) (ordering defendant of BIPA claims brought by consumers to pay over $4 million in AAA fees); <em>Uber Tech., Inc. v. AAA<\/em>, 204 A.D.3d 506, 510 (N.Y. App. Div. 2022) (ordering defendant of reverse discrimination claims brought by customers to pay over $10 million in AAA case management fees).<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>See, e.g.<\/em>, Customer Data Platform Institute, \u201cTrackers and pixels feeding data broker stores,\u201d reporting \u201c47% of websites using Meta Pixel, including 55% of S&amp;P 500, 58% of retail, 42% of financial, and 33% of healthcare\u201d (available at https:\/\/www.cdpinstitute.org\/news\/trackers-and-pixels-feeding-data-broker-data-stores\/); builtwith, \u201cFacebook Pixel Usage Statistics,\u201d offering access to data on over 14 million websites using the Meta Pixel, stating, \u201cWe know of 5,861,028 live websites using Facebook Pixel and an additional 8,181,093 sites that used Facebook Pixel historically and 2,543,263 websites in the United States\u201d (available at https:\/\/trends.builtwith.com\/analytics\/Facebook-Pixel).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Justin Donoho Duane Morris Takeaway: Class action lawsuits and mass arbitrations alleging cybersecurity incidents and data privacy violations are rising exponentially.\u00a0 Corporate counsel seeking to deter such litigation and arbitration demands from being filed against their companies should keep in mind the following four best practices: (1) add or update arbitration clauses to mitigate &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/2024\/06\/03\/four-best-practices-for-deterring-cybersecurity-and-data-privacy-class-actions-and-mass-arbitrations\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Four Best Practices For Deterring Cybersecurity And Data Privacy Class Actions And Mass Arbitrations&#8221;<\/span><\/a><\/p>\n","protected":false},"author":583,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[91,59],"tags":[],"ppma_author":[30],"class_list":["post-1480","post","type-post","status-publish","format-standard","hentry","category-data-breach-class-actions","category-privacy-class-actions"],"authors":[{"term_id":30,"user_id":583,"is_guest":0,"slug":"classactiondefense","display_name":"Class Action Defense","avatar_url":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2020\/10\/dmlogo.jpg","0":null,"1":"","2":"","3":"","4":"","5":"","6":"","7":"","8":""}],"_links":{"self":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts\/1480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/users\/583"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/comments?post=1480"}],"version-history":[{"count":0,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts\/1480\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/media?parent=1480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/categories?post=1480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/tags?post=1480"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/ppma_author?post=1480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}