“Cognizable damage” required for data breach claims, MA appeals court says in a first

Helpful guidance for businesses, and for Massachusetts state courts.

In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that in a suit for damages, “the mere risk of future harm, without more, cannot qualify as a concrete harm” sufficient to establish standing under Article III of the Constitution. (Emphasis added).

Since then, federal district courts and courts of appeal have reached different conclusions about how that principle applies to claims brought by individuals whose personal information was exposed as part of a data breach but who have not suffered a clear injury, such as identity theft or fraudulent charges.

The states have been no less confused, reaching different decisions as to whether data breach plaintiffs have alleged enough of an injury to have standing under the states’ own laws. In some states, the issue has been resolved by decisions from the states’ highest or mid-level appellate courts.

Until very recently, Massachusetts was one jurisdiction where this issue was still up in the air. That changed in June in the case of Cruceta v. J.C. Cannistraro LLC, in which the Appeals Court of Massachusetts held that plaintiffs do not have standing in data breach cases unless they allegedly suffered “cognizable damage” from the breach. 

(Constangy represented the defendant-employer in the Cruceta case.)

The prior lack of clarity

The Massachusetts Supreme Judicial Court has previously explained that “[t]o have standing in any capacity, a litigant must show that the challenged action has caused the litigant injury.”  Furthermore, “[i]njuries that are speculative, remote, and indirect are insufficient to confer standing.” 

Applying these principles, Massachusetts Superior Courts had consistently – but not uniformly – held that plaintiffs whose data was exposed as part of a data security incident must allege a “concrete injury” or “identifiable actual harm” to have standing to bring negligence and related claims against companies who were the victims of data breaches.

The Superior Courts’ approach was generally consistent with the conclusions of the U.S. Court of Appeals for the First Circuit. In Webb v. Injured Workers Pharmacy, LLC, the First Circuit held that the plaintiffs had standing based on the fact that the personal information of the named plaintiff was used “to file a fraudulent tax return,” an “actual misuse.”   

Applying Webb’s rationale, federal district court judges in Massachusetts have consistently dismissed putative class actions arising out of data breaches where there were no “allegations of actual misuse of information.” Indeed, in a 2025 case, the court declared that it was “not aware of any instances in the First Circuit where standing in a data breach case has been established absent some ‘actual misuse’ of the stolen data.”

However, the issue remained “live” at the state court level.

Clarity comes

In February 2023, plaintiff Ramon Cruceta sued his former employer, alleging that the employer had been negligent in failing to protect his personal information, which was exposed as part of an October 2020 ransomware attack.

The trial court granted the company’s motion for summary judgment on multiple grounds, including that “the plaintiff lacked standing to bring his claims because he failed to allege any nonspeculative injury.”

The Appeals Court has now affirmed that decision. The Court said it was “sympathetic to the impact of data breaches,” but said that Mr. Cruceta’s allegations of “severe distress because his private information is accessible to threat actors … is inadequate to state a claim.”

Regarding Mr. Cruceta’s negligence claim, the Court held that he “has not alleged any cognizable damage, such as monetary loss.”

The Appeals Court decision is considered to be only “persuasive authority,” meaning that Superior Courts may, but are not required to, follow it. However, it provides helpful guidance to the lower courts in evaluating future lawsuits by individuals whose personal information was exposed in data security breaches. Because of the significant increase in data breach litigation in recent years, the decision is a welcome and overdue clarification of Massachusetts law.

The Constangy Cybersecurity & Data Privacy Team regularly defends businesses of all sizes and industries against privacy lawsuits. With experience in jurisdictions across the nation, we are happy to help defend your organization. If you’d like to learn more, please contact us at cyber@constangy.com.

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek