Affinity Credit Union v. Apple Inc.

District Court, N.D. California·Decided March 29, 2024·No. 4:22-cv-04174·Unknown

Opinion

AFFINITY CREDIT UNION, et al., Case No. 22-cv-04174-JSW

Plaintiffs, ORDER RESOLVING DISCOVERY v. DISPUTES

APPLE INC., Re: Dkt. No. 72 Defendant.

Now before the Court for consideration is the Joint Letter Brief regarding Disputed Provisions of Proposed Protective Order and Protocol for Electronically Stored Information (“ESI Protocol”). (Dkt. No. 72.) The Court finds the matter appropriate for resolution without further briefing or telephone conference. See Civ. L.R. 7-1(b); Civil Standing Order No. 7. Plaintiffs Affinity Credit Union, Greenstate Credit Union, and Consumers Co-Op Credit Union (“Plaintiffs”) and Defendant Apple Inc. (“Apple”) have submitted competing proposed Protective Orders and ESI Protocols. Although the competing proposed orders are substantially identical, Plaintiffs believe Apple’s desired security and confidentiality measures go too far. Apple counters that stringent measures are necessary because hackers increasingly target law firms to access confidential information, and it fears that certain documents could be used by Plaintiffs to gain commercial advantage in future negotiations. The parties’ dispute seemingly places in conflict two important concerns: on the one hand, expeditiously litigating this putative class action, and, on the other, safeguarding the parties (and innocent non-parties) from disclosure and misuse of their private information. Resolution is much simpler than this dispute would suggest because the least restrictive measures proposed by enters the final Protective Order and ESI Protocol in subsequent docket entries. A. The Court Adopts Provisions from Each of the Proposed Protective Orders. The parties disagree regarding one issue in Section 9 and two issues in Section 11 of the proposed Protective Orders. As discussed below, the Court adopts language from each of the parties’ proposals. 1. The Court Approves Apple’s Language Regarding Discovery Material Designated As “Highly Confidential – Attorneys’ Eyes Only.” The parties agree to include a category of confidential document production for “Highly Confidential” information that “is extremely confidential and/or sensitive in nature and [that] the Producing Party reasonably believes . . . is likely to (1) cause economic harm or significant competitive disadvantage to the Producing Party or (2) reveal personal identifiable information.” (Dkt. No. 72-1, at 1.) Apple seeks to make this category “Attorneys’ Eyes Only,” meaning that no client representatives may view the information. Plaintiffs propose permitting up to three client representatives and their immediate staff to access Highly Confidential materials. Apple argues that Plaintiffs may use the Highly Confidential materials for improper purposes, including in future negotiations with Apple. Plaintiffs contend that Apple’s concern lacks a reasonable basis because Plaintiffs and Apple are not competitors and because Apple uses standardized terms for all issuer banks. While Plaintiffs’ position has merit, the proposed “Highly Confidential” definition only relates to materials that could “cause economic harm or significant competitive disadvantage.” Because Plaintiffs and Apple are not competitors, and because Apple uses standardized terms, this definition cannot realistically cover a significant number of materials that impact Plaintiffs’ ability to assess the strengths and weaknesses of their case. The Court would be skeptical if the “Highly Confidential” designation were used more than sparingly to shield competitive information. The Court thus adopts Apple’s proposed language limiting this category to Attorneys’ Eyes Only. Plaintiffs may challenge the designation of some or all of the materials as Highly Confidential at a later date if Plaintiffs have a good faith basis to believe the designations are 2. The Court Approves Plaintiffs’ Language Regarding Data Security. Apple seeks an order requiring the parties to comply with one of three strict security protocols, reasoning that the trend in recent years has been for firms and courts to require stricter measures. Apple also requests language requiring multi-factor authentication for access to confidential materials. Plaintiffs argue that Apple’s cybersecurity protocols are impractical and expensive. They point out that, in the only identified similar case involving Apple’s proposed protocols, the plaintiffs and their experts spent 250 hours over the course of eight weeks to implement the protocols. (Dkt. No. 72, at 3.) Finally, Plaintiffs assert that Apple’s proposed language regarding multi-factor authentication is overbroad and ambiguous. Apple’s proposed language is a departure from the Model Protective Order for this District. Although the trend may be to adopt increasingly strict cybersecurity protocols, the Court finds that Plaintiffs’ proposed language is more than sufficient. Where the Model Protective Order requires Protected Material to be “stored and maintained. . . in a secure manner,” (see “Model Protective Order for Standard Litigation,” ¶ 7.1, available at https://www.cand.uscourts.gov/forms/model-protective-orders/), Plaintiff’s proposed language goes above and beyond: It requires the Receiving Party to “implement an information security management system (“ISMS”), including reasonable and appropriate administrative, physical, and technical safeguards and network security and encryption technologies governed by written policies and procedures, designed to protect against any reasonably anticipated threats or hazards to the security of such Protected Material and to protect against unauthorized access to Protected Material.” (Dkt. No. 72-1, at 3.) This is more than sufficient. The Court also finds Plaintiffs’ language regarding multi-factor authentication to be sufficient. Apple’s proposed language of “for any access” is vague, and it is unclear how the Court would enforce the provision. It is unclear to the Court if, for example, authentication would be required when opening every draft of a brief or letter, or if authentication when logging into one’s computer is sufficient. Plaintiffs’ language of “to prevent unauthorized access” is judicially administrable: if a breach occurs because an access point lacked multi-factor authentication, the 3. The Court Adopts Plaintiffs’ Language Regarding Data Breach Discovery. The parties define a “Data Breach” as including “any cyberattack or other deliberate security breach. . . including as a result of or following an inadvertent disclosure.” (Dkt. No. 72-1, at 4.) In the event of a Data Breach, “the Parties shall meet and confer in good faith regarding any adjustments that should be made to the discovery process and discovery schedule in this action.” (Id. at 5.) Apple seeks the following language be added: “Further, the Receiving Party shall submit to reasonable discovery concerning the Data Breach.” (Id.) Apple contends that its proposed language is reasonable, appropriate, and fulfills the purpose of the protective order. Plaintiffs respond that it is unreasonable to mandate data breach discovery and assert that a party can make an application for discovery if a breach occurs. The Court is concerned that Apple’s language would invite satellite disputes unrelated to resolution of this action. Moreover, Section 11(c) of the proposed Protective Orders requires compliance with “reasonable request(s) that Receiving Party investigate, remediate, and mitigate the effects of a Data Breach. . . [and] promptly provide any information that is reasonably requested by Producing Party and that relates to any such Data Breach. . . .” (Id. at 4.) If this informal discovery is insufficient, the Producing Party can seek leave to conduct formal discovery from the Court. 4. Leave of Court Is Required to File Documents Under Seal. The Court sua sponte modifies Section 1 and Section 13 of the Protective Order. No documents may be filed under seal without prior authorization from the Cour

Free access — add to your briefcase to read the full text and ask questions with AI

Affinity Credit Union v. Apple Inc., (N.D. Cal. 2024).

Affinity Credit Union v. Apple Inc. (Affinity Credit Union v. Apple Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related