Banc of Am. Merch. Servs., LLC v. Arby's Rest. Grp., Inc.

2021 NCBC 41
North Carolina Business Court·Decided June 30, 2021·No. 20-CVS-426·Published

Opinion

Banc of Am. Merch. Servs., LLC v. Arby’s Rest. Grp., Inc., 2021 NCBC 41.

STATE OF NORTH CAROLINA IN THE GENERAL COURT OF JUSTICE SUPERIOR COURT DIVISION

MECKLENBURG COUNTY 20 CVS 426

BANC OF AMERICA MERCHANT SERVICES, LLC,

Plaintiff and Counterclaim Defendant,

v.

ORDER AND OPINION

ARBY’S RESTAURANT GROUP, ON CROSS-MOTIONS FOR INC., SUMMARY JUDGMENT

Defendant, Counterclaim

Plaintiff, and Third-Party Plaintiff,

v.

VISA, INC.; and MASTERCARD INTERNATIONAL INC.,

Third-Party Defendants.

1. Arby’s Restaurant Group, Inc. operates a nationwide chain of fast-food restaurants. In 2017, it reported a data security breach that exposed the payment card data of many of its customers. Two payment card organizations—Visa, Inc. and Mastercard International Inc.—separately reviewed the incident and concluded that Arby’s had not complied with prevailing industry standards for data security. Arby’s disputed this at the time and continues to dispute it now. Nevertheless, Visa and Mastercard assessed nearly $20 million in penalties and fees. They did not impose these assessments on Arby’s, which has no direct relationship with either card organization. Instead, they imposed the assessments on Banc of America Merchant

Services, LLC (“BAMS”), the bank that sponsored Arby’s as a participating merchant in the payment card networks. 1 2. This case is about who bears ultimate responsibility for the assessments. After exhausting appeals before Visa and Mastercard, BAMS paid the assessments and then asked Arby’s for reimbursement. Arby’s refused; BAMS sued. In short, BAMS believes that it has a right to be indemnified for the assessments under its contract with Arby’s and that Arby’s breached the contract when it refused to pay. Arby’s denies that it has any duty to indemnify BAMS. It also contends that Visa and Mastercard never should have imposed the assessments in the first place and has asserted third-party claims against them.

3. Several motions are currently pending. Visa and Mastercard have each moved to dismiss the third-party claims asserted by Arby’s. A separate opinion, also issued today, addresses those motions.

4. Two other motions are the subject of this opinion. BAMS and Arby’s agreed to defer discovery in favor of early summary-judgment practice as to their claims and defenses against one another. BAMS seeks partial summary judgment; Arby’s contends that it is entitled to summary judgment across the board. For the following reasons, the Court DENIES both motions.

McGuireWoods LLP, by Jodie Herrmann Lawson, and Covington & Burling LLP, by Alexander A. Berengaut, for Plaintiff/Counterclaim Defendant Banc of America Merchant Services, LLC.

1 It would be more accurate to say that Visa and Mastercard imposed the fees on Bank of

America, N.A. (“BANA”), which is related to BAMS. The parties agree, though, that BANA has assigned its claims in this case to BAMS. To avoid unnecessarily complicating the facts, the Court refers to both, together, as BAMS throughout this opinion.

Smith, Anderson, Blount, Dorsett, Mitchell & Jernigan, L.L.P., by Christopher G. Smith, and Orrick, Herrington & Sutcliffe LLP, by Seth Harrington and Douglas H. Meal, for Defendant/Counterclaim Plaintiff/Third-Party Plaintiff Arby’s Restaurant Group, Inc.

Bradley Arant Boult Cummings LLP, by C. Bailey King, Jr. and Bridget V. Warren, and O’Melveny & Myers LLP, by Randall W. Edwards, Megan Havstad, and Eric Ormsby, for Third-Party Defendant Visa Inc.

Cozen O’Connor, by Tracy L. Eggleston, and Golenbock Eiseman Assor Bell & Peskoe LLP, by Martin S. Hyman and Matthew C. Daly, for Third-

Party Defendant Mastercard International, Inc. 2

Conrad, Judge.

I.

BACKGROUND

5. The Court does not make findings of fact when ruling on motions for summary judgment. The following background, drawn from the evidence submitted by the parties, is intended only to provide context for the Court’s analysis and ruling.

6. The issues presented require some understanding of the structure of payment card networks. At the center, of course, are the card organizations. Visa and Mastercard operate the networks that make debit and credit card transactions possible. (See Joint Stip. Suppl. Facts ¶ 1, ECF No. 32 [“Stip.”].) But neither the consumers who use credit and debit cards nor the merchants that accept them have a direct relationship with Visa or Mastercard. Rather, consumers and merchants participate in the networks through intermediaries. Consumers get payment cards from “issuers” (financial institutions that issue the cards), and merchants affiliate with “acquirers” (financial institutions that offer access to the networks). (See Stip.

2 After these motions were filed, the Court granted Ms. Warren, Ms. Lawson, and Ms.

Havstad leave to withdraw as counsel. (ECF Nos. 93, 131, 136.)

¶¶ 3–5.) Acquirers and issuers in turn have contracts with Visa, Mastercard, or both. (See Stip. ¶ 6.)

7. Acquirers and issuers play key roles, again as intermediaries, in processing card transactions. When a consumer presents a card for payment at the point of sale, the merchant transmits the card information to its acquirer. The acquirer then asks the relevant card organization and issuer to authorize the transaction. Assuming authorization is given, the consumer and the merchant complete the transaction, and the issuer pays the merchant sometime later. (See Stip. ¶ 6.)

8. Here, BAMS is an acquirer for Visa and Mastercard and has a contract with each. (See Stip. ¶¶ 7, 10.) Arby’s is one of BAMS’s affiliated merchants. The merchant agreement between Arby’s and BAMS dates to 2009; it is separate and distinct from BAMS’s contracts with Visa and Mastercard. (See Stip. ¶ 9.)

9. This case is about data security—specifically, the responsibilities of BAMS (as acquirer) and Arby’s (as merchant) to safeguard payment card data and to pay for losses resulting from a data breach. Visa and Mastercard publish extensive rules related to data security—and many other things—and incorporate them into contracts with acquirers, including BAMS. (See Stip. ¶ 10.) It is BAMS’s responsibility to ensure that its merchants meet industry standards for data security, formally called Payment Card Industry (“PCI”) Data Security Standards. (See Stip. ¶ 10.)

10. Each card organization also oversees programs designed to remedy losses from a security breach. These include Visa’s Account Information Security (“AIS”)

and Global Compromised Account Recovery (“GCAR”) programs and Mastercard’s Account Data Compromise (“ADC”) program. The details of each program are in the record (swelling to over a hundred pages), but a summary will suffice. (See App. Exs. D, E, G, K, O, ECF No. 33.1.)3 In short, if a merchant suffers a data security incident, Visa and Mastercard may impose assessments on BAMS using various criteria. BAMS has the right to appeal. Assuming the appeal is denied and payment is made, Visa and Mastercard then distribute the funds to participating issuers, ostensibly to compensate them for losses due to fraud and the need to issue replacement cards to consumers. (See App. Ex. O at 1; App. Ex. Q at 12.) The AIS program also takes into account reputational harm to Visa from the incident. (App. Ex. K at 11.) Neither card organization takes a position on whether BAMS can or should seek reimbursement from the merchant for assessments imposed through these programs. (See App. Ex. D §§ 1.10.4.1, 1.12.3.1; App. Ex. E §§ 10.1, 10.2.1; see also App. Ex. H at 1; App. Ex. P at 3.)

11. BAMS’s merchant agreement with Arby’s incorporates the card organization rules issued by Visa and Mastercard. Arby’s must comply with those rules and any applicable “existing and future” PCI Data Security Standards. (App. Ex. A § 13(A) [“Merchant Agrmt.”]; see also Merchant Agrmt. §§ 1, 7(A)(xi).) Section 13, which deals with information security, also requires Arby’s to “engage a certified forensic vendor acceptable to the Card Organizations” after any “suspected or confirmed” data breach. (Merchant Agrmt. § 13(D).)

Free access — add to your briefcase to read the full text and ask questions with AI

Banc of Am. Merch. Servs., LLC v. Arby's Rest. Grp., Inc., 2021 NCBC 41 (N.C. Super. Ct. 2021).

2021 NCBC 41 (Banc of Am. Merch. Servs., LLC v. Arby's Rest. Grp., Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Morales v. Trans World Airlines, Inc.
504 U.S. 374 (Supreme Court, 1992)
Jennings v. United States
374 F.2d 983 (Fourth Circuit, 1967)
Parks Chevrolet, Inc. v. Watkins
329 S.E.2d 728 (Court of Appeals of North Carolina, 1985)
Lane v. Scarborough
200 S.E.2d 622 (Supreme Court of North Carolina, 1973)
Lowe v. Bradford
289 S.E.2d 363 (Supreme Court of North Carolina, 1982)
Gaston County Dyeing MacHine Co. v. Northfield Insurance
524 S.E.2d 558 (Supreme Court of North Carolina, 2000)
Furr v. K-Mart Corp.
543 S.E.2d 166 (Court of Appeals of North Carolina, 2001)
Singleton v. Haywood Electric Membership Corp.
588 S.E.2d 871 (Supreme Court of North Carolina, 2003)
Pleasant Valley Promenade v. Lechmere, Inc.
464 S.E.2d 47 (Court of Appeals of North Carolina, 1995)
State v. Philip Morris USA Inc.
618 S.E.2d 219 (Supreme Court of North Carolina, 2005)
City of Wilmington v. North Carolina Natural Gas Corp.
450 S.E.2d 573 (Court of Appeals of North Carolina, 1994)
Feibus & Co., Inc. v. Godley Const. Co., Inc.
271 S.E.2d 385 (Supreme Court of North Carolina, 1980)
Kirkpatrick & Associates, Inc. v. Wickes Corp.
280 S.E.2d 632 (Court of Appeals of North Carolina, 1981)
Register v. White
599 S.E.2d 549 (Supreme Court of North Carolina, 2004)
Bridgestone/Firestone, Inc. v. Ogden Plant Maintenance Co. of North Carolina
548 S.E.2d 807 (Court of Appeals of North Carolina, 2001)
Bone International, Inc. v. Brooks
283 S.E.2d 518 (Supreme Court of North Carolina, 1981)
Blackwell v. Massey
316 S.E.2d 350 (Court of Appeals of North Carolina, 1984)