In re TJX Companies Retail Security Breach Litigation

246 F.R.D. 389, 69 Fed. R. Serv. 3d 1053, 2007 U.S. Dist. LEXIS 87920, 2007 WL 4199597
District Court, D. Massachusetts·Decided November 29, 2007·No. Civil Action No. 07-10162-WGY·Published·Cited by 19 cases

Opinion

MEMORANDUM AND ORDER

YOUNG, District Judge.

I. INTRODUCTION

This Court has previously discussed the background and progress of this litigation. See In re TJX Cos. Sec. Breach Litig., 524 F.Supp.2d 83, 86-88, 2007 WL 2982994, at *1-3 (D.Mass. Oct. 12, 2007); McMorris v. TJX Cos., Inc., 493 F.Supp.2d 158, 160-61 (D.Mass.2007). As a result, only the most relevant history will be mentioned here.

On September 9, 2007, Amerifirst Bank and its newly added co-plaintiff, SELCO Community Credit Union (collectively, “Amerifirst”), ask the Court to recognize a class action against Fifth Third Bank and Fifth Third Bancorp (“Fifth Third”). Amerifirst, Saugusbank, Collinsville Savings Society, and Eagle Bank join forces with the Massachusetts Bankers Association, the Connecticut Bankers Association, and the Maine Association of Community Banks (collectively, the “issuing banks”) and also seek the certification of a class against the TJX Companies, Inc. (“TJX”).

After thorough briefing, the Court heard oral argument on October 16. In the interim, this Court issued an order granting in part and denying in part Fifth Third and [392]*392TJX’s motions to dismiss, leaving in play only the issuing banks’ claims of negligent misrepresentation and an alleged violation of Massachusetts General Laws Chapter 93A, based on negligent misrepresentation.1

II. DISCUSSION

A plaintiff who seeks to certify a class action has the burden of demonstrating that four prerequisites enumerated in Federal Rule of Civil Procedure 23(a), plus one of the provisions of Federal Rule of Civil Procedure 23(b), are satisfied. Smilow v. Southwestern Bell Mobile Sys., Inc., 323 F.3d 32, 38 (1st Cir.2003) (citing Amchem Prods., Inc. v. Windsor, 521 U.S. 591, 614, 117 S.Ct. 2231, 138 L.Ed.2d 689 (1997)). Rule 23(a) requires that:

(1) the class is so numerous that joinder of all members is impracticable, (2) there are questions of law or fact common to the class, (3) the claims or defenses of the representative parties are typical of the claims or defenses of the class, and (4) the representative parties will fairly and adequately protect the interests of the class.

Fed.R.Civ.P. (23)(a).

Once Rule 23(a)’s initial bar is hurdled, Rule 23(b) sets forth the three situations in which a class action can be maintained. Amerifirst and the issuing banks rely primarily on Rule 23(b)(3), see Issuing Banks’ Memo. Sup. Class Cert. (“Issuing Banks’ Memo.”) [Doc. 128] at 10-18; Amerifirst Memo. Sup. Class Cert. (“Amerifirst Memo.”) [Doe. 130] at 7-19, which permits certification when “the court finds that the questions of law or fact common to the class predominate over any questions affecting only individual members, and that a class action is superior to other available methods for the fair and efficient adjudication of the controversy.” Fed.R.Civ.P. 23(b)(3). Amerifirst and the issuing banks also suggest that Rule 23(b)(2), which allows for certification when “the party opposing the class has acted or refused to act on grounds generally applicable to the class, thereby making appropriate final injunctive relief or corresponding declaratory relief with respect to the class as a whole,” Fed.R.Civ.P. 23(b)(2), is appropriate. See Issuing Banks’ Memo, at 18; Amerifirst Memo, at 19-20.

Although Amerifirst and the issuing banks filed separate motions for class certification, the class definitions in those motions are identical and encompass

all financial institutions [nationwide] who received an alert from MasterCard or Visa related to the security breach of TJX’s computer system in Framingham, Massachusetts and identifying one or more credit or debit cards issued by the financial institution.

Amerifirst Mot. to Cert. Class [Doc. 124] at 2; Issuing Banks Mot. to Cert. Class [Doc. 127] at 1. Interestingly, this definition appears broader than the class that Amerifirst and the issuing banks delineated in their consolidated class complaints, which would have included in the class only “financial institutions that have suffered damages and/or harm as a result of the data breaches.” Issuing Banks’ Am. Compl. [Doc. 81] ¶ 28; Amerifirst Am. Compl. [Doc. 142] ¶ 67.

This Court has serious doubts whether the class as proposed in the motions for class certification is properly defined.2 Fur[393]*393thermore, this Court is uncertain that the class definition set forth in the Amended Complaints is proper because, as the Court will describe below, in many instances it will not be obvious that an issuing bank’s injuries occurred “as a result of the data breaches” as opposed to an unrelated fraud. Where individualized fact-finding is required to identify class members, “the class fails to satisfy one of the basic requirements for a class action under Rule 23.” Crosby v. Social Sec. Admin., 796 F.2d 576, 580 (1st Cir.1986).

Ultimately, however, the Court need not focus on this issue because the dispositive element in this case—the predominance of individualized questions—applies equally to both proposed class definitions.

A. Requirements of Rule 23(a)

The parties apparently agree that the proposed class would fulfill Rule 23(a)’s numerosity and commonality requirements. Rather, the dispute centers around whether the named plaintiffs can be considered typical and whether they can be relied upon adequately to represent absent class members.

1. Typicality

“[A] plaintiffs claim is typical if it arises from the same event or practice or course of conduct that gives rise to the claims of other class members, and if his or her claims are based on the same legal theory.” In re Neurontin Mktg. and Sale Practices Litig., 244 F.R.D. 89, 106 (D.Mass.2007) (Saris, J.); see also Modell v. Eliot Sav. Bank, 139 F.R.D. 17, 22 (D.Mass.1991) (Harrington, J.). The goal underlying the typicality analysis is to ensure that “the interests of the class and the class representatives [are such] that the latter will work to benefit the entire class through the pursuit of their own goals.” Neurontin, 244 F.R.D. at 105-106.

It is obvious that the proposed class as a whole is premised on the same “course of conduct”—namely, the alleged failure of Fifth Third and TJX to maintain proper data security and their alleged failure to notify third parties about this deficiency. It is further apparent that the negligent misrepresentation and Chapter 93A theories of recovery asserted by Amerifirst and the issuing banks theoretically could have caused injury to many members of the proposed class.3

Free access — add to your briefcase to read the full text and ask questions with AI

In re TJX Companies Retail Security Breach Litigation, 246 F.R.D. 389, 69 Fed. R. Serv. 3d 1053, 2007 U.S. Dist. LEXIS 87920, 2007 WL 4199597 (D. Mass. 2007).

246 F.R.D. 389 (In re TJX Companies Retail Security Breach Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Derick Ortiz, v. Sig Sauer, Inc.
2023 DNH 015 (D. New Hampshire, 2023)
Labrier v. State Farm Fire & Casualty Co.
315 F.R.D. 503 (W.D. Missouri, 2016)
Ferreira v. Sterling Jewelers, Inc.
130 F. Supp. 3d 471 (D. Massachusetts, 2015)
In re Hannaford Bros.
293 F.R.D. 21 (D. Maine, 2013)
Donovan v. Philip Morris USA, Inc.
268 F.R.D. 1 (D. Massachusetts, 2010)
De Giovanni v. Jani-King International, Inc.
262 F.R.D. 71 (D. Massachusetts, 2009)
Mogel v. Unum Life Insurance Co. of America
646 F. Supp. 2d 177 (D. Massachusetts, 2009)
In Re TJX Companies Retail SEC. Breach Litigation
564 F.3d 489 (First Circuit, 2009)
AmeriFirst Bank v. TJX Companies, Inc.
564 F.3d 489 (First Circuit, 2009)
In Re TJX Companies Retail Security Breach Litigation
527 F. Supp. 2d 209 (D. Massachusetts, 2007)