Thomas v. Kimpton Hotel & Restaurant Group, LLC

District Court, N.D. California·Decided April 20, 2022·No. 3:19-cv-01860-MMC·Unknown

Opinion

JAKE THOMAS, et al., Case No. 19-cv-01860-MMC

Plaintiffs, ORDER DENYING PLAINTIFFS' MOTION FOR CLASS v. CERTIFICATION; DENYING AS MOOT DEFENDANT'S MOTION TO KIMPTON HOTEL & RESTAURANT EXCLUDE OPINIONS OF PLAINTIFFS' GROUP, LLC, DAMAGES EXPERT Defendant. Before the Court are two motions: (1) plaintiffs Jake Thomas ("Thomas"), Salvatore Galati ("Galati"), and Jonathan Martin's ("Martin") Motion for Class Certification, filed September 21, 2021, and (2) defendant Kimpton Hotel & Restaurant Group, LLC's ("Kimpton") Motion to Exclude the Opinions of Plaintiffs' Damages Expert, filed November 22, 2021. The motions have been fully briefed. Having read and considered the papers filed in support of and in opposition to the motions, the Court rules as follows.1 In the operative complaint, the Third Amended Complaint ("TAC"), plaintiffs allege that Kimpton, an entity that "own[s] or manage[s]" hotels (see TAC ¶ 1), contracted with Sabre Corporation ("Sabre") "to provide a reservation system" (see TAC ¶ 3).2 Plaintiffs further allege they booked hotel reservations at Kimpton hotels (see TAC ¶ 2), and, in so doing, provided "private identifiable information" ("PII") (see TAC ¶¶ 11, 13, 15), which PII was subsequently "accessed by hackers" who "obtained credentials" for Sabre's "Central Reservations system" and "used those credentials to access customer data" (see TAC 1 By order filed March 9, 2022, the Court took the motions under submission. ¶¶ 6, 12, 14, 16). According to plaintiffs, if Sabre had "employed multiple levels of authentication," rather than "single factor authorization," the "hacker would not . . . have been able to access the system." (See TAC ¶ 6.) Plaintiffs further allege that Sabre was Kimpton's "agent" and thus that Kimpton is responsible for Sabre's conduct. (See, e.g., TAC ¶ 23.) Based on the above allegations, plaintiffs, on their own behalf and on behalf of a putative class, assert claims under state law. In an order filed June 30, 2020, the Court granted in part Kimpton's motion to dismiss the TAC. In particular, the Court denied the motion as to three Claims, specifically, the First Claim for Relief, the Third Claim for Relief, and a portion of the Eighth Claim for Relief. As to those three Claims, plaintiffs, by the instant motion, now seek to proceed on behalf of a certified class. A district court may not certify a class unless the plaintiff has "establish[ed] the four prerequisites of [Rule] 23(a)," see Valentino v. Carter–Wallace, Inc., 97 F.3d 1227, 1234 (9th Cir. 1996), namely: "(1) the class is so numerous that joinder of all members is impracticable; (2) there are questions of law or fact common to the class; (3) the claims or defenses of the representative parties are typical of the claims or defenses of the class; and (4) the representative parties will fairly and adequately protect the interests of the class," see Fed. R. Civ. P. 23(a). Further, the plaintiff must establish "at least one of the alternative requirements of [Rule] 23(b)." See Valentino, 97 F.3d at 1234. Rule 23(b)(3), upon which plaintiffs herein rely, provides for certification of a class where "the court finds that the questions of law or fact common to class members predominate over any questions affecting only individual members, and that a class action is superior to other available methods for fairly and efficiently adjudicating the controversy." See Fed. R. Civ. P. 23(b)(3). As noted, plaintiffs seek to proceed with their three remaining Claims on behalf of A. First Claim for Relief: Breach of Contract In the First Claim for Relief, plaintiffs allege that the terms of a "Privacy Statement" located on Kimpton's website were part of the contract formed when each plaintiff and putative class member reserved a hotel room, in that each was "required to accept the Privacy Statement" during the reservations process. (See TAC ¶ 68.) Plaintiffs also allege that the "Privacy Statement" included a "promise to safeguard and protect the [c]lass [m]embers' PII from disclosure to third parties" (see TAC ¶ 70), and that such promise was breached by the "failure to safeguard and protect the PII" (see TAC ¶ 75). In support of their motion for class certification, plaintiffs offer copies of Kimpton's "Privacy Policy" in effect during the relevant time period,3 which Policy contains the following language, on which plaintiffs base their breach of contract claim:

We work diligently to protect the security of your personal information, including credit card information, during transmission by using Secure Sockets Layer (SSL) software, which encrypts information you input. Your data is kept in a highly secure environment protected from access by unauthorized parties. It is important for you to protect against unauthorized access to your password and to your customer profile by ensuring that you logoff when you have finished visiting our site. (See Marquez Decl., filed September 21, 2021, Ex. 10 at 4, Ex. 11 at 4.) Additionally, plaintiffs state they are basing their breach of contract claim on the following statement, which they assert was shown to them on the "payment page" when they made their reservations:

Free access — add to your briefcase to read the full text and ask questions with AI

Thomas v. Kimpton Hotel & Restaurant Group, LLC, (N.D. Cal. 2022).

Thomas v. Kimpton Hotel & Restaurant Group, LLC (Thomas v. Kimpton Hotel & Restaurant Group, LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Fidelity & Guaranty Life Insurance Co. v. Pina
165 S.W.3d 416 (Court of Appeals of Texas, 2005)
Kaplan v. Coldwell Banker Residential Affiliates, Inc.
59 Cal. App. 4th 741 (California Court of Appeal, 1997)
Cruz v. Andrews Restoration, Inc.
364 S.W.3d 817 (Texas Supreme Court, 2012)
Valentino v. Carter-Wallace, Inc.
97 F.3d 1227 (Ninth Circuit, 1996)