Visa Inc. v. Sally Beauty Holdings, Inc.

Court of Appeals of Texas·Decided December 9, 2021·No. 02-20-00339-CV·Published

Opinion

In the

Court of Appeals Second Appellate District of Texas at Fort Worth

No. 02-20-00339-CV

VISA INC., Appellant

V.

SALLY BEAUTY HOLDINGS, INC., Appellee

On Appeal from the 158th District Court Denton County, Texas

Trial Court No. 19-6924-158

Before Sudderth, C.J.; Wallach and Walker, JJ.

Opinion by Chief Justice Sudderth

OPINION

Given how routine credit-card transactions have become, the average card-

carrying American could easily overlook the complex system that makes such transactions possible. One key component of that complex system is its contractual structure, which indirectly links merchants like Appellee Sally Beauty Holdings, Inc. to the network of transactional services provided by companies like Appellant Visa, Inc. The enforceability of certain terms within this contractual structure, as well as the security-related representations made by merchants participating in the Visa network, are at the center of this data-breach case.

After Sally Beauty’s allegedly sub-par network security enabled a credit-card network hack—Sally Beauty’s second in just over a year—Visa assessed approximately $14 million in liquidated damages against the company that linked Sally Beauty to the Visa network: Fifth Third Bank. Fifth Third passed the $14 million assessment on to Sally Beauty and assigned the merchant its claims against Visa. Sally Beauty sued, arguing that Visa had breached its contract with Fifth Third by collecting the $14 million assessment because the liquidated damages provision was an unenforceable penalty under California law. Visa countersued for fraud1 alleging that, in the fourteen months between Sally Beauty’s two hacks, Sally Beauty fraudulently misrepresented its

Visa also countersued for negligence, but it does not appeal the trial court’s 1

adverse summary judgment on its negligence counterclaim.

compliance with network security protocols as well as its intent to remain in compliance.

The parties filed competing motions for summary judgment, and the trial court granted Sally Beauty’s motions on both Sally Beauty’s contract claim and Visa’s fraud counterclaim. The court found that (1) the liquidated damages provision underlying the $14 million assessment was unenforceable under California law, and (2) Visa not only lacked standing to assert fraud but also failed to state a cognizable fraud claim under Texas law.2 We disagree on both counts. First, because the liquidated damages provision is presumed valid under California law and because none of Sally Beauty’s arguments invalidate it, we will reverse the trial court’s breach of contract judgment and hold that the liquidated damages provision is enforceable. And second, because Visa has standing to raise a fraud claim, because Sally Beauty sought dismissal of the fraud claim on the pleadings, and because we take Visa’s pleadings as true and construe them in its favor, we will reverse the trial court’s fraud judgment and hold that Visa stated a cognizable claim for fraud under Texas law. With both summary judgments reversed, we will remand the case for further proceedings.

2 The fraud findings stated above are implied; the trial court indicated the basis for its breach of contract judgment, but it did not indicate the basis for its judgment on Visa’s fraud counterclaim. See Provident Life & Acc. Ins. Co. v. Knott, 128 S.W.3d 211, 216 (Tex. 2003) (“Because the trial court’s order does not specify the grounds for its summary judgment, we must affirm the summary judgment if any of the theories presented to the trial court and preserved for appellate review are meritorious.”).

I. Background

Visa’s credit-card network involves multiple layers of contracts.

A. Network and Contractual Framework Generally, when a customer uses his Visa card at one of Sally Beauty’s beauty-

supply stores, (1) a point-of-sale system at Sally Beauty sends the card information to Sally Beauty’s acquiring bank, Fifth Third; (2) Fifth Third transmits the information via Visa’s network to the bank that issued the customer’s credit card; (3) the card- issuing bank authorizes the transaction; and (4) the authorization message is sent back through the Visa network to Sally Beauty to complete the transaction.3 Visa has contracts with the card-issuing banks and with the acquiring banks (such as Fifth Third), while the acquiring banks have contracts with the individual merchants (such as Sally Beauty). Otherwise, the system participants do not have contracts with one another. Consequently, Visa has established a set of rules to govern the system: the Visa Core Rules.

The Visa Core Rules are incorporated into Visa’s contracts with issuers and acquirers, and the acquirers in turn incorporate the Visa Core Rules into their contracts with merchants. The Visa Core Rules establish, among other things, (1) security requirements for network participants, (2) an investigation procedure for

3 See Landry’s, Inc. v. Ins. Co. of Pa., 4 F.4th 366, 367 (5th Cir. 2021) (describing parallel system).

data hacks, and (3) a system of liquidated damages known as the Global Compromised Account Recovery (GCAR) program.

1. Security Requirements First, the Visa Core Rules protect network security by requiring acquirers to

ensure that any merchant the acquirer connects to the Visa network complies with industry-wide security protocols known as the Payment Card Industry Data Security Standards (PCI DSS).4 Merchants whose Visa transactions exceed a certain threshold are required to undergo an annual security evaluation to ensure ongoing PCI DSS compliance. Sally Beauty was one such merchant.

This annual evaluation is generally conducted by a qualified security assessor (QSA),5 who validates the merchant’s compliance with more than 200 PCI DSS requirements.6 The QSA then completes a three-page summary of these findings, grouping the numerous tested requirements into 12 broad categories, such as “[i]nstall[ing] and maintain[ing] a firewall configuration to protect cardholder data”

4 The PCI DSS were adopted and are maintained by the Payment Card Industry Security Standards Council, LLC.

5 “Independent security organizations qualified by [the Payment Card Industry Security Standards Council] to validate an entity’s adherence to PCI DSS requirements are referred to as ‘Qualified Security Assessor Companies.’” Individuals employed by these companies as QSAs are required to complete an additional qualification process to conduct PCI DSS validation tests.

6 The QSA’s evaluation procedure includes more than 300 tests.

and “[p]rotect[ing] stored cardholder data.”7 The QSA marks the appropriate checkbox on the summary sheet to indicate the merchant’s compliance or noncompliance with each of these 12 categories.8 Both the QSA and the merchant then sign the summary sheet, affirming, among other things, that,

• [a]ll information within the above-referenced [report] and in this attestation [i.e., summary sheet] fairly represents the results of the assessment in all material respects[;]

• [t]he merchant has confirmed with the payment application vendor that [its] payment application does not store sensitive authentication data after authorization[; and]

• [t]he merchant has read the PCI DSS and recognizes that [it] must maintain full PCI DSS compliance at all times.

The Visa Core Rules provide that this signed summary, known as an attestation of compliance (AOC), must be included with the QSA’s report and submitted to the merchant’s acquirer and, ultimately, to Visa.

2. Investigation Procedures The PCI DSS protocols are merely one feature of the Visa Core Rules. The

second relevant feature is the investigation procedures.

In the event of a network hack, the Visa Core Rules require the hacked merchant, upon request, to hire an independent PCI DSS forensic investigator to

Free access — add to your briefcase to read the full text and ask questions with AI

Visa Inc. v. Sally Beauty Holdings, Inc., (Tex. Ct. App. 2021).

Visa Inc. v. Sally Beauty Holdings, Inc. (Visa Inc. v. Sally Beauty Holdings, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Serpa v. California Surety Investigations, Inc.
215 Cal. App. 4th 695 (California Court of Appeal, 2013)
Interstate Contracting Corp. v. City of Dallas
135 S.W.3d 605 (Texas Supreme Court, 2004)
Valence Operating Co. v. Dorsett
164 S.W.3d 656 (Texas Supreme Court, 2005)
Arkoma Basin Exploration Co. v. FMF Associates 1990-A, Ltd.
249 S.W.3d 380 (Texas Supreme Court, 2008)
Intercontinental Group Partnership v. KB Home Lone Star L.P.
295 S.W.3d 650 (Texas Supreme Court, 2009)
Aquaplex, Inc. v. Rancho La Valencia, Inc.
297 S.W.3d 768 (Texas Supreme Court, 2009)
In Re Lisa Laser USA, Inc.
310 S.W.3d 880 (Texas Supreme Court, 2010)
Frost National Bank v. Fernandez
315 S.W.3d 494 (Texas Supreme Court, 2010)
Basic Capital Management, Inc. v. Dynex Commercial, Inc.
348 S.W.3d 894 (Texas Supreme Court, 2011)
Bose Corporation v. Ejaz
732 F.3d 17 (First Circuit, 2013)
Mattei v. Hopper
330 P.2d 625 (California Supreme Court, 1958)
Bondanza v. Peninsula Hospital & Medical Center
590 P.2d 22 (California Supreme Court, 1979)
Perdue v. Crocker National Bank
702 P.2d 503 (California Supreme Court, 1985)
D. A. Parrish & Sons v. County Sanitation District Number 4
344 P.2d 883 (California Court of Appeal, 1959)
Fein v. Permanente Medical Group
695 P.2d 665 (California Supreme Court, 1985)
Kelley v. Upshaw
246 P.2d 23 (California Supreme Court, 1952)
Garrett v. Coast & Southern Federal Savings & Loan Ass'n
511 P.2d 1197 (California Supreme Court, 1973)
Ridgley v. Topa Thrift & Loan Assn.
953 P.2d 484 (California Supreme Court, 1998)