Visa Inc. v. Sally Beauty Holdings, Inc.

Court of Appeals of Texas·Decided December 9, 2021·No. 02-20-00339-CV·Published

Opinion

In the Court of Appeals Second Appellate District of Texas at Fort Worth ___________________________ No. 02-20-00339-CV ___________________________

VISA INC., Appellant

V.

SALLY BEAUTY HOLDINGS, INC., Appellee

On Appeal from the 158th District Court Denton County, Texas Trial Court No. 19-6924-158

Before Sudderth, C.J.; Wallach and Walker, JJ. Opinion by Chief Justice Sudderth OPINION

Given how routine credit-card transactions have become, the average card-

carrying American could easily overlook the complex system that makes such

transactions possible. One key component of that complex system is its contractual

structure, which indirectly links merchants like Appellee Sally Beauty Holdings, Inc. to

the network of transactional services provided by companies like Appellant Visa, Inc.

The enforceability of certain terms within this contractual structure, as well as the

security-related representations made by merchants participating in the Visa network,

are at the center of this data-breach case.

After Sally Beauty’s allegedly sub-par network security enabled a credit-card

network hack—Sally Beauty’s second in just over a year—Visa assessed approximately

$14 million in liquidated damages against the company that linked Sally Beauty to the

Visa network: Fifth Third Bank. Fifth Third passed the $14 million assessment on to

Sally Beauty and assigned the merchant its claims against Visa. Sally Beauty sued,

arguing that Visa had breached its contract with Fifth Third by collecting the $14

million assessment because the liquidated damages provision was an unenforceable

penalty under California law. Visa countersued for fraud1 alleging that, in the fourteen

months between Sally Beauty’s two hacks, Sally Beauty fraudulently misrepresented its

Visa also countersued for negligence, but it does not appeal the trial court’s 1

adverse summary judgment on its negligence counterclaim.

2 compliance with network security protocols as well as its intent to remain in

compliance.

The parties filed competing motions for summary judgment, and the trial court

granted Sally Beauty’s motions on both Sally Beauty’s contract claim and Visa’s fraud

counterclaim. The court found that (1) the liquidated damages provision underlying

the $14 million assessment was unenforceable under California law, and (2) Visa not

only lacked standing to assert fraud but also failed to state a cognizable fraud claim

under Texas law.2

We disagree on both counts. First, because the liquidated damages provision is

presumed valid under California law and because none of Sally Beauty’s arguments

invalidate it, we will reverse the trial court’s breach of contract judgment and hold that

the liquidated damages provision is enforceable. And second, because Visa has

standing to raise a fraud claim, because Sally Beauty sought dismissal of the fraud

claim on the pleadings, and because we take Visa’s pleadings as true and construe

them in its favor, we will reverse the trial court’s fraud judgment and hold that Visa

stated a cognizable claim for fraud under Texas law. With both summary judgments

reversed, we will remand the case for further proceedings.

2 The fraud findings stated above are implied; the trial court indicated the basis for its breach of contract judgment, but it did not indicate the basis for its judgment on Visa’s fraud counterclaim. See Provident Life & Acc. Ins. Co. v. Knott, 128 S.W.3d 211, 216 (Tex. 2003) (“Because the trial court’s order does not specify the grounds for its summary judgment, we must affirm the summary judgment if any of the theories presented to the trial court and preserved for appellate review are meritorious.”).

3 I. Background

Visa’s credit-card network involves multiple layers of contracts.

A. Network and Contractual Framework Generally, when a customer uses his Visa card at one of Sally Beauty’s beauty-

supply stores, (1) a point-of-sale system at Sally Beauty sends the card information to

Sally Beauty’s acquiring bank, Fifth Third; (2) Fifth Third transmits the information

via Visa’s network to the bank that issued the customer’s credit card; (3) the card-

issuing bank authorizes the transaction; and (4) the authorization message is sent back

through the Visa network to Sally Beauty to complete the transaction.3 Visa has

contracts with the card-issuing banks and with the acquiring banks (such as Fifth

Third), while the acquiring banks have contracts with the individual merchants (such

as Sally Beauty). Otherwise, the system participants do not have contracts with one

another. Consequently, Visa has established a set of rules to govern the system: the

Visa Core Rules.

The Visa Core Rules are incorporated into Visa’s contracts with issuers and

acquirers, and the acquirers in turn incorporate the Visa Core Rules into their

contracts with merchants. The Visa Core Rules establish, among other things,

(1) security requirements for network participants, (2) an investigation procedure for

3 See Landry’s, Inc. v. Ins. Co. of Pa., 4 F.4th 366, 367 (5th Cir. 2021) (describing parallel system).

4 data hacks, and (3) a system of liquidated damages known as the Global

Compromised Account Recovery (GCAR) program.

1. Security Requirements First, the Visa Core Rules protect network security by requiring acquirers to

ensure that any merchant the acquirer connects to the Visa network complies with

industry-wide security protocols known as the Payment Card Industry Data Security

Standards (PCI DSS).4 Merchants whose Visa transactions exceed a certain threshold

are required to undergo an annual security evaluation to ensure ongoing PCI DSS

compliance. Sally Beauty was one such merchant.

This annual evaluation is generally conducted by a qualified security assessor

(QSA),5 who validates the merchant’s compliance with more than 200 PCI DSS

requirements.6 The QSA then completes a three-page summary of these findings,

grouping the numerous tested requirements into 12 broad categories, such as

“[i]nstall[ing] and maintain[ing] a firewall configuration to protect cardholder data”

4 The PCI DSS were adopted and are maintained by the Payment Card Industry Security Standards Council, LLC. 5 “Independent security organizations qualified by [the Payment Card Industry Security Standards Council] to validate an entity’s adherence to PCI DSS requirements are referred to as ‘Qualified Security Assessor Companies.’” Individuals employed by these companies as QSAs are required to complete an additional qualification process to conduct PCI DSS validation tests. 6 The QSA’s evaluation procedure includes more than 300 tests.

5 and “[p]rotect[ing] stored cardholder data.”7 The QSA marks the appropriate

checkbox on the summary sheet to indicate the merchant’s compliance or

noncompliance with each of these 12 categories.8 Both the QSA and the merchant

then sign the summary sheet, affirming, among other things, that,

• [a]ll information within the above-referenced [report] and in this attestation [i.e., summary sheet] fairly represents the results of the assessment in all material respects[;]

• [t]he merchant has confirmed with the payment application vendor that [its] payment application does not store sensitive authentication data after authorization[; and]

• [t]he merchant has read the PCI DSS and recognizes that [it] must maintain full PCI DSS compliance at all times.

Free access — add to your briefcase to read the full text and ask questions with AI

Visa Inc. v. Sally Beauty Holdings, Inc., (Tex. Ct. App. 2021).

Visa Inc. v. Sally Beauty Holdings, Inc. (Visa Inc. v. Sally Beauty Holdings, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Serpa v. California Surety Investigations, Inc.
215 Cal. App. 4th 695 (California Court of Appeal, 2013)
Interstate Contracting Corp. v. City of Dallas
135 S.W.3d 605 (Texas Supreme Court, 2004)
Valence Operating Co. v. Dorsett
164 S.W.3d 656 (Texas Supreme Court, 2005)
Arkoma Basin Exploration Co. v. FMF Associates 1990-A, Ltd.
249 S.W.3d 380 (Texas Supreme Court, 2008)
Intercontinental Group Partnership v. KB Home Lone Star L.P.
295 S.W.3d 650 (Texas Supreme Court, 2009)
Aquaplex, Inc. v. Rancho La Valencia, Inc.
297 S.W.3d 768 (Texas Supreme Court, 2009)
In Re Lisa Laser USA, Inc.
310 S.W.3d 880 (Texas Supreme Court, 2010)
Frost National Bank v. Fernandez
315 S.W.3d 494 (Texas Supreme Court, 2010)
Basic Capital Management, Inc. v. Dynex Commercial, Inc.
348 S.W.3d 894 (Texas Supreme Court, 2011)
Bose Corporation v. Ejaz
732 F.3d 17 (First Circuit, 2013)
Mattei v. Hopper
330 P.2d 625 (California Supreme Court, 1958)
Bondanza v. Peninsula Hospital & Medical Center
590 P.2d 22 (California Supreme Court, 1979)
Perdue v. Crocker National Bank
702 P.2d 503 (California Supreme Court, 1985)
D. A. Parrish & Sons v. County Sanitation District Number 4
344 P.2d 883 (California Court of Appeal, 1959)
Fein v. Permanente Medical Group
695 P.2d 665 (California Supreme Court, 1985)
Kelley v. Upshaw
246 P.2d 23 (California Supreme Court, 1952)
Garrett v. Coast & Southern Federal Savings & Loan Ass'n
511 P.2d 1197 (California Supreme Court, 1973)
Ridgley v. Topa Thrift & Loan Assn.
953 P.2d 484 (California Supreme Court, 1998)