Skip to content

Thought Leadership

Cybersecurity class actions against database defendants persist, but hurdles for plaintiffs remain

July 25, 2024

By Sarah Dever Letson, CIPP/C, Meaghan McCaw and Bertina Lou[1]

Two decisions earlier this month from the Court of Appeal for British Columbia left open the question as to whether so-called “database defendants” can be held liable in negligence or statutory privacy torts where, due to their inadequate security, a third-party hacker accesses a person’s private information in the database defendant’s possession.[2]

In both cases, the Court of Appeal concluded that class actions based on negligence and statutory breach of privacy claims were “not bound to fail.”

These cases arguably broaden the potential application of statutory privacy torts to database defendants. Both statutory and common law privacy torts do not require proof of actual damage. However, plaintiffs will still face challenges on proving damages for those claims, such as negligence, that require proof of pecuniary loss.

G.D. v. South Coast British Columbia Transportation Authority, 2024 BCCA 252

In 2020, TransLink was the subject of a cyberattack. Third-party hackers gained access to TransLink’s network drives and were able to view and extract employee personal information. Former employees of TransLink sought to be appointed as the proposed representative plaintiffs in a class proceeding.

The original claim for certification was denied. The statutory tort based on British Columbia’s Privacy Act required that the defendant: (i) wilfully, and, (ii) without a claim of right, (iii) violated the privacy of the plaintiff. The chambers judge concluded that a data custodian cannot be liable under the Privacy Act in the event of a data breach caused by a third-party hacker because this “willful” component would be lacking.

On appeal, the Court concluded that the use of the word “wilfully” will be interpreted differently depending on the statutory purpose and context. The Court found that it is arguable that a person’s reasonable expectation of privacy may include an expectation that their personal information will be safeguarded and protected by the database defendant to whom they entrusted it, so as to protect the privacy in the information. Therefore, depending on the circumstances, it is at least arguable that a database defendant, who has collected plaintiffs’ private information but failed to safeguard it from an unrelated cyber attacker, has committed the statutory tort of “wilful violation of privacy”.

The Court of Appeal also overturned the chambers judge’s denial of certification in negligence. The chambers judge had decided that the claim in negligence amounted to a claim for negligent breach of a statutory duty, a claim that is not permissible at law. On appeal, the Court concluded that it is not plain and obvious that TransLink owed no duty of care in negligence to the appellants whose private information it collected and stored, or that for policy reasons this Court ought to find TransLink should owe no such duties of care.

However, the Court noted that every negligence claim must include the element that the plaintiff suffered harm. It remains an open question whether harm to the class can be properly assessed in the aggregate, in cases where only some of the plaintiffs claim this risk has materialized in that they have been subject to fraud.

Campbell v. Capital One Financial Corporation

Campbell v Capital One Financial Corporation[3] was certified as a multi-jurisdictional class proceeding before the Supreme Court of British Columbia in 2022. The case concerns a hacker’s downloading of the personal and financial information of roughly six million Canadian customers and 100 million American customers of Capital One bank.

The hearing judge had certified the class action for the claims of negligence, breach of contract, breach of statutory privacy torts, and breach of consumer protection legislation, and disallowed five of the other claims: breach of warranty, breach of contractual duty of honest performance, breach of confidence, intrusion upon seclusion, and breach of the Civil Code of Québec.

The appellant appealed the chambers judge’s findings with respect to the claim for breach of confidence based on the wrongful retention of confidential information, and the claim under British Columbia’s Negligence Act assigning joint and several liability to Capital One for the tort of intrusion upon seclusion committed by the hacker.

The Court concluded that the claim of breach of confidence was not made out in the pleadings on the basis that the unauthorized use of the information and any ensuing detriment from that use was attributable to the hacker only, and not to Capital One.

However, consistent with the decision in G.D. v. South Coast British Columbia Transportation Authority, the Court of Appeal did not disturb the finding of the chambers judge that a claim against the database defendant based on the statutory tort found in the Privacy Act was “not bound to fail.”

On the claim under the Negligence Act, the Court of Appeal held that the Negligence Act does not extend to circumstances wherein the conduct of different tortfeasors gives rise to different kinds of damage. The tort of intrusion upon seclusion allows for the recovery of “moral” or “symbolic” damages, where there is no pecuniary loss. To the contrary, in order to be successful, a claim in negligence requires actual loss.

The “intrusion” was committed by the hacker, not Capital One, and the Court held that the Negligence Act cannot be used to hold a negligent party jointly and severally liable for the kind of damage for which it could never have been responsible if acting alone.

How this may affect you

These cases highlight a key distinction between those provinces that have statutory privacy torts (including, notably, Newfoundland and Labrador) and those that do not.

In provinces where there is no statutory privacy tort, such as Ontario, the Ontario Court of Appeal has been clear that if a data custodian was to be liable for the “intrusion” actions of an independent third-party hacker, this would be a “drastic” extension of liability beyond the parameters of the “intrusion upon seclusion” common law tort (see, most recently, Del Giudice v. Thompson, 2024 ONCA 70 at para. 35).

This pair of decisions from the British Columbia Court of Appeal make it clear that the statutory privacy law torts and the common law tort of intrusion upon seclusion are not identical; therefore, the result may vary depending on the facts and jurisdiction of a particular breach.

Lawyers from our Privacy Group are always available to discuss and help you decide on the best strategic approach for your legal issues.


This client update is provided for general information only and does not constitute legal advice. If you have any questions about the above, please contact the authors or a member of our Privacy Group.

Click here to subscribe to Stewart McKelvey Thought Leadership.

[1] At time of publication, Bertina Lou was employed with the Firm as a summer law student.
[2] Campbell v. Capital One Financial Corporation, 2024 BCCA 253 (CanLII) G.D. v. South Coast British Columbia Transportation Authority, 2024 BCCA 252
[3] Campbell v Capital One Financial Corporation, 2022 BCSC 928 (CanLII)

SHARE

Archive

Search Archive


Occupational Health and Safety sentencing decision – Nova Scotia

April 29, 2024

By Sean Kelly & Tiegan Scott Earlier this month, the Provincial Court of Nova Scotia issued its sentencing decision in R v The Brick Warehouse LP, 2024 NSPC 26, imposing a monetary penalty of $143,750 (i.e.,…

Read More

Canada 2024 Federal Budget paves the way for Open Banking

April 22, 2024

By Kevin Landry On April 15, 2024, the Canadian federal budget was released. Connected to the budget was an explanation of the framework for Canada’s proposed implementation of Open Banking (sometimes called consumer-driven banking). This follows…

Read More

Reset for renewables: Nova Scotia overhauls energy regulation and governance in advance of influx of renewable energy

April 5, 2024

By Nancy Rubin and James Gamblin The Government of Nova Scotia has embarked on a path to dramatically reshape the regulation and governance of the energy sector with the passage of Bill 404, the Energy…

Read More

An employer’s guide to human rights law in Atlantic Canada

April 2, 2024

By Kathleen Starke and Annie Gray Human rights landscape Human rights legislation prohibits discrimination in specific contexts, including employment and the provision of services. In all Atlantic Provinces, Human Rights Commissions are responsible for enforcing…

Read More

Recognizing subtle discrimination in the workplace: insights from recent legal cases

March 4, 2024

By Sheila Mecking and Michiko Gartshore Subtle discrimination can have a much stronger and longer effect on employees when not properly addressed. It can also result in costly consequences for an employer who does not…

Read More

Immediate changes to travel eligibility for citizens of Mexico

February 29, 2024

By Brittany Trafford and Brendan Sheridan Today Immigration, Refugees and Citizenship Canada (“IRCC”) has announced significant changes to the travel requirements for Mexican citizens. As of February 29, 2024 at 11:30p.m. Eastern Time, all electronic…

Read More

Updated guidance on business reporting obligations under Canada’s supply chain transparency legislation

February 23, 2024

By Christine Pound, ICD.D., Twila Reid, ICD.D., Sarah Dever Letson, CIPP/C, Hilary Newman and Daniel Roth Introduction As we reported on November 30, 2023, the Fighting Against Forced Labour and Child Labour in Supply Chains…

Read More

Trustees beware! New trust reporting and disclosure requirements under the Income Tax Act are here – are you ready for them?

February 21, 2024

By Richard Niedermayer, K.C., TEP  & Rackelle Awad New trust disclosure rules originally announced on February 27, 2018, are now in force, and trusts with taxation years ending on or after December 31, 2023 are…

Read More

Proposed Criminal Interest Rate Regulations: exemptions to the lower criminal interest rate

February 14, 2024

By David Wedlake and Andrew Paul In late December 2023, the Federal Government issued draft Criminal Interest Rate Regulations under the Criminal Code. These proposed regulations follow the Budget Implementation Act, 2023, No. 1 which…

Read More

Outlook for 2024 Proxy Season

February 9, 2024

By Andrew Burke, Colleen Keyes, Gavin Stuttard, David Slipp and Logan Walters With proxy season on the horizon, many public companies are once again preparing their annual disclosure documents and shareholder materials for their annual…

Read More

Search Archive


Scroll To Top