[ad_1]
Customer lists held by vendors and personal information entered by users to obtain digital wallets or create crypto exchange accounts are enviable targets for hackers. This data can be used to launch targeted phishing programs and related scams to trick holders into divulging their private keys or unknowingly transferring anonymized crypto assets to hackers. A recent case involves a lawsuit brought by customers who purchased a hardware wallet to secure cryptocurrency assets and seek compensation for harms they allegedly suffered as a result of data breaches that exposed their personal information.
A recent Ninth Circuit decision analyzed whether a federal court had personal jurisdiction over a foreign crypto asset wallet provider, an issue that can be important when litigating in this area, given the borderless nature of the crypto asset world. and related services. (Baton v. Ledger SAS, No. 21-17036 (9th Cir. Dec. 1, 2022) (unreported)).
In the case, plaintiffs purchased hardware wallets to store crypto assets. Following data breaches that allegedly exposed personal information provided in connection with wallet purchases (e.g., names, email addresses, mailing addresses, and phone numbers), plaintiffs filed suit against Ledger SAS (” Ledger”), the French company that produced and sold the wallets and Shopify Inc., (“Shopify”), the Canadian company that provided e-commerce services for Ledger’s store, and its US subsidiary (collectively, the ” defendants”). Plaintiffs filed various claims in the California District Court, including negligence and consumer claims in California and other states based on their allegation that Ledger failed to exercise due diligence to secure their personal information.
In seeking dismissal, the defendants asserted that the court had no personal jurisdiction over them: Shopify Inc. argued that it was a Canadian company that is not registered to do business in California and has no California employees and “rogue” individuals who were responsible for a data breach of Shopify, Inc.’s platform (including, allegedly, certain ledger customer transactional records ) were not employees of Shopify, but foreign contractors; Ledger claimed it was a French company with no Californian or American employees. The district court granted the motions and dismissed the action for lack of personal jurisdiction over the defendants. The lower court found no specific jurisdiction over Shopify simply because it provided a software product that allowed Ledger to run an online store for consumers around the world, because it was Ledger, not Shopify, that makes the conscious choice to deliberately direct its product to the Californian forum. . Second, the court dismissed, as a “speculative” and “unwarranted” request for jurisdictional discovery from the plaintiffs seeking information on, among other things, the existence of employees who may have worked with the “rogue” contractors. involved in a breach and the alleged activities of a California-based data protection officer at Shopify. With respect to defendant Ledger, the lower court also found that the mere operation of a universally accessible website alone is generally insufficient to satisfy the requirement that Ledger “expressly designates” its conduct to California.
The Ninth Circuit reversed the dismissal of the action, affirming in part and reversing in part the lower court’s findings on jurisdiction. (Baton v. Ledger SAS, No. 21-17036 (9th Cir. Dec. 1, 2022) (unreported)). The appeals court found that the court had personal jurisdiction over Ledger due to its sales in the state, totaling approximately 70,000 wallets sold to Californians, generating millions of dollars in revenue. The court also said that Ledger’s website is designed to collect California sales tax applicable to buyers whose IP addresses are in California. Taken together, these facts establish “deliberate use” because Ledger’s contact with the forum cannot be characterized as “random, isolated, or incidental.” The court also said the plaintiffs’ claims “arose” from those wallet sales since the personal information was collected for e-commerce and marketing purposes. Yet the court limited the potential universe of claims that the putative class of plaintiffs could bring based on the existence of a broad forum selection clause in Ledger’s terms that requires “[a]any dispute, controversy, dispute or claim arising out of or relating to” the terms shall be brought exclusively in the courts of France. The court held that the choice of forum clause was binding, except in respect of claims under the laws consumer claims brought by California residents, concluding that these claims could not be waived for public policy reasons.
With respect to Shopify, the Ninth Circuit agreed that the present record did not support personal jurisdiction, but ruled that the lower court wrongly denied plaintiffs’ claims to find jurisdiction and an opportunity to amend the complaint to following such a discovery. The court noted that Shopify USA employs a number of people who work remotely from California, and that apparently one of those employees, at the relevant time, held the title of “Vice President, Legal; Data Protection officer”. In the opinion of the appeals court, it is reasonable to infer that Shopify’s California data protection officer “may have had a role in connection with the data breach because he appears to have overseen the policies of relevant privacy concerns and Shopify’s response”, but that more facts were needed. determine whether these activities support the practice of the skill.
2022 saw a record increase in the number of crypto-related hacking incidents (one report found over $3 billion worth of cryptocurrency stolen from January to October). The security incidents have particularly affected decentralized protocols, including the cross-chain bridges and smart contracts underlying DeFi, some of which may have been built on flawed code. These hacking incidents are occurring during the enduring crypto winter downturn, which has been exacerbated by the recent high-profile collapses and bankruptcies in the industry. One would expect more litigation by users against vendors over crypto assets stolen by hackers.
Additionally, this case signals that crypto-related businesses outside of the United States may be subject to the jurisdiction of the country, despite limited contact within its borders. Given the size of the US market, this may be a risk worth taking. To minimize the risk, depending on the company in question, steps can be taken to reduce the likelihood of such a finding.
Consumer law claims against French crypto asset wallet provider could be pursued in California court
The content of this article is intended to provide a general guide on the subject. Specialist advice should be sought regarding your particular situation.
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMilAFodHRwczovL3d3dy5tb25kYXEuY29tL3VuaXRlZHN0YXRlcy9maW4tdGVjaC8xMjczNTU2L2NvbnN1bWVyLWxhdy1jbGFpbXMtYWdhaW5zdC1mcmVuY2gtY3J5cHRvLWFzc2V0LXdhbGxldC1wcm92aWRlci1tYXktcHJvY2VlZC1pbi1jYWxpZm9ybmlhLWNvdXJ00gEA?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]