On this blog, we recently discussed the fact that some franchise systems, franchisors and franchisees are experimenting with table-side or other hand-held credit card swipe equipment. One advantage to such equipment is that the credit card never leaves the possession of the customer, thereby reducing the theoretical risk of data theft. A recent decision from the United States Court of Appeals for the First Circuit reminds us that data theft is real, and that its consequences may include costly legal ramifications.
Anderson v. Hannaford Brothers Co. involved the theft of up to 4.2 million credit card and debit card numbers, security codes and expiration dates from the electronic payment processing system of a national grocery chain. The stolen credit and debit cards had been used at over 270 of the chain’s stores. At least 1,800 cases of credit card fraud resulted from the theft. The fraud was international in scope, with unauthorized charges originating not just in the United States but in foreign countries including France and Spain.
Several cases brought by plaintiffs suffering alleged losses were consolidated into one case before a U.S. District Court Judge in Maine. Fourteen named plaintiffs had unauthorized charges to their accounts; seventeen had their cards canceled by the issuing bank; and two requested replacement cards. The district court dismissed all of the plaintiffs’ claims save for one who had suffered actual losses because the fraudulent charges to her account had not been reimbursed.
The First Circuit disagreed and reinstated claims sounding in theories of negligence and breach of implied contract under Maine law–which all parties agreed was the applicable law. The Court specifically held that mitigation costs such as card replacement costs and the purchase of credit insurance and credit monitoring services were recoverable. Why? Because such costs were “foreseeable” given the global nature of the actual, ongoing fraud, its widespread and pervasive extent, and the fact that the grocery chain could not specifically identify which cards had been compromised. Given such facts, the court found the card holders “were not merely exposed to a hypothetical risk, but to a real risk of misuse.” Accordingly, their decision to mitigate the risk of misuse was a foreseeable and therefore compensable loss.
While some comfort can be taken in the fact that the First Circuit Court of Appeals based its decision at least in part on the fact that actual fraud was ongoing in the Anderson case, franchisors and franchisees should not be complacent. Data theft is real, and the hackers–many of them foreign criminal syndicates–are becoming more and more sophisticated. The Anderson decision, moreover, is one example of the courts taking a harder look at who should bear the costs of mitigating foreseeable harm resulting from card theft. As such, franchise systems, franchisors and franchisees alike should be scrutinizing their agreements with each other as well as with third parties like card processing vendors, banks and their insurance carriers to protect themselves from foreseeable risk.