Standing & Damages

Article III Standing in Privacy Lawsuits: The Doctrine That Decides Them

Key Takeaways

  • TransUnion LLC v. Ramirez states the rule as "No concrete harm, no standing" — a statutory violation alone does not open the federal courthouse door
  • Concreteness turns on whether the asserted harm has a close relationship to a harm traditionally recognised at common law; the Court requires an analogue, not an exact duplicate
  • In a damages suit the mere risk of future harm is not itself concrete, though the same risk can support standing for injunctive relief
  • Standing is not dispensed in gross: every class member must have it to recover individual damages, and it must be shown for each claim and each form of relief
  • A dismissal for lack of Article III standing does not end a case, because state courts are not bound by Article III and many hear the identical claim

Why Standing Decides Privacy Cases

Article III of the Constitution limits the federal judicial power to "Cases" and "Controversies." The doctrine built on that phrase requires a plaintiff to show an injury in fact that is concrete and particularised, traceable to the defendant, and redressable by a favourable ruling. In most fields that requirement is background scenery. In privacy litigation it is frequently the whole case.

The reason is structural. Privacy statutes tend to create rights that are violated the moment a procedure is skipped — a disclosure not given, a consent not obtained, a record not deleted — and to attach fixed statutory damages to the violation without requiring proof of loss. A plaintiff can therefore state a complete statutory claim while having nothing to say about what the violation cost. Whether that is enough for a federal court to hear the claim is the question Article III asks, and it is answered before anyone reaches the merits.

Two Supreme Court decisions supply the framework, and neither arose from a privacy statute in the modern sense. Both construed the Fair Credit Reporting Act, and both concerned credit files rather than the tracking technologies that generate most current litigation. Their reasoning nevertheless governs claims under the Illinois Biometric Information Privacy Act, the Telephone Consumer Protection Act, the Video Privacy Protection Act and every data breach class action filed in federal court.

Spokeo and the Separation of Concrete From Particularised

In Spokeo, Inc. v. Robins, 578 U.S. 330 (2016), the plaintiff alleged that a people-search site had published inaccurate information about him in violation of the FCRA. The Ninth Circuit had found standing because his statutory rights were his own rather than a general grievance. The Supreme Court vacated, holding that the court of appeals had addressed particularisation while skipping concreteness.

The opinion is careful about what Congress can and cannot do. Congress "may elevat[e] to the status of legally cognizable injuries concrete, de facto injuries that were previously inadequate in law," and its judgment about what counts as harm is "instructive and important." But that power has a limit the Court stated directly:

The Court illustrated the point with an example that has been quoted in privacy litigation ever since: a consumer reporting agency might fail to give a required notice about information that is entirely accurate, and "not all inaccuracies cause harm or present any material risk of harm. An example that comes readily to mind is an incorrect zip code." Spokeo also preserved a route in the other direction, noting that "the violation of a procedural right granted by statute can be sufficient in some circumstances to constitute injury in fact," so that a plaintiff "need not allege any additional harm beyond the one Congress has identified."

Spokeo resolved nothing on its own facts. It remanded for the Ninth Circuit to decide whether the particular violations alleged entailed "a degree of risk sufficient to meet the concreteness requirement," and expressly took no position on the answer. The five years that followed produced the divisions the next decision was taken to address.

TransUnion and the Common-Law Analogue Test

TransUnion LLC v. Ramirez, No. 20-297, 594 U.S. ___ (2021), reported at 141 S. Ct. 2190, arose from an OFAC Name Screen product that flagged consumers whose first and last names matched entries on a Treasury Department list of terrorists and drug traffickers. A class of 8,185 people whose files carried such alerts won a jury verdict of roughly $40 million. The parties had stipulated that only 1,853 of them had a misleading report actually sent to a third party during the class period.

The Court opened with the sentence that now frames the entire area: "To have Article III standing to sue in federal court, plaintiffs must demonstrate, among other things, that they suffered a concrete harm. No concrete harm, no standing." It then supplied the test Spokeo had gestured at, asking whether the asserted harm bears a "close relationship" to one "traditionally recognized as providing a basis for a lawsuit in American courts — such as physical harm, monetary harm, or various intangible harms including (as relevant here) reputational harm."

Applied to the class, the test split it. The 1,853 members whose reports reached third parties had suffered something closely analogous to defamation, and had standing. The remaining 6,332, whose files contained the same false alerts but were never disseminated, did not — the Court analogised their position to a defamatory letter drafted and left in a drawer. The two mailing-format claims failed for everyone except the named plaintiff.

The Third Circuit has since read the analogue requirement as a loose one rather than a strict historical match, noting in Clemens v. ExecuPharm that in looking for a common-law analogue "we do not require an exact duplicate," quoting TransUnion itself. The difficulty in practice is less the looseness of the analogy than identifying which traditional harm a modern data practice resembles.

Risk of Future Harm Depends on the Relief Sought

TransUnion's second holding matters most to data breach litigation. The 6,332 plaintiffs argued that the presence of a false terrorist alert in a file that might be disclosed at any time was itself a harm. The Court rejected that for a damages claim, reasoning that "in a suit for damages, the mere risk of future harm, standing alone, cannot qualify as a concrete harm — at least unless the exposure to the risk of future harm itself causes a separate concrete harm."

The limitation is tied to remedy rather than to risk. Citing Clapper v. Amnesty International USA, 568 U.S. 398 (2013), the Court confirmed that "a person exposed to a risk of future harm may pursue forward-looking, injunctive relief to prevent the harm from occurring, at least so long as the risk of harm is sufficiently imminent and substantial," while a plaintiff "must demonstrate standing separately for each form of relief sought." Clapper had also held that plaintiffs "cannot manufacture standing by choosing to make expenditures based on hypothetical future harm that is not certainly impending" — the proposition that governs whether money spent on credit monitoring counts as injury.

The practical consequence is that one set of facts can produce standing for an injunction and none for damages, which is where most privacy class actions live.

The Data Breach Split

Data breach claims are the hardest fit, because the injury usually alleged is the possibility that stolen data will later be misused. The courts of appeals have divided, and the division survived TransUnion.

In Clemens v. ExecuPharm, Inc., No. 21-1506 (3d Cir. Sept. 2, 2022), a ransomware group called CLOP took employee records including Social Security numbers, bank account numbers and passport data, and published them on a dark-web forum. The Third Circuit held the risk sufficiently imminent to be an injury in fact, and read the injury-in-fact standard as disjunctive: an injury must be "actual or imminent," so an unmaterialised risk can qualify if imminent enough. The opinion also catalogued the factors that had been driving outcomes elsewhere — whether the data was actually misused, and whether its nature (identifiers rather than card numbers alone) creates identity-theft exposure.

Its survey of sister circuits shows the spread. The Seventh Circuit had found standing without any allegation of misuse where a breach "increas[ed] the risk of future harm that the plaintiff would have otherwise faced." The Second Circuit in McMorris v. Carlos Lopez & Associates treated misuse affecting anyone in the class as cutting toward standing. The D.C. Circuit in Attias v. CareFirst focused on the identity-theft potential of the data taken. The Eighth Circuit in In re SuperValu held that disclosure of financial information alone, without corresponding personal information, was insufficient.

The restrictive pole is Tsao v. Captiva MVP Restaurant Partners, LLC, No. 18-14959 (11th Cir. Feb. 4, 2021), where the Eleventh Circuit affirmed dismissal of a claim arising from a restaurant payment-card breach. It held the risk of future identity theft insufficiently imminent, and separately held that the plaintiff's own mitigation efforts could not supply the injury, applying Clapper's rule against manufactured standing.

The same breach can therefore produce a viable federal claim in Philadelphia and no federal claim in Atlanta.

Statutory Damages Do Not Substitute for Injury

Privacy statutes commonly fix damages per violation — $1,000 per negligent BIPA violation and $5,000 per reckless one, $500 per TCPA call or text and up to $1,500 for wilful violations. Because these figures are set without proof of loss, they are frequently mistaken for a legislative determination that any violation is an injury. Spokeo forecloses that reading, and TransUnion applied it to a jury verdict already rendered.

What Congress can do, on the Eleventh Circuit's account, is calibrate degree rather than invent kind. Sitting en banc in Drazen v. Pinto, 74 F.4th 1336 (11th Cir. 2023), the court held that receipt of a single unwanted text message is a concrete injury because it "shares a close relationship with the harm underlying the tort of intrusion upon seclusion," adding that although such a message is "insufficiently offensive to satisfy the common law's elements, Congress has used its lawmaking powers to recognize a lower quantum of injury necessary to bring a claim under the TCPA," so the harm "is smaller in degree rather than entirely absent."

That decision replaced the same circuit's earlier holding in Salcedo v. Hanna, 936 F.3d 1162 (11th Cir. 2019), which had found a single text insufficient after examining "history and the judgment of Congress" and declining to generalise from congressional findings about telemarketing calls and junk faxes to text messages. Salcedo had split the Eleventh Circuit from the Ninth, which had found standing in Van Patten on the view that "Congress identified unsolicited contact as a concrete harm" — a reading Salcedo called a "broad overgeneralization."

How the Test Lands on Biometric Claims

BIPA claims have generally fared better than breach claims, because the statute regulates conduct rather than paperwork alone. In Bryant v. Compass Group USA, Inc., No. 20-1443 (7th Cir. May 5, 2020), the plaintiff used fingerprint-enabled vending machines without receiving BIPA section 15(b)'s required disclosures or giving written consent. The Seventh Circuit held that failure inflicted "an invasion of personal rights that is both concrete and particularized": the loss of the ability to make an informed decision about the collection and use of biometric identifiers.

The court distinguished section 15(b), which creates a personal right to informed consent, from section 15(a)'s duty to publish a retention schedule, which it treated as an obligation owed to the public at large rather than to any individual — the public-rights distinction Justice Thomas set out in his Spokeo concurrence.

State Court as the Alternative Forum

Article III binds federal courts only. State courts apply their own justiciability rules, and many are markedly more permissive, so a claim that cannot be heard in federal court may proceed unchanged across the street.

This inverts the ordinary alignment of the parties. Bryant reached the Seventh Circuit because the plaintiff had filed in Illinois state court, the defendant removed to federal court, and then the plaintiff moved to remand on the ground that she lacked the concrete injury Article III requires. The district court agreed with the plaintiff's own argument against her standing and remanded; the defendant appealed and the Seventh Circuit reversed, holding she did have standing and so belonged in federal court. The defendant was arguing for the plaintiff's standing and the plaintiff against it, because each preferred the forum the answer produced.

A dismissal on Article III grounds is therefore not necessarily a defence win. It is a determination about which court hears the case.

The Class Certification Interaction

TransUnion's most consequential procedural holding is short: "Every class member must have Article III standing in order to recover individual damages," quoting Chief Justice Roberts's concurrence in Tyson Foods for the proposition that "Article III does not give federal courts the power to order relief to any uninjured plaintiff, class action or not." The Court added that "standing is not dispensed in gross; rather, plaintiffs must demonstrate standing for each claim that they press and for each form of relief sought."

That makes standing a question about class composition rather than about the named plaintiff alone, and it interacts with Rule 23 predominance: if establishing standing requires individual proof for each member, the individual questions may swamp the common ones. A class defined to include members who cannot show concrete harm faces the problem TransUnion identified directly, which is why class definitions are now drafted around it.

One question the Court expressly left open is when this must be resolved. Footnote 4 of TransUnion states: "We do not here address the distinct question whether every class member must demonstrate standing before a court certifies a class," citing the Eleventh Circuit's decision in Cordoba v. DIRECTV. Whether uninjured members defeat certification or are stripped out later remains unsettled.

What Remains Unresolved

The analogue test asks courts to match modern data practices to nineteenth-century torts, and the matching is contested. Disclosure of viewing or browsing history maps onto public disclosure of private facts, but courts divide on whether disclosure to a single commercial recipient satisfies an analogy built around publicity. Unwanted messages map onto intrusion upon seclusion, as Drazen held. Retention of biometric identifiers without consent has no obvious nineteenth-century counterpart at all.

The data breach split is the largest open division and has persisted through TransUnion rather than being resolved by it, because TransUnion addressed risk of future harm in a suit for damages without settling how imminent a risk must be before exposure itself becomes a present injury. Clemens and Tsao reach different answers on facts that are not far apart. Neither the timing question in TransUnion's footnote 4 nor the breach split has been taken up by the Supreme Court.

Frequently Asked Questions

What is Article III standing in a privacy lawsuit?
It is the constitutional requirement that a plaintiff in federal court show an injury in fact that is concrete and particularised, traceable to the defendant and redressable by the court. TransUnion LLC v. Ramirez states the privacy-specific formulation as "No concrete harm, no standing," meaning a statutory violation on its own does not establish it.
Does a violation of a privacy statute automatically create standing?
No. Spokeo, Inc. v. Robins holds that "Article III standing requires a concrete injury even in the context of a statutory violation," and that a plaintiff cannot rely on "a bare procedural violation, divorced from any concrete harm." Congress may recognise intangible harms, but cannot dispense with the concreteness requirement.
Is the risk that stolen data will be misused enough for standing?
It depends on the relief sought and on the circuit. TransUnion held that in a damages suit "the mere risk of future harm, standing alone, cannot qualify as a concrete harm" unless the exposure causes a separate concrete harm, while the same risk can support injunctive relief if sufficiently imminent and substantial. The Third Circuit found imminence satisfied in Clemens where data was published on the dark web; the Eleventh Circuit found it lacking in Tsao.
Does every member of a class need standing?
To recover individual damages, yes. TransUnion holds that "[e]very class member must have Article III standing in order to recover individual damages" and that standing must be shown for each claim and each form of relief. The Court expressly left open, in footnote 4, whether standing must be demonstrated before a class is certified.
What happens to a privacy claim dismissed for lack of standing?
The federal court loses power to hear it, but the claim itself may survive. State courts are not bound by Article III and apply their own justiciability rules, several of which are more permissive. In Bryant v. Compass Group the plaintiff argued she lacked federal standing in order to return her BIPA case to Illinois state court, and the defendant argued that she had it.
Why do courts compare privacy harms to old common-law torts?
Because TransUnion makes concreteness turn on whether an asserted harm has a "close relationship" to a harm traditionally recognised as a basis for suit in American courts, such as defamation, intrusion upon seclusion or public disclosure of private facts. The Court requires an analogue rather than an exact match — as the Third Circuit put it in Clemens, quoting TransUnion, "we do not require an exact duplicate."

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.