Understanding Data Breach Class Action Eligibility Criteria
This article explains the key eligibility criteria for federal data breach class actions after TransUnion LLC v. Ramirez (2021), focusing on the Article III standing threshold and the deepening circuit splits that make forum selection a critical factor in case viability.
- Jurisdiction
- US Supreme Court
- Court
- Supreme Court of the United States
- AI tool named
- None
- Ruling date
- Jun 25, 2021
- Source document
- View primary court order ↗
- Last verified
- Jul 30, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
Data breach class action lawsuit eligibility criteria now start at a less intuitive place than the breach notice, the size of the incident, or the defendant’s security lapse. In federal court, the first question is Article III standing: has this plaintiff alleged a concrete, particularized, and fairly traceable injury that a federal court may hear?
That threshold hardened after TransUnion LLC v. Ramirez. The Supreme Court held that 6,332 of 8,185 class members lacked standing because their misleading credit files were not disseminated to third parties. The files existed inside TransUnion’s system, and the statutory claim existed, but the Court treated non-disseminated internal processing differently from publication to an outside recipient.[1]
For data breach litigation, that distinction matters because many complaints begin from exposure: data was accessed, copied, posted, offered for sale, or made vulnerable. TransUnion does not make exposure irrelevant. It does make counsel answer a sharper question before pleading a nationwide class in federal court: what concrete harm, or sufficiently imminent risk of harm, belongs to this plaintiff under the law of this circuit?

The Same Breach Can Produce Different Standing Outcomes
The commercial pressure is obvious enough. More than 1,488 data breach class actions were filed in 2024, compared with fewer than 200 in 2017, and reported class certification success rates rose to 40% in 2024 from 16% in 2023.[2] But filing volume does not answer eligibility. A complaint that looks viable in one federal circuit may be dismissed in another on the same injury theory.
| Issue | Why it matters for eligibility | Post-TransUnion fault line |
|---|---|---|
| Present injury | The plaintiff must identify a concrete harm, not merely a technical violation or breach announcement. | Some courts treat misuse or disclosure as enough; others demand closer alignment with recognized harms. |
| Future risk | A plaintiff may rely on threatened identity theft only if the risk is sufficiently substantial and imminent. | Circuits disagree over how much risk is enough and whether mitigation costs can ride on that risk. |
| Common-law analogue | TransUnion asks whether the alleged intangible harm bears a close relationship to traditionally recognized harms. | Courts divide over whether to compare harms broadly or require closer element-by-element similarity. |
| Public disclosure | Dark-web posting may matter if it resembles publication of private information. | Some courts accept dark-web posting as disclosure; others reject particular data-type theories. |
| Traceability | Even actual identity-theft losses must be plausibly tied to the defendant’s breach. | Timing alone may not connect the loss to the incident. |
That table is not a filing checklist. It is the set of gates counsel has to pass through before the merits begin. The order also matters. If the plaintiff cannot plead a concrete injury, or cannot trace a real loss to the breach, a detailed account of deficient cybersecurity may never become legally important in federal court.
Holmes Made the Split Harder to Ignore
Holmes v. Elephant Insurance is now the pressure point for federal data breach standing. In the Fourth Circuit, plaintiffs alleged that a cyberattack exposed personal information and that the stolen data appeared on the dark web. The court’s treatment of standing did not simply choose a side in an existing disagreement; it created new friction around probability, disclosure, and imminence.[3]
First, Holmes adopted a 33% probability threshold for substantial risk of future harm.[3] That number changes how a complaint is read. A plaintiff cannot merely describe identity theft as a serious possible consequence of a breach. In the Fourth Circuit, the plaintiff has to plead facts that push the risk to the court’s substantial-risk line. That is a demanding task when the complaint has only a breach notice, generalized criminal intent, and allegations that monitoring is prudent.
Second, Holmes treated dark-web posting as public disclosure for common-law-analogue purposes.[3] That holding helps plaintiffs on one part of the TransUnion inquiry because dissemination is no longer purely hypothetical once stolen data is posted where others can obtain it. The analogy is not to anxiety about a future crime; it is to disclosure of private information.
Third, Holmes insisted that imminence remains a separate requirement.[3] That is where many complaints become vulnerable. A public disclosure theory may establish a present intangible harm, while a future identity-theft theory still has to explain why the threatened misuse is impending rather than speculative. Combining those theories in one paragraph does not make them the same injury.
The Fourth Circuit’s approach has not been resolved by the Supreme Court. A certiorari petition in Elephant Insurance Co. v. Holmes was filed in March 2026 and dismissed after settlement in May 2026, leaving the splits intact.[3] As of Q3 2026, Holmes remains a circuit-specific answer, not a national rule.
Dark-Web Allegations Do Different Work in Different Circuits
A dark-web allegation is now one of the most consequential pleading facts in a data breach class action, but it does not carry the same weight everywhere. The allegation can serve at least three different functions: proof that data left the defendant’s control, proof of public disclosure, and evidence that future misuse is more likely. Those are related points, not interchangeable ones.
In Green-Cooper v. Brinker, the Eleventh Circuit held that posting stolen data on the dark web established both a present injury and a substantial risk of future injury sufficient for standing.[2] That is a plaintiff-friendly treatment of dark-web posting: dissemination supports a current injury, and the context of criminal posting supports future risk.
Baysal v. Midvale Indemnity Co. went the other way for a narrower theory. The Seventh Circuit rejected standing based on dark-web posting of driver’s license numbers specifically.[2] The important point is not that dark-web allegations never matter in the Seventh Circuit. It is that the court did not treat the phrase “on the dark web” as a universal substitute for pleading concrete injury tied to the data type and misuse theory.
Holmes sits uncomfortably between those instincts. It accepts dark-web posting as public disclosure for one part of the common-law-analogue inquiry, while still requiring a separately imminent risk for future harm.[3] That split treatment is doctrinally tidy and practically severe. It lets a plaintiff get credit for dissemination without automatically receiving standing for every alleged downstream risk.
The Common-Law Analogue Fight Is Not Just Semantics
TransUnion instructs courts to ask whether an asserted intangible harm bears a close relationship to harms traditionally recognized as providing a basis for suit. The current split is over how close that relationship must be.
Barclift v. Keystone Credit Services adopted a comparative-harm approach in the Third Circuit, joining the Tenth Circuit and departing from the Eleventh Circuit’s element-based approach.[4] Under a comparative-harm approach, the court asks whether the alleged injury resembles the kind of harm protected at common law. Under an element-based approach, the court looks more closely at whether the modern statutory or privacy harm satisfies the components of the older analogue.
That difference affects data breach plaintiffs immediately. A broad comparison may allow a court to say that disclosure of sensitive personal information resembles public disclosure of private facts. A stricter element-by-element view may ask whether the disclosure was sufficiently public, whether the information was of the right kind, and whether the alleged harm matches the historical tort closely enough. Both inquiries use TransUnion’s vocabulary. They do not produce the same pleading burden.
Present Injury, Future Harm, and Monitoring Costs Should Not Be Blended Together
The cleanest complaints separate injury theories instead of letting them blur. A plaintiff may allege that private information was disclosed. She may allege that criminals misused the data. She may allege that she faces a substantial and imminent risk of identity theft. She may allege that she spent money or time on mitigation. Each theory has a different standing problem.
Present misuse is usually the easiest to understand and still not always easy to plead. Unauthorized charges, account openings, credit inquiries, tax fraud, or other identity-theft events can be concrete losses. But they must be tied to the defendant’s breach, and the complaint must account for the kind of data exposed. If the breach involved one category of information and the alleged fraud required another, the pleading gap belongs in the standing analysis.
Future-risk allegations require a different showing. A plaintiff who has not yet suffered misuse has to explain why the risk is substantial and imminent under the governing circuit’s standard. Holmes makes that inquiry unusually explicit in the Fourth Circuit through its 33% threshold.[3] Green-Cooper shows a more receptive approach where dark-web posting supports both present and future injury.[2] Baysal shows that the same general kind of allegation may fail when the court is unconvinced that the exposed data creates a cognizable risk.[2]
Monitoring costs sit downstream of that fight. Credit monitoring, freezes, time spent reviewing accounts, and related expenses may reflect sensible behavior by a breach victim. But after TransUnion, mitigation expenses are not automatically concrete injury just because they were incurred after a breach notice. If the underlying risk is too speculative, self-imposed costs may not rescue standing.
Traceability Can Defeat Even a Real-Loss Complaint
Santos-Pagán v. Bayamón Medical Center is the corrective to an overly future-risk-centered account of standing. The First Circuit affirmed dismissal even though the plaintiff alleged actual identity-theft losses, because the complaint did not plausibly trace those losses to the specific breach. Temporal proximity alone was insufficient.[5]
That is the kind of dismissal that should bother both sides. The alleged human harm is not abstract. Someone who experiences identity theft after a medical-center breach may spend months untangling accounts, disputing charges, and trying to restore ordinary financial life. But federal standing requires more than sympathy and sequence. The complaint must plead a plausible causal path from this defendant’s incident to this plaintiff’s loss.
The traceability analysis should be concrete. What data was exposed? When was it accessed or posted? What information was needed to commit the alleged fraud? Did the plaintiff allege other breaches or prior exposure? Does the timing make the causal inference plausible, or merely possible? Santos-Pagán does not say identity-theft losses are never enough. It says counsel cannot make the breach announcement do all the causal work.[5]
Statutory Violations Still Need Concrete Harm
A statutory claim may define duties and remedies, but it does not by itself open the federal courthouse door. TransUnion is explicit on that point: a legislature may elevate harms, but Article III still requires a concrete injury for damages claims in federal court.[1]
In breach litigation, that means counsel should not plead statutory notice violations, privacy duties, or unfair-practice theories as if the violation and standing inquiry are the same thing. The federal complaint still has to identify who suffered what harm. A named plaintiff with only delayed notice and no plausible concrete consequence may face a different standing problem than a plaintiff whose data was posted, misused, or tied to a credible imminent threat.
A Practical Federal Eligibility Screen
Before filing, removing, or moving to dismiss a federal data breach class action, the standing screen should begin with forum and then move to injury. A national answer will be too rough to trust.
- Identify the governing circuit before evaluating the injury theory.
- Separate present injury from future-risk injury instead of pleading them as one blended harm.
- State exactly what data was exposed, whether it was accessed, and whether it was disseminated or posted.
- Match alleged misuse to the data compromised in the breach.
- Treat dark-web posting as a circuit-dependent fact, not a universal standing cure.
- Do not rely on monitoring costs unless the underlying risk or disclosure theory is independently concrete.
Defense counsel will often start from the inverse version of the same screen. If the complaint alleges anxiety but no misuse, ask whether the circuit recognizes the future-risk theory pleaded. If it alleges dark-web posting, ask what kind of data was posted and what the circuit does with public disclosure. If it alleges actual fraud, test the causal chain. If it alleges only a statutory violation, return to TransUnion.
State Court Is an Alternative, Not the Federal Answer
TransUnion’s dissent warned that plaintiffs shut out of federal court may turn to state courts that do not apply Article III in the same way.[1] That is a real strategic consideration. It is not a substitute for the federal standing analysis.
Some plaintiffs may prefer state court when federal standing is doubtful, and defendants evaluating removal have to account for the possibility that a successful Article III challenge may return the dispute to a state forum rather than end it entirely. But without a state-by-state record, the responsible point is limited: federal data breach class action eligibility after TransUnion is not the same inquiry as state-court justiciability or statutory standing.
No Stable National Test Exists as of Q3 2026
The unsettled state of the law is not a reason to plead vaguely. It is the reason to plead with jurisdictional precision. TransUnion supplies the federal gate. Holmes, Green-Cooper, Baysal, Barclift, and Santos-Pagán show how differently that gate is guarded across circuits.
As of Q3 2026, counsel cannot responsibly assess whether dark-web posting, monitoring costs, identity-theft losses, statutory violations, or future-risk allegations are enough without first naming the governing circuit. Only then can the complaint’s injury allegations be measured against the standing test that will actually decide whether the case proceeds.
References
- TransUnion LLC v. Ramirez, 594 U.S. 413, Supreme Court of the United States, 2021, https://www.supremecourt.gov/opinions/20pdf/20-297_4g25.pdf
- An Update on Standing in Data Breach Class Actions, Baird Holm, Feb. 2025, https://www.bairdholm.com/blog/an-update-on-standing-in-data-breach-class-actions/
- Time for SCOTUS to Step In? Yet Another Circuit Court Misapplies TransUnion to a Cyberattack Class Action, and This Time Creates Three Circuit Splits Along the Way, Harvard Journal of Law & Technology, 2026, https://jolt.law.harvard.edu/digest/time-for-scotus-to-step-in-yet-another-circuit-court-misapplies-transunion-to-a-cyberattack-class-action-and-this-time-creates-three-circuit-splits-along-the-way
- Navigating Standing Considerations in Data Breach Class Actions, Hinshaw & Culbertson, Mar. 2025, https://www.hinshawlaw.com/en/insights/blogs/consumer-crossroads-where-financial-services-and-litigation-intersect/navigating-standing-considerations-data-breach-class-actions
- First Circuit Affirms Dismissal of Data Breach Class Action for Lack of Traceable Injury, First Class Defense, https://www.firstclassdefense.com/first-circuit-affirms-dismissal-of-data-breach-class-action-for-lack-of-traceable-injury/
Related records
Tool profile
Browse tool evaluations →Governing regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →