Court allows class action related to Facebook's 2018 breach to proceed; says the 29M users, as a group, can ask for better security procedures, but not damages
Context & Ripple Effects
Facebook has spent years fighting privacy class actions where courts certify the class but strip out money: as far back as 2016, a California court certified the private message scanning suit as a class action while barring monetary damages, and last summer an appeals court forced it to face the Illinois biometric privacy claims over facial recognition. This ruling extends that template to the 2018 breach itself.
First-order effects
- The roughly 29 million affected users can now press Facebook in court for concrete security procedure changes, giving their lawyers leverage to negotiate operational reforms rather than just dismissals.
- Facebook wins the narrower fight on this claim — no damages pool from the 29M users — limiting its immediate financial exposure from the breach litigation.
Second-order effects
- With injunctive relief certified as viable, plaintiffs' firms have a playbook to keep breach suits alive even when damages fail — a path that paid off when Facebook later agreed to improve its security procedures to settle the case (the security-procedures settlement).
- Every dollar Facebook spends hardening its security practices under court pressure becomes a benchmark competitors must match to avoid facing the same class-level demands.
Third-order effects
- If courts keep certifying privacy and breach classes for equitable relief only, platform security becomes something shaped by judicial decree rather than market choice — a structural shift already visible in the parallel logged-out tracking class action allowed to proceed (on appeal).
The trend: US privacy litigation is settling into a pattern where classes win the right to force procedural changes at platforms like Facebook even when monetary damages are off the table.