Have you ever received a data breach notice in the mail, via email by the organization that has been compromised, or even learned through watching the news? You are not alone. If you have questions about whether you may qualify to participate in a lawsuit, or if you would simply like to learn more about the process, then you are in the right place.
Data breaches have become increasingly common. According to the Identify Theft Resource Center’s 2025 Annual Data Breach Report, there was a total of 3,322 data compromises, five percent higher than the previous year. The financial services industry was mainly targeted in data breaches with 739 compromises, followed by healthcare (534), professional services (478), manufacturing (299), and education (188). This report surveyed consumers on whether they received a data breach notice in the past 12 months, and 80% reported that they had. However, not all data breaches are treated the same, nor do they automatically guarantee a lawsuit.
In 2026, 20 states have adopted comprehensive privacy laws, which govern how personal information is collected, stored, and used by government agencies, companies, and other organizations. However, not all privacy laws allow individual consumers to file lawsuits, also known as a Private Right of Action. Instead, some privacy laws rely on state and federal officials to enforce the law, such as a state attorney general. Virginia is one such state. This goes for the majority of U.S. States such as Oregon, New Hampshire, Arizona, Rhode Island, Texas, Florida, Colorado, Connecticut, and Utah. On the other hand, there are exceptions, such as the California Consumer Privacy Act of 2018, which grants a private right of action to “any consumer whose nonencrypted and nonredacted personal information… is subject to an unauthorized access and exfiltration, theft, or disclosure.”
What Can a Consumer Do if No Privacy Statue Applies?
Let’s say a state may have a comprehensive privacy law, but it does not allow an individual consumer to bring a private action, or a consumer’s claim falls outside the scope of a privacy law, she might be able to pursue another form of legal relief. Prior to the adoption of many of these privacy laws, consumers have brought lawsuits under centuries-old common law theories of recovery. These include: negligence, breach of contract, unjust enrichment, and invasion of privacy torts.
It is important to note that a violation of a law or statue may not necessarily create a lawsuit. According to TransUnion v. Ramirez, 594 U.S. 413, the U.S. Supreme Court held that “only plaintiffs concretely harmed by a defendant’s statutory violation have Article III standing to seek damages against that private defendant in federal court.”
In TransUnion, the Supreme Court found that only those whose consumer data was disseminated to a third party had standing to bring a lawsuit for damages under the Fair Credit Reporting Act on their reasonable-procedure claims. Although TransUnion was not a data breach case, it is often used by courts to see if plaintiffs have an injury significant enough to warrant a lawsuit. The most repeated line from the decision is: “No concrete harm, no standing.” Through this inquiry, courts distinguish between the risk of dissemination of information, and actual harm resulting from the disclosure of information to third parties. In the opinion, Justice Kavanaugh explained that there are obvious “tangible harms, such as physical harms and monetary harms.” However, there are also intangible harms that have long been recognized as sufficiently concrete to grant standing, such as “reputational harms, disclosure of private information, and intrusion upon seclusion.” The Court found that those plaintiffs whose data was actually obtained by third parties suffered injuries that were concrete.
Potentially Recoverable Losses
As data breaches become more prevalent across industries and there is an increasing reliance on digital platforms, it is important that consumers know their rights. Data breaches typically affect thousands or millions of people; therefore, many cases are brought as data breach class actions. At Miller Shah, our attorneys have successfully represented certified classes of consumers and other plaintiff groups of all sizes across a wide spectrum of industries and situations.
900 Haddon Avenue, Suite 304-8
Collingswood, NJ 08108
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
NY New York City | 866-540-5505
NY New York City | 866-540-5505
NY New York City | 866-540-5505
NY New York City | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
NY New York City | 866-540-5505
FL Miami | 866-540-5505
PA Philadelphia | 866-540-5505
CA San Francisco | 866-540-5505
NY New York City | 866-540-5505
NY New York City | 866-540-5505
PA Philadelphia | 866-540-5505
NY New York City | 866-540-5505
CT Chester | 866-540-5505
NY New York City | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
CA Los Angeles | 866-540-5505
CA Los Angeles | 866-540-5505
CT Chester | 866-540-5505
CT Chester | 866-540-5505
FL Miami | 866-540-5505
CT Chester | 866-540-5505
NY New York City | 866-540-5505
PA Philadelphia | 866-540-5505
NY New York City | 866-540-5505
CA Los Angeles | 866-540-5505
PA Philadelphia | 866-540-5505
CA Orange County | 866-540-5505
PA Philadelphia | 866-540-5505
CT Chester | 866-540-5505
NY New York City | 866-540-5505
NY New York City | 866-540-5505
NY New York City | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
FL Miami | 866-540-5505
NJ Collingswood | 866-540-5505
NY New York City | 866-540-5505
PA Philadelphia | 866-540-5505
NY New York City | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
CA San Diego | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
PA Philadelphia | 866-540-5505
CA Los Angeles | 310-203-0600