Corpus: 543,223 opinions ·
3,177 judges ·
newest 2026-06-23 · expanding
Coverage ↗
Opinion
govinfo:USCOURTS-casd-3_25-md-03149-3
-1- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF CALIFORNIA IN RE: POWERSCHOOL HOLDINGS, INC. AND POWERSCHOOL GROUP, LLC CUSTOMER SECURITY BREACH LITIGATION. ) ) ) ) ) ) ) ) ORDER GRANTING IN PART AND DENYING IN PART DEFENDANT POWERSCHOOL HOLDINGS, INC. AND POWERSCHOOL GROUP, LLC’S MOTION TO DISMISS (TRACK 1) [Dkt. 285] I. INTRODUCTION This multidistrict litigation arises from a data breach involving Defendants PowerSchool Holdings, Inc. and PowerSchool Group, LLC (collectively, “PowerSchool”). PowerSchool provides cloud-based data management software for students and educators in K-12th. PowerSchool stores sensitive student medical, academic, and other personally identifiable information in a searchable format. Powerschool moves to dismiss the Track 1 Plaintiffs' claims against it. For the reasons set forth below, the Court GRANTS IN PART and DENIES IN PART Powerschool’s motion. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 1 of 34 -2- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 II. BACKGROUND1 It is alleged that PowerSchool is a Sacramento-based provider of educational management software used by schools. Schools require students, parents, and teachers to provide PowerSchool with sensitive personally identifiable information (“PII”), and PowerSchool stores and maintains this data. There are approximately 4,700 school customers, 4,668,000 teachers and 43,800,000 students affected by Powerschool’s maintenance of PII. Powerschool, according to the Complaint, holds out its school software product as being a secure repository of PII data. On December 20, 2024, the criminal group ShinyHunters used the stolen employee credentials of a Powerschool cybersecurity subcontractor (Movate, Inc.) to access PowerSchool’s student information system through its PowerSource portal. PowerSchool discovered the breach on December 28, 2024, and notified customers on January 7, 2025. The hacker(s) exfiltrated PII and demanded a ransom from Powerschool. Powerschool paid the ransom. The Complaint alleges that the breach compromised the PII of approximately 50 million individuals, PII including social security numbers, medical information, financial information, addresses, disability records, and custody information. III. APPLICABLE LAW A motion to dismiss under Federal Rule of Civil Procedure 12(b)(6) tests the legal sufficiency of the claims alleged in the complaint. Under Federal Rule of Civil Procedure 8, a complaint should include a “short and plain statement of the claim showing that the pleader is entitled to relief,” and may be dismissed under Rule 12(b)(6) if the plaintiff fails to state a cognizable legal theory or has not alleged sufficient facts to support such a theory. Somers v. Apple, Inc., 729 F.3d 953, 959 (9th Cir. 2013). The 1 When deciding whether to grant a motion to dismiss, the court generally accepts as true all well-pleaded factual allegations. Ashcroft v. Iqbal, 556 U.S. 662, 664 (2009). The Court is not making findings of fact, but summarizing some of the allegations made in the 436 page, 81 claim, Consolidated Individual Users Class Action Complaint (filed August 11, 2025) (Dkt. 259) (“Complaint”). Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 2 of 34 -3- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 court construes the alleged facts in the light most favorable to the plaintiff. See Retail Prop. Trust v. United Bhd. of Carpenters & Joiners of Am., 768 F.3d 938, 945 (9th Cir. 2014). However, “courts are not bound to accept as true a legal conclusion couched as a factual allegation.” Iqbal, 556 U.S. at 678. To survive a motion to dismiss, a complaint must state a claim to relief that is plausible on its face. Iqbal, 556 U.S. at 678 (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007)). A claim has “facial plausibility when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Twombly, 550 U.S. at 556. If the plaintiff’s explanation is plausible, the complaint survives a motion to dismiss under Rule 12(b)(6), “regardless of whether there is a more plausible alternative explanation.” Iqbal, 556 U.S. at 678. Thus, a “Rule 12(b)(6) motion tests the sufficiency of a complaint; it does not . . . resolve contests surrounding the facts, the merits of the claim, or the applicability of defenses.” W. Ins. Co. v. Frontier Homes, LLC, 2018 WL 8220544, at *2 (C.D. Cal. Mar. 27, 2018) (quoting King v. Rubenstein, 825 F.3d 206, 214 (4th Cir. 2016)). IV. DISCUSSION The Consolidated Individual Users Class Action Complaint (Dkt. 259) sets out 81 claims for relief. By joint motion, a number of claims for relief have already been dismissed without prejudice: Data Breach Notification Statutes: Count XXI: Colorado Security Breach Notification Act Count XXVII: Illinois Personal Information Protection Act Count XXXIX: Maryland Personal Information Protection Act Count XLII: Michigan Identity Theft Protection Act Count XLVIII: Computer Security Breach Law- Mont. Code Ann. §§ 30-14-1704 (1), et seq. Count LII: New Jersey Customer Security Breach Disclosure Act Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 3 of 34 -4- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 Count LVIII: Notice of Security Breach for Personal Information, N.D. Cent. Code §§ 51-30-02, et seq. Count LXIII: Oregon Consumer Identity Theft Protection Act Count LXXVIII: Notice of Unauthorized Acquisition of Personal Information, Wisc. Stat. §§ 134.98 (2), et seq. Uniform Deceptive Trade Practices Acts: Count XXXVIII: Maine Deceptive Trade Practices Act Count XLV: Minnesota Uniform Deceptive Trade Practices Act Consumer Protection Acts: Count XXVI: Idaho Consumer Protection Act Count LXXV: Virginia Consumer Protection Act Count LX: Ohio Consumer Sales Practices Act Count LXV: Pennsylvania Unfair Trade Practices and Consumer Protection Law Common Law Claims: Count II: Negligence Per Se, as brought by the Track One Plaintiffs residing in California, Massachusetts and Michigan. See Order Granting Joint Motion Dismissing Certain Claims (Oct. 2, 2025) (Dkt. 308). Also, the standalone negligence per se claims under California, Massachusetts and Michigan state law, were dismissed without prejudice to the incorporation of the allegations set forth in these claims into the other causes of action in the Consolidated Complaint. Id. Moreover, it was agreed that legal issues raised by Defendants PowerSchool Holdings, Inc., and PowerSchool Group, LLC’s Motion to Dismiss directed at the Track One Plaintiffs’ pleadings are presented to be resolved under the laws of four illustrative jurisdictions: California, Massachusetts, Michigan, and New York. Id. Powerschool seeks dismissal of the remaining claims on two grounds: (a) lack of Article III standing and (b) failure to state a claim under Rule 12(b)(6). Each is addressed in turn. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 4 of 34 -5- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 A. Article III Standing Powerschool urges dismissal asserting that the plaintiffs lack Article III standing. Powerschool’s main argument is that the plaintiffs do not articulate an injury-in-fact. Powerschool says the data breach harm must be “actual” or already suffered for standing. The Plaintiffs say that the data breach harm is “actual” or already suffered because the risk of future fraud is an actual present harm. It is hornbook law that “those who seek to invoke the jurisdiction of the federal courts must satisfy the threshold requirement imposed by Article III of the Constitution by alleging an actual case or controversy.” City of Los Angeles v. Lyons, 461 U.S. 95, 101 (1983). Article III standing requires plausible allegations that: (1) the plaintiff suffered an injury in fact that is concrete, particularized, and actual or imminent; (2) the injury is fairly traceable to the defendant; and (3) the injury would likely be redressed by a favorable decision. TransUnion LLC v. Ramirez, 594 U.S. 413, 423 (2021); Friends of the Earth, Inc. v. Laidlaw Env’t Servs., Inc., 528 U.S. 167, 180–81 (2000). Both sides agree that this is the standard. Instead, the parties disagree about the nature and qualities of an injury-in-fact in a data breach case and what court decisions guide the decision- making. A plaintiff’s alleged injury must be “concrete, particularized, and actual or imminent.” TransUnion, 594 U.S. at 423. At the pleading stage, “[g]eneral allegations” of injury may suffice. Lujan v. Defenders of Wildlife, 504 U.S. 555, 560–61 (1992). At summary judgment, plaintiffs must come forward with evidence that at least produces a genuine issue of material fact. Healy v. Milliman, 164 F.4 th 701, 2026 WL 71863 *17-20 (9th Cir. 2026). At trial, a plaintiff must affirmatively prove the injury for standing. Id. Plaintiffs assert that they have adequately pleaded sufficient facts to establish standing under the current state of Ninth Circuit binding precedent. Plaintiffs say, “[t]here is a trilogy of published and binding Ninth Circuit cases (Healy [v. Milliman, Inc., 164 F.4th 701, 706 (9th Cir. 2026)], [In re] Zappos [888 F.3d 1020, 1027-28 (9th Cir. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 5 of 34 -6- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 2018)], and Krottner [v. Starbucks Corp., 628 F.3d 1139, 1142- 43 (9th Cir. 2010)]) that control the standing analysis on the pre-discovery Motion to Dismiss record here. These cases establish that: (1) pleading an imminent threat of injury (as opposed to an allegation of actual misuse) is sufficient to show Article III standing in a data breach case; (2) an “imminent” injury is shown for all named Plaintiffs if any victim of the same breach has made plausible allegations of actual misuse; and (3) one allegation of actual misuse from a Plaintiff provides standing for the rest of the class at the motion to dismiss stage because misuse allegations show the likelihood of imminent future injury for all.” Plaintiffs’ Rebuttal Brief, Dkt 419, at 1. Powerschool disagrees. In arguing that plaintiffs lack standing, Powerschool looks to the recent decision in Kisil v. Illuminate Educ., Inc., 2025 WL 2589000 (9 th Cir. Sept. 8, 2025) and district court decisions addressing Article III standing in the context of a data breach. For example, Powerschool argues: The Ninth Circuit in [Kisil v.] Illuminate applied settled case law, including TransUnion, to affirm that plaintiffs virtually identical to the No-Injury Plaintiffs had no injury-in-fact to seek damages or injunctive relief based on the data they had alleged. See Kisil v. Illuminate Educ., Inc., 2025 WL 2589000, at *2 (9th Cir. Sept. 8, 2025); In re Illuminate Educ. Data Sec. Incident Litig., 2023 WL 8888839, at *1 (C.D. Cal. Nov. 6, 2023) (describing the data in the Illuminate incident). Def’s Rebuttal Mem., Dkt 419, at 4. The Plaintiffs remonstrate that Kisil cannot carry the legal load Powerschool places on it, arguing, Defendants’ heavy and near singular reliance on the unpublished and non-binding decision in Kisil v. Illuminate Education, Inc., 2025 WL 2589000 (9th Cir. Sept. 8, 2025) is illogical. Even if Kisil were published and controlling on this Court (which it is not), it is inapposite and irrelevant. The plaintiffs in Kisil never alleged plausible misuse of sensitive information, as the breach there did not include any sensitive information. 2025 WL 2589000, at *2. By contrast, no Ninth Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 6 of 34 -7- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 Circuit case has upheld a dismissal based on lack of standing where at least one Plaintiff has alleged misuse of truly sensitive information (as is the case here). Kisil did not (and could not) overrule Zappos which, post-TransUnion, as Healey confirmed, is still controlling on this point. Plaintiffs’ Rebuttal Brief, Dkt 419, at 2. Kisil offers a forward-looking take on the requirements for standing in a data breach case. However, it would be a mistake to strictly rely on Kisil’s conclusions since it lacks precedential value. That kind of mistake has happened before. See W. Watersheds Project v. Grimm, 921 F.3d 1141, 1147 (9th Cir. 2019) (reversing dismissal based on lack of Article III standing that relied on unpublished Ninth Circuit decision) (“The district court erred by relying on Goat Ranchers. That case is unpublished and lacks precedential value. 9th Cir. R. 36-3(a).”). The Ninth Circuit has published only two decisions concerning Article III standing at the outset of a data breach case: Zappos and Krottner. Zappos relied on Krottner and instructs that in data breach cases, a complaint must set forth the nature of the stolen data, the manner of the breach, and the real-world harms that predictably would flow from the theft to establish standing. 888 F.3d at 1027. Under Zappos, a complaint must allege that the risk of future harm plaintiffs face is “fairly traceable to the conduct being challenged,” here, as in Powerschool’s failure to prevent the breach. Id. at 1029. Zappos explains that, “a person whose PII has been obtained and compromised may not see the full extent of identity theft or identity fraud for years . . . And it may take some time for the victim to become aware of the theft,” does not defeat Article III standing. Id. at 1028-29. Applying the controlling precedent of Zappos and Krottner, to this case, Plaintiffs have adequately alleged the requisite injury-in-fact. Taking another run at Ninth Circuit precedent, Powerschool argues that these cases have been abrogated by the Supreme Court’s TransUnion decision. Powerschool claims: Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 7 of 34 -8- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 Plaintiffs argued that the mere risk of “imminent” harm is sufficient, relying on In re Zappos.com, Inc. and Krottner v. Starbucks Corp. Plaintiffs are wrong here too. Both Zappos and Krottner predate TransUnion’s clarification that the “mere risk of future harm, without more, cannot qualify as a concrete harm in a suit for damages.” 594 U.S. at 415. Healy expressly recognized that Zappos was abrogated by TransUnion where the two decisions conflict. Def’s Rebuttal Mem., Dkt 419, at 4 (citations omitted) (emphasis in original). Powerschool’s statement that, “Healy expressly recognized that Zappos was abrogated by TransUnion where the two decisions conflict,” could be misinterpreted by the casual reader. Healy does say that Zappos has been abrogated, but only to the extent that it would have permitted unnamed class members to go to trial without proving standing. Healy, 2026 WL 71863 at *17. Thus, after TransUnion, when it comes to summary judgment or trial, there is a shift and all class members must demonstrate standing. Id. At the same time, Healy cites Zappos with approval for the notion that earlier in a case Article III is satisfied as long as one named plaintiff has standing and a putative plaintiff class has not yet been certified. Id. at * 10. Consequently, Zappos remains largely intact. Zappos follows Krottner. In both cases the sensitivity of the exfiltrated personal information combined with its theft adequately alleged an injury in fact for standing purposes. Zappos, 888 F.3d at 1027. While Plaintiffs will have to support their claimed injuries with more proof as the case progresses, they have demonstrated through plausible allegations that they enjoy Article III standing at this early stage of a putative class action. Powerschool’s approach of assessing the standing of the 170 named plaintiffs by categorizing plaintiffs based on their injuries into three buckets (120 “no injury”, 40 and 9 “other”) 2 may be appropriate later, but today one named plaintiff’s injury suffices for 2 Powerschool argues that not even the “other” plaintiffs have standing, but the argument is not persuasive. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 8 of 34 -9- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 all. Id. at 1028 & n.11 (“[O]nly one Plaintiff needs to have standing for a class action to proceed.”); see also Healy, 2026 WL 71863 at *3 (same). B. Types of Injuries Plaintiffs assert they have suffered or are suffering several types of injuries in this data breach litigation. Among these are: (a) actual or attempted fraud; (b) imminent risk of future harm; (c) diminution in value of personal information; (d) mitigation expenditures; (e) and loss of benefit of the bargain. 1. Actual or Attempted Fraud. Plaintiffs allege that the data breach exposed their names, addresses, email addresses, phone numbers, credit card numbers, and student record information. (Dkt. 259 ¶¶ 281–752.) Numerous Plaintiffs allege that this exposure has now led to actual or attempted fraud following the data breach. For example, Plaintiff Charlotte Renn, a teacher at Floyd County School District, allegedly experienced fraudulent credit card activity around February 26, 2025, following the breach. (Id. ¶¶ 281–83.) As a result, Renn had to obtain reissued credit cards. (Id. ¶ 283.) 2. Imminent Risk of Future Harm. A plaintiff who has not yet experienced misuse of personal information may nonetheless sufficiently allege injury in fact by demonstrating “a credible threat of real and immediate harm stemming from the theft of a laptop containing their unencrypted personal data.” Zappos, 888 F.3d at 1027 (citing Krottner, 628 F.3d at 1143. Such imminent-risk harms “qualify as concrete injuries in fact when they are based on a risk of harm that is either ‘certainly impending’ or substantial.” Id. (quoting I.C. v. Zynga, Inc., 600 F. Supp. 3d 1034, 1052 (N.D. Cal. 2022)). When data thieves target and obtain a consumer’s personal information, it is reasonable to infer “the[] goal in targeting and taking this information was to commit further fraud and identity theft.” Bass v. Facebook, Inc., 394 F. Supp. 3d 1024, 1035 (N.D. Cal. 2019). In Zappos, plaintiffs sued after data theives breached the defendant’s online server and obtained names, account numbers, passwords, email addresses, billing and shipping Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 9 of 34 -10- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 addresses, telephone numbers, and credit and debit card information of over 24 million customers. 888 F.3d at 1023. The Ninth Circuit concluded that plaintiffs sufficiently alleged standing based on the imminent risk of identity theft, even absent actual misuse of the stolen information. Id. at 1028–29. Data theft victims who alleges future injury based on the theft or unauthorized release of personal data, as Plaintiffs do here, satisfy the injury in fact requirement for Article III standing and actual damages. Krottner, 628 F.3d at 1143. The “possibility of future injury may be sufficient to confer standing on plaintiffs; threatened injury constitutes ‘injury in fact.’” Id. at 1142 (quoting Cent. Delta Water Agency, 306 F.3d at 947). Stated differently, “the injury-in-fact requirement can be satisfied by a threat of future harm or by an act which harms the plaintiff only by increasing the risk of future harm that the plaintiff would have otherwise faced, absent the defendant’s actions.” Pisciotta v. Old Nat'l Bancorp, 499 F.3d 629, 634 (7th Cir. 2007), cited with approval, Krottner, 628 F.3d at 1142–43. Here, the facts closely resemble Zappos. The data breach allegedly exposed at least one Plaintiff’s sensitive data and names, social security numbers, phone numbers, emails, medical information, academic records, child custody status, bank and financial information, student and staff identification numbers, and individualized education program information. (Dkt. 259 ¶ 2.) Additionally, Plaintiffs allege that their information has been sold on the dark web further establishing that future misuse is likely and imminent. The fact that other Plaintiffs allege actual fraud following the data breach further supports the conclusion that an imminent risk of identity theft or fraud is impending. The future harm risk here is even greater than the future harm risk described in TransUnion. The data harm in TransUnion was caused by a mischaracterization of a credit profile by an otherwise law-abiding credit agency with no profit motive to publish misinformation about the plaintiffs. In other words, in TransUnion, the data was never in the hands of criminals. Here, Plaintiffs’ data is in the hands of criminals. Here, the data Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 10 of 34 -11- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 harm stems from a criminally-convicted data thief hacking Powerschool’s data storage and exfiltrating Plaintiffs’ data and thereafter using his possession of the plaintiffs’ data to extort money from Powerschool. Plaintiffs allege that other criminals have more recently also attempted to extort money or release the plaintiffs’ data. Accordingly, even Plaintiffs who have not yet experienced misuse of their information have nonetheless sufficiently alleged injury in fact and compensable damages based on the increased, imminent risk of fraud and identity theft. See Zappos, 888 F.3d at 1027. As the Seventh Circuit recognized, plaintiffs “should not have to wait until hackers commit identity theft or credit-card fraud in order to give the class standing” when an objectively reasonable likelihood of such injury exists. Remijas v. Neiman Marcus Grp., LLC, 794 F.3d 688, 693 (7th Cir. 2015). 3. Diminution in Value of PII. A party may suffer injury and cognizable damages for diminution in the value of PII when the plaintiff alleges “details about the existence of an economic market for selling stolen PII, including the fact that PII can be bought and sold at identifiable prices on established markets.” Smallman v. MGM Resorts Int’l, 638 F. Supp. 3d 1175, 1191 (D. Nev. 2022). Here, Plaintiffs allege that their stolen personal information is “valuable” (Dkt. 259 ¶ 248) and that a market exists for the stolen information (Id. ¶¶ 245–50).3 While it remains for later in the proceedings as to whether the claim can be proven, Plaintiffs plausibly allege injury in fact and damages based on diminution in value of their PII. See In re Snowflake, No. 2:23-md-03126-BMM 2025 U.S. Dist. LEXIS 212557 *11. (D. Mont. Oct. 28, 2025) (citing Smallman, 638 F. Supp. 3d at 11914)). 3 In re Zappos.com, Inc., 108 F. Supp. 3d 949, 954 (D. Nev. 2015), later rev’d on other grounds, 888 F.3d 1020 (9th Cir. 2018), rejected the plaintiffs’ claim that the security breach deprived them of the “substantial value” of their personal information where they did not allege they attempted to sell their information and were rebuffed due to a lower price-point attributed to the breach.) (citation omitted). 4 See Remijas, 794 F.3d at 693 (“Presumably, the purpose of [a] hack is, sooner or later, to make fraudulent charges or assume those consumers' identities.”). Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 11 of 34 -12- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 4. Mitigation Efforts. Plaintiffs allege they have expended time and money on mitigation activities, including investigating accounts and purchasing credit monitoring services. (See generally Dkt. 259.) Powerschool argues that such “self-inflicted” mitigation costs cannot confer standing or describe damages. (Dkt. 285 at 30-31.) The Court disagrees, after all, a plaintiff generally has a duty to try to mitigate his damages. “[C]ourts across the country have recognized that harms that result as a consequence of a plaintiff’s knowledge of a substantial risk of identity theft, including time and money spent responding to a data breach or emotion[al] distress can satisfy concreteness.” In re Data Breach Sec. Litig. Against Caesars Ent. Inc., No. 2:24-cv- 00630-GMN-MDC, 2025 WL 2393024, at *4 (D. Nev. Jan. 28, 2025) (quoting Medoff, 2023 WL 4291973, at *4). Injury in fact may be based on a “substantial risk that the harm will occur, which may prompt plaintiffs to reasonably incur costs to mitigate or avoid that harm.” In re Adobe Sys., Inc. Privacy Litig., 66 F. Supp. 3d 1197, 1213 (N.D. Cal. 2014) (quoting Clapper v. Amnesty Int’l USA, 568 U.S. 398, 414 n.5 (2013)). Out- of-pocket mitigation expenses are sufficient to establish injury and damages, including payments for credit monitoring services. See In re Equifax, Inc., Customer Data Sec. Breach Litig., 999 F. 3d 1247, 1263 (11th Cir. 2021) (citation omitted). Plaintiffs have established that a substantial risk of harm exists, as explained above. Their allegations of lost time and money investigating accounts, mitigating the risk of identity theft, and paying for credit monitoring services constitute an injury for which damages can be awarded. 5. Benefit of the Bargain. Plaintiffs assert that PowerSchool failed to provide the product and service for which they paid or the value that their PII provided. (Dkt. 259 ¶¶ 837–40.) Plaintiffs Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 12 of 34 -13- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 further allege that PowerSchool enriched itself through cost-savings rather than expending those funds on data security measures. (Id. ¶ 840.) The contention stretches standard legal theory thin but not to its breaking point. “Under California law, the economic injury of paying a premium for a falsely advertised product is sufficient harm to maintain a cause of action.” Davidson v. Kimberly-Clark., 889 F.3d 956, 965 (9th Cir. 2018) (reh’g en banc denied). For example, in another case, a court found “plausible [p]laintiffs’ . . . allegations that they relied on Adobe’s representations regarding security to their detriment.” See In re Adobe Sys., Inc. Privacy Litig., 66 F. Supp. 3d 1197, 1224 (N.D. Cal. 2014). In Smallman v. MGM Resorts, a court found that a benefit-of-the-bargain theory could support a finding of injury in fact when plaintiffs “overpaid for hotel services that should have been— but were not— accompanied by reasonable data security.” 638 F. Supp. 3d at 1189–90 (D. Nev. 2022).5 It observed the numerous district court decisions already recognize a benefit-of-the-bargain theory where a defendant product promised data security but did not deliver. Id. Similarly, in Baton v. Ledger SAS, 740 F. Supp. 3d 847, 877 (N.D. Cal. 2024), another court determined that a plaintiff “purchased the product with the expectation that the PII he provided in connection with the purchase would be secure. . . . He did not get the benefit of the bargain.” 6 Here, Plaintiffs allege that they were led to believe their data would be secure in exchange for Powerschool safely managing their accounts. As in Baton, Plaintiffs 5 Cf. Facebook Privacy Litig., 572 Fed. Appx. 494, (9th Cir. 2014) (finding allegation that plaintiffs were harmed by dissemination of personal information and by losing the sales value of that information sufficient to show damages for breach of contract and fraud claims); In re Google, Inc. Privacy Policy Litigation, No. 5:12-cv-01382-PSG, 2015 WL 4317479, *5 (N.D. Cal. July 15, 2015) (dismissing a claim where plaintiffs did not allege economic injury from dissemination or impairment of their ability to participate in a market for their information). 6See also Svenson v. Google Inc., No. 13-cv-04080, 2015 WL 1503429, at *4 (N.D. Cal. Apr. 1, 2015) (accepting benefit-of-the-bargain damages where plaintiffs alleged they paid for services that included data protection, the services received were worth less than agreed, and they would not have purchased the services had they known about insufficient data protection.) Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 13 of 34 -14- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 expected that the PII provided to PowerSchool would be kept secure. Plaintiffs’ allegations that PowerSchool failed to implement the necessary security measures to fulfill this promise sufficiently allege an injury in fact and damages under a benefit-of- the-bargain theory. This advertised “security” of Plaintiffs’ data was a “benefit” which they did not receive. Thus, at this stage of the proceedings, Plaintiffs have sufficiently alleged a lost benefit of the bargain injury. C. Traceability and Redressability Plaintiffs have adequately alleged that their injuries are fairly traceable to, and likely caused by, Powerschool. Here, Plaintiffs allege that their personal information appeared on the dark web following the data breach (Dkt. 259 ¶ 1001) and that they began to suffer harm thereafter (Id. ¶¶ 283–84). Plaintiffs further allege that they received multiple fraud alerts from CreditKarma, Rocketmoney, and Experian, including notification that their PII is available on the dark web. (Dkt. 259 ¶ 399.)7 It is reasonable to infer that postings to the dark web following a data breach are traceable to that breach. See Landon v. TSC Acquisition Corp., No. 2:24-cv-03788-SSS- PVC, 2024 WL 5317240, at *4 (C.D. Cal. Nov. 1, 2024). For traceability, a court may consider the cumulative nature of allegations and whether they “fall like dominos, layering on one another to create reasonable inferences” supporting traceability. Bozek v. Arizona Lab. Force, Inc., No. CV-24-02118-PHX-SMB, 2025 WL 264174, at *4 (D. Ariz. Jan. 22, 2025). The following allegations create a reasonable inference that Plaintiffs’ injuries are connected to the data breach: (1) they provided their information to PowerSchool; (2) PowerSchool’s data was stolen by threat actors; (3) they observed their stolen personal information posted online by the hackers; and (4) they experienced harms related to the 7 Dkt. 259 ¶ 399 (For example, shortly after the breach, it is alleged that Plaintiff Suave experienced an extreme increase in spam phone calls, spam text messages, and phishing emails. He had two bank accounts compromised, requiring him to spend several hours on the phone with banks to close them. His bank verified a fraud claim on May 24, 2025, for $78.99). Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 14 of 34 -15- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 data breach. The dark web postings, according to the Complaint, include claims that the information was retrieved from PowerSchool’s “PowerSource” portal. Consequently, it is plausible that information exposed in the data breach could have been used and is being used to commit fraud, particularly given the sensitive nature of the PII exposed and its appearance on the dark web. The Court finds that these allegations, combined with the fraudulent transfers that followed, make it at least plausible that the fraudulent transactions Plaintiffs suffered are traceable to the data breach. Defendants contend that Plaintiffs’ injuries are too speculative and therefore not redressable. (Dkt. 285.) The Court disagrees. It is correct to say that a plaintiff must establish that “it [is] ‘likely,’ as opposed to merely ‘speculative,’ that the injury will be redressed by a favorable decision.” Greenstein v. Kaminer, No. 21-cv-01785-BAS-AHG, 2022 WL 17418972, at *5 (S.D. Cal. Dec. 5, 2022) (quoting Lujan, 504 U.S. at 560–61). But in the Complaint, Plaintiffs here allege actual and imminent concrete injuries, and Plaintiffs allege their injuries will be addressed by money damages and injunctive relief. Thus, Plaintiffs have, at this point, plausibly alleged facts demonstrating all of the standing requirements of Article III and compensable damages to proceed to class certification and summary judgment. D. Negligence Claims Plaintiffs allege Powerschool was negligent (Count I). To state a claim for relief based on negligence under California law, a plaintiff must show that: (1) the defendant had duty to use due care; (2) a breach of that duty; and (3) that the breach was the proximate or legal cause of the resulting injury. Brown v. USA Taekwondo, 11 Cal. 5th 204, 213 (Cal. 2021); Regents of University of California v. Superior Court, 4 Cal. 5th 607, 619 (Cal. 2018). Duty is a question of law for the court. Hernandez v. Jensen, 61 Cal. App. 5th 1056, 1063 (2021). Breach of that duty and causation are questions of fact for the jury. Id. The elements of a claim for negligence under the laws of Massachusetts, New York, and Michigan are similar. See Glidden v Maglio, 722 N.E. 971, 973 (Mass. Sup. Ct. 2000) (same); Stagl v. Delta Airlines, Inc., 52 F.3d 463, 467 (2nd Cir. 1995) Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 15 of 34 -16- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 (describing New York law of negligence); Doe v. Henry Ford health Sys., 308 Mich. App. 592, 600 (same). 1. Duty Plaintiffs allege that PowerSchool owed a duty of care to take reasonable measures to ensure that the agents and associates they entrusted with Plaintiffs’ and Class Members PII . . . implement adequate data security practices to prevent unauthorized third party’s access. Complaint, at ¶¶ 767-798. Plaintiffs have sufficiently alleged that Powerschool owed a duty to Plaintiffs to survive a motion to dismiss. Plaintiffs adequately allege that the risk of harm to their data was foreseeable to PowerSchool. Plaintiffs also adequately allege that Powerschool understood the importance of data security, that data breaches are common, and that it failed to take reasonable steps to prevent this breach. (Dkt. 259 ¶ 9.)8 Powerschool does not suggest -- in the pages of its motion to dismiss -- that it had no duty. And Powerschool does not contend that it did not breach whatever duty it did have. Accordingly, it is fair to say that Plaintiffs plausibly allege that Powerschool owed a duty of care to protect Plaintiffs’ data from foreseeable risk of harm. 2. Damages Instead, Powerschool contends that Plaintiffs have failed to plead the last element of a negligence claim for relief, i.e., injuries resulting from any breach of duty. Powerschool Mem. in Support of MTD, Dkt. 285 at 19-22; Reply Mem. in Support of MTD, Dkt. 360 at 15-17. Thus, Powerschool argues, that if there is no injury, its breach of duty alone fails to state a claim for relief based on the principle that “a negligent act is not actionable unless it results in injury to another.” Fields v. Napa Milling Co., 164 Cal. 8 Dkt. 259 ¶ 9 (Plaintiffs allege that PowerSchool, among other things, “(1) failed to require a multi-factor authentication procedure to enter its systems; (2) failed to require users to change their passwords; and (3) permitted individuals to access PII despite those individuals not needing access to that PII to do their jobs. PowerSchool also failed to encrypt PII within its system. Had PowerSchool taken just one of these basic security measures, the Data Breach could have been easily averted.”). Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 16 of 34 -17- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 App. 2d 442, 447 (1958) (citing 35 Cal. Jur. 2d, Negligence, § 52, p. 549) (“enunciating the complementary Latin reciprocals ‘injuria absque damno’ and ‘damnum absque injuria,’ which properly interpreted mean that a wrong without damage does not constitute a cause of action for damages any more than damage without wrong does not ordinarily constitute a cause of action.”); cf. In re Sony Gaming Networks & Customer Data Sec. Breach Litig., 903 F. Supp. 2d 942, 963 (S.D. Cal. 2012) (observing that allegations may be enough to assert Article III standing based solely on increased risk of future harm while at the same time be insufficient to state a negligence claim for relief). The weakness in Powerschool’s position is that it characterizes Plaintiffs’ Complaint as alleging only an unadorned risk of future injury. But Plaintiffs have gone much farther. Several of the individual named Plaintiffs plausibly allege that which this Court deems to be actual injuries. Moreover, the proof of an actual injury and the damages an injury may have caused are issues left to be decided by a jury. Jensen, 61 Cal. App. 5th at 1063. Accordingly, Powerschool’s motion to dismiss the simple negligence claim (Count I) is denied. Powerschool does make one compelling argument. Powerschool argues for dismissal of a negligence claim based on its alleged failure to timely notify victims of the data breach. Powerschool Mem. in Support of MTD, Dkt. 285 at 22. Plaintiffs assert that Powerschool breached its duties by waiting ten days after learning of the data breach before providing notice to the Plaintiffs/victims, and that the delay exacerbated their injuries. See Complaint at ¶ 790. The claim as stated is wholly conclusory and not plausibly pleaded. Therefore, Powerschool’s motion to dismiss the negligent delay of notification claim as part of the negligence claim (Count I) is granted. E. Negligence Per Se Plaintiffs agreed to voluntarily dismiss their standalone negligence per se claims under California, Massachusetts, and Michigan state law because those states do not recognize negligence per se as an independent cause of action. (ECF No. 307.) As a result, only the negligence per se claim based on New York law remains (Count II). The Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 17 of 34 -18- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 parties also agreed that the substance of Plaintiffs’ negligence per se allegations would be incorporated into Plaintiffs’ other negligence claim (Count I). (Id.; see Dkt. 259 ¶¶ 800- 827.)9 Consistent with the parties’ agreement, the Court permitted Plaintiffs to maintain their negligence per se allegations under the respective state statutes and industry standards as pled within their negligence claim. Concerning the New York law-based claim, Powerschool argues that the federal statutes Plaintiffs rely on do not provide a basis for a negligence per se claim because the federal statutes do not provide a private cause of action. Reply Mem. in Support of MTD, Dkt. 360 at 21. One court applying New York law found that negligence per se could not be based on federal statutes that do not confer a private right of action such as HIPAA and the FTC. See Cohen v. Ne. Radiology, P.C., No. 20 CV 1202 (VB), 2021 WL 293123, at *7 (S.D.N.Y. Jan. 28, 2021) (“And several New York courts have concluded that neither HIPAA nor the FTC Act can sustain a negligence per se claim.”). Other courts applying New York law have come to the opposite conclusion. See e.g., In re Cap. One Consumer Data Sec. Breach Litig., 488 F. Supp. 3d 374, 407–08 (E.D. Va. 2020) (“[B]ecause New York law would permit the Plaintiffs to assert a negligence per se claim premised on a federal statute and because Plaintiffs have adequately done so here—importing the standard of care from the FTC Act—Plaintiffs have plausibly 9 See Dent v. National Football League, 968 F.3d 1126, 1130 (9th Cir. 2020) (quoting Johnson v. Honeywell International Inc., 101 Cal. Rptr. 3d 726, 731 (Ct. App. 2009)) (recognizing that “negligence per se . . . creates an evidentiary presumption that affects the standard of care in a cause of action for negligence”); see also In re Accellion, Inc. Data Breach Litig., 713 F. Supp. 3d 580, 639–40 (N.D. Cal. 2024) (allowing negligence per se allegations under the FTC Act, HIPAA, and other statutes to support elements of negligence claim under California law); Randall v. Michigan High School Athletic Ass’n, 965 N.W.2d 690, 703 (Mich. Ct. App. 2020) (“When a plaintiff proves that an actor has violated the terms of a statute,” the violation serves as “prima facie evidence of negligence.”); Lev v. Beverly Enterprises-Massachusetts, Inc., 929 N.E.2d 303, 313 (Mass. 2010) (“[T]he violation of a statute, ordinance, regulation, or policy is relevant because it constitutes some evidence of a defendant’s negligence.”). Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 18 of 34 -19- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 alleged a claim for negligence per se under New York law.”). Under New York law, even if a statute does not provide a private cause of action, it may still serve as a predicate for a negligence per se claim. German by German v. Fed. Home Loan Mortg. Corp., 896 F. Supp. 1385, 1397 (S.D.N.Y. 1995) (“Although a statutory scheme intended for the protection of a particular class does not expressly provide for civil liability, a court may, in furtherance of the statutory purpose, impose negligence per se, or even strict liability, for a statutory violation.”) (citing Trimarco v. Klein, 56 N.Y.2d 98, 107, 436 N.E.2d 502, 506 (1982)). Because the Court finds that the federal statutes Plaintiffs identify in their Complaint are of the type which would serve as a basis for negligence per se under New York state law, Powerschool’s motion to dismiss the remaining negligence per se claim (Count II) is denied. F. Negligent Training and Supervision Plaintiffs assert a claim for negligent training and supervision (Count IX). Plaintiffs mainly allege that a service provider to PowerSchool, Defendant Movate, had “inadequate data security, training, procedures, and network infrastructures – along with its own failures in hiring and training employees and agents.” Complaint, at ¶¶ 909-924. To state a claim for negligent training and supervision in California, Plaintiffs must allege that “an employer may be liable to a third person for the employer’s negligence in hiring or retaining an employee who is incompetent or unfit. Negligence liability will be imposed upon the employer if it knew or should have known that hiring the employee created a particular risk or hazard and that particular harm materializes.” Delfino v. Agilent Technologies, Inc., 145 Cal. App. 4th 790, 815 (2006).10 “Liability for negligent supervision and/or retention of an employee is one of direct liability for negligence, not vicarious liability.” Id. 10 California follows the rule set forth in the Restatement Second of Agency § 213. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 19 of 34 -20- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 Powerschool moves to dismiss raising two arguments. First Powerschool argues that this claim for relief requires all of the same elements as a claim for simple negligence and based on its arguments that the negligence claims should be dismissed, Powerschool argues the negligent training and supervision claim should be dismissed. Powerschool Mem. in Support of MTD, Dkt. 285 at 24. However, Plaintiffs adequately plead their simple negligence claims and thus, Powerschool’s first argument is unpersuasive. The second argument Powerschool raises is that Plaintiffs failed to plead that Powerschool “knew or should have known” that Movate’s employees were unfit. Id. Powerschool cites as an example, that Plaintiffs did not allege that it knew the Movate employee whose credentials were stolen which led to the breach. But it does not have to plead that it knew of a particular subcontractor’s employee, at the pleading stage. While the Complaint could be more detailed as to how Powerschool’s decision to subcontract work to Defendant Movate caused Plaintiffs’ injuries, at the pleading stage, these allegations are sufficient to support the inference that Powerschool should have known that a data breach would be likely to occur due to “inadequate data security, training, procedures, and network infrastructures at Movate. See e.g., In re Bank of Am. California Unemployment Benefits Litig., 674 F. Supp. 3d 884, 926 (S.D. Cal. 2023), reconsidered on other grounds, No. 21md2992-GPC (MSB), 2024 WL 3174380 (S.D. Cal. June 25, 2024) (denying motion to dismiss negligent hiring and supervision claim where data breach caused by defendant’s subcontractor). Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 20 of 34 -21- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 It is not at all clear that the other three representative jurisdictions of Michigan11, New York12, or Massachusetts13 would recognize a claim for negligent supervision in this 11 For its tort, Michigan law seems to require an injury to a customer at the employer’s physical location, a context not present in Powerschool’s case. There is no dispute about the law in Michigan applicable to this case. It was held in Bradley v. Stevens (1951) 329 Mich. 556, headnote 2, 46 N.W.2d 382, ‘An employer who knew or should have known of his employee's propensities and criminal record before commission of an intentional tort by employee upon customer who came to employer's place of business would be liable for damages to such customer.’ The principle is stated in 34 A.L.R.2d 390, s 9: Negligence; selection or retention of employee. As has already been noted, a duty imposed upon an employer who invites the general public to his premises, and whose employees are brought into contact with the members of such public in the course of the master's business, is that of exercising reasonable care for the safety of his customers, patrons, or other invitees. It has been held that in fulfilling such duty, an employer must use due care to avoid the selection or retention of an employee whom he knows or should know is a person unworthy, by habits, temperament, or nature, to deal with the persons invited to the premises by the employer. The employer's knowledge of past acts of impropriety, violence, or disorder on the part of the employee is generally considered sufficient to forewarn the employer who selects or retains such employee in his service that he may eventually commit an assault, although not every infirmity of character, such, for example, as dishonesty or querulousness, will lead to such result.' Hersh v. Kentfield Builders, Inc., 385 Mich. 410, 412–13, 189 N.W.2d 286, 288 (1971). 12 For its tort, New York law seems to require the plaintiff’s injury to have occurred on the employer’s premises, a context not present in Powerschool’s case. To state a claim for negligent supervision or retention under New York law, in addition to the standard elements of negligence, a plaintiff must show: (1) that the tort-feasor and the defendant were in an employee- employer relationship, (2) that the employer “knew or should have known of the employee's propensity for the conduct which caused the injury” prior to the injury's occurrence, and (3) that the tort was committed on the employer's premises or with the employer's chattels. Ehrens v. Lutheran Church, 385 F.3d 232, 235 (2d Cir. 2004) (citations omitted). 13 For its tort, Massachusetts law seems to require a public-facing employee who injured the plaintiff, a context not present in Powerschool’s case. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 21 of 34 -22- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 case, but Powerschool does not advance an argument to dismiss along these lines. Accordingly, Powerschool’s motion to dismiss the negligent training and supervision claim (Count IX) is denied. G. Invasion of Privacy Claims Powerschool next moves to dismiss the invasion of privacy claims (Count IV; Count XV). Powerschool Mem. in Support of MTD, Dkt. 285 at 25-28. Plaintiffs bring a common law invasion of privacy claim and the California Plaintiffs bring an additional invasion of privacy claim under the California Constitution. “The California Constitution and the common law set a high bar for an invasion of privacy claim. Even disclosure of personal information, including social security numbers, does not constitute an ‘egregious breach of the social norms’ to establish an invasion of privacy claim.” Low v. LinkedIn Corp., 900 F. Supp. 2d 1010, 1025 (N.D. Cal. 2012). Under the California Constitution, “[a]ctionable invasions of privacy must be sufficiently serious in their nature, scope, and actual or potential impact to constitute an egregious breach of the social norms underlying the privacy right.” Id. (citation omitted). A common law invasion of privacy claim must meet similarly high standards. Under a claim for common law invasion of privacy tort, a plaintiff must allege a defendant’s intrusion “in a manner highly offensive to a reasonable person.” Id. (citation omitted). The weakness in Plaintiffs’ claims is that it is not alleged that Powerschool invaded private information. Instead, the allegation is that Powerschool was reckless “by Notably, private employers hiring public-facing employees must exercise reasonable care in selecting those employees and, in retaining them, must continue “exercising reasonable care to ensure that their employees do not cause foreseeable harm to a foreseeable class of plaintiffs.” A private employer who fails to exercise reasonable care in hiring, training, supervising, and retaining such public-facing employees can be liable for its negligence in this regard. Theisz v. Massachusetts Bay Transportation Auth., 495 Mass. 507, 518–19, 252 N.E.3d 1028, 1037 (2025) (citations omitted) Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 22 of 34 -23- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 choosing to implement low-budget security measures with absolute disregard of its consequences and while simultaneously holding itself out to Plaintiffs and Class Members as respecting a higher standard of security,” or by knowing or recklessly disregarding “the fact that organizations handling personally identifiable information are highly vulnerable to cyberattacks and that employing inadequate security and training practices would render them especially vulnerable to data breaches.” Complaint at ¶¶ 859-861. It is not alleged that Powerschool was the actor that invaded Plaintiffs’ reasonable expectation of privacy. Rather it is alleged that an unrelated criminal data thief invaded and exfiltrated Plaintiffs’ highly private information. That is fatal to Plaintiffs’ invasion of privacy claims. See e.g., In re Accellion, Inc. Data Breach Litig., 713 F. Supp. 3d 623, 646 (N.D. Cal. 2024), reconsideration denied, No. 21-CV-01155-EJD, 2024 WL 4592367 (N.D. Cal. Oct. 28, 2024) (“With respect to the intrusion upon seclusion claim, the Court finds that the Complaint has failed to allege that Accellion had acted intentionally with respect to the data breach. The Complaint only alleges that Accellion had “acted knowingly and in reckless disregard” of Plaintiffs' privacy rights. However, as courts in this district have found, there is ‘no authority that suggests that failure to take adequate measures to protect against the intentional intrusion of a third party satisfies the first element of a claim for intrusion on seclusion.’”); In re Shields Health Care Grp., Inc. Data Breach Litig., 721 F. Supp. 3d 152, 164 (D. Mass. 2024) (“Plaintiffs’ claim does not pass muster because Plaintiffs allege only that hackers disseminated their private information and intruded on their privacy, not that [defendant company] Shields did.”) (applying Massachusetts law); see also Polkowski v. Jack Doheny Companies, Inc., No. 2:25-CV-10516, 2025 WL 3079358, at *11 (E.D. Mich. Nov. 4, 2025) (“Michigan courts recognize that the objectionable obtaining of the information must be done by the defendant whom the plaintiffs are suing.”) (applying Michigan invasion of privacy law). None of the cases Plaintiffs cite stand for the proposition that a merely reckless holder of private information may be liable on an invasion of privacy theory. And New Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 23 of 34 -24- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 York does not even recognize a claim for invasion of privacy. Reeves v. City of New York, No. 24-CV-2408 (NRM) (MMH), 2026 WL 309532, at *11 (E.D.N.Y. Feb. 5, 2026) (“Reeves also raises what appear to be common-law invasion of privacy and intrusion on seclusion claims . . . . However, New York law recognizes neither of these common-law causes of action.”) (citations omitted). Accordingly, Powerschool’s motion to dismiss the invasion of privacy claims (Count IV; Count XV) is granted. H. Breach of Fiduciary Duty Claim Plaintiffs allege in Count VII that Powerschool, by “accepting, taking possession, collecting, storing, and processing Plaintiffs’ and Class Members’ highly sensitive data . . . formed a special relationship and became a guardian of Plaintiffs’ and Class Members’ PII.” Plaintiffs allege, inter alia, “Defendants thus had a fiduciary duty to act primarily for Plaintiffs and Class Members, (a) for the safeguarding of Plaintiffs’ and Class Members’ PII; (b) to timely notify Plaintiffs and Class Members of a Data Breach; and (c) to maintain complete and accurate records of what information Defendants store and where they store it.” Complaint at ¶¶ 895-907. Powerschool moves to dismiss the claim. Powerschool says, “[i]t is well- recognized that simply maintaining an individual’s confidential information does not create a fiduciary relationship.” Mem. in Support of MTD, Dkt. 285 at 28-29 (citing In re Ambry Genetics Data Breach Litig., 567 F. Supp. 3d 1130, 1145-46 (C.D. Cal. 2021)). Powerschool cites similar decision under New York and Michigan law. Plaintiffs, remonstrate that none of these cases address the unique setting involving minor schoolchildren victims who were compelled by law to attend school and as a result compelled to used Powerschool’s software product. It is a novel claim but a plausible one in the specific alleged context. It is alleged that Powerschool knew well that it was maintaining the personal information of millions of minor schoolchildren who were in no position to protect themselves from Powerschool’s actions or negligence. Indeed, it was the Powerschool’s prime business. Relative bargaining power was unequal. As a matter Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 24 of 34 -25- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 of policy, schoolchildren deserve to be protected until they reach the age at which they can protect themselves. Therefore, Plaintiffs’ claim for breach of fiduciary duty (Count VII) is plausibly alleged and the motion to dismiss is denied. I. Unjust Enrichment Plaintiffs assert a claim for unjust enrichment against Powerschool (Count III). Complaint at ¶¶ 828-850. Powerschool moves to dismiss, citing In re Sony Gaming Networks & Customer Data Sec. Breach Litig., 903 F. Supp. 2d 942, 973–74 (S.D. Cal. 2012) (“Courts consistently have held that unjust enrichment is not a proper cause of action under California law.”). Mem. in Support of MTD, Dkt. 285 at 29. The Ninth Circuit has since addressed the notion. Astiana v. Hain Celestial Grp., Inc., 783 F.3d 753, 762 (9th Cir. 2015). Astiana observed, [a]s the district court correctly noted, in California, there is not a standalone cause of action for “unjust enrichment,” which is synonymous with “restitution.” However, unjust enrichment and restitution are not irrelevant in California law. Rather, they describe the theory underlying a claim that a defendant has been unjustly conferred a benefit “through mistake, fraud, coercion, or request.” The return of that benefit is the remedy “typically sought in a quasi-contract cause of action.” When a plaintiff alleges unjust enrichment, a court may “construe the cause of action as a quasi-contract claim seeking restitution. Id. 14 To succeed under California law, Plaintiffs must show that Powerschool received and unjustly retained benefits that rightfully belonged to Plaintiffs. The same is true under Michigan law. In re Flagstar Dec. 2021 Data Sec. Incident Litig., No. 22-CV- 11385, 2024 WL 5659583, at *11 (E.D. Mich. Sept. 30, 2024) (“To state a claim for Unjust Enrichment under Michigan law, a plaintiff must demonstrate ‘(1) the receipt of a 14 See Munoz v. MacMillan, 195 Cal. App. 4th 648, 661 (2011) (“Common law principles of restitution require a party to return a benefit when the retention of such benefit would unjustly enrich the recipient; a typical cause of action involving such remedy is ‘quasi-contract.’“). Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 25 of 34 -26- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 benefit by the defendant from the plaintiff and (2) an inequity resulting to the plaintiff because of the retention of the benefit by the defendant.’”). Here, Plaintiffs allege that Powerschool received a benefit in the form of money that should have gone to pay for “appropriate data security measures.” Complaint at ¶831. Similarly, Plaintiffs allege that “PowerSchool enriched itself by saving the costs PowerSchool reasonably should have expended on data security measures to secure Plaintiffs’ and Class Members’ PII. Rather than providing a reasonable level of security that would have prevented the Data Breach, PowerSchool instead calculated to increase its own profits at the expense of Plaintiffs and Class Members by using cheaper, ineffective security measures.” Id. at ¶ 840. This is sufficient to plausibly allege a quasi- contract claim for restitution in California. Under Massachusetts law, an unjust enrichment claim depends on the unavailability of an adequate remedy at law. In re LastPass Data Sec. Incident Litig., 742 F. Supp. 3d 109, 129 (D. Mass. 2024) (“party with an adequate remedy at law cannot claim unjust enrichment”). The same is true under New York law. Toretto v. Donnelley Fin. Sols., Inc., 583 F. Supp. 3d 570, 602 (S.D.N.Y. 2022) (“An unjust enrichment claim is not available where it simply duplicates, or replaces, a conventional contract or tort claim.”). As it remains for trial to determine whether Plaintiffs will enjoy another remedy at law, it is too early to dismiss an unjust enrichment claim at the pleading stage, in any event. Accordingly, Powerschool’s motion to dismiss the unjust enrichment claim (Count III) is denied. J. State Consumer Protection Claims and California’s UCL Claim Powerschool moves to dismiss claims of violating 38 state consumer protection statutes. Plaintiffs have not opposed the motion except as to the California’s Unfair Competition Law claim (“UCL”) (Cal. Bus. & Prof. Code § 17200, et seq.) (Count XVI). For the UCL claim, Powerschool argues that Plaintiff must establish the lack of an adequate other remedy of law, citing Sonner v. Premier Nutrition Corp., 971 F.3d 834, 844 (9th Cir. 2020) (“Under these principles, Sonner must establish that she lacks an Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 26 of 34 -27- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 adequate remedy at law before securing equitable restitution for past harm under the UCL. . . . “). Like the unjust enrichment claim, as it remains for trial to determine whether Plaintiffs will enjoy another remedy at law, it is too early to dismiss the UCL claim at the pleading stage. Powerschool also claims that Plaintiffs have failed to adequately allege a claim under the UCL. “A business practice which is neither unlawful nor fraudulent may nevertheless be unfair under the UCL.” Jordan v. Paul Fin., LLC, 745 F. Supp. 2d 1084, 1099 (N.D. Cal. 2010). “[T]he statute’s ‘unlawful’ prong. . . of the UCL incorporates other laws to make them actionable. Generally, ‘violation of almost any law may serve as a basis for a UCL claim.’” Id. While it remains for trial to see if Plaintiffs can prove the violation of another law and the unfairness of Powerschool’s action or inaction, the claim is plausible. Accordingly, Powerschool’s motion to dismiss the California UCL claim (Count XVI) is denied. K. Data Breach Notification Claims Plaintiffs assert many claims under the data breach notification laws of various states. Some have been voluntarily dismissed (such as Count XX1 for Colorado, Count XXVII for Illinois, Count XXXIX for Maryland, Count XLII for Michigan, Count XLVIII for Montana, Count LII for New Jersey, Count LVIII for North Dakota, Count LXIII for Oregon, and Count LXXVIII for Wisconsin). Some claims remain. However, Powerschool does not specifically identify which remaining claims deserve dismissing, instead, arguing against all such remaining claims on different theories. Mem. in Support of MTD, Dkt. 285 at 43-47. And the Plaintiffs respond in summary fashion as well. Plaintiffs’ Oppo. Dkt. 320 at 57-58. There are three exceptions. Powerschool argues there is no private right of action under the laws of New York, New Mexico, or Massachusetts. Plaintiffs do not disagree about the New York statute. As to the other two state laws, Plaintiffs simply respond that the statutes are silent and that it is an open question. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 27 of 34 -28- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 The Achilles’ heel of all of Plaintiffs’ notification claims is that Powerschool allegedly discharged its notifications duty very quickly. The breach was allegedly discovered on December 28, 2024 and ten days later, including four weekend days, New Year’s eve, and New Year’s day, Powerschool disclosed the incident on its website. Complaint, at ¶¶ 122-124. In this Court’s experience, data breach notifications typically occur months later. Consequently, Plaintiffs’ allegations that the “delay” was unreasonable falls below the plausibility standard for a motion to dismiss. Moreover, Plaintiffs do not plausibly alleged injuries that resulted from the ten day passage of time. Accordingly, Powerschool’s motion to dismiss the remaining state law data breach notification law claims is granted. L. California Penal Code § 502(c)(6) and (7) Plaintiffs assert a violation of California Penal Code § 502(c)(6) and (7) (Count XIX). This statute criminalizes data access in computer systems when done without permission and knowingly. Specifically, § 502 makes it a crime to: “(6) Knowingly and without permission provides or assists in providing a means of accessing a computer, computer system, or computer network in violation of this section” or “(7) Knowingly and without permission accesses or causes to be accessed any computer, computer system, or computer network.” Powerschool moves to dismiss arguing the statute is inapplicable for two reasons. First, it argues that it did not actually participate in the unauthorized hacking, and such an allegation is a requirement of the statute. Second, Powerschool had permission to access Plaintiffs’ data (obviously). Claridge v. RockYou, Inc., 785 F. Supp. 2d 855, 863 (N.D. Cal. 2011) is persuasive. Claridge interpreted these sections in a reasonable way to find that a company (similar to Powerschool) maintaining a database which was hacked by outside actors did not fit the statutory definitions in § 502 of a wrongful actor and dismissed plaintiff’s claim. Accordingly, Powerschool’s motion to dismiss the California Penal Code § 502(c)(6) and (7) (Count XIX) claim is granted. M. California Confidentiality of Medical Information Act Claim Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 28 of 34 -29- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 Plaintiffs assert Powerschool violated the California Confidentiality of Medical Information Act (CIMA) (Cal.Civ.Code § 56) (Count XIV). Complaint, at ¶¶ 978-1007. Powerschool moves to dismiss the claim arguing it does not fall under the Act because it is not a provider of health care. It also argues that its business was not organized for the purpose of maintaining medical information and its software is not designed to maintain medical information. Mem. in Support of MTD, Dkt. 285 at 48-50. It also asserts that the Complaint fails to allege medical information was actually viewed. A California appellate court decision puts these objections to rest. J.M. v. Illuminate Education, Inc., 103 Cal.App.5 th 1125 (Cal.Ct.App. 2024), addressed a similar context and found that the legislature intended the CMIA to address the type of data breach that allegedly occurred in this case. The court said that that California legislature intended to create a cause of action for “negligent storage” which leads to unauthorized access to an individual’s medical information. Id. at 1133. J.M. found that allegations that the Illuminate software company agreed to safeguard medical information but was negligent. Illuminate’s negligence led to the type of harm the legislature sought to prevent in enacting the CMIA, i.e., “[n]egligence causing a data breach that exposed confidential information to cyber hackers.” Id. The court of appeals held that such allegations were sufficient to state a cause of action under the CMIA. Id. J.M. is persuasive and applied here leads to the conclusion that Powerschool could be liable for negligently handling medical information under the CMIA. Accordingly, the motion to dismiss the CMIA claim (Cal.Civ.Code § 56) (Count XIV) is denied. N. California Consumer Privacy Act Claim Plaintiffs allege Powerschool is a business subject to the California Consumer Privacy Act (“CCPA”), that Powerschool violated the requirement to exercise reasonable security measures for their private data and seeks statutory and actual damages (Count XIII). See Cal.Civ.Code §§ 1798.100, et seq. Powerschool moves to dismiss arguing that the CCPA distinguishes between a business and a service provider, imposing liability Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 29 of 34 -30- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 only on a business. Compare § 1798.140(d)(1) (“business”) and § 1798.140(ag)(1) (“service provider”). Powerschool argues that it is solely a “service provider” for purposes of the Act and therefore not liable for damages or penalties under the Act. Mem. in Support of MTD, Dkt. 285 at 51-53; see also Cal.Civ.Code § 1798.150(a) (providing a right to recover damages from a “business” for a consumer who is subject to exfiltration or theft of personal data as a result of a business’ violation of the duty to implement and maintain reasonable security). Oversimplified, the difference is that a “business” collects personal information and “determines the purposes and means of the processing of that information, on the one hand. On the other hand, a “service provider” “processes” personal information received from a business for a business purpose pursuant to a written contract. Powerschool argues that for a viable claim Plaintiffs would have had to allege that Powerschool “determines the purposes and means of the processing of consumers’ information.” Mem. in Support of MTD, Dkt. 285 at 52. That is an overly restrictive understanding of FRCP Rule 8’s short and simple claim requirement. Rule 8 does not require that level of detailed pleading. It remains for the factfinder at a later stage of proceedings to determine whether the facts of Powerschool’s operations qualify it as a business or a service provider under the CCPA. At this early stage of proceedings, Plaintiffs have stated a plausible claim for relief and Powerschool’s motion to dismiss the CCPA claim (Count XIII) is denied. O. Deceit by Concealment Claim Cal.Civ.Code §§ 1709-1710 Plaintiffs assert against Powerschool a claim of deceit by concealment in violation of California Civil Code § 1709 (Count XX). Complaint, at 1063 (citing §1710(3)). Powerschool moves to dismiss arguing that the Complaint fails to adequately allege facts supporting a conclusion that it had a duty to disclose the shortcomings of its security measures. Mem. in Support of MTD, Dkt. 285 at 53-54. Section 1709 creates liability for a company that “willfully deceives another with intent to induce him to alter his position to his injury or risk.” Section 1710 lays out four types of deceit. “There are Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 30 of 34 -31- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 ‘four circumstances in which nondisclosure or concealment may constitute actionable fraud: (1) when the defendant is in a fiduciary relationship with the plaintiff; (2) when the defendant had exclusive knowledge of material facts not known to the plaintiff; (3) when the defendant actively conceals a material fact from the plaintiff; and (4) when the defendant makes partial representations but also suppresses some material facts.’” LiMandri v. Judkins, 52 Cal. App. 4th 326, 336 (1997). Plaintiffs allege Powerschool suppressed or concealed information about how it did not secure Plaintiffs’ personal data, relying on § 1710(3) which defines one type of actionable deceit as “the suppression of a fact, by one who is bound to disclose it, or who gives information of other facts which are likely to mislead for want of communication of that fact.” Plaintiffs’ allege, “Defendants failed to disclose and actively concealed information about the material fact that they did not reasonably or adequately secure Plaintiffs and the California Subclass members’ PII, as well as the material fact that they did not comply with common law and statutory duties pertaining to the security and privacy of Plaintiffs and PII of the California Subclass members. As Defendants knew, their knowledge was exclusive to themselves and was not generally known to the public or to Plaintiffs and the California Subclass members, and had a duty to disclose those material facts to Plaintiffs and the California Subclass members . . . . Defendants knew that the security of the PII of Plaintiffs and the California Subclass members was materially worse than they represented and what Plaintiffs and the California Subclass members reasonably expected. Defendants intentionally concealed or suppressed that fact with intent to defraud Plaintiffs and the California Subclass members.” Complaint, at ¶¶ 1064-1065. Powerschool objects that Plaintiffs did not allege it had a duty to disclose. Mem. in Support of MTD, Dkt. 285 at 53. More accurately, Powerschool says that while Plaintiffs did alleged Powerschool had a duty to disclose, the allegation was too conclousory dismissing it as a “rote allegation.” Nonetheless, Plaintiffs have sufficiently alleged a plausible claim for deceit here. Whether Plaintiffs are able to prove their claim Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 31 of 34 -32- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 at trial is to be decided another day. Powerschool’s motion to dismiss the deceit claim (Count XX) is denied. P. Georgia State Recovery of Expenses OGCA § 13-6-11 Claim Plaintiffs Charlotte Renn, Katherine Stewart and Minor Student R.H.S., and John Rawls and Minor Student C.R., individually and on behalf of the Georgia Subclass, seek payment of their litigation expenses under Georgia statute OGCA §13-6-11 (Count XXV). Complaint, at ¶¶ 1108-1111. Powerschool moves to dismiss for failure to specify the grounds upon which Plaintiffs assert a right to recovery of expenses. Plaintiffs simply allege Powerschool “acted in bad faith, was stubbornly litigious, or caused Plaintiffs and the Georgia Subclass unnecessary trouble and expense regarding the transaction or events underlying this litigation.” More than this was required to state a claim in a Georgia data breach case. In re Equifax, Inc., Customer Data Sec. Breach Litig., 362 F. Supp. 3d 1295, 1344–45 (N.D. Ga. 2019) (“The Consumer Plaintiffs contend that they are entitled to recovery under section 13-6-11 because they have plausibly alleged that ‘Equifax's conduct leading up to the breach was egregious and that both the breach and injury were foreseeable.’”). In that case, egregious conduct and foreseeability was alleged and that was sufficient to state a claim. Id. Plaintiffs here have alleged neither egregious conduct nor that the breach and injury were foreseeable. Georgia Plaintiffs may be able to amend their complaint to state a claim for relief, but the claim as currently stated does not plausibly alleged a claim. Accordingly, Powerschool’s motion to dismiss the Georgia expense recovery claim (Count XXV) is granted. Q. Declaratory Judgment and Injunctive Relief The Declaratory Judgment Act provides a remedy, not an independent cause of action. City of Reno v. Netflix, Inc., 52 F.4th 874, 878–79 (9th Cir. 2022) (“We agree Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 32 of 34 -33- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 with our sister circuits that have considered the issue that the Declaratory Judgment Act does not provide an affirmative cause of action where none otherwise exists.”).15 Here, because Plaintiffs’ negligence claims and other claims for relief may proceed and because Plaintiffs’ declaratory judgment claim is predicated on those claims, Plaintiffs have sufficiently established a plausible claim for declaratory relief. Accordingly, Powerschool’s motion to dismiss the Declaratory Judgment Act claim (Count VI) is denied. V. CONCLUSION For the foregoing reasons, the Court ORDERS that the: 1. motion to dismiss the simple negligence claim (Count I) is denied. 2. motion to dismiss the negligent delay of notification claim as part of the negligence claim (Count I) is granted. 3. motion to dismiss the negligence per se claim based on New York state law (Count II) is denied. 4. motion to dismiss the negligent training and supervision claim (Count IX) is denied. 5. motion to dismiss the invasion of privacy claims (Count IV; Count XV) is granted. 6. motion to dismiss the claim for breach of fiduciary duty (Count VII) is denied. 7. motion to dismiss the unjust enrichment claim (Count III) is denied. 8. motion to dismiss the California UCL claim (Count XVI) is denied. 15 “A plaintiff's inability to rely on the Declaratory Judgment Act to obtain affirmative relief where no cause of action otherwise exists contrasts with the well-established availability of the Act for defensive use against anticipated claims. See Peterson v. Highland Music, Inc., 140 F.3d 1313, 1322 (9th Cir. 1998) (observing that, “[f]requently, the point of a declaratory action is to assert a defense anticipatorily”).” City of Reno, 52 F.4th at 879. Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 33 of 34 -34- 25-md-03149-BEN-MSB 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 9. motion to dismiss remaining state law data breach notification law claims is granted. 10. motion to dismiss the California Penal Code § 502(c)(6) and (7) (Count XIX) claim is granted. 11. motion to dismiss the CMIA claim (Cal.Civ.Code § 56) (Count XIV) is denied. 12. motion to dismiss the CCPA claim (Count XIII) is denied. 13. motion to dismiss the deceit claim (Count XX) is denied. 14. motion to dismiss the Georgia expense recovery claim (Count XXV) is granted. 15. motion to dismiss the Declaratory Judgment Act claim (Count VI) is denied. IT IS SO ORDERED. DATED: March ____, 2026 HON. ROGER T. BENITEZ United States District Judge 18 Case 3:25-md-03149-AJB-MSB Document 436 Filed 03/18/26 PageID.<pageID> Page 34 of 34