Corpus: 543,223 opinions · 3,177 judges · newest 2026-06-23 · expanding Coverage ↗
Opinion

govinfo:USCOURTS-casd-3_25-md-03149-6

U.S. District Court for the Southern District of California · 2026-03-24

· GavelSight synced 2026-09-06 03:44:02

-1- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
 
 
 
 
 
 
 
UNITED STATES DISTRICT COURT 
SOUTHERN DISTRICT OF CALIFORNIA 
 
IN RE: POWERSCHOOL 
HOLDINGS, INC. AND 
POWERSCHOOL GROUP, LLC 
CUSTOMER SECURITY BREACH 
LITIGATION. 
) 
) 
) 
) 
) 
) 
) 
) 

 
ORDER GRANTING IN PART AND 
DENYING IN PART DEFENDANT 
MOVATE, INC.’s MOTION TO 
DISMISS THE SCHOOL DISTRICT 
DIRECT ACTION 
FIRST AMENDED 
CONSOLIDATED COMPLAINT 
(TRACK 2) 
 
[Dkt. 366] 
 
I. INTRODUCTION 
This multidistrict litigation arises from a data breach involving Defendants 
PowerSchool Holdings, Inc. and PowerSchool Group, LLC (collectively, 
“PowerSchool”). PowerSchool provides cloud-based data management software for 
students and educators in K-12th. PowerSchool stores sensitive student medical, 
academic, and other personally identifiable information in a searchable format. 
Powerschool entered into a subcontract with Defendant Movate, Inc. for computer 
technology support services. 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 1 of 15
 
-2- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
Defendant Movate moves to dismiss the Track 2 School District Direct Action 
First Amended Consolidated Master Complaint and the three claims therein brought 
specifically against Movate. For the reasons set forth below, the Court GRANTS IN 
PART and DENIES IN PART Movate’s motion. 
II. BACKGROUND1 
It is alleged that PowerSchool is a Sacramento-based provider of educational 
management software used by schools. Schools require students, parents, and teachers to 
provide PowerSchool with sensitive personally identifiable information (“PII”), and 
PowerSchool stores and maintains this data. There are approximately 4,700 school 
customers, 4,668,000 teachers and 43,800,000 students affected by Powerschool’s 
maintenance of PII. Powerschool, according to the Complaint, holds out its school 
software product as being a secure repository of PII data. 
On December 20, 2024, the criminal group ShinyHunters used the stolen employee 
credentials of a Powerschool cybersecurity subcontractor (Movate, Inc.) to access 
PowerSchool’s student information system through its PowerSource portal. The 
hacker(s) exfiltrated PII and demanded a ransom from Powerschool. Powerschool paid 
the ransom. 
There are two groups of plaintiff school districts. This Order addresses only one of 
the Track 2 groups. The School District Direct Actions First Amended Consolidated 
Master Complaint (“DAC”) (Dkt. 288) sets forth 46 claims for relief. The Complaint 
asserts three claims against Movate: Negligence (DAC Count 8), Negligent Hiring and 
 
1 When deciding whether to grant a motion to dismiss, the court generally accepts as 
true all well-pleaded factual allegations. Ashcroft v. Iqbal, 556 U.S. 662, 664 (2009). 
The Court is not making findings of fact, but summarizing some of the allegations made 
in the 250 page, 46 claim, School District Direct Actions First Amended Consolidated 
Master Complaint (filed September 12, 2025) (Dkt. 288) (“DAC”). 
Movate has not moved to dismiss the other Track 2 Plaintiffs’ School District 
Amended Class Action Complaint (“CAC”) (Dkt. 263) which sets out eight claims for 
relief. 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 2 of 15
 
-3- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
Supervision (DAC Count 9), and Breach of Contract—Third Party Beneficiary ( DAC 
Count 10). The Complaint alleges that the breach compromised the PII of approximately 
50 million individuals, PII including social security numbers, medical information, 
financial information, addresses, disability records, and custody information. 
Movate is a Delaware corporation headquartered in Texas. PowerSchool hired 
Movate to provide technical support, customer service, network operations, and platform 
configuration for its online platform. According to the Complaint, PowerSchool gave 
Movate employees extensive access to the SIS and sensitive PII of students, their 
families, faculty, and teachers. 
 Plaintiffs claim that the attackers used the credentials of Rayson Cruz, a Movate 
employee in the Philippines with access to PowerSchool’s SIS. Multiple school districts 
reportedly identified a “Remote Support connection from the user ‘Rayson Cruz’” as a 
key sign of compromise. Plaintiffs assert that Movate failed to implement basic, 
industry-standard security measures, including credential rotation, multi-factor 
authentication, restrictions on employee access to PII, and proper training and 
supervision for employees and vendors. 
III. APPLICABLE LAW 
Under FRCP Rule 12(b)(2), “[i]n general, the court may exercise personal 
jurisdiction over an out of state defendant consistent with both the forum state’s long-arm 
statute and constitutional due process.” Palomar Health v. Am. Guar. & Liab. Ins. Co., 
2021 WL 4035005, at *2 (S.D. Cal. Sept. 3, 2021), aff’d, 2022 WL 3006356 (9th Cir. 
July 28, 2022). “Where . . . the motion is based on written materials and affidavits rather 
than an evidentiary hearing, a plaintiff is only required to make a ‘prima facie showing of 
jurisdictional facts to withstand the motion to dismiss.’” Id.; Schwarzenegger v. Fred 
Martin Motor Co., 374 F.3d 797, 800 (9th Cir. 2004); Tokio Marine & Nichido Fire Ins. 
Co. v. Precision Trucking, 2009 U.S. Dist. LEXIS 139910, at *7 (S.D. Cal. Oct. 16, 
2009). 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 3 of 15
 
-4- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
 In determining whether a plaintiff has satisfied his burden, uncontroverted 
allegations in the complaint are taken as true. Id. On the other hand, bare bones 
assertions of minimum contacts with the forum or legal conclusions unsupported by 
specific factual allegations do not carry a plaintiff’s pleading burden. Id. (citing Swartz v. 
KPMG LLP, 476 F.3d 756, 766 (9th Cir. 2007)). 
Specific jurisdiction requires a showing that: (1) the defendant purposefully 
availed itself of the forum or purposefully directed its activities toward the forum; (2) the 
claim arises out of or relates to the forum-related conduct; and (3) the exercise of 
jurisdiction would be reasonable. Schwarzenegger, 374 F.3d at 802. 
A motion to dismiss under FRCP 12(b)(6) tests the legal sufficiency of the claims 
alleged in the complaint. Under FRCP 8, a complaint should include a “short and plain 
statement of the claim showing that the pleader is entitled to relief,” and may be 
dismissed under Rule 12(b)(6) if the plaintiff fails to state a cognizable legal theory or 
has not alleged sufficient facts to support such a theory. Somers v. Apple, Inc., 729 F.3d 
953, 959 (9th Cir. 2013). The court construes the alleged facts in the light most favorable 
to the plaintiff. See Retail Prop. Trust v. United Bhd. of Carpenters & Joiners of Am., 
768 F.3d 938, 945 (9th Cir. 2014). However, “courts are not bound to accept as true a 
legal conclusion couched as a factual allegation.” Iqbal, 556 U.S. at 678. 
To survive a motion to dismiss, a complaint must state a claim to relief that is 
plausible on its face. Iqbal, 556 U.S. at 678 (quoting Bell Atl. Corp. v. Twombly, 550 
U.S. 544, 570 (2007)). A claim has “facial plausibility when the plaintiff pleads factual 
content that allows the court to draw the reasonable inference that the defendant is liable 
for the misconduct alleged.” Twombly, 550 U.S. at 556. If the plaintiff’s explanation is 
plausible, the complaint survives a motion to dismiss under Rule 12(b)(6), “regardless of 
whether there is a more plausible alternative explanation.” Iqbal, 556 U.S. at 678. 
Thus, a “Rule 12(b)(6) motion tests the sufficiency of a complaint; it does not . . . 
resolve contests surrounding the facts, the merits of the claim, or the applicability of 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 4 of 15
 
-5- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
defenses.” W. Ins. Co. v. Frontier Homes, LLC, 2018 WL 8220544, at *2 (C.D. Cal. 
Mar. 27, 2018) (quoting King v. Rubenstein, 825 F.3d 206, 214 (4th Cir. 2016)). 
IV. DISCUSSION 
 A. Personal Jurisdiction 
Movate argues that the Court should dismiss Plaintiffs’ claims because the Court 
lacks personal jurisdiction. Movate contends that it is a Delaware corporation with its 
principal place of business in Texas and Plaintiffs fail to allege purposeful, suit-related 
conduct by Movate directed at California or any facts that would fairly justify pulling a 
Texas-based computer tech company into this forum. As discussed in a companion 
Order, the Court lacks general jurisdiction over Movate. However, it may exercise 
specific jurisdiction. 
The parties dispute whether purposeful direction or purposeful availment provides 
the correct analytical framework for specific jurisdiction. Plaintiffs discuss purposeful 
direction, arguing that this is a tort case and that Movate’s conduct was aimed at 
California. Movate asserts a lack of specific jurisdiction under purposeful availment 
analysis. In cases involving negligence or contract-like conduct, courts analyze whether 
the defendant engaged in acts demonstrating purposeful availment rather than Calder-
style purposeful direction. See Schwarzenegger, 374 F.3d at 802–03; Holland Am. Line 
Inc. v. Wartsila N. Am., Inc., 485 F.3d 450, 460 (9th Cir. 2007); Matter of Star & 
Crescent Boat Co., 549 F. Supp. 3d 1145, 1162 (S.D. Cal. 2021). There is no hard line 
distinction between the two approaches. 
The “‘purposeful availment’ requirement ensures that a defendant will not be haled 
into a jurisdiction solely as a result of ‘random,’ ‘fortuitous,’ or ‘attenuated’ contacts, or 
of the ‘unilateral activity of another party or a third person.’” Burger King Corp. v. 
Rudzewicz, 471 U.S. 462, 475 (1985) (internal citations omitted). A showing of 
purposeful availment “typically consists of evidence of the defendant’s actions in the 
forum, such as executing or performing a contract there.” Schwarzenegger, 374 F.3d at 
802. 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 5 of 15
 
-6- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
Movate argues that Plaintiffs have not demonstrated purposeful availment. 
However, under that framework, Plaintiffs have made a prima facie showing. Plaintiffs 
allege that Movate entered into a contract with PowerSchool, a California-based 
company, to provide technical support, customer service, network operations, and 
configuration services for PowerSchool’s SIS. Plaintiffs further assert that, under that 
contract, Movate intentionally accessed California computer systems, including 
PowerSchool’s SIS, and provided services to PowerSchool’s California school-district 
customers. Although Movate argues that the contract was nationwide and that its work 
was done remotely, those points do not negate jurisdiction at this stage. By servicing a 
multi-state school software system that contains sensitive information, including that of 
California students, parents, and teachers, Movate can be said to have assumed the 
benefits and responsibilities of operating as a California company and supporting data 
systems that affect California residents. See Burger King, 471 U.S. at 475-76, 480. 
The second prong is also satisfied. Plaintiffs allege that the breach occurred 
through the misuse of credentials belonging to a Movate employee who had access to 
PowerSchool’s SIS and that Movate’s failures to implement multi-factor authentication, 
credential rotation, least-privilege access, and adequate training enabled the breach. 
Accepting those allegations as true, the Plaintiffs’ claims stem directly from Movate’s 
conduct related to the forum and demonstrate the “something more” required. See 
Panavision Int’l, L.P. v. Toeppen, 141 F.3d 1316, 1322 (9th Cir. 1998). 
As to reasonableness, once the first two prongs are met, Movate bears the burden 
of presenting a compelling case that jurisdiction would be unreasonable. See Glob. 
Commodities Trading Grp., Inc. v. Beneficio de Arroz Choloma, S.A., 972 F.3d 1101, 
1107 (9th Cir. 2020). The relevant factors—including California’s interest in 
adjudicating claims involving the alleged compromise of sensitive information belonging 
to its residents and the efficiency of resolving those claims in this MDL— do not support 
dismissal. See CollegeSource, Inc. v. AcademyOne, Inc., 653 F.3d 1066, 1079 (9th Cir. 
2011). 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 6 of 15
 
-7- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
Movate downplays its role by describing itself as only “providing technical support 
remotely from outside the state, including employees located abroad, on behalf of its 
client, Powerschool under a contract governed by New York law,” calling it an 
“incidental, background commercial relationship.” The Direct Action School Districts 
Complaint paints a different picture of Movate providing technical support for a software 
product requiring technical competency across internet information flow and computer 
network maintenance for hundreds of schools and their millions of students and teachers 
affecting the safe-keeping of extremely important personal information data. The alleged 
role of Movate may have been a commercial relationship in the background, but it is 
hardly plausibly described as “incidental.” The Complaint adequately demonstrates 
Movate’s purposeful availment of the forum. 
Since the first two elements are shown in Plaintiffs’ favor, the exercise of 
jurisdiction is presumptively reasonable and the burden shifts to Movate to present a 
compelling case of unreasonableness. CollegeSource, Inc., 653 F.3d at 1079. This, 
Movate has not done. None of the seven factors articulated by the Ninth Circuit in 
CollegeSource demonstrate that it would be unfair for Movate to defend itself in this 
forum. Id. And although Movate says it has, “no operational presence in the state,” 
Plaintiffs point out that Movate’s website lists an office location in San Jose, California 
and has been registered to do business in California since 2000 with an actively registered 
business agent here. The Direct Action School Plaintiffs sufficiently allege facts 
supporting the fair exercise of personal jurisdiction over Defendant Movant. The motion 
to dismiss for lack of personal jurisdiction is denied. 
B. Negligence 
Movate next argues that even if Plaintiffs can establish personal jurisdiction, the 
Complaint fails to state a negligence claim against Movate because it owed no duty to 
Plaintiffs, and Plaintiffs do not allege facts showing that Movate breached any such duty. 
To establish a negligence claim, Plaintiffs must demonstrate duty, breach, 
causation, and injury. Vasilenko v. Grace Family Church, 3 Cal. 5th 1077, 1083 (2017). 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 7 of 15
 
-8- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
“The existence of a duty is a question of law.” Id. The Court finds that Plaintiffs have 
sufficiently stated a plausible negligence claim upon which relief can be granted. 
1. Duty and Breach 
Movate argues it owed no duty to the Direct Action School District Plaintiffs. 
Movate argues that the foreseeability of a breach does not create a duty, by itself. But the 
Complaint alleges more than foreseeability by itself. Movate says that it had no special 
relationship with the Plaintiffs because it is just a commercial service provider steps 
removed. But the Complaint does allege a special relationship, a special hazard, and a 
special undertaking. 
Movate uses an analogy of a bank’s online system describing Powerschool as the 
bank and Movate as a bank customer. Using this analogy, Movate argues that the bank’s 
online security vulnerabilities are not the customer’s fault. Applying the analogy, 
Movate defends itself by saying Powerschool (like the bank) set up the internet security 
protocols and it (like the customer) was simply using the Powerschool protocols already 
in place. As such, it had no duty to do more, goes the argument. 
A better analogy is that of a grammar school and fenced schoolyard in a 
neighborhood known for predators and criminals. The Plaintiffs are like the school 
requiring vulnerable children to be on its campus. Powerschool is like a school 
contractor hired to erect fencing and gates and padlocks around the schoolyard to keep 
the children safe within. Movate is like the security guard team hired by Powerschool to 
walk the fence line and rattle the gates and provide support to ensure the enclosure is 
secure. Movate attempts to deflect its alleged breach of duty by arguing Powerschool (in 
this analogy) should have built better gates with bigger padlocks and Movate’s security 
guards were not responsible for the security setup they were given. But the better 
analysis in this schoolyard analogy is that Movate’s school security guard team was well 
aware of the vulnerable children inside and the dangerous predators and criminals outside 
yet Movate (as the security guards in this analogy) negligently left the gates open and the 
padlocks on the ground. The allegations in the Complaint plausibly allege that Movate 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 8 of 15
 
-9- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
knew of the precious and valuable content of student and faculty PII, could foresee the 
likelihood of an attempt to exfiltrate the PII by criminals and predators, and negligently 
left the internet gates open with the data padlocks left on the ground. 
Under California law, a defendant has a general duty of reasonable care when their 
conduct creates a risk of harm. Brown v. USA Taekwondo, 11 Cal. 5th 204, 214 (2021). 
Where the defendant did not itself create the risk, a duty to protect may nonetheless arise 
from a special relationship with the plaintiff—one marked by dependency, control, and 
other indicia—even absent contractual privity. Id. at 215–16; In re Accellion, Inc. Data 
Breach Litig., 713 F. Supp. 3d 623, 633–35 (N.D. Cal. 2024) (applying Brown’s 
framework and Regents factors to find a special relationship between a data-transfer 
company and data subjects despite no privity); Bass v. Facebook, Inc., 394 F. Supp. 3d 
1024, 1039 (N.D. Cal. 2019) (failure to comply with minimum data-security standards 
constitutes a classic negligence claim); In re Facebook, Inc. Consumer Priv. Litig., 402 F. 
Supp. 3d 767, 799 (N.D. Cal. 2019) (defendant had responsibility to handle sensitive 
information with care); Castillo v. Seagate Tech., LLC, 2016 WL 9280242, at *3 (N.D. 
Cal. Sept. 14, 2016) (defendant duty-bound to protect personal identifying information it 
obtained). Courts in other jurisdictions have applied the same principle. See In re USAA 
Data Sec. Litig., 621 F. Supp. 3d 454, 469 (S.D.N.Y. 2022); Weekes v. Cohen Cleary 
P.C., 723 F. Supp. 3d 97, 103 (D. Mass. 2024). 
Here, Plaintiffs allege that Movate had broad access to and control over their 
private information, understood its sensitivity, and publicly touted compliance with 
recognized data-security standards. Plaintiffs also allege that Movate failed to put in 
place basic safeguards, even though credential-based attacks on school systems were 
predictable and well-publicized. At the pleading stage, these allegations sufficiently 
establish a duty and breach of the duty. Courts have recognized that the pleading 
standard for breach in data-breach negligence cases is not high, as the occurrence of a 
breach itself permits a reasonable inference of inadequate security at the pleading stage. 
See Schmitt v. Sn Servicing Corp., No. 2:18-cv-00133-JAM-CKD, 2021 WL 3493754, at 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 9 of 15
 
-10- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
5 (E.D. Cal. Aug. 9, 2021) (quoting Flores-Mendez v. Zoosk, Inc., No. C 20-04929 
WHA, 2021 WL 308543, at 4 (N.D. Cal. Jan. 29, 2021)) (when a breach occurs, the thing 
speaks for itself). Here, Plaintiffs go further. The Complaint points out specific failures: 
inadequate training on credential security; failure to rotate employee credentials; failure 
to implement least-privilege access; failure to require multi-factor authentication; and 
failure to limit access to private information. 
2. Causation 
The Complaint plausibly alleges causation. Plaintiffs allege that the breach was 
carried out using the compromised credentials of a Movate employee and that the breach 
would not have occurred had Movate required multi-factor authentication, rotated 
credentials, and limited employee access. Under the authorities cited by the parties, the 
intervention of third-party criminals does not sever causation where the defendant’s 
negligence allegedly created the risk that materialized. See Lugtu v. Cal. Highway 
Patrol, 26 Cal. 4th 703, 725 (2001) (“It is well established that when a defendant's 
negligence is based upon his or her having exposed the plaintiff to an unreasonable risk 
of harm from the actions of others, the occurrence of the type of conduct against which 
the defendant had a duty to protect the plaintiff cannot properly constitute a superseding 
cause that completely relieves the defendant of any responsibility for the plaintiff's 
injuries.”). At this stage, Plaintiffs need only plausibly allege that Movate’s conduct was 
a substantial factor in bringing about the harm. 
Movate emphasizes that its systems were not breached and that PowerSchool 
owned the underlying platform and core security settings. That point may bear on the 
ultimate allocation of responsibility. It does not defeat causation at the pleading stage. 
3. Damages 
Plaintiffs have adequately alleged cognizable damages. The Complaint alleges 
compromise of sensitive information, including Social Security numbers and medical 
information, as well as actual misuse, dark-web exposure, fraudulent activity, credit 
monitoring expenses, and time spent responding to the breach. Those allegations suffice 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 10 of 15
 
-11- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
at the pleading stage. See In re Shield Health Care Grp., Inc. Data Breach Litig., 721 F. 
Supp. 3d 152, 161 (D. Mass. 2024); Accellion, 713 F. Supp. 3d at 637. 
Each of the requirements to state a common law claim of negligence under any of 
the relevant states’ jurisprudence is satisfied by the plausible allegations set forth in the 
Plaintiff’s Complaint. Movate’s motion to dismiss the negligence claim is DENIED. 
C. Negligent Hiring or Negligent Supervision 
Movate next argues that Plaintiffs’ negligent hiring and supervision claim fails 
because Plaintiffs do not allege that Movate knew or should have known of any specific 
risk posed by its employee, Rayson Cruz. 
An employer may be liable for harm caused by negligent hiring, supervision, or 
retention of an incompetent employee, but the plaintiff must allege facts showing the 
employer knew or should have known that keeping the employee posed a risk of the 
specific harm that materialized. See Diaz v. Tesla, Inc., 598 F. Supp. 3d 809, 832–33 
(N.D. Cal. 2022); Gray v. Schenectady City Sch. Dist., 86 A.D.3d 771, 773 (N.Y. App. 
Div. 2011). 
Plaintiffs’ theory extends beyond a propensity claim targeting a single employee. 
They allege systemic failures in training and supervision, including failures to require 
credential rotation, restrict access to sensitive information, and train employees in data 
security practices. At the pleading stage, those allegations are sufficient. Plaintiffs allege 
that Movate, acting as PowerSchool’s agent, had a duty to hire qualified employees and 
to train and supervise them properly, especially since those employees had access to 
sensitive information. Plaintiffs further claim that systemic failures foreseeably 
contributed to the breach. Movate remonstrates that it is plausible that Movate acted with 
due care in its hiring and supervision of Mr. Cruz. That may prove to be true on 
summary judgment or at trial. But Plaintiffs’ allegations plausibly allege a claim of 
negligent hiring, training, or supervision, even without allegations of a prior specific 
tendency toward misconduct by the employee whose credentials were used. See In re 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 11 of 15
 
-12- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
Bank of Am. Cal. Unemployment Benefits Litig., 674 F. Supp. 3d 884, 926 (S.D. Cal. 
2023). 
Movate’s motion to dismiss the negligent hiring and supervision claim is 
DENIED. 
D. Breach of Contract Intended to Benefit Plaintiffs 
Movate’s last contention is that the breach of contract claim based on Plaintiffs as 
direct intended beneficiaries fails to state a claim for relief because Plaintiffs are not 
parties to the contract between Movate and PowerSchool, and they are not mentioned as 
intended beneficiaries. To state a claim for relief, it is important that the Plaintiffs 
plausibly allege facts showing the contract was intended for their direct benefit, otherwise 
the law does not recognize a claim where a plaintiff is simply an incidental beneficiary. 
Under New York law, only an intended beneficiary of a contract may assert a 
claim as a third party. Vista Co. v. Columbia Pictures Indus., Inc., 725 F. Supp 1286, 
1296 (S.D.N.Y. 1989) (citations omitted). “An intended beneficiary is one whose ‘right 
to performance is appropriate to effectuate the intention of the parties to the contract and 
either the performance will satisfy a money debt obligation of the promisee to the 
beneficiary or the circumstances indicate that the promisee intends to give the beneficiary 
the benefit of the promised performance.’” Id. (citations omitted). While the obligation 
to perform to the third party plaintiff need not necessarily be expressly stated in the 
contract (id.), “the intent to benefit a third party must be shown and the benefit must not 
be merely incidental but immediate to such a degree as to indicate the assumption of a 
duty to make reparation if the benefit is lost.” Strauss v. Belle Realty Co, 98 A.D. 2d 424 
*6 (N.Y. App. Div. Dec. 27, 1983) (citations omitted). 
Both parties point to the Global Services Agreement (“GSA”) agreement between 
Powerschool and Movate.2 See Movate’s MTD Dkt. 366, at n.8 and Exh. “A” to 
 
2 The GSA is a contract entered into on March 28, 2022 between Powerschool and 
Movate, Inc., formerly known as SlashSupport, Inc. doing business as CSS Corp. 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 12 of 15
 
-13- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
Declaration of J.D. White. They just differ about whether the terms of the GSA evince 
an intent to directly benefit the Direct Action School Districts. The School District 
Plaintiffs say it does and then point to Section 1.5 and 5.5 of the Data Privacy Agreement 
(“DPA”) which is an amendment to the main contracts between Movate and 
Powerschool, rather than pointing to the GSA. See Oppo. Dkt 381, at 14. The DPA is an 
eight page agreement. Section 1.5 simply define what are education records. Section 5.5 
defines Movate as a “school official” for purposes of the federal Family Educational 
Rights and Privacy Act (“FERPA”) and imposes an obligation to abide by the FERPA 
limitations and requirements imposed on school officials. 
Next, the Plaintiffs point to Section 10.7 of the GSA which describes an obligation 
of Movate to “assist” Powerschool in notifying victims in the event of a data breach. It 
does not impose an obligation on Movate to notify schools or students on its own. 
Plaintiffs then refer back to DPA Sections 2 and 15.1. Section 2 simply describes the 
purpose of the agreement – which is to describe Movate’s responsibilities for handling 
and protecting Powerschool’s customer data. Section 15.1 is no more than an 
acknowledgement that Powerschool’s customer data may include personal data from 
education records. Plaintiffs conclude by asserting that the language of these various 
subsections, when taken together, demonstrate that Plaintiffs are the intended 
beneficiaries. 
The argument is unpersuasive. At most, the agreements demonstrate Powerschool 
required Movate to treat data with care and security for Powerschool’s own benefit and in 
the event of a breach for Movate to assist Powerschool in its notification obligations. 
Beyond that, there is little to suggest that Powerschool’s contract with Movate was 
intended to directly benefit the Plaintiff schools. Instead, the GSA describes ordinary 
contractual intent such that one party, Movate, will work for the direct benefit of the 
other party, Powerschool, in managing its software product in exchange for money paid. 
Plaintiffs concede in their brief that the best evidence of whether the contracting 
parties intended to directly benefit Powerschool’s School District customers “can be 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 13 of 15
 
-14- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
ascertained from the words of the contract itself.” Alicea v. City of New York, 534 
N.Y.S.2d 983, 985 (N.Y. App. Div. 1988) (emphasis added). Here the words of the 
contract do not mention the names of the School District Plaintiffs. Missing from the 
words of the GSA is any provision empowering the School District Plaintiffs to enforce 
the Powerschool / Movate contract. Also missing from the words of the contract are any 
other terms or conditions that Movate was to directly benefit the School Plaintiffs. Like 
the contract in Alicea, Plaintiffs are not signatories, and no part of the GSA or DPA refers 
to the Plaintiffs as third-party beneficiaries. Id. And like the contract at issue in Alicea, 
the GSA and DPA contracts are “devoid of any language showing an intent to allow 
enforcement by plaintiffs.” Id. 
 Therefore, Plaintiffs have not successfully pleaded a plausible claim for breach of 
contract as a third party intended direct beneficiary and Movate’s motion to dismiss is 
granted. In the event that the Direct Action School Plaintiffs discover evidence that they 
were, in fact, the intended direct beneficiaries of the Powerschool / Movate contract, they 
may later move to amend their Complaint. 
V. CONCLUSION 
For the foregoing reasons, the Court ORDERS that the: 
1. The Court exercises personal jurisdiction over Defendant Movate, Inc. 
2. The motion to dismiss the claim for negligence (DAC Count 8) is denied. 
3. The motion to dismiss the claim for negligent hiring, training, or supervision (DAC 
Count 9) is denied. 
4. The motion to dismiss the breach of contract claim based on the theory of intended 
beneficiary (DAC Count 10) is granted. 
 IT IS SO ORDERED. 
DATED: March 24, 2026 
 _________________________________ 
 Hon. Roger T. Benitez 
 United States District Judge 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 14 of 15
 
-15- 
25-md-03149-BEN-MSB 
1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
 
 
 
 
 
 
 
 
 
 
 
 
Case 3:25-md-03149-AJB-MSB Document 444 Filed 03/24/26 PageID.<pageID> 
Page 15 of 15

Passage view · GavelSight