Rodriguez v. Google LLC
11
20-cv-04688-RS (N.D. Cal. Jan. 3, 2024)
and setting and the intruder's motives and
objectives.” Opp. at 13 (quoting Shulman, 18
Cal.4th at 236). Again, Google fails to make a
case for why these additional questions supersede
the central inquiry: whether a reasonable person
would find the intrusion by Google highly
offensive. Instead, Google invokes two cases
decided under the California Invasion of Privacy
Act (CIPA) section 632, which protects
communications made over a “wire, line, or
cable,” to argue that both claims require a factspecific inquiry incapable of class-wide treatment.
See Kight v. CashCall, Inc., 231 Cal.App.4th 112
(2014); Hataishi v. First Am. Home Buyers Prot.
Corp., 223 Cal.App.4th 1454 (2014). Both cases
Google identifies pertain to secretly overheard
phone conversations that were listened to
surreptitiously. Plaintiffs' CIPA section 632 claim,
while previously dismissed, does not control *11
the analysis of the intrusion upon seclusion and
invasion of privacy claims.
Factual inquiries underscoring a § 632 analysis are
inapplicable here. There are no similar individual
issues about whether each plaintiff “reasonably
believed their calls were not being monitored.”
Kight, 231 Cal.App.4th at 119. Here, the relevant
inquiries are primarily Google's uniform
disclosures and users' uniform conduct.
Furthermore, CIPA § 632 is not, as Google
contends, an analog for the common law privacy
tort. As stated above, the test under the state
intrusion upon seclusion and invasion of privacy
claims is an objective one, capable of resolution
class-wide, and while analysis of surrounding
circumstances may sometimes be necessary to
determine whether a user maintained their
reasonable expectation of privacy, here, that
question is eclipsed by the undisputed fact that all
class members switched off their sWAA settings.
Cf. Hart v. TWC, 2023 WL 3568078 at *9.
c. CDAFA
CDAFA makes certain computer-related crimes a
public offense, including to ��knowingly access[]
and without permission take . . . any data from a
computer.” Cal. Penal Code § 502(c)(2). Access
“means to gain entry to, instruct, cause input to,
cause output from, cause data processing with, or
communicate with, the logical, arithmetical, or
memory function resources of a computer,
computer system, or computer network.” Cal.
Penal Code 502(b)(1). Further, to show “damage
or loss” under CDAFA, a plaintiff need not have
suffered a corresponding loss, as “California law
recognizes a right to disgorgement of profits
resulting from unjust enrichment.” Facebook
Tracking, 956 F.3d at 599-600.
Google first argues, incorrectly, that CDAFA
provides for “highly individualized . . .
compensatory damages” limited to the victim's
expenditure, i.e. what was “reasonably and
necessarily incurred by the owner or lessee to
verify that a computer system, computer network,
computer program, or data was or was not altered,
deleted, damaged, or destroyed by the access.”
Opp. at 15 (quoting Cal. Penal Code § 502(b)
(11)). However, the statute provides for
compensatory
damages
including
victim
expenditures. Cal. Penal Code § 502(e)(1).
12
Next, Google asserts that it cannot be all class
members who used apps with Firebase *12 and/or
Google Mobile Ads SDKs suffered “damage or
loss,” as their information was collected for “runof-the-mill record-keeping” and was not
“sensitive, confidential, or even meaningful to
users.” Opp. at 16. Plaintiffs, on the other hand,
argue that they need not prove the at-issue data
was sensitive or not-anonymous, but that “any
damage or loss” is sufficient for standing under
the CDAFA3. Reply at 3; see Facebook Tracking,
956 F.3d at 599-600. Google's definition is too
restrictive, while Plaintiff's is too permissive. In
order to maintain entitlement to the disgorged
profits, plaintiffs must show that they have
standing, i.e. that they “retain a stake in the profits
garnered.” Facebook Tracking, 956 F.3d at 599-
7