What Counts as Privacy Injury After the Ninth Circuit’s Decision in Black v. IEC Group, Inc.?
In Black v. IEC Group, Inc., the Ninth Circuit recognized injury from an alleged disclosure of confidential health information. J.R. Howell examines privacy injury, contract rights, and Article III standing after TransUnion.
By J.R. Howell The American Counsel | October 9, 2026
The Ninth Circuit’s October 9, 2026 decision in Black v. IEC Group, Inc., No. 25-5952, recognizes a concrete injury when a benefits administrator allegedly disclosed sensitive health information entrusted to it under promises of confidentiality. The plaintiffs did not need to show that the disclosure produced an additional financial loss before a federal court could hear their claims. The alleged betrayal of confidence supplied the injury. That conclusion addresses a recurring problem in privacy litigation: courts must decide whether an invasion is itself a legally recognizable harm before demanding evidence of what happened afterward.[1]
The distinction matters well beyond medical records. People give information to businesses for particular purposes. They permit access to some activities while expecting others to remain private. They also spend money and time assessing conduct that may have compromised those expectations. These events can produce different injuries. A court that asks only whether the information was sufficiently sensitive may overlook an economic loss, an intrusion into seclusion, or the betrayal of an accepted confidence.
Black provides a useful way to examine those differences after TransUnion LLC v. Ramirez. Its reasoning connects modern confidentiality obligations to a history of judicial protection against betrayed trust. The opinion also gives contract law a significant role. Courts traditionally heard contract actions without demanding a further pecuniary or physical injury. That history helps explain why a broken confidentiality promise can involve an injury even when the plaintiff cannot assign a market price to the loss.
The argument requires care. Sensitivity is not a universal, independent prerequisite to every kind of privacy injury. Its relevance depends on the interest that was invaded and the historical harm used for comparison. A claim involving exposure of medical records differs from a claim involving unwanted observation or a bill paid to investigate an actual intrusion. Each requires facts about what happened to the plaintiff. An abstract demand that a business obey the law supplies none of those facts.
Actual money and time require their own analysis
The inquiry should begin with the most familiar injuries. A plaintiff who actually paid money because of challenged conduct has alleged something different from a plaintiff seeking a statutory award for a violation. The first identifies an expenditure. The second identifies a remedy. The availability of that remedy does not establish that the plaintiff lost money.
TransUnion treats monetary harm as ordinarily concrete. It also requires an injury fairly traceable to the defendant and redressable through the requested relief. Those requirements make it necessary to identify the payment, its purpose, and its connection to the conduct at issue. They do not make financial loss dependent on the success of a separate informational-privacy theory.[2]
Consider a hypothetical person who receives credible confirmation that an account has been compromised. The person pays for work assessing the compromise and securing the account. The expenditure deserves its own analysis. A finding that the exposed information lacked an intimate quality would not explain away the money spent. The court would still need to consider whether the alleged expense was caused by the defendant’s conduct and whether the requested relief could redress that loss, assuming the legal claim is valid.
That example must be distinguished from buying monitoring because breaches sometimes occur in an industry. In Clapper v. Amnesty International USA, the Supreme Court rejected an effort to establish standing through expenditures responding to speculative surveillance threats. A plaintiff cannot create a federal case simply by choosing to spend money against an unsupported fear. The objective basis for the response matters.[3]
There is another distinction between investigating an event for one’s own purposes and preparing a lawsuit. Steel Co. v. Citizens for a Better Environment recognized the significance of independent investigation expenses while explaining why litigation costs could not manufacture standing. The plaintiff still lacked redressability because the invoked fee provision did not reimburse the independent expenses. The case illustrates why a genuine expenditure and a legally available remedy must be examined separately.[4]
An invoice does not answer the standing question by itself. Work performed to assess a known event can have a purpose apart from litigation. An expert report commissioned solely to develop a complaint has a different purpose. Paying for the report before filing does not necessarily change its character. Courts should examine what the work actually accomplished rather than treating every expense bearing an investigative label alike.
Post-TransUnion data-breach decisions provide more concrete applications. In Bohnak v. Marsh & McLennan Companies, the Second Circuit recognized present mitigation costs in the circumstances of targeted theft and substantial future risk. In Clemens v. ExecuPharm, the Third Circuit considered present consequences after stolen information appeared on the dark web. Neither opinion supports detaching the claimed expense from the circumstances that made the response reasonable.[5]
Time requires similar precision. Webb v. Injured Workers Pharmacy recognized time lost from productive or profitable activity. The First Circuit expressly reserved whether purely personal time independently qualifies. A plaintiff should therefore explain what responding to the event required and what activity was displaced. Time spent restoring access to an account cannot simply be described as lost wages without facts establishing the lost earnings.[6]
The distinction protects sound claims from careless presentation. An afternoon spent addressing a compromise is a real event. Whether it supplies the particular injury asserted depends on the facts and the governing authority. Calling it a monetary loss can obscure the actual argument when no money changed hands. Conversely, describing every response as mere anxiety can obscure time diverted from work or an actual payment for necessary assistance.
Causation remains essential even when the expenditure is clear. In Santos-Pagán v. Bayamón Medical Center, the First Circuit found an adequately alleged injury involving actual fraud that prompted time and approximately $800 in remedial expenses. It nevertheless affirmed dismissal because the allegations did not sufficiently connect the fraud to the defendant’s breach. The existence of an expense did not establish who caused it.[7]
These decisions support a disciplined approach. Identify actual payments and actual demands on time. Examine their purpose and factual connection to the challenged conduct. Distinguish them from statutory damages, speculative precautions, and litigation preparation. Then address the privacy injury separately. The failure of one theory should not substitute for analysis of another adequately supported injury arising from the same event.
A completed privacy injury may precede any further consequence
Privacy claims become more difficult when there is no measurable financial loss. TransUnion directs courts to ask whether an intangible harm bears a close relationship to a harm traditionally recognized as a basis for suit. Its examples include intrusion upon seclusion and disclosure of private information. The required relationship does not demand an exact duplicate of an old cause of action. It nevertheless requires more than the observation that the defendant violated a statute.[8]
That framework makes the choice of comparison consequential. Defamation concerns injury associated with communicating a false statement to someone else. Intrusion concerns an invasion of a protected private sphere. Breach of confidence concerns betrayal by a recipient who accepted information subject to an obligation. Moving a requirement from one category into another can change what the law protects.
For example, a rule requiring subsequent public dissemination makes little sense as a universal condition for recognizing an intrusion. An observer can invade seclusion without broadcasting what was observed. A recipient can betray confidence by disclosing information to an unauthorized person even if the information never reaches a large audience. The analysis should explain why the asserted analogue requires a particular consequence before treating its absence as dispositive.
The difference also affects when the injury occurs. A person may discover an intrusion long after it happened. The delay in discovery does not itself establish that the intrusion remained incomplete. Likewise, harm from exposing a confidence can exist before the recipient uses the information to cause a financial loss. A later consequence may increase damages or support another claim without being necessary to establish the earlier injury.
This does not resolve every digital dispute in a plaintiff’s favor. The plaintiff must identify an actual event involving a protected interest. Software capability is different from operation. Operation on a website is different from examination of a person’s private records. A possibility that information could have been accessed is different from an adequately alleged access. These distinctions identify what requires proof rather than presuming that every unwanted interaction is an injury.
The Fourth Circuit’s en banc decision in American Federation of State, County and Municipal Employees v. Social Security Administration illustrates a completed-access theory. Its standing analysis recognized alleged unauthorized access to private records without requiring subsequent misuse, publicity, or contemporaneous awareness. The court nevertheless vacated the preliminary injunction. Establishing an injury did not establish entitlement to that particular relief.[9]
The analytical consequence is significant. Asking what happened after an intrusion can be useful. Treating an additional event as invariably necessary can leave the intrusion itself unexamined. Courts should first decide whether the plaintiff has described a completed invasion that resembles a historically actionable injury. Only then can they determine whether the asserted theory requires something more.
Black locates the injury in an accepted confidence
The plaintiffs in Black alleged that a benefits administrator disclosed sensitive health information to one or more other plan members in violation of confidentiality promises. The district court dismissed for lack of Article III standing. The Ninth Circuit reversed and remanded. At that stage, the court assessed the sufficiency of the allegations. It did not establish that a disclosure occurred as alleged or impose liability on the administrator.[10]
The appellate court’s explanation begins by separating injury from the cause of action invoked to obtain relief. A plaintiff might invoke negligence, a statute, or a contractual obligation in addressing the same disclosure. The injury does not change merely because the legal label changes. The opinion preserves the requirement of standing for each claim while recognizing that counts resting on the same harm present the same injury question.
This distinction helps avoid an unnecessary pleading confusion. A historical analogue is a way of assessing the alleged harm. It need not be a separately pleaded count. A plaintiff relying on breach of confidence as the historical comparison is identifying why the event has a judicially recognized character. Whether a particular statute or other cause of action provides relief remains a further question.
The history in Black also broadens the discussion beyond modern statutory descriptions of health information. The court examines protections for entrusted materials and commercial confidences. These sources concern obligations arising from the circumstances in which information was received. Their relevance does not depend entirely on whether the information would qualify as intimate personal data under a contemporary regulatory classification.
The court’s use of E. I. Du Pont de Nemours Powder Co. v. Masland is particularly instructive. That decision treated an accepted commercial confidence as significant even while the asserted property interest in the information was contested. Justice Holmes wrote, “The property may be denied, but the confidence cannot be.” The obligation arose from the relationship through which the recipient learned the facts.[11]
That reasoning changes the question a court asks. A claim that information has market value requires examination of the asserted property or economic interest. A claim that a recipient betrayed an accepted confidence requires examination of the duty under which the information was entrusted. Failure to establish the first should not silently dispose of the second. They protect different aspects of the transaction.
Black expresses the point directly: “a trust betrayed is the harm.” Read in context, the statement concerns the historically protected relationship and its alleged breach. It does not make a plaintiff’s subjective disappointment sufficient. The facts must explain why confidence was accepted and what the recipient did in violation of it.[12]
The distinction has practical importance for organizations that obtain information to perform a service. Access is frequently conditional. A person may authorize a particular recipient to process information for a particular purpose without authorizing every later use or disclosure. Treating the original transfer as the end of the privacy inquiry would disregard the terms that made the transfer possible.
A generic hypothetical makes the point. A business gives an adviser internal plans under an express confidentiality obligation for a defined assignment. The adviser later distributes them beyond that assignment. The resulting concern does not depend on whether the plans reveal an embarrassing personal fact. The accepted confidence and its betrayal supply the relevant structure. Whether a modern claim establishes Article III injury would still require a close comparison with the historical harm and facts supporting the alleged breach.
The extension has limits. A commercial relationship alone does not create a duty of confidence. A vague expectation that a business will behave responsibly differs from a specific promise or circumstances imposing a confidentiality obligation. Nor does collection without permission involve precisely the same sequence as disclosure by a recipient who first obtained information lawfully. The legal analysis should preserve those differences.
Black itself involved sensitive health information and alleged confidentiality promises. The history supports examining other kinds of entrusted information. The court did not decide whether every disclosure of entrusted information produces concrete injury. The opinion provides a holding within its facts and an explanation that can inform the next case.
Contract history matters without making every breach sufficient
Black describes the alleged injury as akin to a breach of confidence “or contract.” Contract is relevant because an undertaking can define what the recipient was permitted to do. A confidentiality promise may establish the relationship that makes a later disclosure a betrayal.[13]
The opinion states that breach of contract reinforces its confidence analogy. It then examines the historical availability of contract actions without allegations of pecuniary or physical injury. That history challenges the assumption that a plaintiff must identify a further financial consequence whenever the contractual interest itself has been invaded.
Footnote 3 makes the point through nominal damages. Traditional law sometimes recognized the breach even when substantial compensatory damages could not be shown. The availability of nominal relief was part of the law’s treatment of the wrong. The court compares that recognition to a person stepping onto another’s land without physically damaging it.
The reasoning should be taken seriously without converting it into an unlimited rule. An agreement may protect a concrete interest. It may also contain requirements whose violation, in a particular dispute, has produced no adequately identified concrete harm. Calling both events breaches does not answer the federal question. Courts still must examine the promised performance and the interest allegedly impaired.
The Seventh Circuit’s Dinerstein v. Google demonstrates the difficulty. Its analysis rejected reliance on a bare contractual breach in a case involving deidentified medical information and no plausible reidentification. The court considered the historical argument concerning nominal damages without treating it as dispositive. Black distinguishes the cases before other circuits by reference to the particular confidentiality promises and sensitive health information alleged before it.[14]
The disagreement concerns how much work contract history can do. Black offers broader reasoning about contractual injury while deciding a claim tied to an accepted confidence. Dinerstein resists treating a breach label and nominal-damages history as sufficient by themselves. The opinions do not present identical facts. A persuasive application of Blackshould explain why the breach invaded an interest resembling the historical harm rather than declaring that the word contract ends the inquiry.
Nominal damages also have a separate role in redressability. In Uzuegbunam v. Preczewski, the Supreme Court held that nominal damages could redress a completed injury. That does not allow a plaintiff to create injury simply by requesting a dollar. The order of analysis matters. A court first identifies the completed injury and then asks whether the requested relief can address it.[15]
The land-trespass comparison requires comparable care. Trespass to land and trespass to chattels developed different rules. In Intel Corp. v. Hamidi, California’s Supreme Court refused to treat harmless electronic intermeddling as though it necessarily carried the consequences of an unauthorized entry onto land. Dispossession, impaired functioning, and other injury to protected possessory interests require separate attention.[16]
A computer analogy therefore needs an account of the interest affected. Was there dispossession, impairment, examination of private material, or breach of an accepted limitation? The technical location of an operation may help answer those questions. It cannot substitute for them. A historically grounded argument must explain why the digital event resembles the relevant injury rather than borrowing the most favorable feature of an unrelated tort.
The private sphere and the information obtained are different concepts
Information can be private without being embarrassing. A person may reasonably wish to read an ordinary book, have an unremarkable conversation, or conduct routine affairs without observation by a particular stranger. The private character of the activity and the sensitivity of what an observer learns are related questions. They are not identical.
Suppose a concealed observer watches someone read a novel in a private bedroom. An account of the injury focused only on the novel’s subject would miss the circumstances of observation. The protected interest concerns seclusion. A digital comparison would require identifying the corresponding private sphere and explaining how it was entered.
Common-law authority gives substance to that distinction. In Phillips v. Smalley Maintenance Services, Alabama’s Supreme Court held that acquiring information was not a necessary element of intrusion upon seclusion. The case involved repeated coercive sexual questioning. The plaintiff’s refusal to answer did not eliminate the invasion. The conduct itself interfered with her private affairs.[17]
California’s Hernandez v. Hillsides separates the issues in another way. A jury could find intrusion from the installation of a functioning concealed camera in a shared office even though the employees were never viewed or recorded. The employer nevertheless prevailed because the limited surveillance and its legitimate protective purposes did not satisfy the separate requirement of sufficiently offensive conduct.[18]
These are state substantive-law decisions. Their importance here lies in what they reveal about the interests protected by intrusion. They show that acquired information and the invasion are distinguishable. They also show why the absence of information can remain relevant to another part of the analysis. An argument that obtaining information is not always necessary should preserve both points.
Post-TransUnion decisions involving unwanted communications reinforce the need to identify the particular interest. In Six v. IQ Data International, the Ninth Circuit recognized an intrusion associated with a collection letter sent after counsel-only notice. The Tenth Circuit’s Lupia v. Medicredit similarly addressed an unwanted call and voicemail following a cease-contact request. The injuries concerned interference with repose. Neither required extraction of an intimate secret.[19]
Those cases establish no general rule for automated examinations of devices. Their relevance is narrower and useful. Sensitivity cannot be a universal requirement for every privacy-related injury when some recognized injuries concern unwanted interruption rather than acquisition of information. The proper question is what the particular theory protects.
The Ninth Circuit’s earlier decision in Nayab v. Capital One Bank addresses actual examination of records. It recognized injury from obtaining a credit report without an authorized purpose, without requiring later publication or misuse. The report contained highly personal information. The case predates TransUnion and does not decide an examination that obtained nothing.[20]
The distinction therefore has both support and an unresolved application. Historical privacy law does not invariably require information to be obtained. Whether a particular digital operation resembles an actionable invasion closely enough remains a question of concrete facts. The claimant should identify what was accessed, the limits governing access, and the private interest affected. An assertion that all digital activity belongs to a protected private sphere is too general to perform that work.
Popa makes the choice of analogy consequential
The Ninth Circuit’s decision in Popa v. Microsoft Corp. places a real limit on generalized privacy claims. The court rejected an intrusion analogy based on ordinary online pet-shopping activity and partially masked identifying information. It considered whether the alleged conduct entered a comparably private sphere and resembled the kind of interference historically actionable as intrusion. The allegations did not establish that relationship.[21]
Popa cannot fairly be reduced to a mistaken importation of merits law into standing. The historical comparison necessarily requires identifying what made the alleged event an invasion. Information’s character may help answer that question. So may the activity observed, the means used, and the relationship between the parties.
The harder issue is deciding when those considerations identify the injury and when they become an additional demand for severity. A close relationship to a historical harm allows some differences. If every difference in degree were treated as a difference in kind, statutory protections could never address less severe instances of an established harm. Conversely, an analogy broad enough to cover any unwanted event would provide little constitutional limit.
The debate becomes more intelligible when the claimed interest is stated precisely. A complaint about observation of ordinary activity on a commercial website must explain what private sphere was entered. A complaint about disclosure by a confidant must explain the undertaking and the departure from it. A complaint about money spent responding to a known event must explain the expenditure and its cause. Failure of one explanation does not make the others unnecessary.
In re Facebook Internet Tracking Litigation also requires careful reading. Its frequently cited discussion of collection methods and sensitivity appears in the privacy-merits analysis. Its standing discussion separately rests on allegations involving comprehensive, identified browsing histories collected after users logged out. It would therefore be inaccurate to say that informational context mattered only to the merits.[22]
The relationship between Facebook Tracking, Popa, and Black is more useful than a claim that the newest opinion discarded its predecessors. They involve different alleged invasions. Black adds a historically developed explanation centered on entrusted confidence. It does not overrule Popa or resolve every question about collecting ordinary browsing information.
Courts should ask what work sensitivity is doing in the particular case. It may identify private information. It may explain why an examination is comparable to intrusion. It may bear on whether the conduct was sufficiently offensive for liability. It should not become an unexplained demand appended to every independently alleged injury.
Standing determines access to a court before liability is decided
Standing and merits inquiries can involve the same facts while asking different questions. Standing asks whether this plaintiff has an injury that permits a federal court to decide this dispute. The merits ask whether the defendant violated a duty for which the asserted cause of action provides relief. A fact relevant to both does not erase the distinction.
The Supreme Court’s Federal Election Commission v. Ted Cruz for Senate explains that the standing inquiry assumes the validity of the legal claim. That instruction prevents resolving a disputed entitlement against the plaintiff and then using that merits conclusion to declare that no injury exists. It does not require accepting conclusory factual allegations or treating the existence of concrete harm as established merely because the complaint asserts it.[23]
Sanchez v. Los Angeles Department of Transportation supplies a practical illustration. The Ninth Circuit recognized standing based on the alleged government collection of location data before rejecting the constitutional merits theory. The court’s conclusion that the plaintiff could invoke federal jurisdiction did not establish that the collection violated the Constitution.[24]
The distinction also appears in Mastel v. Miniclip. Shortly after TransUnion, a federal district court recognized standing for alleged unauthorized acquisition of information in a case involving California constitutional privacy. It then dismissed the privacy claim on its merits. The decision is district-level authority and predates Popa. It nevertheless illustrates why jurisdiction and liability should receive separate explanations.[25]
These distinctions should improve the way opinions describe privacy disputes. A court may conclude that no protected private sphere was adequately alleged. It may instead conclude that an intrusion occurred but fell short of the seriousness needed for the asserted tort. Or it may find an injury while rejecting another substantive requirement. The reasoning should identify which conclusion controls.
The same discipline applies to the remedy. Past injury sufficient for damages does not automatically support an injunction against future conduct. A plaintiff seeking prospective relief must establish the necessary threat of future injury and explain how the injunction would address it. In a data-breach case, an order improving a defendant’s security may not retrieve information already held by someone else. Webb illustrates that separation.[26]
The practical cost of confusion can be substantial. A jurisdictional dismissal says the federal court lacks authority to adjudicate the claim as presented. A merits ruling says something about the claim’s legal sufficiency. Describing the former as a finding that the defendant acted lawfully misstates the result. Describing the latter as proof that the plaintiff never experienced an invasion can be equally misleading.
State law helps identify the interest at stake
State law defines many interests that federal courts routinely protect. Property and contract rights are familiar examples. Privacy interests also arise from state statutes, constitutional guarantees, and common law. Their origin should be relevant to understanding what the plaintiff claims to have lost rather than becoming a reason to disregard the interest.
In Magadia v. Wal-Mart Associates, the Ninth Circuit expressly rejected the contention that California, unlike Congress, could not recognize interests supporting federal standing. The opinion cited the longstanding distinction between creating a protected interest and controlling federal jurisdiction. It also denied standing for violations the plaintiff had not personally suffered.[27]
Magadia predates TransUnion. Its recognition of state-created interests does not settle whether its earlier treatment of risk and informational deprivation survives TransUnion. The enduring question is how state law helps identify an individual interest while the federal court independently examines whether that interest suffered a concrete invasion.
The contrary limit is illustrated by Hollingsworth v. Perry. A state’s authorization to defend a law did not by itself confer federal standing. Permission to litigate in the public interest differs from a plaintiff’s own injury. State law cannot make a generalized interest in enforcement into a personal injury merely by authorizing suit.[28]
California constitutional privacy is relevant within that distinction. Hill v. National Collegiate Athletic Associationrecognizes informational and autonomy privacy, including protection against private actors. Sanders v. American Broadcasting Companies explains why exposure to some people does not necessarily eliminate privacy against a different observer or a different means of recording. These decisions help define what privacy protects.[29]
They do not resolve Article III by their own force. TransUnion’s references to injuries recognized by the Constitution use federal constitutional examples. They should not be read as an express holding that every violation of a state constitution automatically supplies federal standing. The argument must connect the state-recognized interest to the plaintiff’s actual injury and the applicable federal analysis.
The Second Circuit’s Maddox v. Bank of New York Mellon Trust Co. requires particular attention here. After TransUnion, the court withdrew its earlier opinion and rejected standing for delayed recording of mortgage satisfactions without adequately alleged concrete harm. The replacement opinion left undecided whether states and Congress receive comparable treatment in identifying protected interests.[30]
The resulting division of responsibility is workable. State law identifies obligations and the interests they protect. Federal standing law determines whether this plaintiff has suffered the concrete injury needed to invoke federal jurisdiction. A court can respect both roles by explaining the interest before assessing the invasion. Treating the state source as irrelevant would impoverish that inquiry. Treating it as conclusive would eliminate the independent federal requirement.
Black offers a related distinction through HIPAA. The court treats congressional protection of health information as relevant even though HIPAA does not itself provide the plaintiffs a private cause of action. Recognition of an interest and availability of a particular remedy are separate matters. That reasoning supports careful attention to legislative judgments without establishing automatic standing from legislative language.[31]
The definition of injury determines access to federal enforcement
These distinctions affect the practical allocation of responsibility. Businesses can obtain information subject to detailed obligations while users retain limited visibility into what happens afterward. If a completed betrayal becomes cognizable in federal court only after identity theft or another financial consequence, the recipient’s confidentiality obligation receives less effective protection during the interval. That consequence follows from the additional injury requirement, even if the obligation itself remains valid.
The burden is especially apparent when the protected interest concerns control over a relationship. A person may have entrusted information because a recipient promised a limited use. Requiring a later financial event changes the conditions under which that promise can be enforced in federal court. The resulting protection would depend partly on what unauthorized recipients choose to do next.
There is a substantial argument on the other side. Federal courts are not general supervisory bodies for every regulatory violation. Statutory damages can encourage litigation in situations where no plaintiff has suffered a cognizable injury. The ability to allege a prohibition and demand an award cannot replace the constitutional requirement of an actual case or controversy. A persuasive account of privacy injury must retain a limiting principle.
The historical comparison supplies one. The plaintiff must identify a protected private interest and an actual event that invaded it in a way closely related to an established harm. A confidentiality theory requires accepted confidence and its betrayal. An intrusion theory requires a private sphere and an interference with it. An economic theory requires actual expenditure or other supported loss. Each formulation supplies facts that can be contested and distinctions that can defeat an insufficient claim.
The structural explanation for standing restrictions also deserves examination. TransUnion invokes concerns about private plaintiffs assuming enforcement authority assigned to the executive. That concern has a different fit when a person seeks to enforce an individual state-created right against a private defendant. The suit may concern an obligation owed specifically to that person rather than a claim to supervise government enforcement.
This is a criticism of the rationale’s application. It is not an exception recognized by the majority. TransUnion itself involved private parties. Its holding cannot be avoided simply by describing a claim as private enforcement. The point is to ask how the justification explains restrictions on a particular form of private litigation rather than assuming that all enforcement actions present the same structural concern.[32]
Thomas P. Schmidt’s scholarship in Standing Between Private Parties examines that mismatch. His argument questions the transfer of standing restrictions developed around governmental litigation into disputes between private parties. It offers a framework for criticism and possible doctrinal revision. Existing claims still must satisfy the governing decisions.[33]
Scholars and legislators can also ask whether the doctrine gives adequate effect to interests traditionally protected through private actions. Black is useful to both inquiries because it shows how historical analysis can recognize a completed injury without waiting for a later monetary consequence.
Courts should explain why an additional consequence is necessary
The first task is to describe the injury accurately. A person who paid for necessary remedial work alleges an economic consequence. A person whose accepted confidence was betrayed alleges an invasion of a relationship. A person subjected to an intrusion alleges interference with a private sphere. The adequacy of each theory depends on its facts and governing law. Calling all three privacy claims should not erase their differences.
For lawyers, that means separating the cause of action from the interest, the event, and the historical comparison. For courts, it means addressing independently supported injuries rather than allowing one failed analogy to dispose of all others. For businesses, it means that a confidentiality obligation cannot be evaluated solely by asking whether a disclosed fact was embarrassing or whether misuse has already produced a bill.
Sensitivity will continue to matter where it helps establish the private character of information or the nature of an intrusion. An actual payment will continue to require causation and an available remedy. A promise will continue to require examination of what was undertaken and what was breached. Those questions should be answered in relation to the interest at issue.
Black demonstrates why the additional-consequence question deserves an answer. Once a plaintiff has adequately identified an invasion closely related to a historically actionable harm, a court should explain what remains missing before insisting on another injury. Otherwise, the requirement may change the interest the law protects. A duty to preserve confidence would become enforceable in federal court only when its betrayal happened to produce something further. The Ninth Circuit’s analysis gives courts a reason to examine the betrayal itself.
Notes
[1] Black v. IEC Grp., Inc., No. 25-5952, slip op. at 3–7, 14–17 (9th Cir. Oct. 9, 2026) (reversing the jurisdictional dismissal based on an alleged disclosure of entrusted sensitive health information).
https://cdn.ca9.uscourts.gov/datastore/opinions/2026/10/09/25-5952.pdf
[2] TransUnion LLC v. Ramirez, 594 U.S. 413, 423–27 (2021) (distinguishing concrete injury from a statutory cause of action and recognizing monetary harm as ordinarily concrete).
https://www.supremecourt.gov/opinions/20pdf/20-297_4g25.pdf
[3] Clapper v. Amnesty Int’l USA, 568 U.S. 398, 414 n.5, 415–18 (2013) (rejecting protective expenditures based on speculative threats while distinguishing substantial risks that may prompt reasonable mitigation).
https://www.govinfo.gov/content/pkg/USREPORTS-568/pdf/USREPORTS-568-398.pdf
[4] Steel Co. v. Citizens for a Better Env’t, 523 U.S. 83, 107–08 & n.9 (1998) (distinguishing independent investigation expenses from litigation costs and finding that the requested relief did not redress the former).
https://www.govinfo.gov/content/pkg/USREPORTS-523/pdf/USREPORTS-523-83.pdf
[5] Bohnak v. Marsh & McLennan Cos., 79 F.4th 276, 285–87 (2d Cir. 2023) (recognizing present mitigation injuries associated with substantial risk after targeted data theft).
https://cases.justia.com/federal/appellate-courts/ca2/22-319/22-319-2023-08-24.pdf
Clemens v. ExecuPharm Inc., 48 F.4th 146, 155–59 (3d Cir. 2022) (recognizing presently experienced consequences in circumstances involving publication of stolen information on the dark web).
https://www2.ca3.uscourts.gov/opinarch/211506p.pdf
[6] Webb v. Injured Workers Pharmacy, LLC, 72 F.4th 365, 375–77 & n.8 (1st Cir. 2023) (recognizing lost productive or profitable time while reserving purely personal time).
https://www.ca1.uscourts.gov/sites/ca1/files/opnfiles/22-1896P-01A.pdf
[7] Santos-Pagán v. Bayamón Med. Ctr., Inc., No. 24-2018, slip op. at 10–16 & n.8 (1st Cir. June 11, 2026) (accepting an alleged injury involving fraud and remedial expenses but affirming dismissal for inadequate traceability).
https://www.ca1.uscourts.gov/sites/ca1/files/opnfiles/24-2018P-01A.pdf
[8] TransUnion, 594 U.S. at 424–27 (requiring a close historical relationship for intangible harm without demanding an exact duplicate of an old cause of action).
https://www.supremecourt.gov/opinions/20pdf/20-297_4g25.pdf
[9] Am. Fed’n of State, Cnty. & Mun. Emps. v. Soc. Sec. Admin., 172 F.4th 361, 368–71 (4th Cir. 2026) (en banc) (recognizing standing based on unauthorized access to private records).
https://www.ca4.uscourts.gov/opinions/251411.P.pdf
Id., slip op. at 1–2, 15–22 (identifying the judges joining each part and vacating the preliminary injunction). Parts I–III commanded nine votes, including the standing analysis in Part III. Part IV’s irreparable-harm analysis was a three-judge plurality.
https://www.ca4.uscourts.gov/opinions/251411.P.pdf
[10] Black, slip op. at 3–7 (describing the confidentiality allegations and the Rule 12(b)(1) posture).
https://cdn.ca9.uscourts.gov/datastore/opinions/2026/10/09/25-5952.pdf#page=3
[11] E. I. Du Pont de Nemours Powder Co. v. Masland, 244 U.S. 100, 102–03 (1917) (recognizing the obligation arising from an accepted commercial confidence despite a dispute about the asserted property interest).
https://supreme.justia.com/cases/federal/us/244/100/
[12] Black, slip op. at 8–14 (tracing protection of entrusted information and identifying betrayal of confidence as the harm).
https://cdn.ca9.uscourts.gov/datastore/opinions/2026/10/09/25-5952.pdf#page=8
[13] Id. at 15–17 & n.3 (using contract history to reinforce the confidence analogy and discussing nominal damages).
https://cdn.ca9.uscourts.gov/datastore/opinions/2026/10/09/25-5952.pdf#page=15
[14] Dinerstein v. Google, LLC, 73 F.4th 502, 514–16, 519–22 (7th Cir. 2023) (rejecting a bare-breach standing theory in the circumstances of deidentified medical information).
https://www.govinfo.gov/content/pkg/USCOURTS-ca7-20-03134/pdf/USCOURTS-ca7-20-03134-0.pdf
Black, slip op. at 15–16 n.3 (distinguishing sister-circuit decisions based on the particular promises and sensitive information alleged).
https://cdn.ca9.uscourts.gov/datastore/opinions/2026/10/09/25-5952.pdf#page=15
[15] Uzuegbunam v. Preczewski, 592 U.S. 279, 292–93 & n.* (2021) (recognizing nominal damages as redress for a completed injury without eliminating the other standing requirements).
https://www.supremecourt.gov/opinions/20pdf/592us2r19_8mjp.pdf
[16] Intel Corp. v. Hamidi, 30 Cal. 4th 1342, 1350–51, 1356, 1359–60 (2003) (distinguishing trespass to chattels from land trespass and rejecting liability for electronic communications that did not injure the relevant property interests).
https://law.justia.com/cases/california/supreme-court/2003/s103781a.html
[17] Phillips v. Smalley Maint. Servs., Inc., 435 So. 2d 705, 709–11 (Ala. 1983) (rejecting actual acquisition of information as a necessary element of intrusion upon seclusion).
https://law.justia.com/cases/alabama/supreme-court/1983/435-so-2d-705-1.html
[18] Hernandez v. Hillsides, Inc., 47 Cal. 4th 272, 293–95, 300–01 (2009) (finding a triable intrusion element despite no recording of the plaintiffs but rejecting sufficiently offensive conduct under the circumstances).
https://law.justia.com/cases/california/supreme-court/2009/s147552/
[19] Six v. IQ Data Int’l, Inc., 129 F.4th 630, 633–35 (9th Cir. 2025) (recognizing an intrusion-related injury from a collection letter sent after counsel-only notice).
https://cdn.ca9.uscourts.gov/datastore/opinions/2025/02/24/23-15887.pdf
Lupia v. Medicredit, Inc., 8 F.4th 1184, 1191–93 (10th Cir. 2021) (recognizing injury from an unwanted call and voicemail after a request to cease contact).
https://www.ca10.uscourts.gov/sites/ca10/files/opinions/010110562706.pdf
[20] Nayab v. Cap. One Bank (USA), N.A., 942 F.3d 480, 491–92 (9th Cir. 2019) (recognizing injury from unauthorized acquisition of a credit report without subsequent publication or use).
https://cdn.ca9.uscourts.gov/datastore/opinions/2019/10/31/17-55944.pdf
[21] Popa v. Microsoft Corp., 153 F.4th 784, 790–93 & n.5 (9th Cir. 2025) (rejecting the alleged intrusion and undeveloped possessory analogies for ordinary website activity).
https://cdn.ca9.uscourts.gov/datastore/opinions/2025/08/26/24-14.pdf
[22] In re Facebook, Inc. Internet Tracking Litig., 956 F.3d 589, 598–603 (9th Cir. 2020) (separately analyzing standing and privacy merits in light of identified browsing histories collected after logout).
https://www.govinfo.gov/content/pkg/USCOURTS-ca9-17-17486/pdf/USCOURTS-ca9-17-17486-0.pdf
[23] Fed. Election Comm’n v. Ted Cruz for Senate, 596 U.S. 289, 298 (2022) (assuming the legal claim’s validity when assessing standing).
https://www.supremecourt.gov/opinions/21pdf/21-12_m6hn.pdf
[24] Sanchez v. L.A. Dep’t of Transp., 39 F.4th 548, 554–59 (9th Cir. 2022) (recognizing standing before rejecting the constitutional merits challenge to government collection of location data).
https://cdn.ca9.uscourts.gov/datastore/opinions/2022/07/08/21-55285.pdf
[25] Mastel v. Miniclip SA, 549 F. Supp. 3d 1129, 1138–42 (E.D. Cal. 2021) (distinguishing standing for alleged acquisition from the merits requirements of California constitutional privacy).
https://www.govinfo.gov/content/pkg/USCOURTS-caed-2_21-cv-00124/pdf/USCOURTS-caed-2_21-cv-00124-3.pdf#page=12
[26] Webb, 72 F.4th at 377–78 (rejecting injunctive standing despite standing to pursue damages).
https://www.ca1.uscourts.gov/sites/ca1/files/opnfiles/22-1896P-01A.pdf
[27] Magadia v. Wal-Mart Assocs., Inc., 999 F.3d 668, 674–78, 680 n.9 (9th Cir. 2021) (recognizing state-created interests while denying standing for violations the plaintiff did not personally suffer).
https://cdn.ca9.uscourts.gov/datastore/opinions/2021/05/28/19-16184.pdf
[28] Hollingsworth v. Perry, 570 U.S. 693, 715 (2013) (rejecting state authorization as a substitute for the requirements of federal standing).
https://supreme.justia.com/cases/federal/us/570/693/
[29] Hill v. Nat’l Collegiate Athletic Ass’n, 7 Cal. 4th 1, 15–20, 35–40 (1994) (recognizing informational and autonomy privacy while defining limits on state constitutional liability).
https://law.justia.com/cases/california/supreme-court/4th/7/1.html
Sanders v. Am. Broad. Cos., 20 Cal. 4th 907, 914–18 (1999) (recognizing that limited exposure to others does not necessarily eliminate privacy against covert recording).
https://law.justia.com/cases/california/supreme-court/4th/20/907.html
[30] Maddox v. Bank of N.Y. Mellon Tr. Co., 19 F.4th 58, 63–66 (2d Cir. 2021) (withdrawing the earlier opinion and requiring adequately alleged concrete harm after TransUnion).
https://www.govinfo.gov/content/pkg/USCOURTS-ca2-19-01774/pdf/USCOURTS-ca2-19-01774-2.pdf
[31] Black, slip op. at 16–17 (considering HIPAA’s recognition of health-information interests despite the absence of a private HIPAA cause of action).
https://cdn.ca9.uscourts.gov/datastore/opinions/2026/10/09/25-5952.pdf#page=16
[32] TransUnion, 594 U.S. at 426–30 & n.3 (requiring concrete harm in private litigation and discussing the separation-of-powers concerns associated with enforcement by uninjured plaintiffs).
https://www.supremecourt.gov/opinions/20pdf/20-297_4g25.pdf
[33] Thomas P. Schmidt, Standing Between Private Parties, 2024 WIS. L. REV. 1 (arguing that standing restrictions developed in governmental litigation do not transfer appropriately to disputes between private parties).
https://repository.law.wisc.edu/s/uwlaw/item/312707