Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. The settlement in Claridge v. RockYou, Inc. ended the private lawsuit without a trial or judicial finding that RockYou was liable for the 2009 breach. An April 11, 2011 order let several contract and negligence theories proceed past the motion-to-dismiss stage, but that procedural ruling only found the allegations sufficient to continue. The later stipulated dismissal resolved the dispute without deciding whether RockYou breached a duty or caused compensable loss.

What the RockYou lawsuit was about

Claridge v. RockYou, Inc., No. C 09-6032 PJH, was a putative class action in the U.S. District Court for the Northern District of California arising from RockYou’s 2009 data breach. The complaint, as summarized in Judge Phyllis J. Hamilton’s April 11, 2011 order, alleged that RockYou failed to adequately secure user information.

The court’s summary says plaintiff Alan Claridge received an email on December 15, 2009 warning that sensitive information might have been compromised. The allegations concerned email addresses, passwords and login credentials for social-network accounts. Those descriptions are allegations and procedural background, not findings made after a trial.

What the April 2011 ruling actually decided

RockYou asked the court to dismiss the complaint. The court granted the motion in part and denied it in part. It did not decide that a breach occurred, that RockYou violated a legal duty or that class members suffered legally compensable damages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Claims that survived

The order refused to dismiss the breach-of-contract, breach-of-implied-contract, negligence and negligence-per-se causes of action. In the order’s numbering, the fifth, seventh, eighth and ninth causes of action continued past the pleading stage.

Claims that were dismissed

Other theories were dismissed, with different combinations of prejudice and permission to amend. The implied covenant of good faith and fair dealing claim was dismissed with leave to amend. Because the ruling was mixed, describing it simply as “RockYou lost” or “the court found RockYou negligent” is inaccurate.

Why surviving a motion to dismiss is not a liability finding

At this stage, the court tests whether the complaint states a legally plausible claim, generally accepting well-pleaded allegations for purposes of the motion. A plaintiff still must prove the elements later. For negligence, those elements include duty, breach and proximate or legal cause. The 2011 order did not make factual findings on those elements.

What the settlement changed—and what it did not

The parties later settled and filed a stipulated dismissal, ending the private litigation. A settlement is a compromise, not an adjudication. The available settlement record and contemporaneous reporting support saying that the case ended without a merits decision on the central breach-liability theories. They do not support treating the settlement as an admission of wrongdoing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contemporary reporting also indicated that the value of the personal data would not be explored further after the dismissal stipulation. That procedural endpoint means the public record does not establish a court-approved valuation of the information or a judicial determination of damages in this action.

Private lawsuit versus FTC enforcement

Readers often combine the class action with a separate Federal Trade Commission proceeding. They involved the same company but different proceedings, legal questions and outcomes.

Proceeding Main question What happened What it does not prove
Claridge v. RockYou, Inc. (N.D. Cal., 2009–2011) Whether the complaint adequately alleged contract and negligence theories arising from the breach Several claims survived the April 11, 2011 motion to dismiss; the parties later settled and dismissed the case No final finding that RockYou breached a duty, caused compensable injury or was liable for the private plaintiffs’ claims
FTC action against RockYou (2012) Whether RockYou’s privacy and security representations, including treatment of children’s information, violated the FTC Act and related requirements The FTC announced a proposed resolution with a civil penalty, security-program obligations, recurring independent assessments and COPPA-related provisions, subject to court approval It was not a liability judgment in the Claridge class action and did not convert the private allegations into an adjudicated breach verdict

What the FTC resolution required

In a March 27, 2012 release, the FTC described a proposed settlement requiring RockYou to stop making certain deceptive privacy and security claims, establish an information-security program, undergo independent security audits every other year for 20 years and address Children’s Online Privacy Protection Act (COPPA) compliance. The release also identified a $250,000 civil penalty. The announcement described the resolution as proposed and subject to court approval.

Those are remedies and commitments from the FTC matter. They should not be presented as findings that RockYou was liable to the private plaintiffs in Claridge.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to state the legal outcome accurately

Accurate description

  • The complaint alleged inadequate security after a 2009 breach involving account information.
  • On April 11, 2011, the court denied dismissal of several contract and negligence claims while dismissing other claims in whole or in part.
  • The parties later settled and dismissed the private case without a merits verdict establishing breach liability.
  • The FTC’s 2012 proceeding was separate and addressed alleged deceptive representations, children’s information and security-program requirements.

Descriptions to avoid

  • “The court ruled that RockYou was negligent.” The order did not make that finding.
  • “The settlement proved RockYou was liable.” The settlement resolved the dispute without adjudicating liability.
  • “The FTC judgment established liability in the class action.” The FTC matter was a separate enforcement proceeding.
  • A definitive count of breached records in the private case. The materials available for this case do not verify a breach-count statistic from the underlying complaint or another original filing.

Bottom line for readers researching the RockYou breach

The RockYou settlement answers the procedural question—how the private case ended—but not the merits question—whether RockYou was legally liable for the alleged security failures. The 2011 order kept several claims alive; the settlement prevented those claims from reaching a trial or final liability ruling. The FTC’s later proposed resolution supplies a separate regulatory record, not a substitute verdict in Claridge.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.