data breach data protection EPIC Amicus OPM In re OPM OPM
D.C. Circuit Greenlights OPM Data Breach Case
The D.C. Circuit Court of Appeals ruled today that the OPM Data Breach case can move forward, reversing an earlier dismissal by a lower court. The case concerns the data breach at the U.S. Office of Personnel and Management in 2015 that affected 22 million federal employees, their friends, and their family members. The Court ruled that victims of the breach have the legal right, or "standing," to sue over the failure to protect their personal data. "It hardly takes a criminal mastermind to imagine how such information could be used to commit identity theft," the Court wrote. EPIC filed an amicus brief supporting the victims' standing and arguing that "when personal data is collected by a government agency, that agency has a constitutional obligation to protect the personal data it has obtained." The Court ruled that OPM did not violate the constitution in this particular case but left the door open to future lawsuits to enforce the right to information privacy.