A data breach does not automatically translate into legally actionable damage. In cybersecurity discussions, the term “Cognizable Damage” can be understood as harm that the law recognizes as sufficiently concrete to support regulatory action, compensation, or—depending on the applicable statute—standing to bring a lawsuit.
This distinction has become increasingly important in the United States, where there is no single comprehensive federal data-breach law. Instead, organizations must navigate a combination of federal sector-specific laws, Federal Trade Commission (FTC) enforcement and state privacy and breach-notification statutes.
Exposure alone may not be Enough
One of the most important developments came from the U.S. Supreme Court’s 2021 decision in TransUnion LLC v. Ramirez. The Court held that a plaintiff generally needs to demonstrate a concrete injury to establish Article III standing in federal court. A statutory violation by itself does not automatically establish an injury.
For cybersecurity victims, this creates an important distinction: the exposure of personal information and actual legally recognizable harm are not necessarily the same thing.
However, that does not mean an organization can treat every breach as harmless merely because victims have not yet lost money.
What can constitute as Recognizable Harm?
A breach becomes considerably more serious from a legal perspective when exposed information results in—or creates a sufficiently established basis for—harm such as identity theft, financial fraud, unauthorized account activity, disclosure of highly sensitive information, reputational injury or other recognized privacy harms.
The FTC has, for example, taken enforcement action where exposed personal information was capable of facilitating identity theft and fraud. In one case involving DealerBuilt, the FTC alleged that hackers downloaded information including Social Security numbers, driver’s license numbers and financial information.
Similarly, the FTC’s action against Drizly demonstrates that regulators can focus on security failures themselves, rather than waiting for every affected consumer to demonstrate financial loss. The agency alleged that inadequate security practices resulted in the exposure of information belonging to approximately 2.5 million consumers.
The “Risk of Harm” Question
This is where U.S. data-breach litigation becomes complicated.
The Supreme Court’s TransUnion decision indicated that the mere risk of future harm, without more, generally does not establish concrete harm for damages claims. However, sufficiently imminent or substantial risks can have legal significance in other circumstances, particularly when seeking injunctive relief.
Consequently, cybersecurity teams should not wait for stolen data to be used before treating an incident seriously. The nature of the compromised information, whether it was actually accessed or exfiltrated, evidence of misuse, and the likelihood and severity of resulting harm can all influence the legal assessment.
International Perspective
The approach differs internationally. The EU GDPR, for example, treats personal-data breaches through a broader regulatory framework involving security obligations, breach notification and potential compensation for material and non-material damage. Other jurisdictions similarly impose notification duties based on the nature of compromised information rather than requiring a victim to prove financial loss first.
For multinational organizations, therefore, “no demonstrated financial loss” should never be interpreted as “no legal exposure.”
A new Cybersecurity Benchmark
Ultimately, a data breach can cross the threshold into cognizable damage when there is a sufficiently concrete connection between the incident and a legally recognized injury—or when applicable regulatory law imposes obligations independent of individual damages.
For CISOs and security teams, the lesson is straightforward: preserve evidence, determine exactly what information was accessed or exfiltrated, assess the realistic risk of misuse, document the investigation and involve legal counsel early.
In the era of ransomware, identity theft and data sold through criminal marketplaces, the question is no longer simply “Was data stolen?” It is increasingly “What harm can this exposure cause, and what does the applicable law recognize it as legally significant harm?”
Join our LinkedIn group Information Security Community!
