Texas Case Summaries
Federal Enforcement »

Cossette v. Jani-King — Data-breach negligence and implied-contract claims survive dismissal

Unreported / Non-Citable

Case
John Cossette, et al. v. Jani-King International, Inc.
Court
U.S. District Court for the Northern District of Texas
Judge
David C. Godbey
Date Decided
August 4, 2026
Docket No.
3:25-cv-01057
Topics
Data Breach, Standing, Negligence, Implied Contract

Background

Jani-King International, a commercial-cleaning franchisor, suffered a cybersecurity attack between November 26 and December 21, 2024. An unauthorized third party allegedly accessed personal information belonging to employees, franchisees, and others, including names, addresses, Social Security numbers, and franchisee financial information. Jani-King notified affected individuals in April 2025.

John Cossette, Sophia Ivy, Shelly Jacquez, Edwin Dalmacio, and Francis Breedlove filed a proposed nationwide class action alleging negligence, negligence per se, breach of implied contract, unjust enrichment, and entitlement to declaratory and injunctive relief. Jani-King moved to dismiss for lack of Article III standing and failure to state a claim.

The Court’s Holding

The court held that Ivy, Jacquez, Dalmacio, and Breedlove adequately alleged standing to seek damages. Their allegations that a targeted attack exposed names and Social Security numbers established an imminent risk of identity theft and a present injury analogous to disclosure of private information. Their related mitigation costs and emotional distress also supported standing. Spam communications alone, diminution in the value of personal information, and loss-of-bargain theories did not.

The court dismissed Cossette for lack of standing because he did not sufficiently allege that his information was exposed in Jani-King’s breach, but it granted leave to amend his standing allegations within 21 days. It also dismissed the request for declaratory and injunctive relief because a second breach was speculative. On the merits, the court allowed the negligence and breach-of-implied-contract claims to proceed, dismissed unjust enrichment, and deferred the negligence per se issue until the choice-of-law analysis at class certification.

Key Takeaways

  • Allegations that a targeted cyberattack exposed names and Social Security numbers can establish standing even without pleaded misuse of the compromised data.
  • Texas law plausibly imposes an independent duty on a business to safeguard personal information it chooses to retain, so the economic loss rule did not bar negligence at the pleading stage.
  • An implied promise to protect required personal information was plausibly alleged, but generalized payments contributing to data-security expenses did not support unjust enrichment.

Why It Matters

The decision permits core damages claims arising from Jani-King’s breach to proceed while drawing limits around common standing theories in data-breach litigation. Plaintiffs must connect their own information to the breach; generalized fears, increased spam, or a speculative future cyberattack are insufficient by themselves.

The ruling also indicates that, under Texas law, data-security obligations may support both tort and implied-contract theories at the pleading stage. The court left negligence per se unresolved because the applicable law may depend on the proposed nationwide class and the later choice-of-law analysis.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top