How to Calculate Damages in a Data Breach Class Action
A framework for estimating class-wide exposure in a data breach case, from statutory damages to actual-harm theories.
Data breach damages are harder to pin down than they first appear, because a single breach usually supports several competing damages theories at once, each with a different evidentiary burden and a different dollar outcome. Some class members can point to concrete financial loss; many others can only point to the exposure of their data and the risk that follows. A defensible damages estimate has to hold all of these theories side by side rather than pretending the class is uniform.
This guide walks through the main damages theories that recur in data breach litigation and how to build a rough class-wide estimate from them. It is an educational explainer of general concepts, not legal advice — applicable law, available theories, and statutory damages figures vary significantly by jurisdiction, the type of data involved, and the specific statute invoked, and should be confirmed against current authority for your case.
Separate the damages theories before you try to add them up
A single breach class typically contains several distinct sub-populations, and treating them as one uniform group overstates or understates the case depending on which theory you default to. Before estimating a number, map out which theories are realistically available and roughly what share of the class each one covers.
- Out-of-pocket loss: documented fraudulent charges, account takeover costs, or fees the class member actually paid.
- Mitigation costs: credit monitoring, credit freezes, identity theft insurance, and time spent responding to the breach.
- Diminished value of personal information: a contested theory that the data itself had market value now lost.
- Increased risk of future identity theft or fraud: viable in some jurisdictions as a standing and damages basis, disputed in others.
- Statutory damages: a fixed per-violation amount available under certain state or federal data-protection statutes, independent of proof of actual harm.
Build the actual-harm estimate from the bottom up
For the sub-class with documented financial loss, damages calculation is comparatively straightforward: sum the documented fraudulent charges, reimbursement gaps, and reasonable mitigation expenses actually incurred, supported by receipts, bank records, or credit reports. This is the most defensible dollar figure in the case because it rests on records rather than inference.
For the much larger sub-class without documented loss, courts have taken different approaches to whether exposure or increased risk alone supports compensable damages. Where mitigation costs are compensable, a conservative estimate uses actual amounts spent on credit monitoring or freezes rather than a hypothetical average, since actual expenditure is far easier to defend against a challenge to the damages model.
Layer in statutory damages where they apply
Where a statute provides a fixed per-violation or per-record statutory damages figure, that number can dominate the case's total exposure, because it multiplies against the full class size regardless of individual proof of harm. Confirm three things before using a statutory figure in a class-wide estimate: whether the statute actually applies to the type of data and the type of breach at issue, whether the statute requires a minimum showing (such as willfulness or recklessness) before the enhanced figure applies, and whether courts have limited or reduced statutory awards on due process or manageability grounds in comparable cases.
Because statutory damages can produce an outsized total relative to any showing of actual harm, expect this figure to be a central point of dispute at class certification and in any settlement negotiation, and model it as a range rather than a fixed multiplier.
Assemble a class-wide range, not a single number
Combine the pieces into a range rather than a point estimate: a low-end figure built only from documented actual harm and reasonable mitigation costs, and a high-end figure that layers in the statutory damages theory at full class size. The real settlement and litigation value of the case usually sits well inside that range, shaped heavily by the probability that a court certifies the class at all and the probability that a statutory damages theory survives a due-process or manageability challenge.
Because so much of this turns on probabilistic gates — certification, statutory applicability, and manageability — treat the damages estimate as one input into a broader expected-value analysis rather than the final word. A structured simulation that lets you move the certification probability, the statutory-applicability probability, and the actual-harm share as separate dials shows how sensitive the total exposure is to each assumption, which is usually more useful than any single headline number.
- Do all class members need documented financial loss to recover?
- Not necessarily. Whether exposure or increased risk alone is compensable, separate from documented fraud, depends heavily on the jurisdiction and the specific claims asserted. Some statutory damages theories do not require proof of actual harm at all. This is why splitting the class into sub-populations by theory, rather than assuming uniform damages, produces a more defensible estimate.
- Why do statutory damages so often dominate the total exposure figure?
- Because a fixed per-violation amount multiplies against the full class size rather than against documented losses, it can produce a total far larger than any actual-harm calculation, especially in large breaches. That is exactly why courts frequently scrutinize statutory damages theories closely at certification and why any estimate should treat the statutory figure as a range tied to a probability of it applying, not a certainty.
- How should mitigation costs like credit monitoring be estimated?
- Use actual amounts class members spent where records exist, rather than an assumed average cost per person. Actual expenditure is easier to substantiate and harder for the opposing side to challenge as speculative. Where the defendant already offered free credit monitoring following the breach, expect that offer to be used to argue mitigation costs were unnecessary or already covered.
This page is an educational explainer, not legal advice, and creates no attorney–client relationship. Juricratic is a simulation engine: every probability-like figure is a dial you set, not a calibrated prediction. Verify every rule, deadline, and figure against the authorities and orders that govern your matter.
Stop estimating one number at a time.
Juricratic models the whole matter as a solvable game and runs it thousands of times — so the settlement value, the risk, and the optimal line all move together when the facts do.
Request access →