
As we have noted on this site in recent years, privacy-related issues have been and remain a significant potential source of D&O risk and liability exposure. In the latest example of the ways that privacy-related concerns can translate into D&O claims, a plaintiff shareholder has filed a shareholder derivative lawsuit against the board and controlling shareholders of company Alphabet alleging that the defendants violated their fiduciary duties by failing to take steps to protect the company from over $4.5 billion in fines, penalties, and settlements arising from alleged privacy violations. A copy of the redacted public version of the September 22, 2026, complaint can be found here.
The Derivative Lawsuit
Alphabet is the corporate holding company for Google, one of the world’s largest technology companies. Google provides its customers free services, and in exchange, according to the complaint, it “mines highly specific information about those customers that it uses to sell targeted ads to advertisers.”
The complaint alleges that under the leadership of its controlling shareholders, Larry Page and Sergei Brin, Alphabet has developed as much user data as possible, even if privacy laws and commitments to users were broken in the process. Alphabet, the complaint alleges, has adopted a “pay the speeding ticket” business model, “in violation of Delaware law.”
The complaint alleges further that Alphabet’s Board was “repeatedly alerted that the Company’s practices violated both applicable laws and its commitment to users,” as the Company was repeatedly fined and as stockholders time and time again raised alarms through shareholder proposals. Despite the “repeated red flags,” the complaint alleges, the Director Defendants “failed to demand that Alphabet implement meaningful corrective measures.”
The complaint also alleges that the company “continued to violate data privacy laws” while “making representations to stockholders to convince them to defeat proxy proposals concerning data privacy.” The defendants, the complaint alleges, “caused Alphabet to misleadingly reassure investors that Alphabet maintained robust privacy controls.”
Had the company maintained such controls, the complaint alleges, “the Company would have avoided the nearly $4.5 billion in fines, penalties, and settlements it has paid to date as a result of its data privacy violations,” not including the massive legal fees the company has also incurred.
The complaint catalogs a lengthy list of privacy violations the company has been accused of in various legal proceedings over the last 15 years, including allegations that, among many other things, the company monitored and used its users’ email messages; illegally tracked and used private information about children under the age of 13 to promote advertising on its YouTube platform; misled users about the extent to which it tracked and shared their location data; and violated state statutes prohibiting the collection of biometric information. (The complaint’s list of alleged privacy violations is quite long and varied.)
The complaint alleges that the defendants’ “knowing disregard for Alphabet’s privacy commitments and legal and regulatory obligations … has exposed Alphabet to massive harm and creates substantial ongoing legal and financial risk for the Company.” The complaint alleges further that the results of the plaintiff’s books and records request show that there has been “scant Board-level consideration of many of the significant privacy issues.”
Finally, the complaint alleges that demand is excused as futile because every member of the Demand Board faces a substantial likelihood of liability for breaching their fiduciary duties, and because at least half of the Demand Board lacks independence.
The complaint alleges that all defendants (including the officer defendants and the controlling shareholder defendants) breached their fiduciary duties, including the duty of oversight. The complaint also alleges violations of Section 14(a) of the Securities Exchange Act of 1934 for alleged proxy misrepresentations; and violations of Section 29(b) of the Exchange Act (seeking rescission of incentive compensation and fees due to violations of Section 14(a)).
The complaint seeks, among other things, to recover an award of damages to Alphabet as well as an order directing Alphabet and the defendants to take all necessary actions to reform and improve Alphabet’s governance and oversight of privacy-related issues and concerns.
Discussion
Over the last several years, privacy and data protection issues have emerged as a significant and growing source of D&O liability risk, with privacy failures leading to securities litigation, derivative suits, regulatory investigations, or allegations of inadequate board oversight.
This new derivative suit against Alphabet’s board represents a follow-on lawsuit, in which the plaintiff alleges that the company’s board should be responsible for liabilities incurred in underlying litigation. This phenomenon of follow-on litigation is nothing new.
We have noted in previous posts this phenomenon in other contexts, as, for example, in the follow-on lawsuit against Uber’s board (discussed here) based on underlying claims of sexual assault or harassment.
Similarly, Microsoft (and other companies) have been hit with follow-on derivative lawsuits alleging that the corporate boards knowingly violated content owners’ copyright rights, resulting in liability in extensive underlying IP litigation. The Microsoft derivative lawsuit is discussed here.
In this most recent instance, the follow-on lawsuit alleges that the defendants’ alleged fiduciary duty breaches resulted in massive liabilities in underlying lawsuits and regulatory actions for alleged privacy violations.
D&O lawsuits alleging privacy issues are not new; as this site has noted, there have been prior lawsuits alleging privacy violations. Indeed, Alphabet itself has been the subject of a prior privacy-related securities class action lawsuit. As discussed here, in February 2024, Alphabet agreed to pay $350 million to settle a securities suit alleging the company had made misleading statements about the company’s ability to protect Google+ user data.
There was in fact a time when this site predicted that privacy-related issues could become a major source of D&O liability. As it has turned out, privacy-related D&O claims have not proven to be as prevalent as we had anticipated. However, this new lawsuit underscores the fact that privacy-related D&O claims have not gone away, and that privacy-related issues remain a significant source of D&O risk.
It is worth noting certain aspects of privacy-related risk have remained potent over the years, for example, with respect to claims alleging violations of BIPA, as discussed here, and with respect to alleged violations of the the EU’s GDPR, as discussed, for example, here. These kinds of claims growing out of statutory privacy liability regimes have been and remain an important aspect of privacy-related D&O exposures.
While the ultimate outcome of the case remains uncertain, this case certainly will be interesting to watch. The new lawsuit reflects a long-standing trend in which plaintiffs’ lawyers attempt to portray privacy failures as failures of corporate governance. The case could further establish privacy and data governance as core fiduciary responsibilities of public-company directors, with implications for many publicly traded companies and their boards of directors.