Sunday, July 26

On the morning of a significant hearing, a certain silence descends upon a federal courthouse. On May 5, the wind outside the Robert V. Denney Federal Building in Lincoln, Nebraska, was doing what it always does in the spring: it was rattling the flags and pushing dust across the sidewalks. Inside, a judge was getting ready to rule on whether ten million dollars was sufficient to put an end to one of the most significant student loan data breaches in recent memory.

Although Nelnet Servicing isn’t as well-known as Sallie Mae or Navient, it was the business that secretly stored the personal data of about 2.5 million borrowers. Social Security numbers, names, and addresses are examples of information that, once lost, is never truly recovered. The breach occurred years ago, but lawsuits take a long time to proceed. As a result, borrowers are now left with a settlement that, depending on who you ask, either represents accountability or a quiet exit ramp for the company.

Nelnet $10 Million Settlement Hearing
Nelnet $10 Million Settlement Hearing

The Fairness Hearing is an odd custom in and of itself. It may take days or even weeks for a judge to make a decision after listening, reviewing objections, and determining whether the agreement on the table is reasonable. Students are not required to attend class. Most won’t. When you watch these cases play out, it seems like the people who are most impacted are rarely the ones in the room. The attorneys are present. The administrators are present. Attendance is permitted for the plaintiffs whose names are listed in the case caption. What about the remaining 2.4 million? They’re probably not aware that today is the day because they’re at work, taking care of their children, and making loan payments.

For its part, Nelnet has consistently insisted that it did nothing improper. The business disputes the claims of carelessness, implied contract violations, and infractions of state consumer protection laws, such as the California Consumer Privacy Act. According to the filings, the goal of the settlement was to avoid the cost and uncertainty of ongoing litigation. In situations like this, that is the typical response. To be honest, it’s also frequently true. Trials are costly. Juries are not always predictable. When compared to years of discovery and the potential for a much higher verdict, ten million dollars may seem like a good deal.

Ten million dollars, however, doesn’t go very far when distributed among 2.5 million people. The individual payouts will be small after service awards for the named plaintiffs, legal fees, and administrative expenses. Reimbursement for documented losses related to identity theft may be granted to certain class members. Others might only get a tiny portion of what’s left. The settlement’s symbolic significance might be more important to many than its monetary value.

This is also part of a larger, recurring narrative. Anthem, T-Mobile, Equifax. The list of businesses that have resolved significant data breach lawsuits has grown to the point where the public’s reaction is now practically scripted. There is a breach. A class is formed. There is an announcement of a settlement. Sometimes years later, a check for a sum that would not cover a tank of gas shows up. In the most honest reading, it is still unclear whether this cycle truly alters corporate behavior.

The judge will decide what happens next. These hearings rarely result in surprises; preliminary approval was given earlier in the process, and final approval is anticipated. However, when the decision is made, one chapter will be closed and a new one will be subtly opened. The borrowers go on. The attorneys go on. Additionally, it’s likely that another business is discovering too late that data security is a must.

Share.

Comments are closed.