Harm is usually the first question
Courts hearing a data breach lawsuit tend to start with what actually happened to the person suing. Federal courts require a concrete injury, and they have not settled how much weight a risk of future misuse carries when nothing has happened yet. Fraudulent accounts, unreimbursed charges, a tax refund diverted by someone else, or medical services billed in your name are easier to point to than worry alone. The type of data matters as well, since exposure of information that can open credit or reach medical records is taken more seriously than exposure of an email address. State courts may apply their own standing rules, which are not always the same.
Documents you already agreed to
Before deciding anything, look at the terms of service or account agreement you accepted from the company. Many contain arbitration clauses and class action waivers that send disputes to individual arbitration rather than court, and some add their own notice steps or contractual time limits. If class cases are already pending over the same breach, filing separately or staying in the class is a real decision, because a later class settlement can release claims for everyone who does not opt out. Neither path suits everyone. Which one fits depends largely on how large and how well documented your losses are.
Records that carry weight
Gather the notice letter, account statements or credit reports showing the misuse, any police or identity theft reports you filed, and correspondence with banks or agencies about fixing the problem. Receipts for anything you paid, and a log of time spent on calls and paperwork, often count for more than people expect. An identity theft report through the FTC's website can also help with creditors. When you meet with us, we review your agreement with the company, the status of any pending cases, and the evidence connecting the misuse to this breach rather than another one, which is often the hardest link to establish.