Greenley v. Kochava, Inc.; Javier v. Assurance IQ, LLC
Summary
This law-firm blog post summarizes a wave of California Invasion of Privacy Act (CIPA) class actions alleging that website and app trackers, session-replay tools, and chat vendors intercept communications or function as pen registers. The article notes that some federal courts (including a Southern District of California decision in Greenley) have allowed pen-register and interception claims to proceed, while other courts have rejected the pen-register theory, creating a split in California federal courts.
Litigation Status
Procedural Posture
The piece describes a wave of class actions in 2025–2026; some pen-register and interception claims have survived pleadings and proceeded to discovery in certain federal courts, while other courts have rejected the pen-register theory — resulting in a regional split.
Reported Holding
The article reports that courts have allowed some claims under California's Invasion of Privacy Act (CIPA) to proceed: a Southern District of California decision in Greenley allowed a §638.51 pen-register claim to proceed against a mobile-app data broker; the article also cites Javier v. Assurance IQ as holding that retroactive consent in a terms-of-service banner is generally insufficient. Multiple courts reportedly have held that the contents of a form a user types can qualify as a "communication" under §631. Federal courts in California are described as divided on the pen-register theory.
What the Court Decided
Per the article: the Southern District of California allowed a §638.51 pen-register claim to proceed in Greenley v. Kochava, Inc.; Javier (as discussed in the article) held that retroactive consent embedded in a terms-of-service banner is generally insufficient under §631; several courts have held that typed-but-not-submitted form contents can be communications under §631.
What the Court Did Not Decide
The article notes courts remain divided and does not report a uniform resolution on whether traditional pen-register/trap-and-trace statutes apply broadly to web trackers and pixels, nor does it report definitive rulings on merits, damages, or class certification for the broader category of web-tracking cases.
Significance
Generally viewed as plaintiff-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- session replay
- Meta Pixel
- TikTok Pixel
- Google Analytics
- fingerprinting scripts
- web chat software
- third-party tracking scripts
Third parties named or identified in tracked sources: Kochava, Salesforce, LivePerson, Zendesk, Meta, TikTok.
Statutes Invoked
- Cal. Penal Code §§ 630–638.55 (including §§ 631(a), 632, 637.2, 638.51)
Claims Asserted
- Cal. Penal Code § 631(a) – interception/reading communications in transit
- Cal. Penal Code § 632 – recording of confidential communications
- Cal. Penal Code § 638.51 – pen register / trap and trace device (installation/use without court order)
- Cal. Penal Code § 637.2 – statutory damages provision
What This Matter May Mean for Website Operators
For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether chat transcripts or typing previews transit a vendor's servers before the visitor presses send; whether advertising pixels transmit page URLs or hashed form data before a consent choice; what page URLs and query strings analytics tools share with third parties. Our scanner tests these behaviors empirically.
Because this matter is pending, anything reported here is procedural — allegations and interim rulings, not final determinations.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website