Javier v. Assurance IQ; D Antonio v. CNN
Summary
This Termly article explains that plaintiffs have invoked the California Invasion of Privacy Act (CIPA) against website tracking, highlighting a 2022 Ninth Circuit decision (Javier v. Assurance IQ) that treated session replay recorded before notice/consent as an interception. The piece lists commonly named trackers (pixels, analytics, session replay, live chat, form/search transmissions) and notes a wave of lawsuits and demand letters targeting websites with California visitors.
Litigation Status
Procedural Posture
The article summarizes the Ninth Circuit decision from 2022 and notes that additional lawsuits and demand letters followed, including a reported matter titled D Antonio v. CNN.
Reported Holding
The article states that the Ninth Circuit (in Javier v. Assurance IQ, 2022) held that session replay software used to record user activity before users were provided a privacy policy could be treated as a form of wiretapping or interception under the California Invasion of Privacy Act.
What the Court Decided
According to the article, the Ninth Circuit concluded that session replay can constitute a form of wiretapping and that recording user activity prior to providing notice/consent was an interception covered by CIPA.
What the Court Did Not Decide
The article does not assert that the court resolved the application of CIPA to all forms of website tracking or every third-party tracker named in later claims.
Significance
Generally viewed as plaintiff-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- session replay / session recording tools
- heatmap and behavior analytics tools
- Meta pixel (Facebook pixel)
- Google Ads conversion and remarketing tags
- Google Analytics
- TikTok Pixel
- LinkedIn Insight Tag
- third-party live chat/chatbots
- on-site search bars and forms
Third parties named or identified in tracked sources: Meta, Google, TikTok, LinkedIn, Assurance IQ, CNN.
Statutes Invoked
Claims Asserted
- California Invasion of Privacy Act (CIPA) wiretapping/interception claims
- Claims alleging interception or secret collection of online activity prior to notice/consent
What This Matter May Mean for Website Operators
California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.
For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether chat transcripts or typing previews transit a vendor's servers before the visitor presses send; whether advertising pixels transmit page URLs or hashed form data before a consent choice; what page URLs and query strings analytics tools share with third parties. Our scanner tests these behaviors empirically.
The reported outcome direction at the statutory interpretation stage reflects how tracked sources characterize the ruling; such rulings are often narrow, posture-specific, and fact-bound rather than broad statements of law.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website