Khamooshi v. Politico LLC
Summary
A federal district court in the N.D. Cal. dismissed a CIPA pen register claim against Politico for lack of Article III standing, applying the Ninth Circuit's Popa decision and finding that allegations of device/browser type and device fingerprints did not allege embarrassing, invasive, or otherwise private information. The dismissal followed an earlier dismissal of the initial complaint and resolves the case at the pleadings stage.
Litigation Status
Procedural Posture
Plaintiffs filed a putative class action in September 2024 alleging that Politico embedded third-party technologies that collected browser/device data, IP address, and other identifying information. The initial complaint was dismissed for lack of standing. Plaintiffs filed an amended complaint adding categories of information; the court dismissed the amended complaint on October 2, 2025, citing Ninth Circuit precedent in Popa.
Reported Holding
The district court dismissed the amended complaint for lack of Article III standing under the standard articulated in the Ninth Circuit's Popa v. Microsoft decision, holding that allegations that third-party technologies collected device type, browser type, and device fingerprints failed to identify "embarrassing, invasive, or otherwise private information" sufficient to establish a concrete privacy injury.
What the Court Decided
The court held the plaintiffs lacked Article III standing to bring a CIPA pen register claim because the allegedly collected information (device type, browser type, and device fingerprints) did not constitute the kind of embarrassing, invasive, or otherwise private information required under Popa to establish a concrete privacy injury.
What the Court Did Not Decide
The court did not reach the merits of whether the alleged data collection violated CIPA's pen register provision or other substantive defenses because it dismissed the case for lack of Article III standing.
Significance
Generally viewed as defense-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- device type detection
- browser type detection
- device fingerprinting
- IP address collection
Statutes Invoked
Claims Asserted
- California Invasion of Privacy Act (CIPA) pen register claim (Cal. Penal Code § 638.51)
- related privacy/wiretapping claims (as pled)
What This Matter May Mean for Website Operators
California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.
The reported outcome direction at the standing stage reflects how tracked sources characterize the ruling; such rulings are often narrow, posture-specific, and fact-bound rather than broad statements of law.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website