Ortiz v. Foris Dax, Inc. (Crypto.com)
Summary
A federal district court in N.D. California issued a split ruling in Ortiz v. Foris Dax: it dismissed the CIPA §631 (wiretapping) claim for lack of pleaded facts about intercepted content but allowed the CIPA §638.51 (pen-register) claim to proceed, reasoning that pen-register provisions can apply to internet tracking such as cookies and pixels. The decision is viewed as a significant federal analysis endorsing the theory that cookies/pixels can function as pen registers.
Litigation Status
Procedural Posture
Putative class action filed October 17, 2025; district court issued a split ruling on May 21, 2026 dismissing the §631 claim with leave to amend and allowing the §638.51 claim to survive.
Reported Holding
The district court dismissed the CIPA §631 (wiretapping) claim for failure to plead facts showing interception of the contents of communications, but denied dismissal of the CIPA §638.51 (pen-register) claim, concluding the pen-register provision can apply to internet tracking such as cookies and advertising/analytics pixels.
What the Court Decided
The court dismissed the plaintiffs' wiretapping (§631) claim with leave to amend because the complaint alleged only categories of data the tracking could collect rather than specific intercepted communications; the court allowed the pen-register (§638.51) claim to proceed, finding the statutory text and legislative history support applying the pen-register provision to internet tracking like cookies/pixels.
What the Court Did Not Decide
The court did not resolve the merits of whether the specific cookies/pixels at issue in fact constituted pen-registers as applied to these plaintiffs, nor did it resolve liability, class certification, or any amended §631 pleading (the §631 dismissal was with leave to amend).
Significance
Generally viewed as plaintiff-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- third-party cookies
- advertising pixels
- analytics pixels
Third parties named or identified in tracked sources: Foris Dax, Inc. (d/b/a Crypto.com).
Statutes Invoked
Claims Asserted
- California Invasion of Privacy Act §631 (wiretapping)
- California Invasion of Privacy Act §638.51 (pen register)
- invasion of privacy (highly offensive intrusion allegation)
What This Matter May Mean for Website Operators
California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.
For operators using similar technologies, the recurring factual questions in matters like this one are whether advertising pixels transmit page URLs or hashed form data before a consent choice; what page URLs and query strings analytics tools share with third parties. Our scanner tests these behaviors empirically.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website