Popa v. Microsoft Corp.
Summary
This Holland & Knight alert describes conflicting rulings in California over whether web-based tracking technologies (e.g., pixels and IP-address collection) fall within CIPA Section 638.51. It highlights the Ninth Circuit's Popa v. Microsoft decision tightening Article III standing requirements and notes divergent district-court outcomes applying Popa to CIPA claims.
Litigation Status
Procedural Posture
Summary of an active wave of CIPA §638.51 litigation: federal district courts in California have reached varying outcomes on motions to dismiss based on Article III standing after the Ninth Circuit's Popa decision; state courts have tended to construe CIPA more narrowly. Specific district judges mentioned include Judge Dana Sabraw (S.D. Cal.) and Judge Kenly Kiya Kato (C.D. Cal.) who dismissed §638.51 claims on standing grounds, and Judge Eumi K. Lee (N.D. Cal.) who denied a motion to dismiss similar allegations.
Reported Holding
The Ninth Circuit in Popa reaffirmed that to satisfy Article III standing in privacy cases plaintiffs must plead a concrete injury by showing the defendant or technology collected embarrassing, invasive, or otherwise private information; mere statutory violations or broad privacy theories are insufficient. California federal district courts have applied Popa variably to CIPA Section 638.51 claims—several judges dismissed claims for lack of standing while others found allegations about tracking pixels and metadata sufficient to plead standing. California state courts, by contrast, have tended to adopt a narrower interpretation of CIPA's pen register definition and found web tracking technologies and IP addresses outside the statute's scope.
What the Court Decided
The Ninth Circuit in Popa clarified Article III standing requirements for privacy cases (requiring concrete, private or embarrassing information be collected). Multiple California federal district courts applied Popa to Section 638.51 cases with mixed results: some dismissed Section 638.51 claims for lack of standing (e.g., Southern District of California, Central District of California), while other judges (e.g., Northern District of California) denied motions to dismiss similar allegations. Judge Charles Breyer denied an interlocutory appeal request regarding whether web-based technologies fall within CIPA's pen register definition, finding no substantial grounds for disagreement among federal courts on that specific question.
What the Court Did Not Decide
The Ninth Circuit's Popa decision did not resolve whether web tracking pixels necessarily constitute a 'pen register' under CIPA §638.51; Popa involved different facts and technologies (session replay) and a different statute. The broader state-federal split over whether website tracking and collected IP addresses fall within CIPA's pen register definition has not been definitively resolved by a California appellate court in this alert.
Significance
Neutral / mixed significance. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- tracking pixels
- session replay
- IP address collection
- browser/device metadata (fingerprinting)
- browser/device metadata
- fingerprinting
Statutes Invoked
- California Invasion of Privacy Act (CIPA) Section 638.51
- California Invasion of Privacy Act Section 638.51
Claims Asserted
- CIPA §638.51 (pen register / trap-and-trace)
- Article III standing (injury-in-fact)
- common law privacy theories (as alleged by plaintiffs)
What This Matter May Mean for Website Operators
California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.
For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether advertising pixels transmit page URLs or hashed form data before a consent choice. Our scanner tests these behaviors empirically.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website