CRANDALL CONSULTING
HomeWebsite Tracking Cases › Popa v. Microsoft Corp.

Popa v. Microsoft Corp.

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

U.S. Court of Appeals for the Ninth Circuit; U.S. District Courts for the Northern, Central, and Southern Districts of California
Court
California
Jurisdiction
Not identified
Decision / Filing Date
Lawsuit
Matter Type
Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

Summary

This Holland & Knight alert describes conflicting rulings in California over whether web-based tracking technologies (e.g., pixels and IP-address collection) fall within CIPA Section 638.51. It highlights the Ninth Circuit's Popa v. Microsoft decision tightening Article III standing requirements and notes divergent district-court outcomes applying Popa to CIPA claims.

Litigation Status

Not identified
Current Status
Mixed
Reported Outcome Direction
Standing
Ruling Stage
None identified
Precedential Weight

Status, direction, and weight describe how tracked public sources characterize this matter as of our last review — they are informational classifications, not legal assessments.

Procedural Posture

Summary of an active wave of CIPA §638.51 litigation: federal district courts in California have reached varying outcomes on motions to dismiss based on Article III standing after the Ninth Circuit's Popa decision; state courts have tended to construe CIPA more narrowly. Specific district judges mentioned include Judge Dana Sabraw (S.D. Cal.) and Judge Kenly Kiya Kato (C.D. Cal.) who dismissed §638.51 claims on standing grounds, and Judge Eumi K. Lee (N.D. Cal.) who denied a motion to dismiss similar allegations.

Reported Holding

The Ninth Circuit in Popa reaffirmed that to satisfy Article III standing in privacy cases plaintiffs must plead a concrete injury by showing the defendant or technology collected embarrassing, invasive, or otherwise private information; mere statutory violations or broad privacy theories are insufficient. California federal district courts have applied Popa variably to CIPA Section 638.51 claims—several judges dismissed claims for lack of standing while others found allegations about tracking pixels and metadata sufficient to plead standing. California state courts, by contrast, have tended to adopt a narrower interpretation of CIPA's pen register definition and found web tracking technologies and IP addresses outside the statute's scope.

What the Court Decided

The Ninth Circuit in Popa clarified Article III standing requirements for privacy cases (requiring concrete, private or embarrassing information be collected). Multiple California federal district courts applied Popa to Section 638.51 cases with mixed results: some dismissed Section 638.51 claims for lack of standing (e.g., Southern District of California, Central District of California), while other judges (e.g., Northern District of California) denied motions to dismiss similar allegations. Judge Charles Breyer denied an interlocutory appeal request regarding whether web-based technologies fall within CIPA's pen register definition, finding no substantial grounds for disagreement among federal courts on that specific question.

What the Court Did Not Decide

The Ninth Circuit's Popa decision did not resolve whether web tracking pixels necessarily constitute a 'pen register' under CIPA §638.51; Popa involved different facts and technologies (session replay) and a different statute. The broader state-federal split over whether website tracking and collected IP addresses fall within CIPA's pen register definition has not been definitively resolved by a California appellate court in this alert.

Significance

Neutral / mixed significance. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.

What This Page Does and Does Not Say

This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.

Technologies at Issue

Statutes Invoked

Claims Asserted

Claims identified in tracked public sources; pleadings may include additional or amended claims.

What This Matter May Mean for Website Operators

California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.

For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether advertising pixels transmit page URLs or hashed form data before a consent choice. Our scanner tests these behaviors empirically.

Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.

Related Intelligence

Sources

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website