Travis Rounds v. Development Dimensions International
Summary
A federal district court in the Central District of California dismissed without leave to amend a complaint alleging that cookies and a 6Sense SDK functioned as a CIPA trap-and-trace device, finding the allegations insufficient to establish a statutory violation and thus personal jurisdiction. The decision indicates that such cookie-based theories will not always succeed in that court.
Litigation Status
Procedural Posture
Plaintiff alleged that DDI installed a 6Sense data-broker SDK on its website that transmitted location and browser/device information to deanonymize users; defendant moved to dismiss for lack of personal jurisdiction; court dismissed complaint without leave to amend.
Reported Holding
The U.S. District Court for the Central District of California dismissed the plaintiff's complaint without leave to amend, concluding that the plaintiff's allegations that cookies and a 6Sense SDK were used did not plausibly establish a statutory violation of Cal. Penal Code § 638.51 (trap-and-trace device) and therefore could not support the exercise of personal jurisdiction.
What the Court Decided
The court granted the defendant's motion to dismiss for lack of personal jurisdiction because the complaint's allegations regarding the use of cookies and a data-broker SDK did not plausibly show a violation of Penal Code § 638.51 and thus did not establish a basis for personal jurisdiction over the defendant.
What the Court Did Not Decide
The court did not permit amendment and did not permit the case to proceed on the merits; it did not adopt a broad, definitive ruling on all possible factual scenarios involving cookies or other tracking technologies beyond the complaint's specific allegations.
Significance
Generally viewed as defense-favorable. Characterizations of significance describe how the matter has generally been discussed in tracked public sources; individual holdings are often narrow, procedural, or fact-specific, and this page does not state or imply broader holdings than the sources support.
What This Page Does and Does Not Say
This page reports what our tracked public sources say about this matter — including, where identified, the procedural posture (for example, a ruling on a motion to dismiss is not a final merits decision). It does not report legal conclusions beyond those sources, does not predict outcomes, and does not constitute legal advice.
Technologies at Issue
- tracking pixels
- cookies
- session replay
- keystroke monitoring
- tag management systems
- third-party tags
- website advertising technology
- browser tracking
- data-broker SDKs
- browser cookies
- software development kit (SDK)
- geolocation
- device information
- browser data
Third parties named or identified in tracked sources: Meta, TikTok, Google, Development Dimensions International, 6Sense, Development Dimensions International, Inc..
Statutes Invoked
- California Invasion of Privacy Act Sections 631 and 638.51 (pen register)
- California Invasion of Privacy Act (CIPA); 638.51
- California Penal Code § 638.51 (and § 638.50(c) definition) — CIPA trap-and-trace provisions
Claims Asserted
- California Invasion of Privacy Act Section 631 (wiretapping/interception)
- California Invasion of Privacy Act Section 638.51 (pen register)
- Electronic Communications Privacy Act (ECPA)
- common law privacy
- unfair competition
- misrepresentation
- CIPA trap-and-trace device claim
- personal jurisdiction
- Cal. Penal Code § 638.51 (trap-and-trace)
- California Invasion of Privacy Act (CIPA) related claims as pleaded
What This Matter May Mean for Website Operators
California Invasion of Privacy Act (CIPA) is an all-party consent statute with a private right of action. Consent standard and private enforceability are the structural features that most shape where website tracking claims are filed and how they are valued.
For operators using similar technologies, the recurring factual questions in matters like this one are when session recording begins relative to consent and whether input masking covers every field; whether advertising pixels transmit page URLs or hashed form data before a consent choice; what page URLs and query strings analytics tools share with third parties. Our scanner tests these behaviors empirically.
The reported outcome direction at the jurisdiction stage reflects how tracked sources characterize the ruling; such rulings are often narrow, posture-specific, and fact-bound rather than broad statements of law.
Detection of a similar technology on a website is an informational risk indicator, not a legal conclusion, and nothing in this section is legal advice.
Related Intelligence
Sources
- Federal Court Rejects Claim that Cookies Are Illegal Trap and Trace Devices
- The Millisecond Problem: How Pre-Consent Tracking Is Driving CIPA Lawsuits in 2026
- Privacy Litigation Update: California Court Rejects "Trap and Trace" Cookie Claims
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website