CRANDALL CONSULTING
HomePrivacy Laws Risk Scanner › California

California Website Tracking, Privacy & Wiretap Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last intelligence update: August 31, 2026

94/100
Risk Guideline
Very High
Risk Level
96%
Evidence Confidence
rising
Trend
13
Tracked Lawsuits
1
Tracked Matters
0
Tracked Demand Letters
5
Reported Claims
Currently required
GPC Opt-Out Signal Status

Lawsuits, demand letters, tracked matters, and reported claims are counted separately and are not interchangeable. Last intelligence update: August 31, 2026.

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

Current Landscape

California remains a focal point for high-intensity litigation activity alleging that website and app trackers, SDKs, session-replay tools, pixels, and related technologies implicate provisions of the California Invasion of Privacy Act (CIPA) (Cal. Penal Code §§ 631, 632, 638.51). Tracked matters show 13 lawsuits, 0 tracked demand letters, and 1 other tracked matter. Cases and orders reported in 2025–2026 reflect competing approaches by state and federal courts to whether pen-register / trap-and-trace provisions and other CIPA sections extend to web-based trackers and SDKs. Reported technologies appearing across tracked matters include SDKs, analytics scripts, tracking pixels, browser cookies, IP address collection via HTTP requests, fingerprinting scripts, session replay tools, chat widgets, tag managers, LiveRamp third-party trackers and related advertising identity-graph techniques, and cookie consent management platforms (CMPs).

Judicial outcomes to date have varied. Some state-court rulings (e.g., NetScout Systems / Blaker v. NetScout Systems) sustained demurrers and dismissed pen-register claims as inapplicable to ordinary website SDKs based on statutory text and legislative context, while other courts denied motions to dismiss (e.g., Nelson v. Reddit, S.D. Cal.) or adopted pen-register framing (e.g., Greenley v. Kochava in federal court). An unpublished Ninth Circuit panel decision in Javier has been reported to suggest Section 631 may apply to certain internet communications and to require prior express consent before recording web interactions, a view that has prompted operational guidance regarding consent and CMP settings. The consolidated In re Meta Android Privacy Litigation reflects another mixed outcome, with several claims surviving and three dismissed with leave to amend, illustrating that courts are still actively parsing technical fact patterns and statutory scope.

Current Litigation Activity

Current litigation component: 100/100.

August 31, 2024 – August 31, 2026
Research Window
rising
Current Filing Trend
2
Filing Velocity
13
Filed Cases (est.)
6
Tracked Matters

Important New Filings

Current Filing & Litigation Trends

Reported filing trends include a growing wave of CIPA pen-register complaints targeting widely used third‑party tags, pixels, analytics tools, and session‑replay/chat vendors; some plaintiffs are using templated pleadings and emphasizing IP/cookie capture and routing to third parties. Federal and state courts in California have reached different conclusions at the pleading stage, producing a developing circuit and intra‑state split that is influencing where and how claims are litigated.

Precedent Landscape: What Courts Have Decided

Precedent component: 66/100. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately — a high number of filings does not by itself indicate strong plaintiff-favorable binding precedent.

2 plaintiff-favorable and 3 defense-favorable decision(s) tracked; 1 carry binding authority.

7
Plaintiff-Favorable
4
Defense-Favorable
0
Mixed / Neutral
1
Binding Decisions
4
Persuasive Decisions

Key Decisions

A settlement is not a binding precedent, and a procedural dismissal (for example, for lack of standing) is not a holding that the underlying technology is lawful. Where courts disagree, that disagreement is reflected rather than resolved.

Current Laws & Relevant Statutes

Regulatory Enforcement

Regulatory enforcement component: 100/100. Regulatory enforcement (agency investigations, sweeps, settlements, guidance, rulemaking) is tracked separately from private litigation and is never counted as a lawsuit.

Agency Guidance

[object Object],[object Object],[object Object],[object Object]

Regulatory trend: active.

Global Privacy Control / Opt-Out Signals

Currently required

GPC / universal opt-out exposure component: 100/100. This component reflects whether the state currently requires or recognizes universal opt-out preference signals (such as GPC) and related enforcement activity, and is a weighted input to the overall risk guideline. It describes the state's legal posture — never any individual website's behavior.

GPC / universal opt-out privacy rights are a different legal theory from wiretap / interception litigation, though both affect third-party website data flows.

StatuteCalifornia Consumer Privacy Act (as amended by CPRA)
CitationCal. Civ. Code § 1798.135; Cal. Code Regs. tit. 11, § 7025
ApplicabilityThe article describes a line of federal decisions finding that CIPA's pen register/trap-and-trace provision can apply to website third-party trackers; it does not identify a statutory or regulatory change establishing new general privacy requirements.
Opt-out scopeSB 690 (as described) would condition the proposed exemption on disclosure and opt-out rights, but the article provides no legislative text.
Universal opt-out requirementNo
Recognized mechanismsGlobal Privacy Control (GPC)

No government guidance or enforcement action described; coverage is limited to court litigation over statutory interpretation.

GPC evidence confidence: 75%.

Learn more about Global Privacy Control → · How GPC posture is weighted in the risk guideline →

Changes Coming in the Next 24 Months

Forward-looking (24-month) component: 100/100. Enacted changes with future effective dates may affect a jurisdiction's forward-looking risk, but are not presented as currently enforceable.

Next material effective date: January 1, 2027 (~4 months until effective).

Coming Into Effect (Enacted)

Law / RegulationEffective DateTime UntilWhat ChangesWho May Be Affected
Assembly Bill 566 (California Opt Me Out Act)
· GPC-related
January 1, 2027~4 months until effectiveMandates browser-level opt-out preference signal implementation, requires consumer notice within browsers, provides liability protection for browser companies sending the signal, and empowers the CPPA to promulgate regulations to implement the statute.Browser developers, website operators and in-scope businesses under the CCPA, and California residents (with potential cross-jurisdictional impacts for non-California users depending on implementation).
California Opt Me Out Act (AB 566)
· GPC-related
January 1, 2027~4 months until effectiveMandates that all web browsers (desktop and mobile) provide a built-in opt-out preference signal by January 1, 2027, which communicates a user's request that sites not sell or share personal information.Web browser companies, businesses subject to the CCPA, and California consumers
Updated CCPA regulations: UOOM confirmation and risk-assessment requirements
· GPC-related
January 1, 2026already effectiveMandates affirmative, visible confirmation to consumers that an opt-out/UOOM was honored; requires documented risk assessments for selling/sharing personal information used for cross-context behavioral advertising.Businesses that sell or share personal information for targeted advertising, including those deploying third-party advertising cookies or pixels.
CPPA final regulations on cybersecurity audits, risk assessments, ADMT, insurance, and updates to existing CCPA regulationsJanuary 1, 2026already effectiveEstablishes compliance deadlines for cybersecurity audits (certification deadlines varying by revenue tier), requires businesses subject to risk assessments to begin compliance Jan 1, 2026 and to submit attestations and summaries by April 1, 2028, and sets ADMT requirements to begin Jan 1, 2027.Businesses subject to the California Consumer Privacy Act / CPPA rules, with specified deadlines that vary by business revenue for cybersecurity audit certification.
AB 566 'Opt Me Out' Act
AB 566
· GPC-related
January 1, 2027~4 months until effectiveWill require browsers to provide built-in universal opt-out signals and shifts certain responsibilities to browser vendors and businesses recognizing those signals.Web browsers, businesses subject to California privacy law
Revised and new CCPA regulations (approved by California OAL/CPPA)
· GPC-related
January 1, 2026already effectiveRequires businesses to provide confirmation that opt-out requests (including those signaled via GPC) have been honored; clarifies cookie-consent/banner rules (closing a banner does not constitute opt-in consent; prominence/symmetry requirements); requires equal or fewer steps to opt-out than opt-in; prevents default selection into financial-incentive programs; requires mechanisms to request PI going back to Jan. 1, 2022 for businesses retaining PI longer than 12 months; requires privacy policies to identify categories of PI disclosed to service providers/contractors in prior 12 months; requires mobile apps to include privacy policy link in app settings; introduces new rules for cybersecurity audits, risk assessments, and ADMT with later compliance deadlines.Businesses subject to the CCPA/CPRA and California-based or serving California consumers, including websites and mobile applications.
Updated CCPA regulations requiring user-facing confirmation that UOOMs are honored
· GPC-related
January 1, 2026already effectiveAdds a requirement for affirmative, visible feedback to users that their opt-out preference signaled via UOOM/GPC was honored.Businesses subject to CCPA regulations that process UOOM/GPC signals; consent management and website UI implementations.

Legislation to Watch (Pending)

Pending bills are not law and may never take effect; they are listed separately from enacted changes.

Important Cases & Tracked Matters

NetScout Systems, Inc. (case name not specified in article)

Los Angeles County Superior Court · 2026-06-01 · lawsuit · Outcome: Defense-favorable · Status: DECIDED · Appeal: unknown

What the court decided: The Los Angeles County Superior Court held that CIPA's pen register and trap-and-trace provisions (Cal. Penal Code § 638.51) apply to telephone communications and not to software (an SDK) used on commercial websites; the court sustained NetScout's demurrer and dismissed the claims with prejudice, denying leave to amend.

What the court did not decide: The court did not address whether website tracking could give rise to other privacy claims under different statutes or regulations (e.g., CCPA/CPRA) or whether other CIPA provisions beyond the pen register/trap-and-trace language might apply.

Nelson v. Reddit, Inc.

United States District Court, Southern District of California · 2026-02-17 · lawsuit · Outcome: Plaintiff-favorable · Status: LITIGATION PENDING

What the court decided: The Court denied Defendant Reddit, Inc.’s motion to dismiss. The Court found the complaint plausibly alleges that the LiveRamp tracker on Reddit’s website can qualify as a pen register under CIPA § 638.50(b) and that the pleading is sufficient at the Rule 12(b)(6) stage. The Court rejected Defendant’s arguments (including that a communication must contain substantive content, that Reddit is exempt as a party, and that the rule of lenity compels dismissal) at the pleading stage.

What the court did not decide: The Court did not resolve the merits of liability or damages, did not enter final judgment, and did not resolve factual disputes beyond the plausibility determination at the pleading stage. The Court also did not adopt or rely on Defendant’s requested judicial notice (denied as moot).

Javier v. Assurance IQ

United States Court of Appeals for the Ninth Circuit · reported claim · Outcome: Plaintiff-favorable · Status: UNKNOWN · Appeal: unknown

What the court decided: The guide reports that in the influential but unpublished Javier v. Assurance IQ decision, the Ninth Circuit concluded that California Penal Code Section 631 applies to internet communications and indicated that California law requires consent before a communication is recorded; the court did not resolve every issue, including whether the vendor was a third party.

What the court did not decide: Whether the vendor in that case was legally a third party and several other factual/legal issues related to vendor status and downstream uses of data.

Javier v. Assurance IQ, LLC and Active Prospect Inc.

United States Court of Appeals for the Ninth Circuit · lawsuit · Outcome: Plaintiff-favorable · Status: DECIDED · Appeal: appeal decided

What the court decided: The Ninth Circuit panel concluded that Section 631 of the California Invasion of Privacy Act requires prior express consent of all parties before using recording technologies; retroactive consent is not sufficient.

What the court did not decide: The panel's decision was limited in scope and did not resolve the district court's alternative footnote ruling that a website operator necessarily is a party to communications on its own site and therefore could not have 'wiretapped' those communications.

Greenley v. Kochava

United States District Court for the Southern District of California · reported claim · Outcome: Pending · Status: LITIGATION PENDING · Appeal: unknown

What the court decided: The source reports that a string of California Superior Court rulings declined to dismiss CIPA pen-register complaints at the pleading stage and that a federal court order in Greenley v. Kochava (S.D. Cal. 2023) explicitly approved the "third-party tracker as pen register" framing.

What the court did not decide: The source does not report definitive rulings on the merits of the underlying privacy claims, class certification, or final resolution of damages; it also does not report any binding higher-court precedent resolving the issue statewide.

In re Meta Android Privacy Litigation

United States District Court for the Northern District of California · 2026-05-11 · lawsuit · Outcome: Mixed · Status: DECIDED

What the court decided: The court granted in part and denied in part Defendants’ motions to dismiss: it dismissed (with leave to amend) Plaintiffs’ pen register, unjust enrichment, and negligent misrepresentation claims, and allowed all other claims in the consolidated complaint to survive dismissal.

What the court did not decide: The court did not resolve the merits of surviving claims, class certification, damages, or any subsequent dispositive motions; it did not adjudicate final liability or any potential defenses beyond whether the pleadings suffice at the motion-to-dismiss stage.

Blaker v. Netscout Systems

Los Angeles Superior Court · 2026-05-27 · lawsuit · Outcome: Defense-favorable · Status: DECIDED · Appeal: unknown

What the court decided: The Los Angeles Superior Court dismissed a CIPA class action with prejudice, concluding that the pen register/trap-and-trace provision (Cal. Penal Code § 638.51) does not reach standard website tracking SDKs and similar routine commercial web infrastructure.

What the court did not decide: The court did not adopt a rule about all forms of online data practices beyond the specific statutory interpretation at issue and the opinion, as described in the source, does not purport to resolve broader regulatory questions about commercial data collection; the source does not report whether any aspects of alternative factual scenarios were decided.

Greenley v. Kochava, Inc.; Javier v. Assurance IQ, LLC

Southern District of California; Northern District of California; Ninth Circuit (as discussed) · reported claim · Outcome: Pending · Status: LITIGATION PENDING · Appeal: unknown

What the court decided: The article reports that courts have allowed some claims under California's Invasion of Privacy Act (CIPA) to proceed: a Southern District of California decision in Greenley allowed a §638.51 pen-register claim to proceed against a mobile-app data broker; the article also cites Javier v. Assurance IQ as holding that retroactive consent in a terms-of-service banner is generally insufficient. Multiple courts reportedly have held that the contents of a form a user types can qualify as a "communication" under §631. Federal courts in California are described as divided on the pen-register theory.

What the court did not decide: The article notes courts remain divided and does not report a uniform resolution on whether traditional pen-register/trap-and-trace statutes apply broadly to web trackers and pixels, nor does it report definitive rulings on merits, damages, or class certification for the broader category of web-tracking cases.

Popa v. Microsoft Corp.

U.S. Court of Appeals for the Ninth Circuit; U.S. District Courts for the Northern, Central, and Southern Districts of California · lawsuit · Outcome: Mixed · Status: UNKNOWN · Appeal: unknown

What the court decided: The Ninth Circuit in Popa reaffirmed that to satisfy Article III standing in privacy cases plaintiffs must plead a concrete injury by showing the defendant or technology collected embarrassing, invasive, or otherwise private information; mere statutory violations or broad privacy theories are insufficient. California federal district courts have applied Popa variably to CIPA Section 638.51 claims—several judges dismissed claims for lack of standing while others found allegations about tracking pixels and metadata sufficient to plead standing. California state courts, by contrast, have tended to adopt a narrower interpretation of CIPA's pen register definition and found web tracking technologies and IP addresses outside the statute's scope.

What the court did not decide: The Ninth Circuit's Popa decision did not resolve whether web tracking pixels necessarily constitute a 'pen register' under CIPA §638.51; Popa involved different facts and technologies (session replay) and a different statute. The broader state-federal split over whether website tracking and collected IP addresses fall within CIPA's pen register definition has not been definitively resolved by a California appellate court in this alert.

Javier v. Assurance IQ; Greenley v. Kochava

Ninth Circuit; U.S. District Court for the Southern District of California · reported claim · Outcome: Mixed · Status: UNKNOWN · Appeal: unknown

What the court decided: The article reports that the Ninth Circuit in Javier held that consent obtained after an interception begins is not consent under CIPA, and that a federal district court in Greenley reasoned the statute's term "process" can cover software, enabling pen register-style claims against tracking technologies.

What the court did not decide: The article indicates courts remain divided and have not uniformly resolved whether specific web tracking tools always meet CIPA's definitions; some complaints have been dismissed with prejudice while other cases or settlements proceeded.

Javier v. Assurance IQ; D Antonio v. CNN

U.S. Court of Appeals for the Ninth Circuit (Javier v. Assurance IQ referenced) · reported claim · Outcome: Plaintiff-favorable · Status: DECIDED · Appeal: appeal decided

What the court decided: The article states that the Ninth Circuit (in Javier v. Assurance IQ, 2022) held that session replay software used to record user activity before users were provided a privacy policy could be treated as a form of wiretapping or interception under the California Invasion of Privacy Act.

What the court did not decide: The article does not assert that the court resolved the application of CIPA to all forms of website tracking or every third-party tracker named in later claims.

Travis Rounds v. Development Dimensions International

United States District Court for the Central District of California (C.D. Cal.) · 2026-03-11 · lawsuit · Outcome: Defense-favorable · Status: DECIDED

What the court decided: The U.S. District Court for the Central District of California dismissed the plaintiff's complaint without leave to amend, concluding that the plaintiff's allegations that cookies and a 6Sense SDK were used did not plausibly establish a statutory violation of Cal. Penal Code § 638.51 (trap-and-trace device) and therefore could not support the exercise of personal jurisdiction.

What the court did not decide: The court did not permit amendment and did not permit the case to proceed on the merits; it did not adopt a broad, definitive ruling on all possible factual scenarios involving cookies or other tracking technologies beyond the complaint's specific allegations.

Technologies Appearing in Claims

Historical Risk Guideline

August 8, 2026: 45/100August 10, 2026: 69/100August 11, 2026: 66/100August 12, 2026: 67/100August 12, 2026: 67/100August 14, 2026: 70/100August 15, 2026: 70/100August 16, 2026: 79/100August 17, 2026: 80/100August 18, 2026: 80/100August 18, 2026: 80/100August 19, 2026: 84/100August 20, 2026: 89/100August 21, 2026: 89/100August 22, 2026: 89/100August 23, 2026: 94/100August 24, 2026: 94/100August 25, 2026: 94/100August 26, 2026: 95/100August 27, 2026: 95/100August 28, 2026: 94/100August 30, 2026: 94/100August 31, 2026: 94/100
DateRisk GuidelineLevelConfidenceTracked Lawsuits
August 19, 202684Very High96%11
August 20, 202689Very High96%11
August 21, 202689Very High96%11
August 22, 202689Very High96%11
August 23, 202694Very High96%11
August 24, 202694Very High96%11
August 25, 202694Very High96%11
August 26, 202695Very High96%12
August 27, 202695Very High96%12
August 28, 202694Very High96%13
August 30, 202694Very High96%13
August 31, 202694Very High96%13

What Businesses Should Review

Businesses operating in California may consider a focused technical review that maps third‑party trackers, SDKs, and tag-manager configurations; documents what identifiers (cookies, IP addresses, device fingerprints, local host ports, etc.) are collected and where they are sent; examines CMP settings and consent flows for any recording or session‑replay features (including whether opt‑in is required and how retroactive consent is logged); evaluates controls to block or sandbox high‑risk third parties (e.g., LiveRamp trackers, advertising identity graphs, session‑replay scripts); and tests honoring of GPC/Do Not Sell/Share signals. These operational steps are presented as technical risk‑management suggestions while courts continue to examine the legal contours of CIPA in web‑tracking contexts.

Data Quality

52
Primary Sources
187
Total Tracked Sources
fresh
Evidence Freshness
August 30, 2026
Last Research Run
August 31, 2026
Most Recent Source

187 source(s), 52 primary; evidence is fresh.

Methodology & Limitations

Statistics on this page are generated by the Crandall Consulting litigation intelligence engine. Publicly available sources (court and government materials, recognized legal press, professional analysis, and industry reports) are discovered through automated web research, classified into a tiered source hierarchy, and reduced to structured facts with full source provenance. Risk guidelines and evidence-confidence scores are computed by a deterministic formula from those stored facts — never by an AI model directly (AI explains findings; it never assigns a score). Counts labeled "tracked" reflect matters identified in our source set and are not official court statistics.

The overall risk guideline is composed of six deterministically weighted components: statutory structure (25%), current litigation activity (25%), prior precedent (18%), GPC / universal opt-out posture (15%), regulatory enforcement (9%), and the forward-looking 24-month horizon (8%). When a state's GPC status is limited data, that component is excluded and the remaining weights are renormalized — limited data never reads as lower exposure. Current litigation activity is measured over recent windows (velocity), not lifetime volume, so a jurisdiction with high historical activity but declining current filings reflects that decline. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately. Full details are on the methodology page.

Sources

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

All State Pages

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website