California Website Tracking, Privacy & Wiretap Litigation
Current Landscape
California remains a focal point for high-intensity litigation activity alleging that website and app trackers, SDKs, session-replay tools, pixels, and related technologies implicate provisions of the California Invasion of Privacy Act (CIPA) (Cal. Penal Code §§ 631, 632, 638.51). Tracked matters show 13 lawsuits, 0 tracked demand letters, and 1 other tracked matter. Cases and orders reported in 2025–2026 reflect competing approaches by state and federal courts to whether pen-register / trap-and-trace provisions and other CIPA sections extend to web-based trackers and SDKs. Reported technologies appearing across tracked matters include SDKs, analytics scripts, tracking pixels, browser cookies, IP address collection via HTTP requests, fingerprinting scripts, session replay tools, chat widgets, tag managers, LiveRamp third-party trackers and related advertising identity-graph techniques, and cookie consent management platforms (CMPs).
Judicial outcomes to date have varied. Some state-court rulings (e.g., NetScout Systems / Blaker v. NetScout Systems) sustained demurrers and dismissed pen-register claims as inapplicable to ordinary website SDKs based on statutory text and legislative context, while other courts denied motions to dismiss (e.g., Nelson v. Reddit, S.D. Cal.) or adopted pen-register framing (e.g., Greenley v. Kochava in federal court). An unpublished Ninth Circuit panel decision in Javier has been reported to suggest Section 631 may apply to certain internet communications and to require prior express consent before recording web interactions, a view that has prompted operational guidance regarding consent and CMP settings. The consolidated In re Meta Android Privacy Litigation reflects another mixed outcome, with several claims surviving and three dismissed with leave to amend, illustrating that courts are still actively parsing technical fact patterns and statutory scope.
Current Litigation Activity
Important New Filings
- NetScout Systems, Inc. (case name not specified in article)
- Javier v. Assurance IQ
- Javier v. Assurance IQ, LLC and Active Prospect Inc.
- Greenley v. Kochava
- In re Meta Android Privacy Litigation
- Blaker v. Netscout Systems
- Greenley v. Kochava, Inc.; Javier v. Assurance IQ, LLC
- Popa v. Microsoft Corp.
Current Filing & Litigation Trends
Reported filing trends include a growing wave of CIPA pen-register complaints targeting widely used third‑party tags, pixels, analytics tools, and session‑replay/chat vendors; some plaintiffs are using templated pleadings and emphasizing IP/cookie capture and routing to third parties. Federal and state courts in California have reached different conclusions at the pleading stage, producing a developing circuit and intra‑state split that is influencing where and how claims are litigated.
Precedent Landscape: What Courts Have Decided
2 plaintiff-favorable and 3 defense-favorable decision(s) tracked; 1 carry binding authority.
Key Decisions
- Javier v. Assurance IQ; D Antonio v. CNN
- NetScout Systems, Inc. (case name not specified in article)
- Javier v. Assurance IQ, LLC and Active Prospect Inc.
- Blaker v. Netscout Systems
- Schallert v. Palo Alto Networks, Inc.
Current Laws & Relevant Statutes
- California Invasion of Privacy Act (CIPA) § 631 — Cal. Penal Code § 631 · all-party consent · private right of action · statutory damages
- CIPA § 632 (Confidential Communications) — Cal. Penal Code § 632 · all-party consent · private right of action · statutory damages
- CIPA § 638.51 (Pen Register / Trap and Trace) — Cal. Penal Code § 638.51 · private right of action · statutory damages
Regulatory Enforcement
- Multistate investigative sweep focused on UOOM/GPC compliance — California Attorney General and California Privacy Protection Agency (in coordination with Colorado and Connecticut Attorneys General)
- Healthline Media settlement (reported) — California Attorney General
- California GPC/opt-out enforcement activity (early 2026) — California enforcement agencies (as reported)
- California Privacy Protection Agency fines against Ford Motor Co. and PlayOn Sports — California Privacy Protection Agency (CalPrivacy)
- California privacy agency statement regarding Ford opt-out process — California privacy agency
- Disney CCPA settlement (referenced) — California Attorney General
- Sephora enforcement action (referenced) — California Attorney General
- California DOJ settlement with The Walt Disney Company — California Department of Justice - Office of the Attorney General
- State regulators focusing enforcement on opt-out compliance
- Multi-state investigative sweep regarding Global Privacy Control compliance (CA, CO, CT) — letters sent to businesses — California Department of Justice; California Privacy Protection Agency; Colorado Attorney General; Connecticut Attorney General
Agency Guidance
[object Object],[object Object],[object Object],[object Object]
Global Privacy Control / Opt-Out Signals
Currently required
| Statute | California Consumer Privacy Act (as amended by CPRA) |
|---|---|
| Citation | Cal. Civ. Code § 1798.135; Cal. Code Regs. tit. 11, § 7025 |
| Applicability | The article describes a line of federal decisions finding that CIPA's pen register/trap-and-trace provision can apply to website third-party trackers; it does not identify a statutory or regulatory change establishing new general privacy requirements. |
| Opt-out scope | SB 690 (as described) would condition the proposed exemption on disclosure and opt-out rights, but the article provides no legislative text. |
| Universal opt-out requirement | No |
| Recognized mechanisms | Global Privacy Control (GPC) |
No government guidance or enforcement action described; coverage is limited to court litigation over statutory interpretation.
Learn more about Global Privacy Control → · How GPC posture is weighted in the risk guideline →
Changes Coming in the Next 24 Months
Next material effective date: January 1, 2027 (~4 months until effective).
Coming Into Effect (Enacted)
| Law / Regulation | Effective Date | Time Until | What Changes | Who May Be Affected |
|---|---|---|---|---|
| Assembly Bill 566 (California Opt Me Out Act) | January 1, 2027 | ~4 months until effective | Mandates browser-level opt-out preference signal implementation, requires consumer notice within browsers, provides liability protection for browser companies sending the signal, and empowers the CPPA to promulgate regulations to implement the statute. | Browser developers, website operators and in-scope businesses under the CCPA, and California residents (with potential cross-jurisdictional impacts for non-California users depending on implementation). |
| California Opt Me Out Act (AB 566) | January 1, 2027 | ~4 months until effective | Mandates that all web browsers (desktop and mobile) provide a built-in opt-out preference signal by January 1, 2027, which communicates a user's request that sites not sell or share personal information. | Web browser companies, businesses subject to the CCPA, and California consumers |
| Updated CCPA regulations: UOOM confirmation and risk-assessment requirements | January 1, 2026 | already effective | Mandates affirmative, visible confirmation to consumers that an opt-out/UOOM was honored; requires documented risk assessments for selling/sharing personal information used for cross-context behavioral advertising. | Businesses that sell or share personal information for targeted advertising, including those deploying third-party advertising cookies or pixels. |
| CPPA final regulations on cybersecurity audits, risk assessments, ADMT, insurance, and updates to existing CCPA regulations | January 1, 2026 | already effective | Establishes compliance deadlines for cybersecurity audits (certification deadlines varying by revenue tier), requires businesses subject to risk assessments to begin compliance Jan 1, 2026 and to submit attestations and summaries by April 1, 2028, and sets ADMT requirements to begin Jan 1, 2027. | Businesses subject to the California Consumer Privacy Act / CPPA rules, with specified deadlines that vary by business revenue for cybersecurity audit certification. |
| AB 566 'Opt Me Out' Act | January 1, 2027 | ~4 months until effective | Will require browsers to provide built-in universal opt-out signals and shifts certain responsibilities to browser vendors and businesses recognizing those signals. | Web browsers, businesses subject to California privacy law |
| Revised and new CCPA regulations (approved by California OAL/CPPA) | January 1, 2026 | already effective | Requires businesses to provide confirmation that opt-out requests (including those signaled via GPC) have been honored; clarifies cookie-consent/banner rules (closing a banner does not constitute opt-in consent; prominence/symmetry requirements); requires equal or fewer steps to opt-out than opt-in; prevents default selection into financial-incentive programs; requires mechanisms to request PI going back to Jan. 1, 2022 for businesses retaining PI longer than 12 months; requires privacy policies to identify categories of PI disclosed to service providers/contractors in prior 12 months; requires mobile apps to include privacy policy link in app settings; introduces new rules for cybersecurity audits, risk assessments, and ADMT with later compliance deadlines. | Businesses subject to the CCPA/CPRA and California-based or serving California consumers, including websites and mobile applications. |
| Updated CCPA regulations requiring user-facing confirmation that UOOMs are honored | January 1, 2026 | already effective | Adds a requirement for affirmative, visible feedback to users that their opt-out preference signaled via UOOM/GPC was honored. | Businesses subject to CCPA regulations that process UOOM/GPC signals; consent management and website UI implementations. |
Legislation to Watch (Pending)
- Senator Anna Caballero CIPA reform bill (unnumbered in article)
- Senate Bill 690
- SB 690
- Senate Bill No. 690 (2025–26) — Crimes: invasion of privacy
- Senate Bill 690 (referenced)
- Potential legislative clarification of CIPA
- California bill passed by legislature to require browsers to offer UOOMs (pending governor's signature)
- SB 690
- SB 690 (proposed amendment to CIPA)
- California bill requiring browsers to offer universal opt-out mechanisms (UOOMs)
Important Cases & Tracked Matters
NetScout Systems, Inc. (case name not specified in article)
What the court decided: The Los Angeles County Superior Court held that CIPA's pen register and trap-and-trace provisions (Cal. Penal Code § 638.51) apply to telephone communications and not to software (an SDK) used on commercial websites; the court sustained NetScout's demurrer and dismissed the claims with prejudice, denying leave to amend.
What the court did not decide: The court did not address whether website tracking could give rise to other privacy claims under different statutes or regulations (e.g., CCPA/CPRA) or whether other CIPA provisions beyond the pen register/trap-and-trace language might apply.
Nelson v. Reddit, Inc.
What the court decided: The Court denied Defendant Reddit, Inc.’s motion to dismiss. The Court found the complaint plausibly alleges that the LiveRamp tracker on Reddit’s website can qualify as a pen register under CIPA § 638.50(b) and that the pleading is sufficient at the Rule 12(b)(6) stage. The Court rejected Defendant’s arguments (including that a communication must contain substantive content, that Reddit is exempt as a party, and that the rule of lenity compels dismissal) at the pleading stage.
What the court did not decide: The Court did not resolve the merits of liability or damages, did not enter final judgment, and did not resolve factual disputes beyond the plausibility determination at the pleading stage. The Court also did not adopt or rely on Defendant’s requested judicial notice (denied as moot).
Javier v. Assurance IQ
What the court decided: The guide reports that in the influential but unpublished Javier v. Assurance IQ decision, the Ninth Circuit concluded that California Penal Code Section 631 applies to internet communications and indicated that California law requires consent before a communication is recorded; the court did not resolve every issue, including whether the vendor was a third party.
What the court did not decide: Whether the vendor in that case was legally a third party and several other factual/legal issues related to vendor status and downstream uses of data.
Javier v. Assurance IQ, LLC and Active Prospect Inc.
What the court decided: The Ninth Circuit panel concluded that Section 631 of the California Invasion of Privacy Act requires prior express consent of all parties before using recording technologies; retroactive consent is not sufficient.
What the court did not decide: The panel's decision was limited in scope and did not resolve the district court's alternative footnote ruling that a website operator necessarily is a party to communications on its own site and therefore could not have 'wiretapped' those communications.
Greenley v. Kochava
What the court decided: The source reports that a string of California Superior Court rulings declined to dismiss CIPA pen-register complaints at the pleading stage and that a federal court order in Greenley v. Kochava (S.D. Cal. 2023) explicitly approved the "third-party tracker as pen register" framing.
What the court did not decide: The source does not report definitive rulings on the merits of the underlying privacy claims, class certification, or final resolution of damages; it also does not report any binding higher-court precedent resolving the issue statewide.
In re Meta Android Privacy Litigation
What the court decided: The court granted in part and denied in part Defendants’ motions to dismiss: it dismissed (with leave to amend) Plaintiffs’ pen register, unjust enrichment, and negligent misrepresentation claims, and allowed all other claims in the consolidated complaint to survive dismissal.
What the court did not decide: The court did not resolve the merits of surviving claims, class certification, damages, or any subsequent dispositive motions; it did not adjudicate final liability or any potential defenses beyond whether the pleadings suffice at the motion-to-dismiss stage.
Blaker v. Netscout Systems
What the court decided: The Los Angeles Superior Court dismissed a CIPA class action with prejudice, concluding that the pen register/trap-and-trace provision (Cal. Penal Code § 638.51) does not reach standard website tracking SDKs and similar routine commercial web infrastructure.
What the court did not decide: The court did not adopt a rule about all forms of online data practices beyond the specific statutory interpretation at issue and the opinion, as described in the source, does not purport to resolve broader regulatory questions about commercial data collection; the source does not report whether any aspects of alternative factual scenarios were decided.
Greenley v. Kochava, Inc.; Javier v. Assurance IQ, LLC
What the court decided: The article reports that courts have allowed some claims under California's Invasion of Privacy Act (CIPA) to proceed: a Southern District of California decision in Greenley allowed a §638.51 pen-register claim to proceed against a mobile-app data broker; the article also cites Javier v. Assurance IQ as holding that retroactive consent in a terms-of-service banner is generally insufficient. Multiple courts reportedly have held that the contents of a form a user types can qualify as a "communication" under §631. Federal courts in California are described as divided on the pen-register theory.
What the court did not decide: The article notes courts remain divided and does not report a uniform resolution on whether traditional pen-register/trap-and-trace statutes apply broadly to web trackers and pixels, nor does it report definitive rulings on merits, damages, or class certification for the broader category of web-tracking cases.
Popa v. Microsoft Corp.
What the court decided: The Ninth Circuit in Popa reaffirmed that to satisfy Article III standing in privacy cases plaintiffs must plead a concrete injury by showing the defendant or technology collected embarrassing, invasive, or otherwise private information; mere statutory violations or broad privacy theories are insufficient. California federal district courts have applied Popa variably to CIPA Section 638.51 claims—several judges dismissed claims for lack of standing while others found allegations about tracking pixels and metadata sufficient to plead standing. California state courts, by contrast, have tended to adopt a narrower interpretation of CIPA's pen register definition and found web tracking technologies and IP addresses outside the statute's scope.
What the court did not decide: The Ninth Circuit's Popa decision did not resolve whether web tracking pixels necessarily constitute a 'pen register' under CIPA §638.51; Popa involved different facts and technologies (session replay) and a different statute. The broader state-federal split over whether website tracking and collected IP addresses fall within CIPA's pen register definition has not been definitively resolved by a California appellate court in this alert.
Javier v. Assurance IQ; Greenley v. Kochava
What the court decided: The article reports that the Ninth Circuit in Javier held that consent obtained after an interception begins is not consent under CIPA, and that a federal district court in Greenley reasoned the statute's term "process" can cover software, enabling pen register-style claims against tracking technologies.
What the court did not decide: The article indicates courts remain divided and have not uniformly resolved whether specific web tracking tools always meet CIPA's definitions; some complaints have been dismissed with prejudice while other cases or settlements proceeded.
Javier v. Assurance IQ; D Antonio v. CNN
What the court decided: The article states that the Ninth Circuit (in Javier v. Assurance IQ, 2022) held that session replay software used to record user activity before users were provided a privacy policy could be treated as a form of wiretapping or interception under the California Invasion of Privacy Act.
What the court did not decide: The article does not assert that the court resolved the application of CIPA to all forms of website tracking or every third-party tracker named in later claims.
Travis Rounds v. Development Dimensions International
What the court decided: The U.S. District Court for the Central District of California dismissed the plaintiff's complaint without leave to amend, concluding that the plaintiff's allegations that cookies and a 6Sense SDK were used did not plausibly establish a statutory violation of Cal. Penal Code § 638.51 (trap-and-trace device) and therefore could not support the exercise of personal jurisdiction.
What the court did not decide: The court did not permit amendment and did not permit the case to proceed on the merits; it did not adopt a broad, definitive ruling on all possible factual scenarios involving cookies or other tracking technologies beyond the complaint's specific allegations.
Technologies Appearing in Claims
- software development kit (SDK)
- web analytics
- LiveRamp third-party tracker
- HTTP requests / IP address collection
- browser cookies / cookie-based tracking
- third-party advertising identity graph
- LiveRamp tracker
- browser cookies
- IP address collection via HTTP requests
- cookies
- IP address collection
- web tracking / online advertising tracking
- session replay tools
- tracking pixels
- fingerprinting scripts
- chat widgets
- analytics tools
- chatbots
- website tracking
- third-party trackers
- tag managers
- analytics scripts
- advertising scripts
- cookie consent management platforms (CMPs)
- web session recording
Historical Risk Guideline
| Date | Risk Guideline | Level | Confidence | Tracked Lawsuits |
|---|---|---|---|---|
| August 19, 2026 | 84 | Very High | 96% | 11 |
| August 20, 2026 | 89 | Very High | 96% | 11 |
| August 21, 2026 | 89 | Very High | 96% | 11 |
| August 22, 2026 | 89 | Very High | 96% | 11 |
| August 23, 2026 | 94 | Very High | 96% | 11 |
| August 24, 2026 | 94 | Very High | 96% | 11 |
| August 25, 2026 | 94 | Very High | 96% | 11 |
| August 26, 2026 | 95 | Very High | 96% | 12 |
| August 27, 2026 | 95 | Very High | 96% | 12 |
| August 28, 2026 | 94 | Very High | 96% | 13 |
| August 30, 2026 | 94 | Very High | 96% | 13 |
| August 31, 2026 | 94 | Very High | 96% | 13 |
What Businesses Should Review
Businesses operating in California may consider a focused technical review that maps third‑party trackers, SDKs, and tag-manager configurations; documents what identifiers (cookies, IP addresses, device fingerprints, local host ports, etc.) are collected and where they are sent; examines CMP settings and consent flows for any recording or session‑replay features (including whether opt‑in is required and how retroactive consent is logged); evaluates controls to block or sandbox high‑risk third parties (e.g., LiveRamp trackers, advertising identity graphs, session‑replay scripts); and tests honoring of GPC/Do Not Sell/Share signals. These operational steps are presented as technical risk‑management suggestions while courts continue to examine the legal contours of CIPA in web‑tracking contexts.
Data Quality
187 source(s), 52 primary; evidence is fresh.
Methodology & Limitations
Statistics on this page are generated by the Crandall Consulting litigation intelligence engine. Publicly available sources (court and government materials, recognized legal press, professional analysis, and industry reports) are discovered through automated web research, classified into a tiered source hierarchy, and reduced to structured facts with full source provenance. Risk guidelines and evidence-confidence scores are computed by a deterministic formula from those stored facts — never by an AI model directly (AI explains findings; it never assigns a score). Counts labeled "tracked" reflect matters identified in our source set and are not official court statistics.
The overall risk guideline is composed of six deterministically weighted components: statutory structure (25%), current litigation activity (25%), prior precedent (18%), GPC / universal opt-out posture (15%), regulatory enforcement (9%), and the forward-looking 24-month horizon (8%). When a state's GPC status is limited data, that component is excluded and the remaining weights are renormalized — limited data never reads as lower exposure. Current litigation activity is measured over recent windows (velocity), not lifetime volume, so a jurisdiction with high historical activity but declining current filings reflects that decline. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately. Full details are on the methodology page.
Sources
- Post-Popa v. Microsoft, Courts in California Keep the Standing Bar High for Web-Tracking Claims
- Website Privacy Lawsuits Under CIPA: Current State of the Law
- Recent rulings narrow reach of CIPA, but broader privacy fight continues
- ORDER by Judge Araceli Martinez-Olguin DENYING 18 Motion to Dismiss (Filed on 4/29/2026)
- California Website Tracking, Privacy & Wiretap Litigation
- Privacy Litigation Report: Takeaways From March 2026 Decisions
- Universal Opt-Out Mechanisms: Which States Require Them
- The Federal Wiretap Act & Website Tracking Litigation
- Key Areas to Watch as Website Technology Litigation Continues to Surge
- Website Tracker Litigation Continues to Pose Compliance Headache: Updates on CIPA and Related Litigation
- Your Opt-Out Button Might Not Be Doing What You Think It Is
- Florentino Javier v. Assurance IQ, LLC, No. 21-16351 (9th Cir. May 31, 2022) (Memorandum)
- CIPA Web-Tracking Claims Crushed in NetScout Ruling
- The Pen-Register Split: Why the Same Tracker Survives in One California Court and Fails in Another
- Torres v. SeatGeek, Inc. — ORDER (No. 25-cv-07118-LB)
- ORDER Denying Defendant Reddit, Inc.'s Motion to Dismiss Class Action Complaint
- Courts Still Divided on Whether California Privacy Law Applies to Website Tracking: 4 Rulings in 10 Days Highlight Business Confusion
- California CIPA and Website Tracking in 2026: Consent, GPC, and the “Do Not Sell or Share” Rule
- Bill Text: CA SB690 | 2025-2026 | Regular Session | Amended
- Global Privacy Control (GPC)
- CIPA Website Tracking Lawsuits: Old California Law Now in Play
- Pfizer faces CIPA class action over alleged post-opt-out personal data sharing
- Defending CIPA / Meta Pixel Website-Tracking Arbitration Claims (California)
- IAPP 2026 Privacy Litigation Report: U.S. Privacy Lawsuits Surge
- The CIPA Playbook: Consent, Tracking, and What to Do If You Get a Demand Letter
All State Pages
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website