Illinois Website Tracking, Privacy & Wiretap Litigation
Current Landscape
In Illinois the tracked litigation activity is currently modest: one tracked putative class action is pending. Relevant state and federal statutes that appear in tracked matters include the Illinois Eavesdropping Act (720 ILCS 5/14-1 et seq.) and the Illinois Biometric Information Privacy Act (BIPA) (740 ILCS 14/1 et seq.), and courts are also being asked to apply federal statutes in related privacy claims. The technologies appearing across tracked matters include third-party tracking pixels and scripts (e.g., Meta/Facebook Pixel and Facebook Conversions API), cookies (including example c_user cookies and first-party cookies), Google Analytics and other Google tracking tools, browser fingerprinting, IP and device identifiers, session replay and form-field capture, SDKs, URL/form field capture, appointment forms, patient portals, and a range of third-party vendors (Meta/Facebook, Google, LinkedIn, TikTok, Microsoft, Amazon).
Current Litigation Activity
Current Filing & Litigation Trends
Filing activity tracked in Illinois is currently limited to one filed case, but the matters focus on a consistent set of technologies and factual patterns: use of tracking pixels and analytics (including server-side conversion tools), cookie-based identifiers, form-field and URL capture, session replay, and cross-vendor data transfers. Courts in the tracked matter are parsing statutory theories under the Illinois Eavesdropping Act, VPPA-related allegations, and federal privacy statutes at the pleading stage.
Precedent Landscape: What Courts Have Decided
No decided precedent with a clear substantive direction is currently tracked.
Current Laws & Relevant Statutes
- Illinois Eavesdropping Act — 720 ILCS 5/14-1 et seq. · all-party consent · private right of action
- Illinois Biometric Information Privacy Act (BIPA) — 740 ILCS 14/1 et seq. · private right of action · statutory damages
Regulatory Enforcement
Agency Guidance
Global Privacy Control / Opt-Out Signals
Limited data
Learn more about Global Privacy Control → · How GPC posture is weighted in the risk guideline →
Changes Coming in the Next 24 Months
Coming Into Effect (Enacted)
Legislation to Watch (Pending)
Important Cases & Tracked Matters
Dawson v. The University of Phoenix, Inc.
What the court decided: The district court granted in part and denied in part Defendant University of Phoenix’s motion to dismiss. The court found Plaintiff plausibly pleaded that the University is a video tape service provider and that plaintiff is a consumer, and rejected the defendant’s arguments that the VPPA is unconstitutional and that statutory damages require proof of actual damages. The court dismissed VPPA claims to the extent premised on disclosures to Google, LinkedIn, TikTok, Microsoft, and Amazon, allowed other claims to proceed (Counts II and III) as to Facebook, Google, LinkedIn, TikTok, Microsoft, and Amazon, and dismissed certain allegations that the University directed third-parties to illegally intercept communications.
What the court did not decide: The court did not resolve the factual merits of whether the University actually disclosed protected information to third-parties, did not adjudicate liability or damages on the merits, and did not resolve at summary judgment or trial whether any particular vendor unlawfully intercepted communications. It likewise did not enter final judgment on any claim.
Technologies Appearing in Claims
- Facebook Tracking Pixel
- cookies (e.g., c_user cookie)
- browser fingerprinting
- IP addresses
- unique device identifiers
- machine unique identifiers
- third-party tracking pixels and scripts
- cookies
- third-party tracking technologies (Meta/Facebook, Google, LinkedIn, TikTok, Microsoft, Amazon)
- pixels
- session replay
- AdTech / third-party tracking tools
- website tracking tools
- scheduling tools / form submission
- checkout/ordering interfaces
- Meta Pixel
- TikTok Pixel
- Google Analytics
- fingerprinting
- session-replay tools
- customer-service chatbots
- fingerprinting scripts
- web chat software
- third-party tracking scripts
- Meta Pixel (Facebook Business Tools)
Historical Risk Guideline
| Date | Risk Guideline | Level | Confidence | Tracked Lawsuits |
|---|---|---|---|---|
| August 11, 2026 | 40 | Moderate | 20% | 0 |
| August 12, 2026 | 40 | Moderate | 42% | 0 |
| August 14, 2026 | 41 | Moderate | 63% | 1 |
| August 16, 2026 | 41 | Moderate | 78% | 1 |
| August 17, 2026 | 41 | Moderate | 84% | 1 |
| August 18, 2026 | 41 | Moderate | 84% | 1 |
| August 20, 2026 | 41 | Moderate | 84% | 1 |
| August 21, 2026 | 41 | Moderate | 84% | 1 |
| August 22, 2026 | 41 | Moderate | 84% | 1 |
| August 23, 2026 | 41 | Moderate | 87% | 1 |
| August 26, 2026 | 41 | Moderate | 90% | 1 |
| August 31, 2026 | 41 | Moderate | 90% | 1 |
What Businesses Should Review
Technical review suggestions for businesses operating in this landscape: perform an audit of all third-party scripts, pixels, SDKs and server-side trackers; map data flows from client pages (especially video players, appointment/patient portals, and form pages) to vendor endpoints; minimize collection and transmission of identifiable or sensitive fields, and disable or reconfigure tools that capture form fields or session replay on sensitive pages; implement or review consent-management and cookie controls; ensure logging, access controls, retention limits, encryption in transit and at rest, and up-to-date vendor DPAs that address data handling and deletion requests; and document decisions and settings so that technical configurations and contractual terms can be correlated if litigation or regulatory inquiries arise.
Data Quality
22 source(s), 8 primary; evidence is fresh.
Methodology & Limitations
Statistics on this page are generated by the Crandall Consulting litigation intelligence engine. Publicly available sources (court and government materials, recognized legal press, professional analysis, and industry reports) are discovered through automated web research, classified into a tiered source hierarchy, and reduced to structured facts with full source provenance. Risk guidelines and evidence-confidence scores are computed by a deterministic formula from those stored facts — never by an AI model directly (AI explains findings; it never assigns a score). Counts labeled "tracked" reflect matters identified in our source set and are not official court statistics.
The overall risk guideline is composed of six deterministically weighted components: statutory structure (25%), current litigation activity (25%), prior precedent (18%), GPC / universal opt-out posture (15%), regulatory enforcement (9%), and the forward-looking 24-month horizon (8%). When a state's GPC status is limited data, that component is excluded and the remaining weights are renormalized — limited data never reads as lower exposure. Current litigation activity is measured over recent windows (velocity), not lifetime volume, so a jurisdiction with high historical activity but declining current filings reflects that decline. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately. Full details are on the methodology page.
Sources
- Privacy Litigation Report: Takeaways From March 2026 Decisions
- When a Website Becomes a Wiretap
- When a Website Becomes a Wiretap
- L.C. v. Fertility Centers of Illinois, PLLC (N.D. Ill. Dec 8, 2025) - Memorandum Opinion and Order
- Lisota v. Heartland Dental, LLC et al, 1:2025cv07518 - Document 38 (N.D. Ill. 2026)
- U.S. Cybersecurity and Data Privacy Review and Outlook – 2025
- The ECPA: A Federal Private Right of Action for Privacy Policy Inaccuracies? (And What You Can Do to Cut Off Class Action Lawsuits)
- Multi-Court Split on Website Tracking Federal Wiretapping Claims Creates Compliance Confusion: 6 Strategies to Avoid Risk
- AHA urges court to dismiss tracking tech lawsuit against Endeavor Health
- Nourish Stuck With Wiretap Claim Over Use of Google Web Tracker
- AHA asks court to dismiss website-tracking lawsuit against Endeavor Health
- Doe et al v. Veradigm, Inc., No. 1:2025cv10147 - Document 60 (N.D. Ill. 2026)
- AHA asks court to dismiss website-tracking lawsuit against Endeavor Health
- Dawson v. The University of Phoenix, Inc., No. 1:2025cv03497 - Document 52 (N.D. Ill. 2026)
- Multi-Court Split on Website Tracking Federal Wiretapping Claims Creates Compliance Confusion: 6 Strategies to Avoid Risk
- So v. Hyatt Hotels Corp.
- When Your Own Website Becomes the “Wiretap”: Defending Illinois Businesses Against Pixel Tracking Class Actions Under the Federal Wiretap Act
- Dawson v. The University of Phoenix, Inc., No. 1:2025cv03497 - Document 52 (N.D. Ill. 2026)
- Tips for Protecting Your Business from Wiretap Lawsuits Targeting Companies with Consumer-Facing Websites
- California SB 690 Spares Email Pixel Wiretap Suits
- Juhyun So v. Hyatt Hotels Corporation
- How Website Wiretapping Lawsuits Work: Tracker to Demand Letter
All State Pages
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website