Analysis
Looking Ahead: Pixel Tracking Litigation under ECPA and CIPA can Provide Useful Guidelines for the Supreme Court in Salazar v. Paramount Global
October 5, 2026 |
Introduction
As the Supreme Court prepares to hear the upcoming privacy case in Salazar v. Paramount Global under the VPPA, broader trends in pixel tracking litigation reveal concerted efforts to counteract harmful online tracking and surveillance. Though Salazar is one example, plaintiffs have pursued these cases under a number of different legal theories, alongside federal and state laws to protect consumers from unauthorized third-party data disclosures.While the circuit split reveals conflicting interpretations of the definitions of consumers under the VPPA, plaintiffs’ documented successes in third-party pixel tracking litigation provide useful guidelines for the VPPA’s application to modern technologies in our digital age. This analysis will discuss the major issues raised in pixel tracking litigation in other courts to further contextualize the Salazar decision. Read EPIC’s related analysis of the Salazar v. Paramount case here.
What are pixel trackers?
Pixels are small pieces of code that website and mobile application operators embed into their websites to track users’ interactions and behaviors with their platforms. These third-party tracking technologies collect information about users online, including their interactions with a site, buttons clicked, mouse movements, or even whether a user presses “play” on a video. Companies often use pixel trackers in conjunction with embedded cookies to track users online. Pixel trackers commonly also collect users’ IP addresses as proxies for their browsing locations, as well as users’ interactions with certain advertisements displayed on a website. Pixel tracking technologies transmit this data to other companies, including data brokers, advertisers, and major technology companies like Meta or Google, which develop and deploy their own pixel trackers. Companies like Meta, Google, and TikTok have been at the epicenter of a slew of pixel tracking litigation lawsuits because they have been known to surreptitiously use their pixel trackers to indirectly collect data about internet users and build invasive consumer profiles for targeted advertising purposes. The proliferation of pixel tracking presents harms in the widespread collection of individuals’ data and risks exposing sensitive information pertaining to an individual’s health, religion, policial views, race, gender, or sexual orientation.
Violations of ECPA, CIPA, and invasions of other privacy statutes provide historical analogues to common law privacy harms traditionally recognized by American courts
Plaintiffs have increasingly brought wiretapping, pen register, and trap and trace claims under the Electronic Communications Privacy Act (ECPA), and the state-equivalent California Invasion of Privacy Act (CIPA) to sue website and mobile app operators that deploy third-party tracking technologies without users’ consent. Plaintiff successes in these pixel tracking lawsuits stem in large part from how well they demonstrate Article III standing to sue, which requires plaintiffs to show that they have suffered a concrete, actual, and particularized harm that is traditionally recognized in American courts. As enumerated by the Supreme Court in its 2021 TransUnion LLC v. Ramirez decision, it is not enough for plaintiffs to claim a mere legal injury from a company’s general violation of a federal statute. Plaintiffs must go a step further in demonstrating how that company’s conduct (which includes allowing third-party pixels to surreptitiously collect user data on their websites) led to a plaintiff’s particularized harm. Across various circuits, plaintiffs have frequently analogized their standing claims to common law privacy torts such as 1) invasion of privacy, 2) intrusion upon seclusion, and 3) public disclosure of private facts.
Invasion of privacy claims under CIPA and ECPA are well-articulated in the Ninth Circuit
California plaintiffs have covered significant ground in the Ninth Circuit, using CIPA and common law privacy protections to successfully push back against harmful pixel tracking practices while vindicating their consumer privacy rights. The Ninth Circuit provides a robust and authoritative framework that limits third-party data tracking of consumers’ browsing patterns. Numerous district courts have reinforced that concrete invasions of privacy injuries result from companies’ nonconsensual collection and distribution of individuals’ sensitive information for targeted advertising purposes.
The Northern District of California has determined that individuals have a reasonable expectation of privacy in their sensitive browsing activities and habits. In the Northern District of California, plaintiffs have successfully argued that they have a legally-protected privacy interest in controlling the dissemination of their sensitive or personal information under CIPA. Several of these cases show that data sensitivity can range anywhere from an individual’s personal health status to data patterns that function as proxies for an individual’s race or gender. InIn re Google RTB Consumer Priv. Litig., 606 F. Supp. 3d 935, 947 (N.D. Cal. 2022), the Court explained that personal data can include the collection and dissemination of website users’ IP addresses, geolocation data, web-browsing information, search terms, or the sensitive websites that a user visits relating to an individual’s religion, sexual orientation, and health. In Shah v. MyFitnessPal, Inc., 824 F. Supp. 3d 906, 914, the Court held that the plaintiff had standing to sue MyFitnessPal, a fitness tracking app under CIPA on grounds that the company’s app unlawfully collected and disclosed his personal nutrition and health information to third-party advertising and analytics companies from the app’s embedded tracking technologies. In Katz-Lacabe v. Oracle Am., Inc., 668 F. Supp. 3d 928, 936 (N.D. Cal. 2023), the plaintiffs plausibly alleged that Oracle unlawfully collected and disclosed their sensitive personal information under CIPA, which included their race, location, political affiliation, and medical information via third-party tracking pixels. And in Krzyzek v. OpenX Techs., Inc., 817 F. Supp. 3d 857, 862–63 (N.D. Cal. 2026), the Court held that the plaintiffs sufficiently alleged OpenX Technologies’ capture of their sensitive IP addresses, hashed email addresses, and operating system information using its OpenX pixel across many third-party websites that the plaintiffs browsed constituted a highly offensive intrusion of privacy sufficient to establish standing. These decisions underscore that CIPA applies to the unlawful interception of users’ electronic communications with a website or application so long as a plaintiff sufficiently alleges that the disclosure contained sensitive information.
An additional common thread across these decisions is the lack of consent from users when third-party pixels intercept their browsing data. In California, lack of consent is a critical element to plaintiffs’ invasion of privacy claims under CIPA. Without a website or app user’s express consent or knowledge of how they may be tracked by third-party pixels from outside companies the sale or disclosure of their personal data likely violates their reasonable expectation of privacy. In re Meta Android Priv. Litig., No. 25-cv-04674-RFL, 2026 U.S. Dist. LEXIS 104066, at *1 (N.D. Cal. May 11, 2026) further contextualizes the scope of consent relative to pixel tracking on social media platforms, with the Northern District of California explaining that an app user would not reasonably expect their browsing data to be linked to their personal social media accounts through “backdoor” arrangements with third-party companies.
In that case, Meta used its own Meta Pixel to link Android users’ browsing activity to their Facebook and Instagram app profiles. This tracking allowed Meta to construct detailed targeted advertising profiles for each user. The plaintiffs sufficiently alleged invasion of privacy and intrusion upon seclusion claims on grounds that a reasonable user would not believe that their Android browsing activity is linked to their personal Facebook or Instagram account through Meta Pixel tracking software. As made clear in other district court cases, a company’s use of pixel tracking to pinpoint users’ digital identities from their social media platforms is yet another example of invasive data collection that compromises an individual’s reasonable expectation of privacy. In broader context, this case, like many others in the Northern District of California, underscores that website and mobile application users have the right to control the dissemination of their personal information, including preventing social media giants from accessing their unrelated browsing activity. California courts have reinforced that if companies fail to show that plaintiffs consented to third-party data disclosures of sensitive data, they are unlikely to prevail in dismissing a plaintiff’s CIPA claims.
The success of intrusion upon seclusion claims under federal privacy laws varies by circuit
There’s a growing body of Article III caselaw that analogizes privacy injuries suffered from third-party pixel tracking to the common law tort of intrusion upon seclusion. Invasion of privacy is in part predicated on a highly offensive intrusion upon one’s private affairs, and in these cases the personally identifiable information of individuals. While some circuits have decided that a website that embeds third-party tracking software to collect user data constitutes a highly offensive intrusion, other circuits have held that these data practices are routine, commercial behaviors.
In an early DOGE data demand case, the Fourth Circuit established a comprehensive bridge between unauthorized data collection by third parties and the resulting privacy invasions that intrude on one’s private affairs. A slew of lawsuits emerged in response to DOGE’s improper data disclosures under the Trump II administration, including when the Social Security Administration granted DOGE access to the medical records and sensitive financial information of millions of people. As noted by the Fourth Circuit in AFSCME v. SSA, 2025 U.S. App. LEXIS 10420, intrusion upon seclusion occurs when there is an “intentional intrusion upon the solitude or seclusion of another or his private affairs or concerns that would be highly offensive to a reasonable person.” This decision underscores that highly offensive intrusions of privacy can stem from unauthorized data disclosures.
Plaintiffs in the Second and Ninth Circuits have also successfully established standing by explaining that third-party pixel trackers are highly offensive intrusions on their reasonable expectations of privacy. In both circuits, courts agreed with plaintiffs when they demonstrated their personal data was aggregated into non-anonymous, individualized user profiles by way of pixel tracking. InD’Antonio v. Cable News Network, Inc., No. 24 CV 3132 (VM), 2026 U.S. Dist. LEXIS 78088, at *1 (S.D.N.Y. Apr. 9, 2026)for example, the court denied CNN’s motion to dismiss in a CIPA class action pertaining to CNN‘s installation of third-party pixel trackers on CNN.com. There, the plaintiffs established standing by demonstrating that the pixel tracking software embedded on CNN’s website aggregated their personal browsing data into comprehensive user profiles. These cases underscore that the more particularized a third-party’s data tracking becomes, the more likely these practices are to disrupt one’s reasonable expectation of privacy in a highly offensive manner.
Cases in other circuits have had the opposite result. In the Third Circuit, plaintiffs were unsuccessful in establishing Article III standing when they failed to specifically identify how third-party tracking technologies surreptitiously collected their personal information, beyond routine commercial behaviors like mouse movements, clicks, scrolls, keystrokes, and text entries on a given website. In the First Circuit, a Massachusetts District Court granted the defendant’s motion to dismiss in a spy pixel privacy class action for lack of standing. In Campos v. TJX Companies, Inc., No. 24-cv-11067, the court held that the plaintiff’s claims of her privacy interests being intruded upon did not constitute a cognizable injury in fact. There, the plaintiff alleged that TJX, a large retail store, embedded pixel tracking software in its promotional emails and collected her personal data from her interactions with the emails and her email server as well as location information without her consent. However, the Court rejected the argument that this constituted a highly offensive intrusion of her privacy, holding that the emails were not considered personal or private enough information to be protected by this tort. Because the plaintiff consented to receiving the promotions, TJX’s collection of her “reading habits” did not constitute private, personal information that this common law tort was intended to protect.
In In re BPS Direct, LLC; Cabela’s, LLC Wiretapping Litigation, No. 23-3235 (3d Cir. 2026), the Third Circuit held that the plaintiff did not plausibly allege that there was “an intrusion of her solitude or seclusion as to her person or private affairs” through Bass Pro Shops and Cabela’s use of comparable session replay technology to capture users’ website interactions. While this case held that the plaintiffs whose credit card information was captured via session-replay code adequately alleged an Article III injury-in-fact, the Third Circuit reached an appellate-level split between the purchasing-plaintiffs who transmitted their payment information on Defendants’ websites and the non-purchasing plaintiffs who only browsed the website. Without a showing that the websites collected and disseminated non-purchasers’ private information using pixel trackers, the non-purchasing plaintiffs’ clicks, scrolls, and searches for outdoor products were not plausibly private because those plaintiffs entered no personal or sensitive information when accessing the defendant’s website. In Cook v. GameStop, Inc., 148 F.4th 153, the Third Circuit similarly held that the mere recording of ordinary website activity via session replay code, without capturing personal or sensitive information does not constitute a concrete injury for Article III standing, and that the plaintiff’s alleged harm from GameStop’s installation of session replay code on its retail website that captured users’ mouse movements, clicks, and other interactions did not amount to an intrusion upon Cook’s privacy interests.
Federal wiretapping, pen register, trap and trace, and eavesdropping claims under ECPA, CIPA, and state wiretapping/eavesdropping equivalents have proliferated across various circuits
Digital wiretapping and eavesdropping cases are becoming increasingly common across jurisdictions.
In addition to alleging common law invasions of privacy, plaintiffs are increasingly leveraging their state’s wiretapping laws and communications privacy acts comparable to CIPA to litigate against pixel tracking technologies that unlawfully intercept and record their electronic communications across the internet. In the Ninth Circuit, district courts have repeatedly held that other provisions of CIPA are not limited to traditional telecommunications and can be applied to modern technologies like pixel trackers to ensure “greater protection to privacy interests.” Matera v. Google Inc., No. 15-cv-04062, 2016 U.S. Dist. LEXIS 107918, 2016 WL 8200619, at *19 (N.D. Cal. Aug. 12, 2016). In Javier v. Assur. IQ, LLC, No. 2 1-16351, 2022 U.S. App. LEXIS 14951, the Ninth Circuit held that section 631(a) of CIPA applies to internet communications like third-party pixel trackers. In Thomas v. Papa John’s International Inc., the plaintiff alleged that Papa John’s unlawfully eavesdropped and wiretapped by capturing customers’ website interactions using tracking software and sent the data to a third-party.
Since the Ninth Circuit’s ruling in Javier v. Assurance IQ, LLC et al. in 2022, the Second, Seventh, and Ninth Circuits have seen a proliferation of digital wiretapping cases, with federal cases prominent in California, Illinois, and New York and across various industries including healthcare, technology, and real estate. Florida and California have been classified as high litigation areas, whereas New York and Illinois have been grouped into moderate litigation areas. In Pattison v. Teladoc Health, Inc., 2025 U.S. Dist. LEXIS 121044, the Southern District of New York allowed plaintiffs’ ECPA claims to proceed against Teladoc Health on grounds that the plaintiffs sufficiently enumerated the defendant’s unauthorized interception and dissemination of their personal health information. There, plaintiffs alleged that Teladoc Health, a global virtual care and telemedicine company, intentionally used tracking pixels and APIs to disclose users’ personal health information to Meta to deploy targeted advertisements.
In the Seventh Circuit, Stein v. Edward-Elmhurst Health is now on appeal from the Northern District of Illinois. Class action patients have alleged that the defendant’s embedded pixel tracking software in the MyChart portal automatically transmitted their personal information to Meta in violation of HIPAA. Additionally, plaintiffs allege an ECPA violation on due to defendant’s alleged intentional interception of their electronic communications with MyChart that were then disseminated to Meta. In Podraza v. Nourish, Inc., the plaintiffs’ ECPA and CIPA wiretapping claims survived on grounds that they did not consent to the disclosure of their private health information. There, the court held that the defendant unlawfully intercepted their communications for the purpose of disclosing it to Google in violation of HIPAA.
In Florida, plaintiffs are also using their state’s wiretapping law and the Florida Security of Communications Act to assert that tracking pixels and session replay software intercepted their electronic communications on websites without their consent. There has been a surge of class actions, demand letters, and small-claims filings in Florida courts that have survived the motion to dismiss stage. In W.W. v. Orlando Health, Inc., No. 6:24-cv-1068-JSS-RMN, 2025 WL 722892 (M.D. Fla. 2025), the court denied the defendant’s motion to dismiss under the Florida Security of Communications Act relative to the defendant’s transmission of user interactions using pixel tracking software. In Magenheim and Neil v. Nike Inc inthe Southern District of Florida, plaintiffs alleged that Nike’s website surreptitiously used pixel tracking software to capture users’ personal data and that it in turn shared this data with third parties without their consent. Pennsylvania and Illinois district courts have also seen increased filings against third-party pixel trackers.
Courts have regularly found that pen register and trap and trace laws apply to third-party pixel trackers
Numerous district courts across circuits have interpreted pen register and trap and trace provisions of their states’ invasion of privacy statutes, as well as ECPA, to argue that third-party pixel tracking technologies that collect and disseminate IP addresses constitute unlawful pen registers and or trap and trace devices. In Florida, companies have started to receive demand letters threatening class actions under Florida wiretapping law based on the “trap and trace” theory, which has become more prominent under Florida’s Security of Communications Act.
The Ninth Circuit has frequently adopted an expansive view of CIPA by broadly applying it to digital and tracking technologies. The California Supreme Court’s decision in Flanagan v. Flanagan, 41 P.3d 575, 581 (Cal. 2002), enables this broad interpretation. In Vishal Shah v. Fandom, Inc., the Court explained that pen registers are not limited to traditional phone registers and are inclusive of third-party tracking technologies that record IP addresses. In that case, the court determined that Fandom’s use of third-party tracking software (“Trackers”) on its website were unauthorized pen registers under §638.51(a) of CIPA. Numerous other Ninth Circuit district courts have recognized “website-based trackers” as pen registers, holding that surreptitiously embedded tracking software that identifies consumers, gathers data, and correlates that data through unique fingerprinting can constitute a pen register. Courts have added that the California legislature’s chosen definition of a pen register inclusive as to the form of the collection tool.
Conclusion
The proliferation of pixel tracking litigation across various circuits reveals a growing trend among consumers who seek to control the dissemination of their sensitive information to third-party companies. In an effort to counteract ubiquitous online tracking and surveillance, plaintiffs have analogized third-party pixel tracking as violations to their fundamental right to privacy. California district courts have provided foundational and comprehensive reasoning in support of plaintiffs who have articulated how nonconsensual data collection and disclosure intrudes upon their reasonable expectations of privacy under CIPA and ECPA. Plaintiffs in other circuits and states have begun following suit in leveraging their state invasion of privacy laws and federal statutes to challenge companies’ unlawful interception of their electronic communications with websites and mobile applications. And in light of the upcoming Salazar decision, these decisions further contextualize the common trends and legal theories that plaintiffs have articulated when asserting that third-party pixel tracking constitutes a concrete harm to their privacy.
Support Our Work
EPIC's work is funded by the support of individuals like you, who allow us to continue to protect privacy, open government, and democratic values in the information age.
Donate