On July 20, 2026, another California federal court denied class certification in a putative privacy class action involving a company’s cookie-based advertising platform. Lewis v. Magnite, Inc., 2:25-cv-03448-MWC-SSC (C.D. Cal. July 20, 2026). The plaintiffs alleged that Magnite secretly installed tracking cookies—called “khaos IDs”—on users’ browsers to collect data for targeted advertising. The claims
Class Action
California Assembly Committee Advances CIPA Reform
On July 1, 2026, the California Assembly’s Committee on Privacy and Consumer Protection passed SB 690, a bill that would amend the California Invasion of Privacy Act (CIPA) to cut off the flood of litigation that has hit companies across industries for the last several years.
By way of background, dozens of states have…
CIPA Reform: Is a Whittled-Down Version of SB 690 on the Verge of Becoming Law? A Recent Committee Vote Gives Businesses a Glimmer of Hope.
In recent years, a handful of pro se plaintiffs and plaintiffs’ firms have sent tens of thousands of demand letters to businesses, threatening class action lawsuits under the California Invasion of Privacy Act (CIPA) unless those businesses pay settlements averaging $10,000 to $25,000.
The demands typically assert claims under CIPA arising from businesses’ alleged use…
Another Internet Tracking Class Action Failed at Certification—Here’s Why It Matters
Wiretapping class actions based on websites’ use of common tracking technologies continue to rise. And because many courts have allowed these cases to survive motions to dismiss, businesses often feel pressure to settle early—even when they have strong defenses.
Much of that pressure comes from the threat of a class wide judgment reaching eight or…
Website Tracking in Limbo: SCOTUS to Clarify Video Privacy Protection Act as California Privacy Law Remains a “Total Mess”
A sharp contrast in the speed of obtaining appellate review is emerging between two key privacy statutes. While the U.S. Supreme Court is set to resolve a circuit split over the Video Privacy Protection Act (VPPA), litigants grappling with the California Invasion of Privacy Act (CIPA)—a statute one federal judge recently described as a “total…
New Wiretap Cases Target Hospitals Using Meta Pixel
As we discussed in a recent webcast, there has been a surge in litigation focused on companies’ use of Meta Pixel, which is tracking code that enables the sharing of user online activity with Facebook. Recent litigation has alleged that use of Meta Pixel with online videos violates the Video Privacy Protection Act (VPPA). …
Webinar Recording – Assessing the Surge in Wiretap Litigation
In the past several months, plaintiff’s lawyers have filed dozens of class action lawsuits under state wiretap laws, some of which provide for statutory damages of $5000 per occurrence or more. The lawsuits focus on the use of chatbots, “session replay” software, and tracking code embedded in websites. Plaintiffs contend these tools enable the…
Third Circuit Becomes First Court of Appeals to Address Article III Standing in a Data Breach Case Post TransUnion
The Third Circuit recently became the first federal appellate court to address the question of whether the victim of a data breach has Article III standing to bring a claim for damages based on the fear of identity theft since the Supreme Court’s decision in TransUnion v. Ramirez in 2021. The Third Circuit, in Clemens …
Verdict in Favor of Plaintiffs in First BIPA Jury Trial – Potential Damages Still Unresolved
The jury returned a verdict in favor of the plaintiffs in the first trial for violations of the Illinois Biometric Privacy Act (“BIPA”), which was conducted in the District Court for the Northern District of Illinois. Rogers v. BNSF Ry. Co., No. 1:19-cv-03083. A jury found that BNSF Railway violated BIPA by maintaining an…
Third Circuit Ruling in Wiretap Case May Bring Greater Scrutiny to Privacy Policy Disclosures
In a class action with potentially significant impact on data sharing disclosures that companies routinely provide in online privacy policies, the Third Circuit recently ruled that NaviStone, a third party marketing service, was not a “direct party” under the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) and thus was potentially subject to liquidated damages…