Website tracking litigation continues to evolve quickly, and companies that use cookies, pixels, session replay technologies, chatbots, or other tracking tools should be paying close attention. What began as a focused wave of claims has become a nationwide litigation risk, with plaintiffs asserting claims under the California Invasion of Privacy Act, the federal Electronic Communications Privacy Act, and analogous state privacy laws.

Although defendants have secured meaningful victories, the legal landscape remains far from settled. Plaintiffs are also adjusting their theories in response to recent decisions, and the battleground is increasingly shifting from broad legal principles to the details of a company’s website practices: what disclosures were provided, when consent was obtained, whether consent mechanisms worked as represented, and how opt-ins and opt-outs were implemented.

Key Developments

Courts Continue to Examine the Limits of Privacy-Based Injury

The Third Circuit recently affirmed the dismissal of a putative class action challenging a defendant’s use of session replay code. Plaintiffs alleged that the technology intercepted and recorded website communications in violation of privacy laws. The court found that plaintiffs lacked standing and observed that it would be difficult to establish “a de facto invasion of privacy” where a website had made no express promise not to collect user data.

The decision also includes an important cautionary note. Citing its prior precedent, the Third Circuit distinguished between a website’s failure to obtain consent and allegations that a company expressly represented it would not collect certain information but did so anyway. That distinction may become increasingly important as plaintiffs focus on alleged gaps between corporate disclosures and actual data practices.

The Standing Debate Persists

A federal court in New York recently underscored the continuing divide among courts addressing Article III standing in website tracking cases. The plaintiff alleged that the defendant used third-party trackers to collect visitors’ IP addresses and other data. Reviewing decisions from multiple districts, the court noted that similar allegations have produced different outcomes and that no single determinative allegation reconciles the split. The court nevertheless concluded that several of the plaintiff’s allegations plausibly alleged a concrete injury sufficient to survive a motion to dismiss.

The Ninth Circuit also recently certified for interlocutory appeal the question whether the unauthorized disclosure of IP addresses and similar identifiers constitutes concrete injury sufficient to confer Article III standing. In doing so, the court acknowledged the significant split among district courts within the circuit. The forthcoming decision could provide much-needed guidance on standing requirements in website tracking litigation and may influence the viability of these privacy claims in federal court.

Even when a defendant prevails on standing in federal court, plaintiffs may pursue the same underlying claims in state court. Companies should therefore consider the jurisdiction, assigned judge, and specific allegations before deciding whether to pursue a standing defense.

The Rise of Pre-Consent Tracking Claims

Recent defense victories have not slowed filings. Instead, plaintiffs are refining their pleadings to account for—and test the limits of—recent court decisions.

One emerging theory is that companies must obtain consent before any data interception occurs.

A recent federal court decision illustrates the potential traction of this theory. The plaintiff alleged that third-party cookies on the defendant’s website began collecting and transmitting detailed user data the moment she landed on the website—before she could reject non-essential cookies. According to the complaint, the data collection occurred without her consent and despite her later decision to reject non-essential cookies. At the motion-to-dismiss stage, the court held that the plaintiff’s selection was allegedly ineffective because the website had already collected, tracked, and transmitted her data before she was able to direct it not to do so.

Relatedly, some complaints now allege that companies continue transmitting data to third parties even after users opt out of tracking or data sharing. In one case, a federal court found that allegations that a company created an expectation that user data would not be collected—but then collected it anyway—were sufficient to plead injury.

Newer complaints are also challenging the accuracy of privacy policies themselves, arguing that even where consent is obtained, it may not be enforceable if the underlying disclosures are incomplete or inaccurate.

What This Means for Companies

In this environment, reducing litigation risk requires more than technical compliance with federal and state privacy laws. Companies should consider practical steps to align website practices, disclosures, and consent mechanisms, including:

  • Review website and application technologies to understand what tracking tools are deployed, when they activate, what data they collect, and where that data is transmitted.
  • Evaluate cookie banners and other consent tools to ensure that notices are clear, accurate, and aligned with actual website functionality.
  • Test consent and opt-out mechanisms to confirm they operate as represented, including before and after a user makes a consent choice.