
Pixels, Wiretaps, and the Ways Your Website Can Steer You Into Murky Waters
Peter Bogdasarian and David D. Piper
share this page
Significant ink has been spilled over the past few years over state privacy laws and enforcement actions. (View our pieces from last May and last October regarding the California Privacy Protection Agency’s enforcement actions over alleged violations of the state’s data privacy laws.) However, private litigants have been equally, if not more, aggressive in bringing a variety of claims against website operators. When considering the potential privacy risks attached to the design of its privacy policy and website, a company needs to consider the potential litigation risk that can attach to certain decisions, especially with respect to its deployment of third-party analytics.
Claims over websites typically involve some combination of contract, equity (unjust enrichment), statutory and tort claims. Whatever the basis, all of these claims ordinarily start with a fundamental proposition: the failure to appropriately disclose and/or seek consent for the website’s use of third-party analytics from “big data” (Google Analytics, Meta’s Pixel, Microsoft’s LinkedIn cookies, etc.) that serve to track and profile users during their interactions with the website.
Recent Privacy Litigation Against Website Operators
Of the potential menu of claims available to plaintiffs, the one that often presents the rudest surprise is a claim that a company’s website is violating a wiretapping statute by recording and sharing users’ interactions with third-party analytics providers. These statutes typically provide for penalties that can scale beyond what a layperson might expect. For example, Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA) provides for civil damages to be “computed at the rate of $100 a day for each day of violation, or $1,000, whichever is higher,” along with punitive damages and attorney fees (18 Pa. C.S. § 5725). The California Invasion of Privacy Act (CIPA) allows a person who has been injured to seek $5,000 per violation (Cal. Penal Code § 637.2). In many jurisdictions, these kinds of wiretapping claims have been found sufficient to survive motions to dismiss and, in one notable instance, have resulted in a significant jury verdict. Earlier this month, Forbes Media preliminarily agreed to a $10 million settlement to resolve wiretapping claims under CIPA.
However, plaintiffs have not had it all their way in the courts. For example, the Massachusetts Supreme Judicial Court tossed the plaintiffs’ wiretapping claims in Vita v. New England Baptist Hospital, 494 Mass. 824 (2024), a case in which the plaintiffs had alleged that their interactions with a hospital’s website were subject to tracking technologies. Applying the rule of lenity, the court held that it could not “conclude with any confidence that the Legislature intended ‘communication’ to extend so broadly as to criminalize the interception of web browsing and other such interactions.” (The rule of lenity is a legal principle of judicial restraint originating out of criminal law that requires a court to resolve ambiguous or unclear criminal statutes in the way most favorable to the defendant. The Massachusetts Supreme Judicial Court looked to the rule of lenity because the wiretapping statute also established criminal penalties — fines and/or imprisonment — for violations of the statute.)
In the Third Circuit, although plaintiffs could take heart from a favorable ruling in Popa v. Harriet Carter Gifts, 52 F.4th 121 (2022), finding that WESCA applied to interactions with websites, subsequent decisions from the U.S. Court of Appeals for the Third Circuit have gone against plaintiffs on issues of personal jurisdiction and/or Article III standing. (See, e.g., Hasson v. Fullstory, 114 F4th 181 (3rd Cir. 2024) (upholding dismissal of cases for lack of personal jurisdiction); Cook v. GameStop, 148 F.4th 153 (3rd Cir. 2025) (plaintiff who interacted with a website but did not input any sensitive or personal information did not suffer a sufficiently concrete injury-in-fact); and Popa v. Harriet Carter Gifts, (3rd. Cir. 2026) (upholding dismissal of claims as lacking a cognizable Article III harm).)
The California Senate attempted to address litigation over CIPA in 2025, but the bill (SB 690) died in the California Assembly. However, there is a forthcoming case to watch in Variety Media v. Superior Court of the State of California, where the defendant is challenging the application of CIPA to ban the collection of IP addresses, arguing that the California Consumer Privacy Act (CCPA) should govern rather than CIPA and the courts should apply the rule of lenity (following the lead of the Massachusetts Supreme Judicial Court) to bar the application of CIPA to website tracking.
Next Steps
In short, while there is the potential for relief on the horizon, this is hotly contested terrain with the potential for significant litigation spend (through a combination of counsel fees and/or settlements). The best way to steer clear of these risks is for a company to: (1) understand the third-party tracking technologies in use on its website(s) (including, but not limited to, what the tracking technologies “see” when users interact with the site through forms, search bars, etc.); (2) appropriately disclose the use of third-party tracking technologies (and to comply with regulations regarding opting out from same); and (3) to consider coming in for an annual privacy checkup with counsel to get a holistic look at its compliance with privacy laws and regulations.