David D. Piper
Partner
Business Vantage Point Blog
Go to Business Vantage Point BlogPixels, Wiretaps, and the Ways Your Website Can Steer You Into Murky Waters
May 27, 2026Significant ink has been spilled over the past few years over state privacy laws and enforcement actions. (View our pieces from last May and last October regarding the California Privacy Protection Agency’s enforcement actions over alleged violations of the state’s data privacy laws.) However, private litigants have been equally, if not more, aggressive in bringing a variety of claims against website operators. When considering the potential privacy risks attached to the design of its privacy policy and website, a company needs to consider the potential litigation risk that can attach to certain decisions, especially with respect to its deployment of third-party analytics. Claims over websites typically involve some combination of contract, equity (unjust enrichment), statutory and tort claims. Whatever the basis, all of these claims ordinarily start with a fundamental proposition: the failure to appropriately disclose and/or seek consent for the website’s use of third-party analytics from “big data” (Google Analytics, Meta’s Pixel, Microsoft’s LinkedIn cookies, etc.) that serve to track and profile users during their interactions with the website. Recent Privacy Litigation Against Website Operators Of the potential menu of claims available to plaintiffs, the one that often presents the rudest surprise is a claim that a company’s website is violating a wiretapping statute by recording and sharing users’ interactions with third-party analytics providers. These statutes typically provide for penalties that can scale beyond what a layperson might expect. For example, Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA) provides for civil damages to be “computed at the rate of $100 a day for each day of violation, or $1,000, whichever is higher,” along with punitive damages and attorney fees (18 Pa. C.S. § 5725). The California Invasion of Privacy Act (CIPA) allows a person who has been injured to seek $5,000 per violation (Cal. Penal Code § 637.2). In many jurisdictions, these kinds of wiretapping claims have been found sufficient to survive motions to dismiss and, in one notable instance, have resulted in a significant jury verdict. Earlier this month, Forbes Media preliminarily agreed to a $10 million settlement to resolve wiretapping claims under CIPA. However, plaintiffs have not had it all their way in the courts. For example, the Massachusetts Supreme Judicial Court tossed the plaintiffs’ wiretapping claims in Vita v. New England Baptist Hospital, 494 Mass. 824 (2024), a case in which the plaintiffs had alleged that their interactions with a hospital’s website were subject to tracking technologies. Applying the rule of lenity, the court held that it could not “conclude with any confidence that the Legislature intended ‘communication’ to extend so broadly as to criminalize the interception of web browsing and other such interactions.” (The rule of lenity is a legal principle of judicial restraint originating out of criminal law that requires a court to resolve ambiguous or unclear criminal statutes in the way most favorable to the defendant. The Massachusetts Supreme Judicial Court looked to the rule of lenity because the wiretapping statute also established criminal penalties — fines and/or imprisonment — for violations of the statute.) In the Third Circuit, although plaintiffs could take heart from a favorable ruling in Popa v. Harriet Carter Gifts, 52 F.4th 121 (2022), finding that WESCA applied to interactions with websites, subsequent decisions from the U.S. Court of Appeals for the Third Circuit have gone against plaintiffs on issues of personal jurisdiction and/or Article III standing. (See, e.g., Hasson v. Fullstory, 114 F4th 181 (3rd Cir. 2024) (upholding dismissal of cases for lack of personal jurisdiction); Cook v. GameStop, 148 F.4th 153 (3rd Cir. 2025) (plaintiff who interacted with a website but did not input any sensitive or personal information did not suffer a sufficiently concrete injury-in-fact); and Popa v. Harriet Carter Gifts, (3rd. Cir. 2026) (upholding dismissal of claims as lacking a cognizable Article III harm).) The California Senate attempted to address litigation over CIPA in 2025, but the bill (SB 690) died in the California Assembly. However, there is a forthcoming case to watch in Variety Media v. Superior Court of the State of California, where the defendant is challenging the application of CIPA to ban the collection of IP addresses, arguing that the California Consumer Privacy Act (CCPA) should govern rather than CIPA and the courts should apply the rule of lenity (following the lead of the Massachusetts Supreme Judicial Court) to bar the application of CIPA to website tracking. Next Steps In short, while there is the potential for relief on the horizon, this is hotly contested terrain with the potential for significant litigation spend (through a combination of counsel fees and/or settlements). The best way to steer clear of these risks is for a company to: (1) understand the third-party tracking technologies in use on its website(s) (including, but not limited to, what the tracking technologies “see” when users interact with the site through forms, search bars, etc.); (2) appropriately disclose the use of third-party tracking technologies (and to comply with regulations regarding opting out from same); and (3) to consider coming in for an annual privacy checkup with counsel to get a holistic look at its compliance with privacy laws and regulations.When the Harvest Brings in Privacy Violations — and a Record $1.35M Fine
October 23, 2025The California Privacy Protection Agency (CPPA) is back with a new settlement, this time with the largest rural lifestyle retailer in the United States, Tractor Supply Co. In the settlement, announced September 30, Tractor Supply agreed to a $1.35 million fine — the largest in the CPPA’s history, according to the agency. Tractor Supply also agreed to implement broad remedial privacy measures and to have a corporate officer or director certify compliance with the settlement for the next four years. The CPPA noted the decision is the first to address the significance of CCPA privacy notices and job applicants’ privacy rights. A Question of Temporal Scope In its press release announcing the settlement, the CPPA indicated that it opened its investigation into the company after receiving a consumer complaint. Back in August, the CPPA went to court to enforce an investigative subpoena against Tractor Supply seeking information on the company’s compliance dating all the way back to January 1, 2020. In its subpoena enforcement action, the CPPA alleged that Tractor Supply resisted the five-year lookback as outside the scope of the CPPA’s enforcement authority (since the CPPA’s regulations implementing the California Consumer Privacy Act (CCPA) were not finalized until March 2023). The settlement between the CPPA and Tractor Supply terminated that litigation and covers only the period from January 1, 2023, through July 1, 2024. Interestingly, the settlement requires Tractor Supply to acknowledge that the CPPA’s authority to investigate potential violations of the CCPA includes the period prior to January 1, 2023. Given the parties’ agreement to a temporal limitation on the conduct that favored Tractor Supply’s interpretation of the CPPA’s authority and the CPPA’s voluntary dismissal of its subpoena enforcement action, the CPPA appears to have been willing to compromise on this point to reach a resolution. The (Alleged) Violations The settlement alleges two broad categories of violations of Californians’ privacy rights by Tractor Supply: the handling of consumer requests to opt out of the sale/sharing of their personal data and the notifications to consumers (including job applicants) of their personal privacy rights. Opt-out requests have been a regulatory priority for the CPPA in 2025. Earlier this year, the CPPA settled with American Honda Motor Co. and Todd Snyder Inc. over (among other things) those companies’ handling of consumer opt-out rights. In settling with Tractor Supply over the handling of opt-out requests, the CPPA identified three types of violations: While Tractor Supply included a form on its website to allow a consumer to opt out of the sale of his or her personal information, the submission of that form did not interact with the third-party tracking technologies used by Tractor Supply for advertising and the form had no impact upon how the company shared consumers’ personal information. Until July 2024, Tractor Supply’s website did not process opt-out preference signals and the company did not explain in its privacy policy how opt-out preference signals would be processed (for example, if the signal applied to the device, browser, consumer account and/or offline sales). Tractor Supply did not include the necessary provisions required by the CCPA to protect consumer personal data in its contracts with third parties, service providers and contractors. (These provisions must identify the limited and specified purposes for which the personal information can be used, limit the recipient’s use of the personal information to the specified purposes, and require compliance with the CCPA, including that the third party must offer the same level of privacy protection as its principal.) With respect to Tractor Supply’s privacy policy, the CPPA noted that it failed to provide the detailed disclosures required and failed to apprise consumers of their rights under the CCPA. These disclosures must include the categories of personal information the business collected in the preceding 12 months, the categories of sources from which the information was collected, and the specific business or other purpose for which the information was collected. The policy must also affirmatively state whether the business sold, shared or disclosed personal information over the preceding 12 months. The policy must identify the categories of recipients to whom personal information was sold, shared or disclosed and the specific business purpose behind that sharing. A company is required to update its privacy policy on an annual basis but allegedly Tractor Supply published its original privacy policy in September 2018, updated it in November 2021, and then had not updated it again until after it learned of the CPPA’s investigation. Tractor Supply also allegedly failed to notify job applicants of their rights under the CCPA. The company had a pop-up disclosure in place for job applicants from California, but this disclosure did not provide job applicants with any detail regarding their CCPA rights or a description of how to exercise those rights. The Settlement Terms As aforementioned, the penalty levied on Tractor Supply is the largest obtained by the CPPA to date. In a departure from its past practices in the Honda and Todd Snyder settlements, the CPPA did not tie any of the $1.35 million fine to a specific number of violations or to its statutory authority, making it difficult to ascertain how the CPPA calculated this figure. Also as noted above, Tractor Supply also agreed to detailed undertakings to bring it into compliance with the CCPA. These include modifying its existing practices, conducting a detailed inventory of its own tracking technologies, modifying the design of its website to address opt-out requests, and taking certain steps to notify affected consumers. Tractor Supply also agreed that it will provide the CPPA’s Enforcement Division with a written certification of compliance with the settlement for the next four years, along with certain additional reporting. Lessons Learned The CPPA’s latest settlement confirms that it continues to engage in granular investigations that delve into the design and operation of a company’s website and the accompanying structure of its consumer privacy program to determine if the company is actually operating in a manner that complies with the CCPA. Privacy programs must therefore be implemented in a holistic fashion where the different pieces (such as opt-out forms) handshake with other aspects of the company’s web presence (such as its analytics) and also reach into the company’s contractual relationships and information-sharing practices. This puts further emphasis on the importance of building good privacy hygiene into a company’s products and operations from their inception, rather than attempting to bolt it on later in the life cycle. This enforcement action demonstrates that the handling of the rights of an individual consumer can lead to an investigation. There is a much larger community of privacy enthusiasts out there who will take heart from the story the CPPA tells in this settlement. The investigation that led to the settlement was based on a complaint from a single consumer. This story will certainly encourage amateur (and professional) students of privacy rights to look for additional problems for the CPPA to investigate. And while the CPPA found itself facing some resistance with respect to the temporal scope of its enforcement authority, it still harvested the most significant settlement in its history from the fertile fields of Tractor Supply’s own privacy program.The California Privacy Protection Agency Has Thoughts About Your Website — and Fines to Make You Pay Attention
May 12, 2025In its first major enforcement action, the California Privacy Protection Agency recently settled with American Honda Motor Co., a California corporation with its principal place of business in the state, for alleged violations of the California Consumer Privacy Act (CCPA) related to the company’s implementation of programs addressing rights granted consumers by the CCPA. Honda agreed to change its business practices and to pay a $632,500 fine. This settlement is the first time the agency has settled with a public company over alleged violations of consumer rights. The agency has previously settled with a number of data brokers for the failure to register with the agency. (See, i.e., “CPPA Settles with First Set of Data Brokers” (November 14, 2024); “CPPA's Enforcement Division Inks Settlement with Fifth Data Broker” (January 29, 2025).) Prior to the creation of the agency, the California Attorney General enforced the CCPA and settled with a number of public companies. The Settlement The California Privacy Protection Agency’s Enforcement Division alleged the following conduct by Honda violated California consumers’ privacy rights: Placing excessive burdens on the exercise of certain privacy rights. The configuration of an online privacy management tool. Obstructing consumers’ use of authorized agents to exercise privacy rights on their behalf. Entering into contracts that failed to appropriately protect consumer privacy rights. Under the CCPA, consumers in California have certain rights to direct how a business uses and/or retains their data, including the right to know, the right to delete, the right to opt out of the sale or sharing of their personal information, the right to correct, the right to limit the use of their information for certain purposes (such as targeted advertising), and the right to non-discrimination. Honda chose to use a single form to manage contact with consumers wishing to exercise their rights under the CCPA. The agency alleged that Honda’s use of a uniform process to address requests under the CCPA unduly burdened consumers. The agency argued that the right to opt out of the sale or sharing of personal information, and to limit the use or disclosure of a consumer’s personal information, should not be subject to the same verification requirements as, say, the right to delete. Honda faced a similar issue with its method for consumers to authorize an agent to make a request on their behalf. Honda’s program required the consumer to directly confirm they had authorized their agent to make any kind of request related to the exercise of their rights. The agency’s position was that Honda made it too difficult for consumers’ agents to opt out of the sale or sharing and to limit the use or disclosure of their clients’ personal information. Honda used a well-known compliance vendor for privacy solutions to provide a cookie management tool for its websites. This tool allowed consumers to manage the use of cookies (split into necessary, performance, functional and advertising cookies) on Honda’s websites. The tool required a consumer to opt out by toggling each category of cookies to “inactive” and then clicking a button to confirm the selection. However, a consumer could opt back in by clicking a single button (“Allow All”). The agency argued that by allowing the consumer to opt in through a single button press but requiring the consumer to select each individual category to opt out, the conduct violated the CCPA by making the process to opt out more burdensome than the option to opt in. The agency further opined in the settlement that a banner that provided a choice between accepting all cookies and a second screen allowing consumers to opt out would be asymmetric and that an equal or symmetrical choice would need to be between “Accept All” and “Decline All.” Because many websites require certain cookies from the user, such a choice would need to be phrased as something closer to “Decline All but Necessary Cookies” to make the appropriate disclosure. Finally, with respect to the contractual issues, Honda sold, shared and/or disclosed consumers’ personal information collected through its websites to advertising companies that used it for advertising and marketing purposes. Under the CCPA, Honda was required to have contracts with these companies that identify the limited and specified purposes for which consumers’ personal information could be used and that would require the advertising companies to afford consumers the same level of protection under the CCPA that Honda required. According to the settlement, Honda failed to make the necessary contractual arrangements with its partners. The agency is authorized to impose a fine of $2,500 for each violation (or $7,500 for each intentional violation) of the CCPA. The agency tied $382,500 of the $632,500 total fine to 153 consumers who were identified as having been impacted by the verification and/or authorization requirements. The agency did not attempt to explain how it calculated the remaining $250,000 as an appropriate penalty for the other conduct described in the settlement. Takeaways The CCPA regulates the conduct of any entity meeting at least one of three thresholds: (1) has more than $25 million gross annual revenue; (2) annually buys, sells or shares the personal information of at least 100,000 consumers or households; or (3) derives more than 50% of its annual revenues from selling or sharing consumers’ personal information. Honda met the first two thresholds of the CCPA’s test. With its principal place of business located in California (and a considerable volume of business in the state), Honda also provided the CCPA with a target comfortably inside its jurisdictional reach. The settlement demonstrates that the agency is taking a very granular approach in identifying what it believes to be violations of the CCPA. Most of the violations alleged to have taken place in this settlement stem from the configuration of privacy rights on Honda’s website. For example, a website designer may find it convenient to use a single form for the exercise of any privacy right, but the agency is taking the position that coding shortcuts violate California law and there need to be different forms for different rights. Cookie banners and configuration systems need to be scrutinized to determine if exercising a right requires more clicks than waiving it. One of Honda’s remedial undertakings is to consult a user experience (UX) designer to evaluate its methods for submitting privacy requests. Honda also agreed to certify its compliance, provide additional training to its employees, and to make changes to its contracting process. As the country’s first dedicated privacy organization, the agency is well aware of the focus and attention its enforcement actions garner. In fact, the mission statement for the agency promises to “vigorously enforce the law against businesses that violate consumers’ privacy rights.” As the agency continues to develop, we expect the number of enforcement actions to increase. The net effect of this settlement is that personnel with responsibilities for privacy compliance (whether in the form of internal specialists or outside counsel) need to not only examine whether they are providing a means through which California consumers can exercise their rights, but also must carefully evaluate how consumers utilize these methods.