There has been a significant increase in claims arguing that website advertising cookies, pixels and similar technologies violate the California Invasion of Privacy Act’s restrictions on pen registers and trap-and-trace devices. As the U.S. District Court for the Central District of California noted in Byars v. Hot Topic Inc. (656 F. Supp. 3d 1051, 105/1-/20 (C.D. Cal. 2023)), it is common for CIPA litigators to simply “copy and paste” their complaints “over and over again” to target new companies as potential violators. These CIPA lawsuits can disproportionately affect small businesses and can force them to choose between incurring costs to defend their business practices in court or through arbitration or settling the matter quickly to resolve the issue and make it go away.
Unfortunately for businesses, a July ruling by the Central District of California will likely increase the volume of CIPA claims for the foreseeable future. In Dino Moody v. C2 Educational Systems, Judge R. Gary Klausner denied the defendant’s motion to dismiss the CIPA claim it was facing. He concluded that the plaintiff’s allegations suggesting that the defendant’s use of the TikTok marketing pixel on its corporate website might be comparable to unlawfully installing a pen register or trap-and-trace device, thus potentially violating CIPA, were plausible.
It is the first time a federal court has adopted such a broad interpretation of CIPA, and it may set a precedent for state courts to rule in the same manner. The plaintiff’s counsel in C2 Educational Systems told Law.com that these CIPA claims “have become quite valuable” given Judge Klausner’s recent holding, which could be an indication that privacy advocates will increase their search for CIPA violations and target businesses with additional lawsuits.
There are several measures businesses can undertake to avoid these CIPA claims, including adopting an opt-in approach to using third-party website advertising technologies.
Background: Dino Moody v. C2 Educational Systems
C2 Educational Systems provides online tutoring programs and, like many other businesses, operates a public-facing website that deploys advertising cookies and pixels.
On May 22, plaintiff Dino Moody filed a class action against C2 Education, alleging that the C2 website unlawfully processed data related to him and other users without their express or implied consent.
Specifically, the complaint alleged the C2 website deployed the TikTok pixel to capture form data entered by users on the C2 website (e.g., name, date of birth, addresses) and undertake a fingerprinting process to uncover the identities of individuals who accessed the C2 website. It argued that these activities violated Section 638.51(a) of the California Penal Code, which generally prohibits a person from installing or using a pen register or a trap-and-trace device without proper consent or a court order.
C2 Education filed a motion to dismiss and put forth several arguments describing why the plaintiffs were not entitled to relief. These arguments mirror those raised by many other defendants in CIPA actions filed in California state court.
For example, the motion to dismiss argued that, based on the text and structure of CIPA, the law’s provisions on pen register and trap-and-trace devices are intended to regulate the interception of specific, targeted telephonic communications rather than general website tracking pixels. It also cites a federal court decision that concluded pen registers and trap-and-trace devices are limited to physical devices attached to telephone lines, and therefore they exclude website tracking software.
Separately, the motion to dismiss argued that the plaintiffs were not entitled to relief because of CIPA’s user consent exception. In particular, C2 Education argued that it – and not the plaintiffs – is the user of the C2 website, and C2 Education consented to this data processing by installing the TikTok pixel in the first instance.
In his ruling, Judge Klausner indicated on multiple occasions that C2 Education’s arguments were “persuasive” but did not satisfy the level of certainty needed to allow the case to be dismissed at its current stage of litigation.
Perhaps most importantly, Judge Klausner rejected C2 Education’s argument that CIPA does not provide a private right of action for violations arising from Section 638.51(a) because it is a criminal statute that imposes only criminal penalties. According to Judge Klausner, the complaint demonstrates that C2 Education collected the plaintiffs’ information “through the use of the TikTok Software ... constituting an invasion of privacy,” which “are actionable injuries” under the law.
Risk Mitigation Measures
Given Judge Klausner’s holding and the contradictory CIPA opinions emerging from California state courts, organizations should adopt measures to better safeguard themselves against CIPA lawsuits.
For instance, organizations should ensure they appropriately document how their websites collect, process and retain data, including through advertising pixels and cookies. They should also establish protocols for modifying website configurations and specifically delegate authority and accountability to an official to approve such changes.
Companies should ensure their privacy statements and terms of service properly address their data processing activities, including ensuring compliance with the broad range of privacy notice requirements outlined in the myriad consumer data protection laws in the United States.
An organization’s website terms of service should clearly specify governing law and dispute resolution processes applicable to its online services, including provisions prohibiting class actions. Organizations should ensure their notices and terms are legally binding on end users, for example, by using click-wrap agreements.
Opt-In Consent for Targeted Advertising
One of the more aggressive tactics that an organization can undertake to protect itself from CIPA claims is to require all end users to affirmatively agree to the use of advertising cookies and pixels, even though this all-encompassing opt-in approach is contradictory to the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act of 2020 (CPRA).
For example, under the CCPA/CPRA, Californians have the right to opt out of a covered business using advertising cookies and pixels. The law gives more opt-out rights to Californians if a business uses advertising cookies and pixels to collect consumers’ sensitive personal data, such as their precise geolocations, in certain circumstances.
However, under the CCPA/CPRA, a covered business cannot use such advertising cookies and pixels about Californians under age 16 or under age 13 without prior opt-in authorization from them or their parents or guardians, respectively.
Further, the CCPA/CPRA does not apply to all businesses located in, or doing business in, California. Rather, it only applies to a subset of companies that collect large volumes of personal information or generate significant revenue each year. In creating these applicability thresholds, the California legislature reflected the interests of its citizens not to impose complex mandates on small businesses’ online cookie or pixel management practices.
Notwithstanding the CCPA/CPRA’s general opt-out framework for deploying advertising cookies and pixels designed to collect nonsensitive data from individuals over age 16, all organizations doing business in California may consider adopting an all-encompassing opt-in consent approach to the deployment of their advertising cookies and pixels to safeguard themselves from CIPA-related litigation.
Such an opt-in consent process will better enable organizations to invoke the user-consent exception within CIPA and defeat arguments that the use of advertising cookies and pixels causes an invasion of privacy or other harm to a website end user.
Conclusion
By thoroughly examining the plain text, structure and legislative history of CIPA and other California privacy laws, there are strong arguments that website advertising cookies and pixels should not be considered pen registers and trap-and-trace devices under the law.
If a contrary interpretation of CIPA were to be adopted, then many organizations could be exposed to criminal liability for not obtaining proper cookie consent from each end user who voluntarily accesses their websites or online applications.
However, until this issue is fully resolved by the courts or the California legislature, organizations should consider implementing risk mitigation measures to deter CIPA lawsuits in the first instance, which may include adopting an all-encompassing opt-in approach for deploying advertising cookies and pixels on their websites.
This article may be reproduced, in whole or in part, with the prior permission of Thompson Hine LLP and acknowledgement of its source and copyright. This publication is intended to inform clients about legal matters of current interest. It is not intended as legal advice. Readers should not act upon the information contained in it without professional counsel.
This document may be considered attorney advertising in some jurisdictions.
© 2024 THOMPSON HINE LLP. ALL RIGHTS RESERVED.
