Washington Legal Foundation (WLF) has published Thompson Hine's comprehensive analysis of the California law governing the use of pen registers and trap and trace devices (the “California Pen/Trap”) and explains why it does not prohibit the use of website advertising cookies and pixels. The analysis offers practical and informative guidance on how to respond to and defend against a growing wave of legal claims based on the California Pen/Trap Law.
In recent years, California has seen a dramatic increase in the number of complaints and legal demands targeting organizations that embed advertising cookies and pixels within their websites. Particularly, they allege that the use of these cookies and pixels violates statutorily protected privacy rights by unlawfully tracking and recording a website end user’s behavior or communications.
These lawsuits have been attractive to plaintiffs because the privacy statutes they rely upon include monetary damages that an aggrieved party is able to recover, often on a “per violation” basis. They also require courts to apply archaic privacy frameworks, such as wiretapping and pen/trap statutes, to novel forms of technology. In addition, these statutes are often agnostic as to whether the data collection is from a website operating in a consumer context or from a business merely conveying general commercial information. The WLF paper outlines the relevant legal framework and provides five arguments for why advertising cookies and pixels are not pen register or trap and trace devices under California Pen/Trap Law.
“We believe that these lawsuits alleging that website advertising cookies and pixels are akin to pen registers and trap and trace devices are based on a misunderstanding of recent case law arising from the Southern District of California. There is no case law directly supporting this position, and there are strong legal arguments to challenge them,” said Thompson Hine partner and Privacy & Cybersecurity practice co-chair Steven Stransky, who co-authored the analysis. “This is an important issue that impacts any organization with a public-facing website.” Stransky is a former legal advisor to the President’s National Security Council and has a broad range of experience in privacy and cybersecurity.
Notwithstanding the lack of legal support for such legal claims, Stransky expects that organizations will continue to be targeted with these types of lawsuits and must spend time and capital resolving them.
“WLF was pleased to have the opportunity to publish this paper,” said Glenn Lammi, Vice President of Legal Studies at WLF. “Mr. Stransky and his co-authors make a compelling case for courts’ dismissal of these types of lawyer-driven claims that contort state law.”
