Key Point: In a significant ruling for the AI industry, the Ninth Circuit vacated a preliminary injunction against Perplexity AI, holding that Amazon was unlikely to succeed on its Computer Fraud and Abuse Act (CFAA) and California Comprehensive Data Access and Fraud Act (CDAFA) claims. The court concluded that Perplexity’s AI Assistant is a “tool, not a person” for statutory purposes, and that it is the user who “accesses” websites visited using the AI-powered Comet browser. The decision provides the first major appellate guidance on how the CFAA applies to agentic AI systems, though the court was careful to cabin its holding to the specific facts presented.

Key point: Amendments to California Senate Bill (SB) 690 would foreclose private rights of action for pen register and trap and trace law and apply to cases brought within previous two years.

The Privacy and Consumer Protection Committee of the California State Assembly heard testimony on support and opposition to SB 690 late Wednesday, July 1.

Key point: Three takeaways from May decisions: (1) cookie banners cut both ways for plaintiffs and defendants; (2) generic wiretapping “contents” allegations lose while transaction-specific ones survive; and (3) courts are splitting on whether a profit motive satisfies the crime-tort exception.

Welcome to our monthly update on how courts across the U.S. have handled privacy litigation involving website tools such as cookies, pixels, session replay, and similar technologies. In this post, we cover decisions from May 2026.

Key point: Two courts in 2026 have allowed CCPA claims to proceed based on adtech use without addressing whether adtech discloses “personal information” under the CCPA

According to plaintiffs’ interpretation of a May 2026 decision from the Northern District of California, if your company uses Google Analytics, Meta Pixel, or other third-party tracking technology on its website, you may be exposed to not only wiretapping or trap-and-trace claims under the California Invasion of Privacy Act (CIPA) or federal law, but also claims under the California Consumer Privacy Act (CCPA) even if you never experience a data breach.

Key point: (1) Plaintiffs who expand their class definition beyond the complaint risk losing both certification and their class representative on limitations grounds; (2) Banners that require users to interact before accessing website may be sufficient to establish consent; (3) What makes tracking “highly offensive” is becoming clearer; (4) the “in transit” requirement continues to divide courts; (5) Courts demand more than labels to survive a standing challenge.

Welcome to Part Two of our series that examines the ECPA as a private right of action for privacy policy inaccuracies.  In Part One of this series, we examined how a wave of state-law wiretapping litigation — predominantly under California’s Invasion of Privacy Act (CIPA) — set the stage for a new and more expansive federal class action litigation threat.  After years of plaintiffs targeting websites that deploy tracking technologies such as pixels and cookies, a series of defense wins in 2025 (and pending legislative action) encouraged plaintiffs’ firms to seek alternative theories. They found one in the Electronic Communications Privacy Act (ECPA). 

Key Points: An August 2025 federal court ruling has opened the door for plaintiffs to use alleged inaccuracies or misrepresentations in a company’s privacy policy and other privacy disclosures as the basis for a federal wiretapping claim under the Electronic Communications Privacy Act (“ECPA”).

Unlike state wiretapping claims like CIPA, class action plaintiffs can file ECPA claims nationwide and they can carry statutory damages of $100 per day of violation or $10,000, whichever is greater. Plaintiffs’ firms are increasingly leading with ECPA claims in demand letters and class action complaints.

Companies can take steps to help insulate themselves from litigation by assessing and modifying their privacy policy and other data processing disclosures.

Introduction

Any company with a privacy policy that operates a website using so-called tracking technologies such as pixels, cookies, software development kits, or third-party analytics tools (which is practically every company) should be aware of the real class action risk associated with the federal wiretapping law known as the Electronic Communications Privacy Act (ECPA or Wiretap Act) and its “crime-tort” exception.  We have data mined and analyzed thousands of privacy lawsuits using AI to track plaintiff lawyers’ allegations and patterns.

Key point: Five takeaways from March 2026 decisions: (1) Courts diverge on “purpose” requirement in ECPA’s crime-tort exception; (2) Courts consider ECPA exception outside the health care industry; (3) Contradictory statements in privacy policies can defeat consent even when tracking tech use is disclosed; (4) Courts provide guidance on website design to establish consent; and (5) Three courts allow negligence claims to proceed but nix negligence per se claims.

Welcome to our monthly update on how courts across the U.S. have handled privacy litigation involving website tools such as cookies, pixels, session replay, and similar technologies. In this post, we cover decisions from March 2026.

Key point: (1) Courts grapple with nonstatutory damage claims in “broken banner” cases; (2) Courts dismiss CIPA claims where plaintiffs failed to explain delays; (3) New privacy litigation trend takes off as two courts deny motions to dismiss under Washington’s Commercial Electronic Mail Act; (4) Motion to transfer based on forum selection clause in terms of use denied, highlighting risks for cookie banners; (5) VPPA circuit split deepens: as two more courts reject “ordinary observer” test but SCOTUS again refuses to resolve.

Welcome to our monthly update on how courts across the U.S. have handled privacy litigation involving website tools such as cookies, pixels, session replay, and similar technologies. In this post, we cover decisions from February 2026.