Cookies and tracking pixels are used on millions of websites for analytics, advertising, fraud prevention, customer service and basic website functionality.
Their widespread use does not mean every implementation is legally identical.
California and federal courts are increasingly being asked to determine whether particular tracking technologies amount to unlawful interception, eavesdropping or collection of electronic communications.
For businesses, the important question is usually not simply whether the website uses cookies. It is what the technology collects, when it collects it, and where the information goes.
Not Every Cookie Does the Same Thing
Some cookies are necessary to keep a visitor logged in, remember a shopping cart or operate basic website functions.
Other tools may:
- identify a device or browser;
- measure page views;
- track advertising conversions;
- record search terms;
- transmit the complete URL visited;
- identify products placed into a shopping cart;
- transmit form entries or contact information;
- associate browsing activity with an advertising profile; or
- replay portions of a visitor’s interaction with a webpage.
Those differences can determine which privacy theory, if any, is implicated.
Why “Contents” Matter Under Federal Law
The federal Wiretap Act defines an “intercept” as acquisition of the contents of an electronic communication through an electronic or other device.
“Contents” includes information concerning the substance, purport or meaning of the communication.
As a result, a claim involving only technical metadata can present a different issue from one alleging transmission of full URLs, search queries, form entries or other data revealing what the user was actually communicating.
Recent cases involving website advertising technology have focused closely on these distinctions.
Consent and Timing
A website operator should distinguish between having a privacy policy and obtaining consent that precedes the conduct a claimant challenges. The two are not necessarily the same.
In Javier v. Assurance IQ, LLC, the Ninth Circuit concluded that consent obtained after an alleged interception could not retroactively authorize conduct that had already occurred under CIPA section 631.
Disputes may therefore focus on what information was allegedly acquired, when the acquisition occurred, what disclosures the visitor was presented with, and whether legally sufficient consent preceded the challenged conduct.
The analysis remains fact-specific, and the presence or absence of a particular notice does not by itself resolve it.
Third-Party Vendors Matter
Modern websites frequently rely on outside technology providers.
A business may install software supplied by an analytics platform, advertising company, data provider or customer-service vendor without fully understanding what data the software sends back to that vendor.
Important questions include:
- Does the vendor receive only information necessary to provide a service?
- Can the vendor use the information for its own advertising or profiling?
- Does the vendor combine the information with data obtained elsewhere?
- Are full URLs transmitted?
- Can URLs disclose search terms or sensitive information?
- Are form fields or shopping activities transmitted?
- Does the vendor receive persistent identifiers?
- What does the contract authorize the vendor to do?
A privacy-policy statement describing a vendor as a “service provider” should therefore be compared with the actual technical behavior and contractual rights.
CIPA and Federal ECPA Protect Different Interests
Businesses should not treat “website privacy law” as one single statute.
CIPA section 631 generally raises questions concerning interception or acquisition of communication contents or meaning.
CIPA sections 638.50 and 638.51 involve a different concept: pen-register and trap-and-trace technology concerning routing, addressing and signaling information rather than contents.
Federal ECPA and Wiretap Act claims have their own definitions, party and consent rules, and crime-tort exception.
A claim that fails under one statute therefore may still be asserted under another.
The Federal “Crime-Tort Exception”
Under the federal Wiretap Act, an interception normally may fall within the party or one-party-consent exception under section 2511(2)(d).
But the statute withdraws that protection where the interception is undertaken for the purpose of committing another criminal or tortious act.
The Ninth Circuit requires that prohibited purpose to be independent from the interception itself.
Website cases have produced differing applications of that rule.
Some courts have found sufficient allegations where plaintiffs claim that intercepted data was deliberately used or disclosed in violation of separate privacy obligations. Others have been less willing to equate ordinary commercial advertising activity with the independent prohibited purpose required by the statute.
For businesses defending these cases, this can become an important distinction.
Does SB 690 Change the Analysis?
Potentially, but only for one category of California claims.
The current version of SB 690 would restrict the private right of action for CIPA section 638.51 website and application pen-register claims. Under the proposed amendment, only the Attorney General could bring that type of action under section 637.2 against a private actor.
It does not, however, presently eliminate:
- CIPA section 631 claims;
- federal ECPA claims;
- other potentially applicable California causes of action; or
- federal statutes that may apply to particular types of information.
Businesses should therefore not assume that SB 690, even if enacted, resolves every website privacy theory.
Six Issues Businesses Should Understand About Website Tracking
1. Identify the Technology at Issue
Different technologies perform different functions. Advertising pixels, analytics tools, session-replay software, chat systems, authentication cookies, and other scripts should not automatically be treated as legally equivalent.
2. Determine What Information Is Collected or Transmitted
The nature of the information can be critical. An IP address or technical identifier may present a different issue from a full URL, search query, form entry, shopping activity, or other information revealing the substance of a communication.
3. Examine When the Alleged Collection Occurred
Timing can matter, particularly where a claimant alleges that information was acquired before legally sufficient consent. The inquiry should focus on the actual conduct alleged rather than merely the existence or absence of a particular website notice.
4. Understand the Role of Third Parties
A third-party technology company may operate merely as a service provider, or it may have broader rights concerning information it receives. That distinction can affect the legal analysis under both California and federal law.
5. Compare the Alleged Conduct With the Statute Actually Asserted
A CIPA section 631 claim, a CIPA section 638.51 claim, and a federal ECPA claim involve different statutory language and potentially different defenses. A claimant should not be permitted to treat these theories as interchangeable merely because each involves website data.
6. Review Representations and Contractual Relationships
Privacy policies, website terms, vendor agreements, and other representations may become relevant to consent, the alleged purpose for collecting information, the role of third-party vendors, and, in federal cases, the asserted crime-tort theory.
The documents should therefore be evaluated together with the technical facts rather than in isolation.
Practical Takeaway
Website privacy litigation should not be reduced to the question of whether a website uses cookies or displays a consent banner.
The potentially important questions are considerably more specific:
- What communication allegedly was intercepted?
- Did the information constitute legally protected “contents”?
- Who received it?
- When did the alleged acquisition occur?
- Was the recipient a party to the communication or acting for a party?
- What consent, if any, existed?
- If the federal crime-tort exception is asserted, what independent criminal or tortious purpose is alleged?
- Which particular statute creates the claimed private right of action?
Those distinctions can substantially affect both liability and settlement value.
A business facing a CIPA, ECPA, or other website privacy demand should consider having experienced litigation counsel evaluate the statutory theory and underlying technical evidence before determining how to respond.
Related practice areas: Civil Litigation · Business and Commercial Litigation