By Rashmi Pathiyil – Associate – Legal
Cookie banners, a 1967 wiretap law, and the fraud theory every website owner should understand
You click “Reject All” on a cookie banner and move on, assuming the website respected your choice. Recent lawsuits allege that this is not always what happens.
Some plaintiffs allege that websites continue using cookies, tracking pixels, and other tools to send visitor data to third parties even after users opt out. The legal risk is not simply that tracking occurred. It is the gap between what the website represented and what the technology did after the user made a choice.
That gap can be costly.
Nobody In the Boardroom Wants to See the Numbers
A March 2026 ArentFox Schiff analysis reported that plaintiffs filed more than 1,000 lawsuits under the California Invasion of Privacy Act in 2025 alone.[1] The statute’s private right of action is one reason the exposure attracts attention. An injured person may seek $5,000 per violation or three times actual damages, whichever is greater.[2]
For a website with millions of visits, potential exposure can add up quickly even before a court decides whether a claim has merit.
That is why cookie-banner compliance is no longer only a privacy issue. It is also a litigation risk.
A Cold War Statute Aimed at Your Homepage
CIPA was enacted in 1967, long before cookies or websites existed. Its original privacy provisions were framed around telephone and telegraph communications.[3]
Plaintiffs are now applying two parts of that decades-old statute to modern websites. Section 631(a) addresses unauthorized interception and access to the contents of communications, while Section 638.51 restricts the installation or use of “pen registers” and “trap and trace” devices without a court order, subject to statutory exceptions.[4]
In simplified terms, Section 631(a) focuses on the contents of communications. Sections 638.50 and 638.51 focus on dialing, routing, addressing, or signaling information rather than contents.
How We Got Here
The first major wave of lawsuits focused on session-replay technology, which can record how visitors interact with a website.
In Javier v. Assurance IQ, an unpublished Ninth Circuit memorandum held that, for the alleged Section 631(a) interception, consent had to precede the interception; retroactive consent was insufficient.[5] The court did not decide whether the plaintiff had impliedly consented to the collection.
Then came Popa v. Harriet Carter Gifts. The Third Circuit held under Pennsylvania law that an interception could occur when communications were captured at the visitor’s browser and routed to a third-party server.[6] The federal posture later changed: in March 2026, a nonprecedential Third Circuit decision concluded that Popa lacked Article III standing and directed that the removed action be remanded to state court.
The Ninth Circuit addressed a related “contents” question in Mikulsky v. Bloomingdale’s. In an unpublished, nonprecedential memorandum, the court revived a Section 631(a) claim because the plaintiff plausibly alleged that session-replay software captured the contents of her communications rather than merely record information about them.[7] The decision is useful as an illustration of pleading sufficiency, but it is not binding precedent.
The Defense Side Has Been Winning Too
Companies have also won important cases.
In Gutierrez v. Converse, an unpublished Ninth Circuit memorandum affirmed summary judgment for Converse in a case involving a website chat tool. The plaintiff could not show that Salesforce actually read her messages or attempted to read them.[8] That evidentiary gap was fatal to the relevant Section 631(a) theory.
Judge Bybee went further in a separate concurrence. He read the first clause of Section 631(a) as directed to traditional telephone wiretapping rather than internet communications.[9] The concurrence is not binding, but it reflects judicial resistance to extending every part of a 1967 statute to modern web traffic.
Standing has created another defense. In Popa v. Microsoft, the Ninth Circuit held that the plaintiff had not shown a sufficiently concrete privacy injury from the session-replay activity alleged there. The court compared the observation of website activity to a store employee noticing which aisles a shopper visits.[10]
A California federal court later drew on similar standing logic in Khamooshi v. Politico, dismissing a pen-register claim because information such as device type, browser type, and device fingerprints was not sufficiently private or invasive to establish Article III standing.[11]
But Jurisdiction Is Breaking the Plaintiffs’ Way
Companies based outside California should not assume that California courts are necessarily out of reach.
In Briskin v. Shopify, the en banc Ninth Circuit held that Shopify was subject to specific personal jurisdiction in California based on allegations that it deliberately installed tracking software on a California user’s device, knew the user was in California, and used the resulting data for its own commercial purposes.[12]
For online businesses, the jurisdictional lesson is significant. Deliberate data-collection conduct directed at a user known to be in California can create California contacts even without California-specific advertising.
The Newer Theory- The Banner Itself May Be the Problem
The newer cases focus less on tracking in the abstract and more on what the website told users before the tracking continued.
If a website offers a “Reject All” button, a user clicks it, and trackers covered by that choice continue to run, the dispute may sound not only in privacy law but also in misrepresentation. The question becomes whether the interface accurately described what would happen after the user opted out.
D’Antonio v. Smith & Wesson shows how these theories can separate. The website offered “Accept Cookies,” “Reject All,” and “Manage Privacy Preferences,” and the plaintiffs alleged that tracking continued after they selected “Reject All.”[13] The court dismissed the CIPA wiretapping and pen-register claims with leave to amend because the complaint did not adequately allege interception of the plaintiffs’ own communications and, for the pen-register theory, the relevant dialing, routing, addressing, or signaling information. It nevertheless allowed common-law privacy claims, fraud claims of two plaintiffs, and unjust enrichment to proceed.[14] The contract, implied-covenant, and trespass-to-chattels theories were dismissed with leave to amend.[15]
De Ayora v. Inspire Brands shows how much can turn on pleading detail. In December 2025, the court dismissed the complaint because claims sounding in fraud did not satisfy Rule 9(b)’s particularity requirement.[16] After amendment, the June 2026 order denied dismissal of fraud, unjust-enrichment, and common-law privacy claims and allowed the pen-register theory to proceed where timely. But the court dismissed the wiretapping claim with leave to amend and held several CIPA claims time-barred, some with prejudice.[17]
Camplisson v. Adidas highlights the consent problem when a site relies only on footer disclosures. Adidas allegedly used a TikTok pixel and Microsoft Bing tracker without an affirmative consent mechanism. The court allowed the Section 638.51 pen-register claim to proceed and rejected the consent argument at the pleading stage because the footer links were not conspicuous and the site lacked affirmative assent.[18]
Shah v. Politico presents the fraud theory even more directly. The plaintiff alleged that Politico allowed users to turn off performance and advertising cookies but continued placing cookies and sending data after the opt-out.[19] The court dismissed the CIPA wiretap and pen-register claims as untimely as pleaded, with leave to amend, but denied dismissal of the common-law fraud claim.[20]
The practical point is narrower than saying that every failed CIPA claim becomes fraud. Different causes of action have different elements, and a misleading consent interface may leave state-law theories in play even when a CIPA theory is dismissed.
The Legislature Is Still Moving
California lawmakers have continued to respond to the wave of CIPA website litigation.
As of August 2026, SB 690 had cleared the Assembly Appropriations Committee 15–0 and had been ordered to third reading. The July 2 amendment no longer contains the bill’s earlier broad “commercial business purpose” exemption. Instead, the current text would amend Section 637.2 so that, for a Section 638.51 violation alleged to arise from conduct on an internet website, online application, or mobile application, an action against a private actor under Section 637.2 may be brought only by the Attorney General. The bill would apply that limitation retroactively to specified pending claims.[21]
SB 690 has not yet become law. Until the legislative process is complete, businesses must operate under CIPA as it currently stands.
So How Worried Should You Be?
The risk is real, but the present case law does not support treating every tracking configuration as equivalent.
Most of the decisions discussed here are pleading-stage rulings. Gutierrez reached summary judgment on a different Section 631(a) theory. Taken together, the cases identify litigation pathways, standing requirements, and pleading rules and they do not establish a uniform merits rule for cookie-banner fraud.
A narrower pattern is visible. Section 631(a) claims in the cases discussed here often turn on whether the plaintiff identifies a communication and plausibly alleges interception of its contents. Pen-register cases turn on the statutory characterization of tracker data and, in federal court, Article III injury. Courts also remain divided over whether Section 638.51 reaches ordinary website-tracking software at all.[22]
Fraud claims ask a different question. What did the banner say? What happened after the user made a choice? Can the plaintiff plead misrepresentation, reliance, injury? Where Rule 9(b) applies? and the circumstances of the alleged fraud with particularity.[23]
In short, businesses should take these claims seriously, but the current case law supports a measured, fact-specific assessment rather than treating every use of website tracking technology as creating the same level of legal exposure.
The Part That Does Not Need a Law Degree
Do not promise users more privacy than your website provides.
If a banner says, “Reject All,” the site should disable every non-essential tracker covered by that choice. If certain cookies remain necessary for security, fraud prevention, or basic website functions, say so clearly.
The recurring litigation risk is the mismatch between what the user is told will happen and what the website actually does next.
[1] D. Reed Freeman Jr. et al., CIPA Plaintiffs Target Cookie Banners, Join State Regulators in Attack on Opt-Out Compliance, ArentFox Schiff Priv. Couns. (Mar. 31, 2026), https://www.afslaw.com/perspectives/privacy-counsel/cipa-plaintiffs-target-cookie-banners-join-state-regulators-attack-opt.
[2] Cal. Penal Code § 637.2(a) (West 2026).
[3] Cal. Penal Code §§ 630, 631(a) (West 2026).
[4] Cal. Penal Code §§ 638.50(b)–(c), 638.51(a)–(b) (West 2026).
[5] Javier v. Assurance IQ, LLC, No. 21-16351, 2022 WL 1744107, at *1–2 (9th Cir. May 31, 2022) (mem.).
[6] Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121, 131–33 (3d Cir. 2022); see also Popa v. Harriet Carter Gifts, Inc., No. 25-1760, slip op. at 2–4 (3d Cir. Mar. 26, 2026) (nonprecedential) (vacating and remanding with instructions to remand to state court for lack of Article III standing).
[7] Mikulsky v. Bloomingdale’s, LLC, Nos. 24-3564, 24-3837, mem. at 2–3 (9th Cir. June 20, 2025) (unpublished).
[8] Gutierrez v. Converse Inc., No. 24-4797, 2025 WL 1895315, at *1 (9th Cir. July 9, 2025) (mem.).
[9] Id. at *2–3 (Bybee, J., concurring in part and concurring in the judgment).
[10] Popa v. Microsoft Corp., 153 F.4th 784 (9th Cir. 2025).
[11] Khamooshi v. Politico LLC, No. 24-cv-07836-SK, 2025 WL 2822879, at *3 (N.D. Cal. Oct. 2, 2025).
[12] Briskin v. Shopify, Inc., 135 F.4th 739 (9th Cir. 2025) (en banc).
[13] D’Antonio v. Smith & Wesson Inc., No. 25-cv-03085-PCP, slip op. at 2–3 (N.D. Cal. Feb. 17, 2026).
[14] Id. at 7–11.
[15] Id. at 11–14; see also Intel Corp. v. Hamidi, 30 Cal. 4th 1342 (2003).
[16] De Ayora v. Inspire Brands, Inc., No. 25-cv-03645-AGT, 2025 WL 3707561, at *3–4 (N.D. Cal. Dec. 22, 2025).
[17] De Ayora v. Inspire Brands, Inc., No. 25-cv-03645-AGT, slip op. at 4–14 (N.D. Cal. June 8, 2026).
[18] Camplisson v. Adidas Am., Inc., No. 25-cv-00603-GPC-KSC, 2025 WL 3228949, at *7, *9 (S.D. Cal. Nov. 18, 2025).
[19] Shah v. Politico LLC, No. 25-cv-05213-NW, 2026 WL 323269, at *1–4 (N.D. Cal. Feb. 6, 2026).
[20] Id. (denying dismissal of the common-law fraud claim while dismissing the CIPA wiretap and pen-register claims as untimely as pleaded, with leave to amend).
[21] S.B. 690, 2025–2026 Leg., Reg. Sess., as amended July 2, 2026, § 1 (Cal. 2026); California State Assembly, Daily File, Aug. 28, 2026, S.B. 690.
[22] Compare Camplisson v. Adidas Am., Inc., No. 25-cv-00603-GPC-KSC, 2025 WL 3228949, at *7 (S.D. Cal. Nov. 18, 2025), with Gonzalez Merical v. The Joint Corp., No. 1:26-cv-00974-KES-SAB, findings and recommendations (E.D. Cal. Aug. 3, 2026) (discussing Blaker v. NetScout Sys., Inc., No. 25STCV31283, 2026 WL 1709143, at *3–4 (Cal. Super. Ct. May 26, 2026)).
[23] See De Ayora v. Inspire Brands, Inc., No. 25-cv-03645-AGT, 2025 WL 3707561, at *3–4 (N.D. Cal. Dec. 22, 2025); Shah v. Politico LLC, No. 25-cv-05213-NW, 2026 WL 323269 (N.D. Cal. Feb. 6, 2026).
For more practical litigation drafting tips, pleading and legal research insights, follow LawCompany.