The Privacy Filter: A Briefing on Privacy Law and Policy

CIPA Lawsuits, Tracking Technology Lawsuits, and Why Privacy Takes Center Stage

Brian McGinnis, Owen Agho, and Lyric Menges Season 1 Episode 5

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 25:23

What happens when decades-old wiretapping laws collide with modern website technology?

In this episode, Brian McGinnis and Lyric Menges unpack the growing wave of website tracking litigation under the California Invasion of Privacy Act (CIPA) and the federal Electronic Communications Privacy Act (ECPA). They explore why businesses across industries are receiving demand letters and lawsuits over common website tools such as cookies, pixels, analytics platforms, chat features and session replay technologies.

The discussion breaks down the technologies at the center of these claims, the legal theories plaintiffs are advancing, and the practical steps organizations can take to assess and reduce risk. Brian and Lyric also discuss how technical website audits, privacy disclosures, consent mechanisms and cross-functional governance are becoming increasingly important as litigation continues to evolve.

SPEAKER_01

Welcome to the Privacy Filter, Lawrence and Thornburg's briefing on privacy law and policy. Subscribe for the latest updates.

SPEAKER_00

Hi everyone, my name is Brian McGuinness, and this is the Privacy Filter. Pleased to be joined today by my colleague and friend Lyric Mingus out of our Los Angeles office. And Lyric, today we're going to dig in on something we're seeing clients get hit with left and right, SIPA lawsuits. All of our clients have websites. They're putting the technologies that their marketing teams, their web teams need and want up on the websites, common things like tracking pixels and general website analytics, doing exactly what they're being told to do and following all the statutes that exist on how to legally deploy these technologies across their sites. But we're seeing a ton of plaintiffs out there and wannabe plaintiffs coming along and suing these companies based off of laws that were created before email and websites even existed. Larek, just to tee us off and get us started on the topic today before we get into any of the details, a general counsel's phone rings on a Friday afternoon. They get an email on a Saturday. It says, hey, take a look at this. We've got an arbitration demand. We've got a lawsuit that just came in. What is SIPA? What's going on? What does that call look like for our clients?

SPEAKER_01

So these cases, as you mentioned, often involve statutes that were written a long time before modern websites, cookies, pixels, all of these technologies really existed. But plaintiffs are using these older laws, especially the California Invasion of Privacy Act or CIPA, and in some cases the Federal Electronic Communication Privacy Act or ECPA to challenge these routine digital tools that many businesses have on their websites. And that is what makes this litigation wave so important is that we're not only talking about companies doing something that are that is obviously invasive, we're talking about ordinary business websites using common tools for analytics, advertising, chat functionality, conversion tracking, troubleshooting, and user experience improvement. So for general counsels, the legal question is whether those tools are merely part of operating a modern website, or whether under these older wiretap style statutes, they can be framed as intercepting or recording or disclosing user communications without consent. And these calls typically are framed as here's the technology that we think you're using, and this is why it's a violation of these statutes.

SPEAKER_00

A lot to cover. What are we seeing in the litigation? Uh, and what companies, importantly, should actually be doing to defend themselves and not get caught out with one of these suits. Uh, so that's what we're going to cover today on the privacy filter. Let's get into it, Lyric. I want to start with just a basic question. Talk us through, you know, we hear business leaders talking about website tracking lawsuits, or, you know, they're kind of treating it as a marketing problem or an IT problem in some cases. Tell us a little bit more about why this is actually a serious privacy litigation issue right now? Who's getting hit? What do those suits look like? Who's at risk?

SPEAKER_01

So everyone is getting hit. This is one of the areas of law where there is not a particular kind of target. It is if you have a website, if that website is accessible to plaintiffs sitting in California or other state-specific statutes, or even federally, you are susceptible to these lawsuits if you utilize any sort of cookie or tracking technology. And I want to take a step back really quickly and define what these tracking technologies are, because when plaintiff's lawyers say website tracking technologies, we're usually actually talking about a broad category of tools that collect information about how users interact with a website, app, or digital service. And these include cookies, pixels, tags and tag managers, analytics tools, session replay tools, chats and chatbots, SDKs, or embedded media and plugins. And then there's the other side, which is advertising and retargeting tools, which a lot of companies that are privacy informed have already implemented measures to address. But from a business perspective, as you mentioned, these tools are often used for legitimate purposes. So fraud prevention, analytics, debugging, and from a litigation perspective, that's not the issue. It's not the issue is not why this tool is used. The issue is what data is collected, when it is collected, whether a third party receives it, and whether the user consented before the collection. And it's a privacy issue specifically because often the plaintiffs will point to whether the company's privacy closures accurately describe the practice and whether their cookie banner or other pop-up accurately discloses their practice and represents how the tools are being implemented and when they're being implemented. And this last point matters because a lot of companies have privacy policies that say generally, we use cookies in analytics, but the actual website may be firing pixels, session replay scripts, advertising tags, and third-party scripts before a user has meaningfully consented. Or even if the user has meaningfully consented, that consent in practice isn't actually occurring prior to these technologies firing. So the gap between disclosure and technical reality is where the risk often lives. And that's why this is uniquely a privacy law issue.

SPEAKER_00

Yeah, and we're way beyond, you know, sort of the traditional we use cookies on this website, uh, disclosure that you've seen in privacy notices for a long time. Um I know you've got a fantastic technical background as well. Tell us a little bit more, uh, sort of in plain English. What are pixels? What are session replay tools? What are these technologies actually doing? Why are they on the websites?

SPEAKER_01

Sure. So let's start with cookies. And I don't mean the chocolate chip cookies that you can pick up in the mall. I mean the small files that are placed on a user's browser that can remember preferences, maintain a session, or support advertising. And pixels are small snippets of code that can transmit information back to a third party. So this is often used for advertising analytics or conversion tracking or retargeting. There's a really well-known pixel called the MetaPixel that is utilized to specifically support advertising, but there are many others, and these are very common technologies. And for tag managers, Google Tag Manager, for example, can be used to deploy and manage multiple scripts across a website. And these are really helpful tools. And analytics tools at the same time manage traffic, page views, user flows, referral sources, device information, and conversion events. This is really helpful for marketing teams, especially when looking at what pages on their website are most successful, what is driving the most user interaction. Session replay tools are basically recreating and replaying a user's interaction with the website. And I find that a lot of companies, when they're using tag managers specifically, will also deploy a session replay tool just to get that extra boost of data. Was that these are really helpful for websites, but the flip side of that is deploying them in a way that is correct, privacy informed, and allows a user to obtain meaningful consent?

SPEAKER_00

Yeah, I was just gonna say, like, you know, these things are incredibly common. Most marketing teams use this stuff. So I think a lot of our clients have the question of like, if everybody's doing this, uh, it's legitimate uses, we're complying with all the statutes that exist on this. What's the risk here? What why are we getting hit with these lawsuits? Why are we getting hit with these demands if we are following what the laws tell us we have to do a tracking technology?

SPEAKER_01

Right. And that's the really complicated aspect of this because California's wiretap privacy statute, CIPA, was originally enacted in the 1960s, and plaintiffs are now using it to challenge modern website tracking. And the statute includes several provisions, but in website tracking litigation, there are two specific theories that we see the most. And the first is section 631, which is often framed as this wiretapping or eavesdropping theory. So the plaintiffs are alleging that a company or a third-party vendor embedded on the company's website reads, learns, records, intercepts the contents of a user's communication without consent. The second is 63851, which concerns pen registers and trap and trace devices. And plaintiffs are increasingly arguing that these digital tracking tools, pixels, SDKs, cookies, analytic scripts, they function as modern pen registers or trap and trace devices because they capture routing and addressing, signaling source, or identifying information. And this theory really gained traction after a major case where a court allowed a SIPA pen register theory to proceed based on allegations that a software collected and transmitted user data. And SIPA has become especially attractive to plaintiffs because it can provide statutory damages. Under SIPA section 637, plaintiffs may seek the greater of $5,000 per violation or three times actual damages. This creates a really significant exposure for class or mass arbitration settings because per violation adds up really quickly. And I think that damages structure is one reason these cases are being filed against businesses across all industries. Like I said, the plaintiffs don't have a specific target in mind. It's does your website have these routine technologies and how can we use that in our advantage?

SPEAKER_00

Yeah, and how can we take these, like you said, 1960s era telephone wiretapping statutes where people are literally uh tapping in to listen to phone calls and applying that to the technology of putting sort of a tech piece of technology in the middle of a user showing up at a website, sending information or having information collected about them more often, and then sending that off to a third party. We see Neta, we see LinkedIn, uh those types of pixels a lot. So an innovative creative theory. We started seeing these pop up really in California under CIPA. Uh, I know that it's expanded. Um, we've got some other states that are doing this, you know, Florida, Illinois, uh, New Jersey, I think we've seen some cases in as well. But I think we've had a lot of clients kind of take the state-specific view of this. Oh, we're not in California, we don't have to worry about this. Uh, tell us why that's not the case with the ECPA.

SPEAKER_01

That's definitely not the case with the ECPA and even with CIPA, because what's being alleged is not that the defendant or the company is sitting in California. It's that someone from California or any of these specific states have accessed the website. The ECPA is the federal counterpoint of this. It includes the Wiretap Act and the Stored Communications Act. And in the website tracking context, plaintiffs are arguing that a company or a vendor intercepted electronic communications without consent. But the ECPA has some important limitations and defenses here, including the party exception, which can make federal claims harder in certain fact patterns. And I think that employer career pages is likely the most susceptible when it comes to ECPA litigation, because the risk of pixels on employer websites and job application pages where tracking could capture or infer sensitive information specifically, such as disability disclosures, veteran status, or applicant activity, really drives what we see a lot of the ECPA litigation claims.

SPEAKER_00

Yeah. And of course, as a federal statute, uh there's no hiding behind state law anymore. This is a coast to coast thing. So you start down this path. Let's get it up to speed here, get us current, like what does the current litigation look like in this space? Uh, we've kind of covered what these lawsuits are, why they're happening. Tell us what's going on right now in this space that you're seeing with the claims that are being brought or at least threatened to be brought.

SPEAKER_01

So previously we saw this really early wave of cases that focused heavily on session replay tools. And now we're seeing, after the Ninth Circuit's decision in 2022, we're seeing pixels, chat tools, analytic scripts, SDKs, cookies, and other tracking technologies. So what started off as just a session replay tool-based litigation has now expanded into the entire universe of web tracking technologies. And I think that this is really important for understanding what companies should be aware of because a lot of times we'll have general counsel, client, whoever it may be, say, okay, well, we weren't in charge of our own website. And here that doesn't really matter because you may be hiring someone else to develop this technology for you or set up your website, but you're still the data controller at the end of the day because you are receiving the initial communications, the initial data. And we're hopeful that with pending legislation currently moving through state legislature, that we will see some relief here. But personally, I don't anticipate that happening for the next year or two at least.

SPEAKER_00

Yeah, and the spread and where these things are being brought obviously makes that more difficult too. Talk a little bit about, I guess, how these are being handled. One of these notices shows up in your inbox. Uh, what are we seeing with clients in terms of how they actually address these, how they actually handle them? I don't know if you've got a specific example you want to go in on, but um, my sense is almost none of these, very few of these, are being litigated for the reason that it doesn't make financial sense uh to try and go through an entire court case about this uh when they're offering payouts, you know, between $10,000 and $25,000, let's say. So what's what's the typical flow that you see in most of these that we're dealing with right now?

SPEAKER_01

Well, the typical flow I see is usually a client call. I think that's the most important step. I think it's important to not only explain what these statutes are, but also what these technologies are and really present a formal landscape for addressing what the company is doing. And oftentimes, as you said, it doesn't make financial sense to fully litigate these claims because these technologies are being used by everyone. And when they are litigated, they're litigated as a class, and the litigation expenses add up really quickly, as opposed to immediately engaging in settlement conversations with the other side or implementing back-end remediation efforts where that is the principal demand. And what I find is really helpful for me is looking at HAR files and really looking at the code that's being used and when the code is firing, when these pixels are being deployed, and understanding both the technical aspect of the website and the legal implications that that creates. And I think that's really helpful for clients too. And based off feedback I've gotten, what they really appreciate is having someone not only who understands the technical aspects of this, but also the legal implications and how to remedy that. And so we'll often see these cases settle very quickly, but that also, and rightly so, promotes the client to ask us in turn, how can we fix this? How can we prevent this in the future? And we're seeing companies as a result of this really unfortunate wave of cases become more privacy-informed, more privacy-focused, and really take those remediation steps that I believe are critical in addressing not only the current technology that's subject to this, but any technology in the future that may come up and be used as a loophole in some really older statutes.

SPEAKER_00

Yeah, talk a little bit more about the importance of that hard file. So let's say a client contacts us and says, What do we do about this? Obviously, the first thing we don't do is jump into court over it. Uh, take us through the initial process that we work through uh in assessing the validity of the claim, the risk to the client, and then sort of initial phases of uh for that particular circumstance, depending upon the outcome of those initial steps. Here's what we recommend to go forward.

SPEAKER_01

So the hard file is important. And what the hard file really is, is a compilation of scripts and code that are run when someone accesses a website. And if you've ever used developer tools, you can go to the network tab and really track as you're poking around on a website what's operating and when. And what these plaintiffs firms are doing is they'll use either their own proprietary software or third-party tools and look at a website and essentially have the hard file capture everything that occurs beginning when they immediately load the web page to what tabs they click on, whether or not they actually click on a cookie banner if one exists. If they consent, does the consent actually operate? And the HAR file, in technical terms, explains all of that in a series of code. And we'll typically initially ask for this when we begin conversations with the other side, because sometimes they don't even have a HAR file, or other times they're reusing the same screenshots from prior litigation, and it's not unique to that plaintiff. And I think it's important to not jump into let's get this settled as fast as possible without really understanding do they even actually have a claim? Because if they don't have a claim, you shouldn't have to pay.

SPEAKER_00

They're operating at such high value right now, or volume right now, that it's uh they don't always do their diligence on the front end to make sure that they can actually prove the claims that they're saying. And so, you know, taking a look through that R file, making sure they do have the receipts that their claims are in fact accurate and applicable to the client and that particular version whenever they looked at it. Uh, we've seen uh and been able to help clients get out of some of these claims just based on inaccuracy of the facts from from some of the plaintiff's attorneys, right?

SPEAKER_01

Exactly.

SPEAKER_00

So we get this, we look through it. Let's say the the HAR file checks out uh the website is doing what they said they'd do. Again, we're not jumping straight to court. We've seen everything from, well, you know, maybe we're just gonna ignore this and see what happens. Is the plaintiff or purported plaintiff actually going to bring a suit? Are they going to bring the arbitration that they're threatening? Uh we engage them potentially in settlement negotiations back and forth. Have you seen any shifts in that lately? Anything changing uh in the way that these are getting handled?

SPEAKER_01

Not particularly, although we are seeing an increase in the amount of plaintiff's firms that are bringing these. What started off as just a select couple few has now grown, especially with other states having similar statutes that other plaintiff's firms sitting in other jurisdictions can utilize. So it's now not so much a we know the three musketeers that bring these cases. It's we know the category of cases that plaintiffs' firms generally are bringing, and sometimes it's also pro-se plaintiffs, and that presents its own hurdles when dealing with anyone who isn't represented by an attorney because it's a more complicated negotiation structure and making sure that they are fully informed and complying with all rules of professional conduct here. But I think it's important to recognize that it's not just the same individuals that are bringing all of these cases. It's now grown, and that's one of the shifts that we've seen that I think is really important. Because even if you've settled one claim from one firm, that doesn't preclude other firms, other plaintiffs from bringing the exact same claim that you had already settled with another party, which is why the privacy audits and really getting into privacy compliance after the first version of this is so critical.

SPEAKER_00

Yeah, key point. Like if you get hit with one of these, that's not only uh triggering a you know a responsibility or an obligation, I would say, to get it resolved and behind you, but certainly what do we do to prevent this from happening again and get more of these claims? Because settling one doesn't mean that you're going to prevent yourself from that. So I guess if I'm in-house counsel, if I'm a marketing team, like who's at risk of this? Are there particular industries, particular types of websites that are higher risk? Or if I just want to know, am I clear? Can I, you know, cross this off the list of things to worry about? What do we need to have people looking at on their sites or considering or asking questions of the technical team about so that they can't get some peace of mind that they're no longer subject to getting hit with one of these?

SPEAKER_01

Sure. I think that's a great way to wrap this up and bring it full circle here is that it's a really complicated task for in house counsel who is responsible for overseeing everything and mastering everything, and then also having to deal with IT marketing and systems that they may not be accustomed to working with before. So I think the key thing here is ask your IT teams, your marketing Teams, what is our tech stack? What do we actually use? What have we used in the past? When did that change occur? And making sure that there's open dialogue between all of these different departments so that everyone is aware if there actually is a risk. And something that I think we do, which is really beneficial to our clients and everyone who asks us for opinions on these matters, is we can all obviously advise on a privacy policy and revise that to be compliant with the ever-changing US landscape. But we can also provide the technical audit that a lot of these plaintiffs' firms will also be doing on their end to point out technologies that are firing inaccurately. And so I think having that technical audit done on websites, the applications that you're utilizing simultaneously with a privacy policy revision or just a general privacy impact assessment is really critical to prevent either the first lawsuit coming your way or future claims brought by other plaintiffs' firms. I would say that understanding the tech stack, working with counsel, and making sure that you stay aware of these changing regulations is the way to best posture yourself to prevent liability.

SPEAKER_00

Yeah, this is an area where we're still seeing a lot of changes and updates, and especially as you know, there's continuing threats to shut down these actions under SIP in California. They're shifting jurisdictions and looking for other avenues to uh to keep them rolling. So great advice. But yeah, generally what we've covered today, it's a lot of um technical work, understanding what your website's doing, what technologies are in use, are they compliant, uh, backing that up with the online privacy notice and having language in there that clearly discloses it. Uh, and then the sort of cookie pop-up banner consent that marketing teams hate, um, but really is really one of the only ways that we can um help our clients ensure that they avoid these things going forward is to have some minimal language on there that is making these proper disclosures uh to avoid these lawsuits and stay off of these lists of these plaintiffs firms. Lyric, any other final key takeaway that we've got for the audience uh that's stuck with us this long that we can give to them beyond those things that uh can help them avoid being the victim of one of these suits?

SPEAKER_01

I think that the key advice here is know what is on your website, right? Know what data it collects, know who receives it, obtain consent where it's appropriate, honor the opt-outs, and make sure your disclosures match the technology. Because if your website's talking to third parties, the plainest lawyers are listening.

SPEAKER_00

Great takeaway. All right. Well, let's end it there. Thank you to everybody for joining us today. Lyric, huge thank you to you for taking the time to share your knowledge and expertise, both on the legal side and the technical side, of course. Uh, great guests to have on to walk us through this. Uh, if you guys want to keep up with us on this issue, we're btlaw.com, uh, all over LinkedIn and wherever you find the podcast. We are just at the initial stages here of getting going with the privacy filter, and we'll continue to bring uh more of this type of content and improving content to you as we uh get things figured out and move forward on all of this. But until next time, thanks for joining us. I'm Brian McGinnis, and thanks for joining the Privacy Filter.