In a recent decision challenging Google’s Gemini AI features, a California federal court held that allegations concerning an AI tool’s capabilities, without facts showing actual access or use of plaintiffs’ data, were insufficient to demonstrate the “concrete” harm required for Article III standing. Thele v. Google LLC, 2026 WL
Continue Reading Gemini Tracking Allegations Fall Short of Article III StandingData Privacy and Cybersecurity
Letting the Cat Out of the Bag: Named Plaintiffs’ Own Conduct Defeats Privacy Claims
In a decision highlighting the importance of testing standing through discovery, a Florida federal court dismissed privacy claims at the class-certification stage after concluding that neither named plaintiff could establish Article III standing. Although the plaintiffs’ allegations survived a motion to dismiss, discovery later exposed their “utter disregard” for the allegedly private information at issue, leaving them with nothing more than “a bare statutory violation.” Cobbs v. PetMed Express, Inc., 2026 WL 2234135 (S.D. Fla. July 31, 2026).
Continue Reading Letting the Cat Out of the Bag: Named Plaintiffs’ Own Conduct Defeats Privacy ClaimsCalifornia Legislature Advances Bill Targeting Wave of CIPA Pen Register Lawsuits
On July 1, 2026, a California legislative committee advanced amendments to SB 690 that would eliminate private suits asserting website-based “pen register” claims under the California Invasion of Privacy Act (“CIPA”), leaving enforcement exclusively to the California Attorney General. The amendments come amid a surge of lawsuits and demand letters challenging the use of website technologies under the pen register provision, which the committee described as a “poster child for abusive lawsuits.” According to the committee analysis, “[b]ecause the potential liability can be staggering,” businesses often settle quickly, thereby “encouraging vexatious litigants to continue blasting out demand letters.”
Continue Reading California Legislature Advances Bill Targeting Wave of CIPA Pen Register LawsuitsCalifornia Court Dismisses Amended Complaint in Hotel Website Wiretapping Suit for Lack of Article III Standing
Recently, a California federal judge dismissed—for the second time—a suit asserting that Sojern, Inc., a travel marketing platform, violated the Federal Wiretap Act and California privacy laws by allegedly deploying “tracking technology” on two hotel websites. Crano v. Sojern, Inc., 2026 WL 1670136 (N.D. Cal. June 9, 2026).
Continue Reading California Court Dismisses Amended Complaint in Hotel Website Wiretapping Suit for Lack of Article III StandingFirst Circuit Scrutinizes Causation Issues to Find No Article III Standing in Data Breach Case
The First Circuit recently affirmed a Puerto Rico district court’s ruling dismissing a class action suit arising from a 2019 ransomware attack against a hospital in which 522,493 patients’ personally identifiable information (“PII”) and protected health information (“PHI”) was allegedly accessed by hackers, albeit in “encrypted” form. See Santos-Pagán v. Bayamon Medical Center, No. 24-2018, 2026 WL 1693930 (1st Cir. June 11, 2026).
Continue Reading First Circuit Scrutinizes Causation Issues to Find No Article III Standing in Data Breach CaseStanding Found, But Negligence Fails: Eastern District of Michigan Dismisses Data Breach Claims for Lack of Causation
In a consolidated putative class action arising out of an alleged data breach, In re A-Line Staffing Solutions Data Security Incident Litigation, Case No. 24-cv-11917 (E.D. Mich. May 27, 2026), a Michigan district court declined to dismiss the complaint under Rule 12(b)(1) but granted the defendant’s motion to dismiss without prejudice on Rule 12(b)(6) grounds. The decision exemplifies a theme in such data breach cases: even where plaintiffs clear the Article III standing hurdle, their allegations may still fail to state a claim.
Continue Reading Standing Found, But Negligence Fails: Eastern District of Michigan Dismisses Data Breach Claims for Lack of CausationThird Circuit Addresses Standing in Website Wiretapping Claims—Again
The Third Circuit continues to draw a firm line on Article III standing in website “wiretapping” cases. Just weeks after the court’s decision in Harriet Carter Gifts, the court has issued yet another decision reinforcing that the alleged collection of data through third party tools does not create a concrete injury unless the tools capture truly sensitive, identifying information.
Continue Reading Third Circuit Addresses Standing in Website Wiretapping Claims—AgainWiretapping Suit Meets Triple Defeat: No Standing, Consent Established, Class Allegations Rejected
Continuing the trend of early dismissals in website wiretapping cases, a California federal court has dismissed a putative class action challenging the use of third-party pixel technology on nonprofit food bank websites. Timothee v. Meta Platforms, Inc., No. 25-CV-05106-LB, 2026 WL 1130363 (N.D. Cal. Apr. 27, 2026). The court held plaintiffs failed to plausibly plead concrete injury to establish Article III standing, consented to the third party’s receipt of their information, and proposed an impermissibly broad nationwide class.
The plaintiffs in Timothee alleged that several nonprofit food banks embedded third-party pixel technology into their websites, which collected and transmitted users’ addresses and “intent to receive nutrition assistance.” Some plaintiffs further alleged that the pixel technology collected detailed information about “financial hardship,” “disability status, mobility status, and urgency of [their] need for food assistance.” According to plaintiffs, this information was then used by the third party to target them with advertisements. The plaintiffs claimed these transmissions violated the California Invasion of Privacy Act (“CIPA”), the Federal Wiretap Act, and various California privacy and common-law doctrines. The court disagreed, dismissing plaintiffs’ claims, with leave to amend, on three grounds.
Continue Reading Wiretapping Suit Meets Triple Defeat: No Standing, Consent Established, Class Allegations RejectedAnother Court Dismisses Website Privacy Suit for Lack of Article III Standing
Adding to a growing body of case law following the Ninth Circuit’s decision in Popa v. Microsoft Corporation, a California federal court has dismissed for lack of subject matter jurisdiction a privacy suit against a news website, holding that the plaintiffs failed to allege a concrete injury sufficient to establish Article III standing. In Re: USA Today Co., Inc. Internet Tracking Litigation, 2026 WL 932655, at *3 (N.D. Cal. Apr. 6, 2026).
Continue Reading Another Court Dismisses Website Privacy Suit for Lack of Article III StandingSensitive Search Terms Not Enough To Establish Article III Standing Under Popa
A recent decision from the Southern District of California underscores a point courts have made increasingly clear after the Ninth Circuit’s precedential decision in Popa v. Microsoft: alleging the disclosure of online activity—even activity touching on sensitive health topics—is not enough, by itself to establish Article III standing. As the Court put it, the mere allegation that a defendant disclosed “sensitive health related” search terms, without any indication in the search terms that they “were tied to his personal medical history,” cannot establish a concrete injury. Maghoney v. Dotdash Meredith, Inc., 2026 WL 497402 (S.D. Cal. Feb. 23, 2026) (emphasis added).
Continue Reading Sensitive Search Terms Not Enough To Establish Article III Standing Under Popa