Recently, a California federal judge dismissed—for the second time—a suit asserting that Sojern, Inc., a travel marketing platform, violated the Federal Wiretap Act and California privacy laws by allegedly deploying “tracking technology” on two hotel websites. Crano v. Sojern, Inc., 2026 WL 1670136 (N.D. Cal. June 9, 2026).
Continue Reading California Court Dismisses Amended Complaint in Hotel Website Wiretapping Suit for Lack of Article III StandingTechnology
Standing Found, But Negligence Fails: Eastern District of Michigan Dismisses Data Breach Claims for Lack of Causation
In a consolidated putative class action arising out of an alleged data breach, In re A-Line Staffing Solutions Data Security Incident Litigation, Case No. 24-cv-11917 (E.D. Mich. May 27, 2026), a Michigan district court declined to dismiss the complaint under Rule 12(b)(1) but granted the defendant’s motion to dismiss without prejudice on Rule 12(b)(6) grounds. The decision exemplifies a theme in such data breach cases: even where plaintiffs clear the Article III standing hurdle, their allegations may still fail to state a claim.
Continue Reading Standing Found, But Negligence Fails: Eastern District of Michigan Dismisses Data Breach Claims for Lack of CausationThird Circuit Addresses Standing in Website Wiretapping Claims—Again
The Third Circuit continues to draw a firm line on Article III standing in website “wiretapping” cases. Just weeks after the court’s decision in Harriet Carter Gifts, the court has issued yet another decision reinforcing that the alleged collection of data through third party tools does not create a concrete injury unless the tools capture truly sensitive, identifying information.
Continue Reading Third Circuit Addresses Standing in Website Wiretapping Claims—AgainWiretapping Suit Meets Triple Defeat: No Standing, Consent Established, Class Allegations Rejected
Continuing the trend of early dismissals in website wiretapping cases, a California federal court has dismissed a putative class action challenging the use of third-party pixel technology on nonprofit food bank websites. Timothee v. Meta Platforms, Inc., No. 25-CV-05106-LB, 2026 WL 1130363 (N.D. Cal. Apr. 27, 2026). The court held plaintiffs failed to plausibly plead concrete injury to establish Article III standing, consented to the third party’s receipt of their information, and proposed an impermissibly broad nationwide class.
The plaintiffs in Timothee alleged that several nonprofit food banks embedded third-party pixel technology into their websites, which collected and transmitted users’ addresses and “intent to receive nutrition assistance.” Some plaintiffs further alleged that the pixel technology collected detailed information about “financial hardship,” “disability status, mobility status, and urgency of [their] need for food assistance.” According to plaintiffs, this information was then used by the third party to target them with advertisements. The plaintiffs claimed these transmissions violated the California Invasion of Privacy Act (“CIPA”), the Federal Wiretap Act, and various California privacy and common-law doctrines. The court disagreed, dismissing plaintiffs’ claims, with leave to amend, on three grounds.
Continue Reading Wiretapping Suit Meets Triple Defeat: No Standing, Consent Established, Class Allegations RejectedSensitive Search Terms Not Enough To Establish Article III Standing Under Popa
A recent decision from the Southern District of California underscores a point courts have made increasingly clear after the Ninth Circuit’s precedential decision in Popa v. Microsoft: alleging the disclosure of online activity—even activity touching on sensitive health topics—is not enough, by itself to establish Article III standing. As the Court put it, the mere allegation that a defendant disclosed “sensitive health related” search terms, without any indication in the search terms that they “were tied to his personal medical history,” cannot establish a concrete injury. Maghoney v. Dotdash Meredith, Inc., 2026 WL 497402 (S.D. Cal. Feb. 23, 2026) (emphasis added).
Continue Reading Sensitive Search Terms Not Enough To Establish Article III Standing Under PopaStand Aside: Third Circuit Throws Out Harriet Carter Gifts Federal Wiretapping Case On Standing Grounds
We have routinely highlighted the proliferation of wiretapping class actions, and the variety of approaches courts have taken to address them. One common pitfall for plaintiffs in these types of cases is standing, an issue highlighted in a recent Third Circuit case throwing out a proposed federal class action against Harriet Carter Gifts and NaviStone Inc., and remanding it to state court.
The case, Popa v. Harriet Carter Gifts, Inc., No. 25-1760 (3d. Cir. 2026), involved plaintiff’s allegations that Harriet Carter Gifts and NaviStone tracked her browsing activity on Harriet Carter’s website while she shopped for pet stairs, purportedly in violation of the Pennsylvania Wiretapping and Electronic Surveillance Control Act. After removal, the district court twice granted summary judgment for the defendants, and both decisions were appealed to the Third Circuit.
Continue Reading Stand Aside: Third Circuit Throws Out Harriet Carter Gifts Federal Wiretapping Case On Standing GroundsPennsylvania Court Dismisses WESCA Suit Alleging Use of Analytics Tools Against Health System, Requiring “Specifics” for an “Actionable Dispute”
Recently, a Pennsylvania federal judge dismissed a suit challenging the use of a third-party website analytics tool by defendant Highlands Healthcare, Inc., an integrated health system with eight hospitals in Pennsylvania. The Court concluded plaintiffs had failed to plead the “specifics” of their interactions with defendant’s website, which were “essential to convert [the] case” from a “law-school hypothetical to an actionable dispute” under the Pennsylvania Wiretapping and Electronic Surveillance Control Act (“WESCA”), the state law analog to the Federal Wiretap Act. Muraski v. Penn Highlands Healthcare, Inc., 2026 WL 353041 (W.D. Pa. Feb. 9, 2026).
Continue Reading Pennsylvania Court Dismisses WESCA Suit Alleging Use of Analytics Tools Against Health System, Requiring “Specifics” for an “Actionable Dispute”A Closer Look: The Discoverability of Artificial Intelligence Prompts
Are AI prompts, and their generative outputs, discoverable in litigation? A handful of recent district court cases suggest the answer depends on whether the AI prompts and outputs constitute attorney work product.
In Tremblay v. OpenAI, Inc., 2024 WL 3748003 (N.D. Cal. Aug. 8, 2024), the court held that AI prompts written by lawyers can constitute opinion work product when used for litigation-related purposes. The court explained that AI “prompts were queries crafted by counsel and contain counsel’s mental impressions and opinions about how to interrogate [an AI tool], in an effort to vindicate Plaintiffs’ copyrights against the alleged infringements.” In so doing, the court squarely rejected defendant’s argument that AI prompts and outputs only rise to the level of fact work product as opposed to opinion work product. That distinction is important, as opinion work product is offered near-absolute protection from disclosure whereas fact work product is discoverable upon a showing of substantial need for the materials and an inability to secure a substantial equivalent without undue hardship.
Continue Reading A Closer Look: The Discoverability of Artificial Intelligence PromptsWebsite Wiretapping Roundup: 2025 Decisions and Developments
In 2025, courts continued to issue significant decisions concerning the application of wiretap and privacy laws to pixels, session replay, and other website technologies. Over the past year, we have featured posts discussing claims regarding website analytics and advertising tools brought under the federal Wiretap Act, the California Invasion of Privacy Act (“CIPA”), the Video Privacy Protection Act (“VPPA”), and other laws. A selection of posts highlighting important developments in this area is below.
Continue Reading Website Wiretapping Roundup: 2025 Decisions and DevelopmentsSixth Circuit Denies Permission to Appeal Class Certification Order Raising Questions of Consent and Fail-Safe Classes
In many privacy and other technology-related class actions, the question of whether consumers consent to the practice at issue is central. In these cases, class action defendants have defeated motions for class certification by successfully arguing that consent is an individualized issue that is not susceptible to common proof. And though class action plaintiffs may try and avoid this problem by excluding consenting individuals from their class definition, that solution can create new problems, including impermissible “fail-safe” classes—i.e., classes that cannot be defined until a case is resolved on the merits.
Continue Reading Sixth Circuit Denies Permission to Appeal Class Certification Order Raising Questions of Consent and Fail-Safe Classes