top of page

NYLJ “The Changing Landscape of Online Privacy Litigation: Personally Identifiable Information and Article III Standing in Federal Court”

2 days ago
9 min read

Updated: 15 hours ago

By Steve Kramarsky


Online privacy has long been a fertile topic for regulation and legal disputes, but over the past two years litigation in the area has exploded. In that time thousands of new cases have been filed (many of them putative class actions) and tens of thousands of pre-suit demand letters have been sent, all based on common website technologies designed to improve user experience, evaluate website performance, or select, deliver, and track ads. These claims, sometimes called “web tracker,” “tracking pixel” or “cookie” cases, focus on technologies that collect user information, such as the advertising trackers offered by Meta and X, or the website analytics captured by Google. They allege that the collection and use of that information by third parties is a violation of state privacy or wiretapping laws, most notably the California Invasion of Privacy Act (“CIPA”).


The Explosion of CIPA “Pen Register” Litigation


Thousands of these cases have been brought or threatened in recent months by a small handful of plaintiffs’ firms and pro se litigants, and the volume is only increasing. The most basic cases and demand letters, which are not limited to California businesses, currently focus on CIPA Section 638.51, a law passed in the 1960s to prohibit the use of warrantless pen registers or “trap and trace” devices on telephone lines. Under CIPA Section 637.2, anyone subject to a violation of Section 638.51 may pursue statutory damages of $5,000 per violation, without any showing of actual harm. CA Penal Code §§ 637.2, 638.51.


In 2023 and 2024, a few decisions from the California federal courts held that CIPA was not limited to telephone transmission hardware, and that software and website trackers could constitute “pen registers” under Section 638.51. Although these cases did not establish that the collection and transmittal of IP addresses alone was per se a violation of CIPA, they opened the door to that argument, and a flood of litigation followed. Essentially every website records at least some analytics and logs information about website visits, including IP addresses, regardless of what consent management tools are used and how they are configured. Those basic facts are easy to plead in a cookie-cutter complaint or demand letter, and this ease of pleading (coupled with statutory damages for each website visit) produced an explosion of CIPA “pen register” claims and demands so widespread that the California legislature has recently had to step in.  


On August 28, 2026, the California Legislature passed SB 690, which amends CIPA Section 637.2 to remove the private right of action “for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application,” leaving enforcement of the pen register section up to the Attorney General. The amendment is retroactive to actions filed in the last two years, and (assuming the Governor signs it) should eliminate the threat of cookie-cutter pen register claims that potentially target almost all online applications and websites, regardless of their content or privacy practices.

The Next Phase and a New York Analysis


While the amendment (if signed) will likely scale back the flood of threat letters designed to elicit quick, nuisance value settlements, it will not eliminate CIPA claims. CIPA Section 631, the main California wiretapping statute, remains unchanged. It prohibits making “any unauthorized connection,” to any electronic transmission medium to “attempt to read, or to learn the contents or meaning of any message, report, or communication” in or through California. This section of CIPA (like other state and federal privacy and anti-wiretapping laws) provides broad protection against the unauthorized interception of electronic communications, and most well drafted web privacy complaints will include a CIPA Section 631 or similar claim based on state privacy law.


The difference between these claims and the pen register claims is that they require a more detailed pleading of the kind of information collected, the use made of that information, the consent mechanisms in place, and related facts around the actual function of the website. Where pen register claims could (sometimes) survive a dispositive motion based on the simple allegation that a website collected IP addresses, these more complex claims are generally based on technologies designed to collect more specific information about the user or the user experience. These include advertising tracking pixels, website cookies, analytics platforms, session loggers (used to determine how visitors navigate the site), chat tools, and AI agents. These technologies collect data about the user (well beyond a simple IP address) and transmit it to a third party, which can be the basis for a privacy claim. Courts dealing with these cases face a series of threshold questions: What information was collected? How sensitive was it? How was it used? Was the user given appropriate notice and an opportunity to consent or opt out? Was the notice accurate, and did the consent mechanism function as expected?


In recent cases, some Courts have avoided the complex technical and factual issues around user notice and consent management with a more basic finding: that plaintiffs lacked standing to sue, due to lack of cognizable injury. In these cases, courts have examined the specific information collected and determined that it does not implicate a legally protected privacy interest sufficient to confer Article III standing. While courts in New York are divided on this argument, a recent decision from Judge Paul Engelmayer in the Southern District of New York, Hayward, et al. v. mParticle, Inc., et al., No. 25 CIV. 8173 (PAE), 2026 WL 2582794 (S.D.N.Y. Sept. 1, 2026), provides a detailed analysis of the issue and offers strong support for the defense under Second Circuit law, even where the claims in the complaint arise under CIPA.


Hayward: A CIPA Claim in the New York Courts


Hayward is, in many ways, a typical website privacy case. Hayward and the three other plaintiffs are California residents who use services and applications such as Venmo, Peacock, and the NBC App, which implement a user tracking system called IDSync, supplied by defendant mParticle, Inc. Defendants mParticle and its parent company Rokt US Corp. are Delaware companies headquartered in New York. Rokt also runs “an AI-powered e-commerce marketing platform” that selects and provides targeted advertising using the IDSync product. Id., at *1. Plaintiffs alleged that defendants captured their personally identifiable information (“PII”) from the services and applications they used, using it to build online profiles of them and serve targeted advertising to them. The complaint alleges violations of California data security and privacy laws (including CIPA §§ 631 and 638.51, among others) and the California state constitution.


Plaintiffs make extensive allegations about the mParticle IDSync system, and the opinion describes the system in detail. Essentially, according to the complaint, any time a person uses a participating website or application, mParticle’ s embedded software (or its interface code built into the website) captures the user’s “email, customer ID, or device identifier.” Id. This information is used to create a unique mParticle ID and associated profile for the user, which is built up over time from information captured across multiple websites and services visited by the user that participate in the mParticle system. As mParticle builds up data from “new inbound data streams” the profile for a given user can be supplemented to include “a user’s age, full name, gender, phone number, address, city, state, zip code, and country, plus event data reflecting specific actions the user has taken and the advertising audiences and campaigns to which the user has been assigned.” Id., at *2. Plaintiffs also allege that mParticle “enriches” the user data it collects from other available sources to build a more detailed user fingerprint, specifically regarding the user’s shopping habits and preferences.


Plaintiffs further allege that mParticle uses various techniques (such as CNAME cloaking, which masks the ultimate destination IP address for internet traffic) to hide its data collection and avoid privacy features such as “Do Not Track,” private browsing, and cookie blocking, and that it uses the collected data to power machine-learning models for predictive advertising. They allege that defendants integrate the IDSync product into various advertising platforms with which they share data for profiling, and that the value of the collected data is demonstrated by defendant Rokt’s purchase of mParticle for approximately $300 million. Id., at *3. 


Plaintiffs filed their complaint in federal court in the Northern District of California but defendants, headquartered in New York, successfully moved to transfer venue to the Southern District of New York. Defendants’ decision to move to transfer turned out to be dispositive, as the court, guided by Second Circuit precedent, dismissed the claims for lack of Article III standing.


The Standing Analysis in New York


The factual allegations in Hayward tell an unsettling story for anyone unfamiliar with modern device fingerprinting and ad profiling technology, but the reality is that some kinds of user information are collected routinely by websites and third parties even when privacy measures are in place. Before a court can address those systems and practices, it must answer the threshold question of whether the specific information at issue is legally protected. The mere allegation that the collected material constitutes PII is not enough to confer Article III standing, and without that standing the court has no basis even to reach defendants’ alleged conduct.


In Hayward, defendants moved to dismiss, asserting that the complaint did not “plead a cognizable injury in fact” required for standing. Id., at *5. Given this threshold issue, the Court first addressed an issue that neither party had briefed: what law to apply? Although the underlying claims in the complaint were a matter of California state substantive law, the Court held that Article III standing is “a quintessential question of federal law” and therefore Second Circuit case law, rather than that of the Ninth Circuit, would apply to the standing analysis.


Having made that decision, the Court examined the specific allegations in the complaint, all of which related to defendants obtaining and monetizing plaintiffs’ alleged PII, and considered several potential sources of legally cognizable injury.


The Court first examined potential injury for “Invasion of Privacy.” It held, however, that under Second Circuit law, the “personal information that the SAC alleges mParticle obtained from the named plaintiffs falls short of that required to make out an injury in fact.” Id., at *6. In its analysis, the Court reviewed the allegations relating to each named plaintiff and cataloged the information allegedly collected and classified by plaintiffs as PII. This information included names, email addresses, phone numbers, various unique user IDs and advertising IDs, and (for one plaintiff) video titles and IDs for some video content. Plaintiffs also alleged that mParticle was able to collect information about their Venmo payments, including the fact that they had made a payment, the recipient’s name and username, the amount of the transaction, and the accompanying “note” entered with the transaction.


In reviewing these classes of information, the Court noted that a plaintiff claiming injury from the disclosure of personal information must either demonstrate “actual injuries” from the disclosure or “a substantial risk of harm.” Since the complaint contains no assertion of actual injury to any plaintiff, the Court looked to the “substantial risk” standard which, in the Second Circuit, requires exposure of “highly sensitive” personal data that creates “a high risk of identity theft or fraud.” Id., at 7, citing McMorris v. Carlos Lopez & Assocs., LLC, 995 F.3d 295, 303 (2d Cir. 2021). Reviewing the recent case law in New York, the Court held that the specific allegations in the complaint could not meet this standard. It specifically noted that “[c]ourts in the Second Circuit have held that the disclosure of addresses, telephone numbers, email addresses, device identifiers, and the like are insufficient to support finding a cognizable injury.” 2026 WL 2582794, at 7-8 (collecting cases). As to the Venmo transactions, the Court held that the information allegedly disclosed (which did not include credit card information or passwords) was not likely to lead to a risk of future harm and thus could not support standing absent a claim of present injury.


The Court also considered and rejected two other potential sources of cognizable legal injury: “Intrusion Upon Seclusion” (a developing tort related to invasion of privacy that may occur when a complaint alleges interference with records “concerning the plaintiffs’ most sensitive private affairs,” id., at 11) and “Impact on Plaintiffs’ Devices.” The Court rejected the former, holding that the information at issue does not involve the “personal and intimate details about traditionally private elements of the lives of the named plaintiffs” as required by the existing case law in the Circuit. It rejected the latter because the allegation of harm from additional computational load imposed by tracking technologies on plaintiffs’ devices was too speculative or de minimis to support standing. As a result, the Court dismissed the complaint without prejudice for lack of subject matter jurisdiction.


The Changing Face of Privacy Litigation


The coming changes to California law (assuming SB-690 is signed), coupled with some recent decisions from California’s appellate courts, are likely to reduce or eliminate the flood of cookie-cutter pen register claims and demand letters, but there is no indication that online privacy litigation is otherwise slowing down. The lesson of Hayward and similar recent decisions is that, as these cases become more involved, the facts matter. Article III standing is not a magic bullet, and decisions on liability in these cases across jurisdictions have been highly variable and fact dependent. Courts look closely at what data was collected, how it was shared and used, and what disclosures and consents were in place.


Companies facing privacy litigation risk should thus be aware that their data collection and sharing practices may come under the legal microscope and should act accordingly, especially in industries that deal routinely with sensitive customer information, such as finance, e-commerce, and healthcare. Customer data collection, user tracking, consent management, advertising, and analytics are not especially sexy systems. They are often handed over to third party vendors for management, or deployed once, without legal consultation, and never reviewed or audited for ongoing compliance. In the current, shifting privacy landscape, that is a recipe for potentially costly liability. A series of best practices around privacy (including data minimization, functioning consent systems, appropriate policies, and timely auditing) can substantially limit risk if and when a demand letter comes.

This article first appeared in the New York Law Journal on September 14, 2026.

 
 

© 2026 Dewey Pegno & Kramarsky LLP                                                                                  

In some jurisdictions, this may be considered attorney advertising.

bottom of page