In the last 18 months, tens of thousands of pre-suit demand letters and thousands of lawsuits have been filed against companies for one thing: their websites work like every other website. Pixel litigation – claims that routine tracking technologies such as cookies, pixels, and session replay tools violate wiretapping laws – has become one of the fastest-growing and most aggressive areas of class action risk in the country. The message is clear: if your business has a website, you are at risk.
What started in California has spread nationwide, and the exposure is staggering. With statutory damages of $5,000 per violation, a single pixel firing across 100,000 page views could theoretically expose a company to $500 million in liability – no actual harm required. A recent California ruling has given defendants powerful new ammunition, but the best protection is still taking proactive measures to reduce your risk before a demand letter ever arrives.
What Is Pixel Litigation?
Pixel litigation challenges the use of common website tracking technologies as unlawful interception or recording of user communications.
The tools at issue typically include:
- Advertising pixels (for example, Meta, TikTok, and X)
- Analytics platforms (such as Google Analytics)
- Session replay tools (software that records how a visitor navigates and interacts with a page)
- Chat and form capture tools
These tools automatically collect data such as device identifiers, browser characteristics, IP addresses, routing information, and user interactions – sometimes before a user takes any affirmative action. Plaintiffs characterize this activity as the digital equivalent of:
- Wiretapping
- Eavesdropping
- Pen register surveillance
- Unauthorized recording of communications
- Invasion of privacy
The Legal Theories Behind the Claims
Pixel lawsuits follow a highly repeatable structure, asserting overlapping statutory claims:
- California Invasion of Privacy Act (CIPA) – § 631 (wiretapping); § 632 (eavesdropping); and § 638.51 (pen register/trap and trace)
- Federal Wiretap Act (ECPA)
- State wiretap statutes – for example, Pennsylvania (WESCA) and Florida (FSCA)
- Video Privacy Protection Act (VPPA) – which restricts sharing consumers' video-viewing data
- State consumer protection/unfair or deceptive acts or practices (UDAP) statutes
Plaintiffs do not need to prove they were actually harmed. Statutory damages alone – $5,000 per violation under CIPA – make these cases economically viable to file, even when no real injury occurred.
Enter NetScout: A Potential Inflection Point
The recent decision in Blaker v. NetScout Systems, Inc. is one of the most significant developments to date in this space. The plaintiff alleged that a website pixel collected routing and device-level data to create a "digital fingerprint" that was transmitted to a third party before consent was obtained. The court rejected the claim outright – not on technical grounds, but on statutory interpretation.
The court held that CIPA's pen register provision applies only to telephone communications, not to website activity. This is a critical shift. Prior cases often turned on whether a specific tool met the statutory definition; NetScout holds that the statute does not apply to websites at all. Because the theory failed as a matter of law, the court sustained a demurrer without leave to amend, resulting in dismissal with prejudice and making NetScout uniquely powerful compared to earlier, narrower defense wins.
What NetScout Changes – and What It Doesn't
What it changes:
- Undermines a core plaintiff's theory under § 638.51
- Supports early dismissal strategies
- Gives defendants leverage in settlement negotiations
What it doesn't change:
- It is not binding authority on other courts
- Courts remain split on similar issues
- Other CIPA provisions, especially § 631, remain active
- Consent remains the strongest practical defense
Bottom line: NetScout is a shield – not a safe harbor. Earlier defense wins often turned on specific technologies – whether a TikTok pixel qualified as a trap and trace device or whether a Meta pixel intercepted communications "in transit." NetScout moves the fight upstream – to the statute itself.
Legislative relief may also be coming. As we discussed in a recent alert, California Senate Bill 690 (SB 690) would amend CIPA to curb the litany of class action litigation targeting companies' use of cookies, pixels, and similar online tracking technologies – at least under some theories.
Article III Standing Dismissals
Article III standing has also developed into a formidable defense to CIPA class actions in federal court. In just the last few months, several cases have been dismissed for lack of standing:
- Crano v. Sojern, Inc: The plaintiff did not allege the collection of "personal" information analogous to the "highly offensive" interferences or disclosures actionable at common law. Allegations regarding how the defendant's technology theoretically works failed to establish an actual injury to the plaintiff.
- In re USA Today Co., Inc. Internet Tracking Litig.: Disclosure of IP addresses, location, browser type, and similar information was not highly offensive to a reasonable person, and no reasonable expectation of privacy existed for such unprotected disclosures. Allegations concerning "unique and persistent identifiers" were too vague to establish a concrete injury.
- Shah v. Talentbridge: Generic search terms on a public job site involved no protectable privacy interest and, thus, no Article III standing.
- Schallert v. Laird Superfood: Pleading what a pixel is capable of capturing is not the same as pleading what it actually captured, and the latter must be alleged to avoid dismissal for lack of Article III standing.
The Repeat Players Driving Pixel Litigation
Like many mass litigation trends, pixel litigation is not driven by the entire plaintiffs' bar. A relatively small group of firms and serial plaintiffs account for a disproportionate share of demand letters and lawsuits, including plaintiffs' firms Tauler Smith LLP, Swigert Law Group, and Manning Law, as well as pro se litigants such as Vivek Shah and Joseph Sides.
This repeat-player dynamic matters for your response strategy. These filers target many companies in rapid succession using similar or identical allegations, focus on widely deployed technologies, and use low filing costs to create settlement pressure. Defendants can expect predictable claims, rapid iteration in response to new case law, and fast escalation timelines. Recognizing the firm or plaintiff early can materially change both strategy and outcome.
This is particularly so with respect to Vivek Shah—perhaps the most prolific serial digital privacy litigant in the nation—who was just ruled a vexatious litigator by a California federal court and barred from filing any new action asserting CIPA or similar causes of action without prior court approval. Shah v. Crane Commn's, Inc., No. 26 CV 3070 (C.D. Cal. July 20, 2026), Dkt. No. 34. This development is a significant win for the countless number of companies who have been on the receiving end of extortion-style demand letters and complaints alleging the ubiquitous use of web analytics and marketing tools violate CIPA and other digital privacy statutes. Post-Crane, defendants now hold powerful, judicially endorsed leverage against Shah-style shakedown demands. But the decision does not resolve the merits of CIPA's application to website tracking, and the outsized liability exposure generated by digital privacy class actions remains – making comprehensive compliance and risk mitigation, guided by experienced outside privacy counsel, as essential as ever.
We have defended and resolved cases against nearly all of these filers. In one recent matter, we secured early dismissal for a retail client facing a CIPA § 638.51 demand by leveraging the NetScout holding before the case progressed to costly discovery. In another, we resolved a session replay claim for a health care company at a fraction of the initial demand by demonstrating factual defenses the plaintiff had overlooked.
The Plaintiff's Playbook
Despite the variety of claims, most pixel cases follow a predictable lifecycle:
- Technical reconnaissance: Plaintiffs and their counsel use browser developer tools or automated scanners to identify tracking technologies and third-party data flows on a company's website.
- Evidence packaging: Screenshots, network logs, and code snippets are compiled – often framed as proof of "interception" or data transmission.
- Demand letter: A pre-suit letter asserts statutory violations, often attaches a draft complaint, and emphasizes potential damages.
- Settlement pressure: The demand leverages statutory damages exposure and litigation costs to push for early resolution.
- Litigation or abitration: If unresolved – or unanswered – the plaintiff files suit or initiates arbitration, often with minimal changes to the draft complaint.
If You've Already Received a Demand Letter
If a demand letter is already on your desk, time is critical. Here's what to do – and what not to do:
- Consult counsel before responding: Most demand letters include tight response deadlines designed to pressure quick settlements. Responding without experienced counsel – or ignoring the letter entirely – can both create problems. Contact experienced privacy litigation counsel first.
- Preserve evidence immediately: Place a litigation hold on all website configurations, consent logs, privacy policies, and cookie/pixel deployment records as of the date of the alleged violation. This evidence is essential to both the defense and any potential counterclaims.
- Assess your actual exposure: The statutory damages figures in demand letters are often wildly inflated. An experienced litigation team can quickly assess whether the claims have merit, which defenses apply, and what realistic exposure looks like.
- Act within 48 – 72 hours: Early engagement with outside counsel creates options – including potential pre-suit resolution – that disappear once litigation is filed.
Practical Implications for Businesses: Six Steps to Shrink Your Liability Footprint
Companies that have not received a demand letter should act now – both to reduce the odds of getting one and to strengthen their defenses if they do. Here's how:
- Inventory and map all tracking technologies: Audit every cookie, pixel, software development kit (SDK), session replay tool, chatbot, and analytics script across all websites and mobile apps, documenting what each collects, when it fires, and which third parties receive the data. Automated scans frequently surface "shadow" tags deployed without legal review; because marketing teams add tags continuously, inventories should be refreshed regularly.
- Configure consent management to actually block trackers: The core allegation in most CIPA suits is that trackers transmitted data before the visitor consented. A cookie banner alone is insufficient if non-essential trackers fire on page load; a properly configured consent management platform must block them until the visitor affirmatively opts in, with auditable consent logs. Because the operative question is "whether the user agreed to the specific use or collection," consent language should specifically identify third-party disclosures, not merely first-party collection.
- Align privacy disclosures with actual practices: Privacy policies and cookie notices should accurately describe the tracking technologies in use, the data collected, and the third parties that receive it. Gaps between disclosures and real-world data flows are a central theory in these class actions – and can independently create liability under California's Unfair Competition Law (UCL) and similar state consumer protection statutes.
- Scrutinize high-risk tools: Session replay, chat, and pixels on sensitive pages carry the greatest CIPA § 631 exposure because they can capture the substance, i.e., "content," of user communications. Suppress keystroke and form-field capture, redact free-text inputs, and keep third-party trackers off pages where users submit sensitive information. That is the lesson of recent health care pixel cases, including In re Meta Pixel Healthcare Litig., 647 F. Supp. 3d 778 (N.D. Cal. 2023).
- Practice data minimization: Configure analytics and advertising tools to collect only what the business actually uses, enabling IP truncation, restricted data processing modes, and limited retention where available. Data that is never collected cannot support a claim, and minimization simultaneously advances compliance with the California Consumer Privacy Act (CCPA) and many other consumer privacy laws that now make data minimization a mandatory legal obligation.
- Monitor the landscape and calendar recurring audits: Track evolving CIPA case law and the plaintiffs' bar's ongoing pivot to new theories under the California Comprehensive Computer Data Access and Fraud Act (CDAFA), federal Wiretap Act, and the Video Privacy Protection Act (VPPA). A compliance program validated against last year's opinions may not withstand this year's.
Industry-Specific Considerations
While pixel litigation affects virtually every company with a website, certain industries face heightened exposure, including:
- Health care: Following Meta Pixel Healthcare, health care providers, telehealth platforms, and health technology companies face acute scrutiny. Pixels on patient portals, appointment scheduling pages, and symptom checkers create compounded HIPAA and CIPA exposure.
- Financial services: Banks, fintechs, and insurance companies collecting sensitive financial information through online applications and account portals are prime targets, particularly under CIPA § 631 theories focused on the "content" of communications.
- E-commerce and retail: Heavy reliance on advertising pixels (Meta, TikTok, Google) for conversion tracking and retargeting creates broad exposure. Session replay tools used to analyze shopping behavior add additional risk.
- Media and publishing: VPPA claims targeting video content, combined with extensive AdTech integrations, make media companies frequent targets – particularly where video-viewing data is shared with third-party platforms.
The Bottom Line
Pixel litigation is not a passing trend – it is a structural shift in privacy enforcement. Companies should assume that claims will continue to expand, theories will continue to evolve, and plaintiffs will keep refining their playbooks. The companies best positioned to defend these cases are those that treat website tracking as a core legal and compliance issue, not a background technical function.
How We Can Help
Baker Donelson's privacy team has defended dozens of pixel litigation matters and advised hundreds of companies on website compliance, tracking technology audits, and litigation readiness. We know the repeat plaintiffs, we know their playbooks, and we know how to win – or resolve cases efficiently when aggressive yet measured litigation is not the right answer. If you've received a demand letter or a complaint, or if you want to get ahead of this risk, contact the authors directly – Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP; Alex Koskey, CIPP/US, CIPP/E, PCIP; and David Oberly – or another member of Baker Donelson's Data Privacy and Cybersecurity, Digital Marketing, AdTech, and Consumer Privacy Compliance, or Privacy Litigation Teams.