Skip to Main Content
Publications

CIPA Class Certification Denied: What Lewis v. Magnite Means for Website Operators

Web tracking remains the most active frontier in privacy class action litigation, with thousands of lawsuits targeting companies that deploy cookies, pixels, and similar technologies on consumer-facing websites. The latest wave contends that these ubiquitous tools violate the California Invasion of Privacy Act's (CIPA) prohibition on "pen registers" and "trap and trace devices." Until now, those battles have been fought at the pleading stage, not at CIPA class certification.

That changed with Lewis v. Magnite, Inc., 2026 WL 2254788 (C.D. Cal. July 20, 2026), one of the first major decisions to test whether CIPA website tracking claims can be certified for class treatment. The Magnite court denied certification of proposed classes targeting Magnite's ad tech tracking cookie, holding that individualized questions of class member identification, consent, standing, and damages overwhelmed any common issues.

The main takeaway: Magnite demonstrates that even where CIPA claims survive the pleadings, Rule 23 poses a formidable barrier to classwide liability, though the decision leaves the underlying litigation risk fully intact, making proactive compliance as critical as ever.

Magnite: Individualized Issues Doom CIPA Class Certification

Magnite, a supply-side platform in the digital advertising ecosystem, assigns website visitors a "Khaos ID," an alphanumeric string unique to a visitor's device and browser combination, stored in its "Khaos Cookie" on the user's browser. When a visitor opens a participating webpage, the Khaos ID can be transmitted back to Magnite through real-time bidding and matched against third-party identifiers to facilitate targeted ads. The Magnite plaintiffs alleged that this architecture operates as an unlawful pen register under CIPA § 638.51, alongside additional CIPA and federal wiretapping claims, and invasion of privacy and unjust enrichment theories. They sought certification of a California Pen Register Class, defined as all California residents who had the Khaos Cookie installed on their devices, together with California and nationwide classes of individuals from whom Magnite collected personally identifiable information (PII). The court found numerosity, adequacy, and commonality satisfied, the latter based on the single common question of whether the Khaos Cookie constitutes a pen register under CIPA.

From there, however, the plaintiffs' motion unraveled. The court held the lead plaintiff was typical only of the Pen Register Class. The other two classes required proof that Magnite collected PII, yet the plaintiffs offered no evidence of what information Magnite actually collected about the lead plaintiff. Tellingly, Magnite could identify data associated with the lead plaintiff only after he located the Khaos ID on his own browser, with the help of a retained expert, and provided it to Magnite to search its records.

The centerpiece of the ruling was predominance, where the court identified four independent grounds for denial. First, determining who is even in the class would require user-by-user inquiries. Whether a Khaos Cookie was ever set depends on the browser used, its privacy settings, and whether the specific page visited was configured to request the Khaos ID at all. A single individual could have multiple Khaos IDs, while multiple individuals sharing a device could have the same one. And because Magnite operates pseudonymously, it "does not know who is behind a given alphanumeric string," the plaintiffs offered no feasible classwide method of identifying members.

Second, consent. Putative class members visited many different websites with materially different privacy policies, cookie banners, and disclosure practices. What disclosures each class member encountered, whether they agreed, and how they understood them would require individualized adjudication, precisely the analysis that defeated certification in In re Google RTB Consumer Privacy Litig., 2024 WL 2242690 (N.D. Cal. Apr. 4, 2024), and Calhoun v. Google LLC, 349 F.R.D. 588 (N.D. Cal. 2025).

Third, standing. Citing a recent Ninth Circuit decision involving a technology company, the court reiterated that a statutory violation alone does not confer Article III standing. The plaintiffs offered no method for evaluating concrete harm on a classwide basis, nor any evidence that Magnite collected PII like names, phone numbers, or email addresses in the first place.

Fourth, damages. The plaintiffs asserted that Magnite's records would identify the number of individuals whose information was collected but offered no evidence or expert methodology to support that claim, in contrast to the detailed classwide models credited in Rodriguez v. Google LLC, 2024 WL 38302 (N.D. Cal. Jan. 3, 2024). Without a viable classwide damages methodology, certification failed under Comcast Corp. v. Behrend, 569 U.S. 27 (2013). For the same reasons, a class action was not a superior method of adjudication.

Magnite Is Not an Outlier: Four Courts, One Pattern

Over the past several months, three other federal courts, on both coasts, have refused to certify website tracking privacy classes on strikingly similar grounds:

  • In a recent case involving a national financial services company, the court denied certification because what information was actually transmitted, whether each user consented to a varying mix of disclosures, and whether each suffered a concrete injury all demanded individualized proof.
     
  • In In re Meta Pixel Tax Filing Cases, 826 F. Supp. 3d 1217 (N.D. Cal. 2026), the court reasoned that individualized questions as to what "data" was collected from each class member through the Meta Pixel precluded class treatment. The Meta Pixel court also highlighted the critical difference between the collection of any data, IP addresses and generic URLs, for example, and the collection of sensitive data. In many website tracking class actions, only the latter is sufficient to constitute a cognizable injury conferring standing.
     
  • And most recently, in Cobbs v. PetMed Express, Inc., 2026 WL 2234135 (S.D. Fla. July 31, 2026), the court dismissed for lack of standing without reaching Rule 23, after discovery showed the named plaintiffs never read privacy policies and freely shared the same information publicly.

Read together with Magnite, these decisions confirm that class certification, not the pleadings, is now the decisive battleground in website tracking litigation. The same structural defects recur across jurisdictions and technologies: plaintiffs cannot show on a classwide basis what data was actually captured, or who was concretely harmed. Cobbs adds a further weapon, demonstrating that discovery into named plaintiffs' actual privacy practices can unravel standing that survived the pleading stage and end the case entirely.

For defendants, the four rulings supply a coordinated, multi-jurisdictional playbook; for the plaintiffs' class action bar, they are a warning that artfully pleaded allegations will not withstand evidentiary scrutiny. But none of these decisions slows the pace of new filings, and none relieves companies of the compliance imperative discussed below.

Business Implications

Lewis v. Magnite is a categorically different kind of defense victory than the pleading-stage wins attacking the viability of § 638.51 theories that preceded it. Magnite establishes that even when those theories survive, Rule 23 supplies a second, and perhaps more formidable, line of defense.

The decision also exposes the pseudonymity paradox at the heart of ad tech class actions: the anonymity plaintiffs decry is precisely what defeats certification. Where a defendant genuinely cannot link its identifiers to real-world identities, neither can plaintiffs identify class members, prove classwide collection of PII, establish concrete harm, or model damages. Defendants are well-advised to mine Magnite for its defense roadmap.

That said, Magnite should not be overread. It is a district court decision, not binding precedent, and a certification denial does not extinguish individual claims, or stem the tide of new filings and pre-suit demand letters, though defendants have gained ground there too, with a serial CIPA plaintiff declared a vexatious litigant in July. Courts also continue to reach conflicting conclusions on CIPA's scope, as illustrated in the Camplisson decision green-lighting pen register claims and another recent decision allowing a CCPA claim to proceed past the motion to dismiss stage. Companies should treat Magnite as a powerful shield to raise in litigation, not a license to pause or relax compliance.

What to Do Now: Strategic Compliance and Risk Mitigation

While the CIPA landscape remains in flux, companies with any digital presence should work with experienced privacy counsel to integrate the following priorities into comprehensive compliance programs:

  1. Sensitive data safeguards. Sensitive data has emerged as a prime target of the plaintiffs' class action bar, privacy regulators like the California Attorney General, whose July 2025 ruling we addressed in this alert, and state legislatures alike. Many of the largest recent CIPA settlements have involved sensitive data, including Kaiser Permanente (up to $47.5 million) and Aspen Dental ($18.7 million). States are simultaneously moving to prohibit sensitive data sales and transfers outright, which carries penalties of $50,000 per record. Map every category of sensitive data you collect, prevent website tracking tools from capturing it wherever feasible, and subject any collection, use, or sale of sensitive data to the highest level of compliance rigor.
     
  2. Affirmative, meaningful consent. Consent remains the strongest practical defense to website tracking claims of any stripe. Deploy clickwrap consent mechanisms, tested before launch to confirm that no tracking technologies "drop" or "fire" until consent is affirmatively manifested.
     
  3. Transparent disclosures. Privacy policies and notices must clearly and conspicuously identify all tracking technologies in use, including third-party cookies and identifiers deployed through the ad tech supply chain, and must accurately reflect actual data practices.
     
  4. Vendor management. Pay careful attention to third-party vendors and how they process and share the data that flows through tracking technologies. Ensure contracts with ad tech partners and other vendors require compliance with applicable law, limit data use, bar unauthorized sharing of PII, and include indemnification obligations.

The Final Word

Magnite confirms that the structural realities of pseudonymous ad tech tracking make CIPA website tracking claims exceptionally difficult to certify, handing defendants a potent new weapon in the class action fight. But with filings continuing at high volume and conflicting rulings still being issued, litigation exposure tied to everyday website tracking tools remains substantial. Companies that pair the Magnite defense playbook with robust, proactive compliance will be best positioned to avoid becoming targets, and to defeat the claims that do arrive.

Who companies choose to guide them matters just as much. The measures outlined above deliver their full protective value only when designed with the courtroom in mind, built to withstand the pleading-stage, certification, and settlement-driving pressures that decisions like Magnite, Cobbs, Ingraham, and Meta Pixel now define. Companies must partner with experienced privacy counsel who bring deep, real-time knowledge of privacy class action litigation trends, not merely regulatory advisors, to design, pressure test, and, when necessary, defend their compliance programs.

How Baker Donelson Can Help

Baker Donelson's Privacy Litigation team has significant experience defending federal Wiretap Act, CIPA, FSCA, WESCA, and similar digital privacy class actions and pre-suit demand letters involving repeat plaintiffs' firms and pro se litigants in this space. We have also advised hundreds of companies on website compliance, risk mitigation strategies, and litigation readiness. If you have received a demand letter or a complaint, or want to proactively get a step ahead of this risk, contact David Oberly or another member of Baker Donelson's Data Privacy & Cybersecurity, Digital Marketing, AdTech, & Consumer Privacy Compliance, or Privacy Litigation teams.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept