Why It Matters: Web tracking litigation has come to dominate the privacy class action landscape, leaving companies across industries scrambling to assess their exposure. Recently, the threshold question in these disputes has shifted from statutory coverage to constitutional standing: whether the plaintiff suffered any concrete injury at all. The dismissal of one such class action for this very reason marks a significant win for companies with websites and litigants alike (and a clear illustration that the standing inquiry now turns on the content of the data collected by trackers, not the sophistication of the technology responsible for the collection). A plaintiff who cannot show that trackers captured information that is "embarrassing, invasive, or otherwise private" cannot maintain a federal web tracking suit, no matter how many tracking technologies he or she catalogues.
The Case
In Magliocca v. United Healthcare Servs., Inc., No. 2:25-cv-03388, 2026 WL 2444750 (E.D. Cal. Aug. 19, 2026), a California federal court dismissed with prejudice a putative web tracking class action involving a health insurance and benefit plan provider's purported deployment of more than 150 third-party tracking technologies on its website. The court held that even detailed allegations of session recording and canvas fingerprinting on a consumer-facing website cannot establish an Article III injury-in-fact where the substance of the information collected amounts to nothing more than generic, publicly available browsing activity.
The Popa Framework
Popa v. Microsoft Corp., 153 F.4th 784 (9th Cir. 2025), is the controlling lens. There, the Ninth Circuit held generalized allegations of privacy injury are constitutionally insufficient to confer standing in web tracking cases. Intangible harms can qualify, but under Spokeo, Inc. v. Robins, 578 U.S. 330 (2016), they must bear a close relationship to harms traditionally recognized in common law, and the common law privacy torts require interferences or disclosures that would be "highly offensive to a reasonable person." Where trackers collect routine website interaction data (mouse movements, clicks, keystrokes, URLs visited), the collection is, in the Ninth Circuit's memorable analogy, more akin to "a store clerk's observing shoppers in order to identify aisles that are particularly popular or to spot problems that disrupt potential sales" than to an actionable intrusion. Popa, 153 F.4th at 791.
The dividing line the case law has drawn since is between single-site observation of non-sensitive browsing, on one hand, and the collection of genuinely sensitive content or the compilation of what the Ninth Circuit has called a "cradle-to-the-grave profile" of personal information gathered across the internet over extended periods of time, on the other.
The Magliocca Decision
The Magliocca plaintiff visited the defendant's website after clicking on an advertisement to research Medicare supplement coverage. During her visit, she entered her ZIP code, viewed plans available in her county, and clicked on "Plan G" and Medicare plans "endorsed by AARP." The plaintiff, however, ultimately chose not to enroll or begin the enrollment process, thus ending her brief engagement with the website. Based on these unremarkable allegations, she brought a putative class action alleging violations of the California Invasion of Privacy Act (CIPA), federal Electronic Communications Privacy Act (ECPA), California Comprehensive Computer Data Access and Fraud Act (CDAFA), and the right to privacy enshrined in the California Constitution.
Following the dismissal of her original complaint for lack of a constitutionally sufficient injury-in-fact, the plaintiff escalated her allegations considerably in her amended pleading, claiming the defendant deployed "155 third-party trackers, including 47 cookies, 19 different canvas fingerprints, and one session recorder" supplied by a host of different vendors. Tracking the Ninth Circuit's guidance in Popa, the plaintiff also reframed her injury as the common law torts of intrusion upon seclusion and unauthorized disclosure of private information, alleging the trackers' collection of her "private health-insurance interests and financial-coverage preferences" was highly offensive and produced downstream injuries in the form of targeted advertising for health insurance products.
The court was not swayed. Applying Popa, it emphasized that intangible privacy harms confer standing only where the information collected is "embarrassing, invasive, or otherwise private." The only information the plaintiff actually entered was a ZIP code; everything else was browsing activity involving "publicly available health information" about generic insurance plans she never purchased. The court dismissed the action with prejudice. As the court put it: "[t]his case begins and ends with standing."
What It Means for Your Business: Impact and Implications
For web tracking defendants, Magliocca is a game-changer, serving as proof that the Popa standing framework can shut down even health care-related class actions at the threshold, despite plaintiffs' favorite argument that anything touching health is inherently sensitive. The court squarely rejected that premise: browsing publicly available plan information does not "reflexively" become private because the operator is a health insurer, and an age-related inference from clicking AARP-endorsed Medicare plans does not create the "cradle-to-the-grave profile" of sensitive information the Ninth Circuit requires for a concrete injury.
Key Takeaways
Four features of the court's reasoning deserve particular attention:
- Content controls, not method. Allegations cataloguing sophisticated tools, such as session replay, canvas fingerprinting, and dozens of cookies do not establish standing unless sensitive data is actually collected or disclosed.
- Health-adjacent is not health data. Generic browsing of publicly available insurance plan pages, plus a ZIP code, is not "embarrassing, invasive, or otherwise private."
- Demographic inferences are not enough. Even an inference of a user's age bracket from Medicare browsing failed to establish a concrete injury.
- Standing challenges can end cases outright. With plaintiff's counsel unable to proffer curative allegations, dismissal was entered with prejudice.
What to Do Now: Strategic Compliance and Risk Mitigation
Website operators, particularly health care and financial services entities, should treat Magliocca as a map of where liability exposure begins and engage experienced outside counsel early to evaluate risk. Counsel with deep experience in web tracking litigation can help companies navigate the evolving Popa standing framework, identify vulnerabilities before plaintiffs do, and build a defensible compliance posture.
Companies should work with their legal teams to take the following proactive steps:
- Tracker auditing. Inventory every third-party tracker, pixel, session replay tool, and fingerprinting technique running on websites, mobile apps, and other digital properties. Separately, map what each tracker actually captures and transmits, and classify it by sensitivity (with particular attention to authenticated pages, search fields, forms, and chat features).
- Sensitive data protocols. Wall off sensitive user journeys from third-party trackers (or obtain robust, documented consent before they fire).
- Disclosures. Update privacy policies, cookie disclosures, and consent management platforms to accurately reflect tracking practices.
- Vendor management. Ensure vendor contracts impose stringent data use limitations, indemnification obligations, and litigation cooperation requirements.
- Litigation response playbooks. Build standing-based dismissal arguments into litigation response playbooks (Popa and Magliocca supply the roadmap).
How Baker Donelson Can Help
Baker Donelson's Privacy Litigation Team has significant experience defending federal Wiretap Act, CIPA, FSCA, WESCA, and similar web tracking/digital privacy class actions and pre-suit demand letters involving repeat plaintiffs' firms and pro se litigants in this space. We have also advised hundreds of companies on web compliance, risk mitigation strategies, and litigation readiness. If you have received a demand letter or a complaint, or want to protectively get a step ahead of this risk, contact David Oberly, Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP, or another member of Baker Donelson's Data Privacy and Cybersecurity, Digital Marketing, AdTech, and Consumer Privacy Compliance, or Privacy Litigation Teams.