Alerts

California Court Dismisses Website Tracking Lawsuit: What It Means for Companies Using Third-Party Analytics

New ruling highlights the potential limits of alternative privacy claims and the risks that remain for companies deploying tracking technologies
By Odia Kagan
Locked network laptop
Share on:

Key Points

  • If California's SB 690 limits CIPA claims, alternative causes of action are available but far from easy. A federal court dismissed intrusion upon seclusion, public disclosure of private facts, federal wiretapping, and unjust enrichment claims, finding that plaintiffs face significant hurdles when attempting to fit modern data collection practices into traditional legal theories.
  • The federal Wiretap Act's "crime-tort" exception remains a live risk for companies that are parties to communications. Courts have found the exception potentially applicable where data is used for an independently wrongful purpose, including conduct that allegedly violates HIPAA, privacy laws, or representations in a company's own privacy policy.
  • Sensitive data categories, especially children's information, continue to receive heightened scrutiny. While this court found that children's involvement did not change the outcome, regulators treat children's data as particularly sensitive, and businesses should not treat this ruling as a free pass.

A new decision from the U.S. District Court for the Central District of California in Reisberg v. Renaissance Learning may provide insight into what website and app tracking litigation could look like if California's SB 690 becomes law and limits certain claims under CIPA, the California wiretapping law.

The case involved Renaissance, a K-12 educational platform that schools required students to use. Plaintiffs, including children under 13, alleged that Renaissance collected and shared personal information through numerous third-party analytics, advertising, and identity-resolution technologies. They asserted a wide range of privacy, wiretapping, and unjust enrichment claims.

The court dismissed all claims without leave to amend. In doing so, the court repeatedly stated that plaintiffs were attempting to fit modern data collection and sharing practices into traditional common law causes of action, and the court was unwilling to expand those doctrines beyond their historical boundaries.

The case is notable for companies that deploy third-party trackers in their applications. It provides potential insight into three questions that are top of mind right now:

  • If SB 690 becomes law, how viable are the alternative causes of action plaintiffs have begun asserting alongside or instead of CIPA claims?
  • Does it matter whether tracking occurs only within a company's own website or application rather than across multiple websites?
  • Does the analysis change when the data belongs to children?

Alternative Claims Are Available, but Not a 'Slam Dunk'

If California SB 690 is signed into law, the wave of website tracking lawsuits may ebb, but there are still plenty of causes of action available to plaintiffs under California law, other state laws, and federal law.

This decision highlights, however, that those alternative causes of action come with their own significant hurdles.

Intrusion Upon Seclusion

These claims require more than the collection and disclosure of information on a company's own platform. Courts may look for evidence that the defendant intruded into a private place, conversation, or matter, such as by tracking users outside the platform or continuing tracking across other sites. Courts also require the intrusion of privacy to be done "in a manner which is highly offensive to a reasonable person." Routine practices, including the collection of internet browsing data and persistent identifiers, may not suffice. Courts frequently focus on the nature and sensitivity of the information at issue when determining whether the alleged conduct constitutes an egregious breach of social norms.

Public Disclosure of Private Facts

These claims may require more than sharing information with vendors, analytics providers, or advertising partners. Plaintiffs may face challenges showing both that the disclosure was sufficiently "public" and that the information disclosed was sufficiently intimate or sensitive.

Here, the court acknowledged that Renaissance allegedly shared information with numerous third parties, many of which were large and sophisticated companies. Nevertheless, it concluded that such disclosures were not equivalent to disclosure to the "public at large."

Plaintiffs also faced a second hurdle: showing that the information disclosed was sufficiently sensitive or intimate to be highly offensive to a reasonable person. The court pointed to examples from prior cases involving such disclosures, including dissemination of photographs of a decapitated corpse, disclosure of HIV status, improper use of mental health records, and information associating a person with sexual molestation, while acknowledging that less extreme facts could also potentially qualify.

However, the allegedly disclosed information largely consisted of information about how students interacted with Renaissance's platforms, including page visits, content interactions, and video content viewed through the platform. The court concluded that plaintiffs had not plausibly alleged disclosure of sufficiently intimate private facts to satisfy the claim.

Federal Wiretapping Claims

Claims under the federal Electronic Communications Privacy Act (ECPA) face the additional obstacle of the party exception, which generally shields a party to a communication from liability. Plaintiffs therefore may be required to invoke the crime-tort exception by showing that the interception was undertaken for an independent criminal, tortious, or otherwise wrongful purpose.

The court noted that courts are divided on whether the crime-tort exception applies when a defendant's primary motivation is financial gain, but appeared persuaded by the view that a profit motive does not automatically defeat application of the exception.

The exception has been found potentially applicable in situations involving any of the following:

  • Violations of HIPAA.
  • Disclosures that contradict representations made in a company's privacy policy.
  • Uses of intercepted information that independently violate state law, including privacy-related causes of action.

Here, however, the court found that plaintiffs failed to plausibly allege any independent criminal, tortious, or otherwise wrongful purpose, particularly after the court dismissed the underlying privacy claims.

Unjust Enrichment

These claims may require plaintiffs to establish not only that their information conferred a cognizable benefit, but also that there was an underlying wrongful act making retention of that benefit inequitable. The court was skeptical that the alleged collection of personal information alone was sufficient and further concluded that plaintiffs had failed to establish any underlying actionable wrong that would make retention of the alleged benefit unjust.

In short, while plaintiffs are increasingly asserting alternative claims alongside or instead of traditional CIPA theories, this decision demonstrates that those claims are far from a "slam dunk" and often involve elements that are substantially more difficult to satisfy.

Sensitive Information Will Always Be More Sensitive

Courts remain focused on the sensitivity of the information at issue. Health information, mental health data, financial information, and similarly sensitive categories of data continue to receive heightened scrutiny. By contrast, usage analytics, browsing behavior, and device identifiers may face greater challenges supporting common law privacy claims, at least absent additional facts.

Children's Information May Be Sensitive

While this court was not persuaded that the involvement of children materially changed the analysis, businesses should not view that holding as a free pass. Regulators, including the FTC, have consistently treated children's information as particularly sensitive, and children's privacy remains a significant enforcement priority.

On-Platform vs. Cross-Site Tracking

Courts may be more receptive to claims involving tracking that extends beyond a company's own website or app than claims involving data collection that occurs solely within the company's own platform. Here, the court rejected the claims despite the company having shared the information with third parties that use it for their own purposes. However, this conduct may still run afoul of privacy and consumer protection laws, and similar cases have been the subject of significant regulatory enforcement, especially when dealing with information of minors and children.


For more information, please contact Odia Kagan at 215.444.7313 or okagan@foxrothschild.com, or another member of our national Privacy & Data Security practice group.


This information is intended to inform firm clients and friends about legal developments, including the decisions of courts and administrative bodies. Nothing in this alert should be construed as legal advice or a legal opinion. Readers should not act upon the information contained in this alert without seeking the advice of legal counsel. Views expressed are those of the authors and not necessarily this law firm or its clients.