Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherBrowse by ChannelAbout the NetworkJoin the NetworkProductsSub-MenuProducts OverviewBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAbout UsContactSubscribeSupport
Book a Demo
Search
Close

When Satire Meets Statute: The Onion’s VPPA Class Action

By Roma Patel on June 5, 2025
Email this postTweet this postLike this postShare this post on LinkedIn

Video Privacy Protection Act (VPPA) class action lawsuits have been on the rise, and the owner of the The Onion, a popular satire site, finds itself the subject of a recent one. On May 16, 2025, a plaintiff-initiated litigation against Global Tetrahedron, LLC, the owner of The Onion, alleges that the defendant installed the Meta Pixel on its website, with host videos for streaming, without user knowledge.

The plaintiff alleges that, unbeknownst to consumers, the Meta Pixel tracks users’ video consumption habits “to build profiles on consumers and deliver targeted advertisements to them.” According to the complaint, the Meta Pixel is configured to collect HTTP headers, which contain IP addresses, information about the user’s web browser, page location, and document referrer (the URL of the previous document or page that loaded the current one). Since the Meta Pixel is reportedly attached to a user’s browser, “if the user accesses Facebook.com through their Safari browser, then moves to theonion.com after leaving Facebook, the Meta Pixel will continue to track that user’s activity on that browser.” The complaint also alleges that Meta Pixel collects a Meta-specific value called the c-user cookie, which is a unique user ID for users logged into Facebook. By combining the points of data collection, the complaint asserts, the Onion transmits personally identifiable information to Meta.

In a novel approach, the complaint uses screenshots of the plaintiff’s ChatGPT conversation to demonstrate how ChatGPT can help an ordinary user decipher what information is allegedly being disclosed to Meta through the Onion website. According to the screenshots, when the plaintiff asked ChatGPT how to check if a website was disclosing their browsing activity to Meta, the plaintiff was directed to use developer tools to inspect the page’s network traffic. Each internet browser has an integrated developer tool, which allows developers to analyze network traffic, measure performance, and make temporary changes to a page. Any website user can open the developer tool, as ChatGPT directed the plaintiff to do.

Following ChatGPT’s instructions, the plaintiff reportedly opened the developer tool page for the Onion website. Then, the plaintiff uploaded a screenshot of the Onion’s developer tool onto ChatGPT. ChatGPT analyzed the request in the screenshot and broke down the parameters contained within, including Pixel ID, Page Views, URL, and Facebook cookie ID. Many VPPA complaints in recent months have described the technical processes behind tracking technologies, but by using ChatGPT in this complaint, the plaintiff underscores how such large language model tools can help an average website user decipher seemingly complex technical concepts and better understand the data flows from tracking technologies.

The case reflects a broader trend in VPPA litigation, in which plaintiffs are challenging the use of third-party tracking technologies on sites that offer any form of video content. As VPPA litigation evolves, this case could peel back another layer of risk for publishers across industries providing video streaming content.

Photo of Roma Patel Roma Patel

Roma Patel focuses her practice on a broad range of data privacy and cybersecurity matters. She handles comprehensive responses to cybersecurity incidents, including business email compromises, network intrusions, inadvertent disclosures and ransomware attacks. In response to privacy and cybersecurity incidents, Roma guides clients…

Roma Patel focuses her practice on a broad range of data privacy and cybersecurity matters. She handles comprehensive responses to cybersecurity incidents, including business email compromises, network intrusions, inadvertent disclosures and ransomware attacks. In response to privacy and cybersecurity incidents, Roma guides clients through initial response, forensic investigation, and regulatory obligations in a manner that balances legal risks and business or organizational needs. Read her full rc.com bio here.

Read more about Roma PatelEmailRoma's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy & Data Security
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • Resource Center
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center
  • Blogging 101

New to the Network

  • Tennessee Insurance Litigation Blog
  • Claims & Sustains
  • New Jersey Restraining Order Lawyers
  • New Jersey Gun Lawyers
  • Blog of Reason
Copyright © 2025, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo