Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Privacy Litigation Report: Takeaways From August 2026 Decisions

By Dustin Taylor on September 22, 2026
Email this postTweet this postLike this postShare this post on LinkedIn
Blogs_PrivacyCyberAI_OG_PrivacyLitigationReport

Table of Contents

  • 1. One Judge Concludes § 631 Does Not Apply to the Internet
  • 2. A Cookie Banner That Merely Points to a Privacy Policy Did Not Establish Consent
  • 3. A Banner That Allegedly Fails to Honor an Opt-Out Can Support a § 632 Claim
  • 4. The Privacy Policy Must Describe What the Tracking Technologies Actually Do

Key point: Four takeaways from August decisions: (1) a federal magistrate judge concluded CIPA § 631 does not apply to internet communications but that § 632 does; (2) a cookie banner that merely pointed to a privacy policy did not establish consent to third-party data sharing; (3) a banner that offers, but fails to honor, users a choice can supply the “confidential communication” element of a § 632 claim; and (4) a consent defense depends on whether the privacy policy actually describes the third-party disclosures that tracking technologies make.

Welcome to our monthly update on how courts across the U.S. have handled privacy litigation involving website tools such as cookies, pixels, session replay, and similar technologies. In this post, we cover decisions from August 2026. We are focusing on statutes that would not be impacted by the pending Senate Bill 690 (SB 690), which has passed the California Assembly and Senate and was sent to Governor Gavin Newsom for signature. Although SB 690 provides sweeping reform for defendants facing pen register and trap and trace claims under California law, it leaves §§ 631 and 632 untouched, along with every non-CIPA theory, including claims brought under the ECPA, CDAFA, and the California constitutional right to privacy, among them. The plaintiffs’ bar is widely expected to refocus on those theories, and the four takeaways from August decisions discussed below preview how that shift may play out, including where the fights over §§ 631 and 632 will occur, and why cookie banners and privacy policies will carry even more weight than they do today.

Many courts are currently handling data privacy cases across the U.S. Although illustrative, this update is not intended to be exhaustive. If there is another area of data privacy litigation you would like to know more about, please reach out. The contents provided below are time-sensitive and subject to change. If you are not already subscribed to our blog, consider doing so to stay updated. If you are interested in tracking developments between blog posts, consider following us on LinkedIn.

Link to 1. One Judge Concludes § 631 Does Not Apply to the Internet 1. One Judge Concludes § 631 Does Not Apply to the Internet

Most courts continue to apply § 631 to website tracking without giving serious consideration as to whether a 1967 wiretapping statute reaches internet communications at all. Three of this month’s four decisions followed that path, allowing § 631 claims premised on pixels to proceed without addressing the threshold question.

An August 3 findings and recommendations from a Magistrate Judge in the Eastern District of California reached a different conclusion. In that case, the plaintiff alleged that she booked a chiropractic appointment through a website that transmitted her name, phone number, email address, and clinic selection to several third parties. After inviting supplemental briefing on the question, the court concluded that § 631(a) does not apply to internet communications. As to the first clause, the court adopted Judge Bybee’s concurrence in an unpublished 2025 Ninth Circuit decision, which reasoned that the clause’s text, legislative history, and later amendments, together with the Legislature’s enactment of the CCPA to address online privacy, foreclose applying a provision directed at “telegraph or telephone” wires to the internet. As to the second clause, the court relied on a 2025 Northern District of California decision invoking the rule of lenity: because § 631 is a criminal statute, and because courts’ interpretations in civil cases shape criminal exposure, ambiguity in its reach should be resolved narrowly. The court found further support in two recent Los Angeles Superior Court decisions declining to extend CIPA’s pen register and trap-and-trace provisions to website tracking tools, reasoning that the Legislature knows how to reference internet communications when it wants to. Finally, it discounted the frequently cited 2022 Ninth Circuit memorandum, Javier v Assurance IQ, which stated § 631(a) applies to internet communications, characterizing that statement as unreasoned and nonprecedential.

Two things temper the decision’s reach. It is a magistrate judge’s recommendation subject to de novo review by the district judge, and the § 631 analysis is an alternative ground. The court itself also acknowledged that the question remains open, recommending leave to amend so the plaintiff could preserve the claim. Notably, the same court refused to extend that reasoning to § 632, calling the argument that § 632 does not reach internet cases “patently untrue.” The court noted the Legislature’s 2017 enactment of § 632.01, which expressly contemplates disclosure of confidential communications through websites and social media.

Link to 2. A Cookie Banner That Merely Points to a Privacy Policy Did Not Establish Consent 2. A Cookie Banner That Merely Points to a Privacy Policy Did Not Establish Consent

An August 7 decision from the Northern District of Illinois involved a health insurer’s public website that allegedly duplicated users’ HTTP requests and sent them to TikTok, Meta, Google, and LinkedIn through embedded pixels. The site’s cookie banner stated, in its entirety:

“We use cookies on this website to give you the best experience and measure website usage. By continuing to use this website, you consent to these cookies. For more information, view our privacy policy.”

The linked privacy policy disclosed that the operator may use pixel tags to track user actions and that social networking sites such as Facebook, Instagram, or LinkedIn could record a user’s visit and use that information to serve relevant ads.

The court first concluded that the policy’s content covered the challenged conduct. The court rejected the argument that the policy needed to specify that shared data might be health-related, finding that on an insurer’s website, all browsing necessarily relates to healthcare.

But the court also found there was no basis to conclude that the plaintiffs assented to the policy. The plaintiffs characterized the policy as a browsewrap that failed because the banner told users they were consenting to “these cookies,” not to the policy’s terms.

The court agreed with the plaintiffs, finding implied consent means consent in fact, not constructive consent, and a banner that tells users a privacy policy exists is not enough. As the court put it, users must have encountered “some indication, in the cookie banner or elsewhere, that at least suggested the kind of third-party data sharing at issue here.” Because the banner said nothing about third-party sharing, the consent defense failed.

Consent is a defense to §§ 631 and 632 regardless of what happens to § 638.51, and it will become a more central battleground as plaintiffs consolidate around those provisions. This decision suggests that the defense turns not only on what the privacy policy says but on whether the banner itself signals that data flows to third parties.

Link to 3. A Banner That Allegedly Fails to Honor an Opt-Out Can Support a § 632 Claim 3. A Banner That Allegedly Fails to Honor an Opt-Out Can Support a § 632 Claim

An August 12 decision from the Southern District of California addressed the opposite banner design: one that offered users a choice. The home décor retailer’s banner, headed “We value your privacy,” explained that the site used cookies and tracking technologies and offered a “Cookie Settings” button through which users could reject optional targeting technologies. The plaintiff alleged that she clicked “Cookie Settings,” rejected the optional cookies, and then browsed rug listings and searched for “rugs” and third-party trackers nonetheless intercepted her search terms, product views, and cart activity.

The court found the “confidential communication” element of CIPA § 632 satisfied by the opt-out alone. Because the plaintiff rejected the optional tracking cookies, she plausibly expected that her communications would not be intercepted.

This decision shows the importance of not only having a banner, but ensuring it works appropriately. Although merely searching for rugs — or as in the first decision we covered, submitting contact information and a clinic choice — may be routine browsing behavior, a malfunctioning banner can transform those communications into “confidential” communications.

Link to 4. The Privacy Policy Must Describe What the Tracking Technologies Actually Do 4. The Privacy Policy Must Describe What the Tracking Technologies Actually Do

An August 13 decision from the Northern District of California involved a telehealth platform that connects users seeking prescription skin treatments with physicians. The plaintiff alleged that she answered a series of questions about her skin condition to obtain a prescription and that third-party pixels on the site transmitted that information to third parties.

The website owner argued that its privacy policy disclosed collection of the very information at issue. The court set aside the parties’ dispute over whether the plaintiff had adequate notice of the policy, holding that even assuming notice, the policy did not disclose that health information would be sent to third parties because the policy’s only provision concerning disclosure, as opposed to collection, suggested the website would not disclose the information to tracking technology companies:

“With your consent, [the company] will share your Medical Information via confidential channels to a doctor or other medical professional regarding your diagnosis and treatment.”

The policy’s pixel section fared no better. It described automatic recording of “certain technical information” about user interactions but said nothing about disclosure to third parties.

For health care and wellness websites in particular, the gap between what the privacy policy says and what the tag inventory does will remain a primary source of exposure regardless of what the governor decides.

Photo of Dustin Taylor Dustin Taylor

Dustin is a privacy litigator who helps clients navigate the rapidly evolving landscape of data privacy and security laws. His holistic approach helps clients achieve their objectives — whether that means winning in court or proactively avoiding litigation altogether.

Read more about Dustin TaylorEmailDustin's Linkedin Profile
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Privacy + Cyber + AI
  • Organization:
    Troutman Pepper Locke
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo