Website pixel litigation has become one of the most active and unsettled areas of consumer privacy class action practice. For years, many companies treated tracking pixels, analytics scripts, cookies, tags, software development kits, session replay tools, and advertising integrations as routine marketing infrastructure. A local retailer used them to measure conversions. A professional services firm used them to improve ad targeting. A health-adjacent website used them to understand visitor behavior. A media site used them to monetize traffic. A business that never considered itself a “video provider,” “wiretapper,” or “data broker” might have allowed third-party code to run on its website simply because the technology was recommended by a marketing vendor or embedded through a standard advertising platform. That ordinary implementation choice is now the foundation of a wave of lawsuits alleging violations of the Video Privacy Protection Act, federal and state wiretap statutes, and common-law or constitutional privacy rights. ¹
The basic theory is easy to understand even though the technical and legal details are complex. A website operator places third-party code on its site. A visitor lands on a page, views content, watches a video, searches for a product, completes a form, clicks a button, or logs into an account. The code allegedly causes information about that interaction to be transmitted to a third party such as a social media platform, analytics provider, advertising network, or session replay company. Plaintiffs then argue that the website did not merely collect ordinary website analytics; it disclosed legally protected information about a person’s private activity without sufficient consent. The precise claim depends on the statute. Under the VPPA, the focus is whether the website knowingly disclosed personally identifiable information concerning a consumer’s video-viewing activity. Under wiretap theories, the focus is whether the website or its vendor intercepted the contents of an electronic communication. Under broader privacy theories, the question becomes whether the data collection was offensive, inadequately disclosed, contrary to stated privacy promises, or otherwise actionable. ¹ ²
The reason ordinary business websites are being sued is that modern websites often behave like complicated data-sharing environments rather than static brochures. A single webpage can contain scripts from advertising platforms, embedded video providers, social plug-ins, customer support widgets, payment processors, heatmap tools, chatbots, A/B testing services, and consent management platforms. Some of these tools are loaded directly by the website. Others are loaded through tag managers or downstream vendor scripts. Business owners may believe they know what is installed, but a technical audit often reveals a broader ecosystem. Plaintiffs’ firms and technical consultants can scan websites, identify pixels or third-party requests, and then pair those findings with legal theories that were written long before today’s digital advertising architecture existed. This mismatch between old privacy statutes and modern web technology is the engine driving the litigation.
The VPPA is the most surprising statute in this area because it began as a video rental privacy law. Congress enacted it to prevent disclosure of a person’s video rental or viewing history, and the statute creates liability when a video tape service provider knowingly discloses personally identifiable information concerning a consumer. The statute defines a consumer to include a renter, purchaser, or subscriber of goods or services from a video tape service provider, and it defines personally identifiable information to include information identifying a person as having requested or obtained specific video materials or services. ¹ Although that language sounds dated, plaintiffs have argued that it applies to websites that host or embed prerecorded video content and use tracking pixels that allegedly transmit video titles, URLs, Facebook IDs, cookie identifiers, or other digital identifiers to third parties.
For ordinary businesses, the important lesson is that a website does not have to look like Netflix or a traditional media company to attract a VPPA claim. A trade association with educational videos, a retailer with product demonstration clips, a sports site with highlights, a nonprofit with recorded webinars, a software company with tutorial videos, or a professional firm with embedded marketing videos may all be examined through a VPPA lens. The plaintiff’s theory usually depends on the combination of video content, a user relationship such as registration or subscription, and a disclosure pathway to a third party. A business that merely publishes written content may face a lower VPPA risk, but the presence of video content changes the analysis, especially if the business also encourages users to sign up for newsletters, accounts, memberships, rewards programs, or gated content.
One of the central VPPA disputes is who counts as a “consumer.” Plaintiffs often argue that a person who signs up for a free newsletter, creates an account, registers for access, or otherwise provides contact information has become a subscriber of goods or services from the website operator. Defendants often respond that the subscription must relate to audiovisual goods or services, not merely to a general newsletter or unrelated website benefit. The Second Circuit’s decision in Salazar v. National Basketball Association illustrates the plaintiff-friendly side of this debate. There, the court held that the plaintiff plausibly qualified as a subscriber under the VPPA after signing up for the NBA’s online newsletter, even though the newsletter itself was not necessarily an audiovisual product. The court’s reasoning matters because many ordinary websites use free newsletters or account registrations as part of their marketing strategy, and those relationships can become the alleged basis for VPPA “consumer” status.⁴
Another central VPPA dispute is what qualifies as personally identifiable information. Plaintiffs usually argue that a pixel disclosure can identify a user when the transmitted data includes a video title, URL, cookie, account identifier, Facebook ID, or other information that the recipient can connect to a real person. Defendants usually argue that raw digital identifiers and strings of code are not the kind of information the VPPA was meant to cover, particularly when an ordinary person could not look at the data and identify a specific viewer’s video history. The Second Circuit’s decision in Solomon v. Flipps Media adopted the “ordinary person” standard and held that information constitutes personally identifiable information only if it would allow an ordinary person to identify a consumer’s video-watching habits.⁵ That approach narrows VPPA exposure in some jurisdictions, but it does not eliminate risk everywhere because courts have not always applied the same test in the same way.
The practical result is that VPPA exposure is highly fact-specific and jurisdiction-dependent. A business cannot assume that every video page with a pixel creates liability, but it also cannot assume that ordinary marketing technology is immune from challenge. The key questions include whether the business is a video tape service provider, whether the plaintiff is a consumer under the statute, whether the allegedly disclosed information identifies the person and the specific video material, whether the disclosure was knowing, and whether legally sufficient consent was obtained. The statutory damages remedy is another reason these cases are attractive to plaintiffs. The VPPA permits recovery of actual damages but not less than liquidated damages of $2,500 per person, along with other potential relief. ¹ In a putative class action, that statutory damages framework can create significant settlement pressure even where liability is disputed.
Wiretap claims are different in theory but often arise from the same website conduct. The federal Wiretap Act, as amended by the Electronic Communications Privacy Act, generally prohibits the intentional interception, disclosure, or use of the contents of wire, or electronic communications unless an exception applies. ² Plaintiffs bringing pixel or session replay claims often allege that a website visitor’s interactions with the website are electronic communications and that a third-party vendor contemporaneously intercepted those communications. In a session replay case, the alleged interception may involve keystrokes, clicks, mouse movements, page views, form entries, or other interaction data. In a pixel case, the alleged interception may involve the transmission of URLs, page titles, search terms, button clicks, purchase events, or account-related information to an advertising platform.
The federal wiretap theory faces several important defenses. One defense is that the website operator is a party to the communication and therefore may consent to the recording or transmission, subject to statutory limits. Another defense is that the data at issue is not the “contents” of a communication but rather routing, addressing, analytics, or event data. A third defense is that the vendor functions as a service provider for the website rather than an unauthorized eavesdropper. A fourth defense is user consent, especially where the website provides clear disclosures through a cookie banner, privacy policy, terms of use, account registration flow, or preference center. These defenses can be powerful, but they are not automatic. Courts examine how the technology actually works, what data is transmitted, whether the vendor uses the data for its own purposes, and whether the user was given meaningful notice before the challenged data collection occurred. ²
State wiretap laws add another layer of risk, and California’s Invasion of Privacy Act has been especially important. Section 631 of CIPA prohibits certain forms of wiretapping and eavesdropping, and plaintiffs have attempted to apply it to websites that use pixels, chat tools, analytics scripts, and session replay software.³ CIPA claims are attractive because California has a large consumer population, an active plaintiffs’ bar, and statutory remedies that can make even small, alleged privacy violations expensive. The legal debate often turns on whether the third-party technology provider is merely an extension of the website operator or whether it is a separate eavesdropper that learns the contents of a communication without consent. The answer can depend on the vendor’s role, contractual rights, data retention practices, independent use of the data, and the timing and clarity of the website’s disclosures.
Common-law and constitutional privacy claims are often pleaded alongside VPPA and wiretap claims. These claims may be styled as intrusion upon seclusion, invasion of privacy, unjust enrichment, negligence, breach of implied contract, breach of privacy policy, or violation of a state constitutional privacy right. Their purpose is often to provide alternative routes to liability if a statutory claim fails. For example, if a court concludes that a pixel disclosure is not personally identifiable information under the VPPA, the plaintiff may still argue that the same conduct was an unreasonable intrusion into private online activity. If a court concludes that the federal Wiretap Act does not apply because the website was a party to the communication, the plaintiff may still argue that the website’s disclosures were misleading or exceeded the scope of consent. These claims are usually harder to certify and prove than statutory claims, but they increase litigation complexity and discovery costs.
Consent is the most important practical issue for ordinary business websites. Many pixel lawsuits turn not only on what data was collected, but also on whether the visitor agreed to the collection before it happened. Consent is not a magic word that appears in a privacy policy and defeats every claim. It must be evaluated in context. A court may ask whether the disclosure was prominent, whether the user had a real choice, whether the policy described the relevant categories of data and recipients, whether the banner appeared before nonessential tracking began, whether the website honored opt-out choices, and whether the consent language was broad enough to cover the specific technology at issue. In the VPPA context, consent has statutory requirements and must be handled with particular care. ¹ In wiretap and CIPA cases, consent often depends on whether the user had notice of the interception or recording and continued to use the service after receiving that notice. ² ³
Cookie banners are therefore both helpful and dangerous. A well-designed banner can support a consent defense by giving users timely notice and control. A poorly designed banner can become Exhibit A for the plaintiff. Problems arise when banners say that cookies are used only to improve the site while undisclosed third-party advertising pixels transmit detailed event data. Problems also arise when tracking begins before the user has accepted nonessential cookies, when rejecting cookies does not actually stop tracking, when the privacy policy is vague about third-party advertising partners, or when the website buries material disclosures behind multiple layers of confusing text. A business that uses a consent banner should treat it as a compliance mechanism that must be technically tested, not as a cosmetic pop-up added to the site.
Privacy policies also deserve more attention than they often receive. Many policies are drafted broadly to preserve flexibility, but pixel litigation rewards precision. If a website shares browsing activity, device identifiers, page URLs, video viewing activity, purchase events, search terms, or form interactions with advertising or analytics partners, the policy should accurately describe those practices in plain language. If the business uses Meta Pixel, Google advertising tags, TikTok Pixel, Microsoft advertising tools, session replay, chat tools, or similar technologies, counsel should consider whether the policy’s description of “service providers,” “analytics,” “advertising partners,” and “personal information” actually matches the technical implementation. A policy that promises not to share personal information while third-party code transmits identifiers and behavioral events may create unnecessary litigation risk.
Video content should be reviewed separately because it can trigger a different risk profile. The safest approach is to identify every page containing prerecorded video content and determine whether any third-party trackers fire on those pages. Businesses should determine whether the tracker transmits video titles, page URLs revealing the video title, embedded player events, watch progress, account identifiers, cookies, hashed email addresses, or social media identifiers. The business should also determine whether videos are accessible to anonymous visitors or only to logged-in users, subscribers, members, or newsletter registrants. A website that combines video content, user registration, and advertising pixels presents a more obvious VPPA target than a website that hosts no video content or suppresses nonessential trackers on video pages. ¹
The role of vendors is another recurring issue. Businesses frequently rely on web developers, marketing agencies, analytics consultants, and advertising platforms to install and configure tracking technologies. That delegation does not eliminate legal responsibility. In litigation, plaintiffs often argue that the website operator knowingly disclosed data because it chose to install the tool, configured the pixel, or benefited from the resulting advertising analytics. Defendants may respond that they did not know the specific data fields being transmitted or that the vendor’s code operated in unexpected ways. Those arguments can matter, but they are stronger when the business has documented its vendor review, limited the vendor’s data rights, configured privacy-enhancing settings, and periodically audited the site. A business that never inventoried its pixels may have a harder time arguing that the challenged disclosure was unexpected.
Ordinary businesses should also understand that not all pixels are equal. Some technologies transmit only basic page-load events or aggregated analytics. Others transmit detailed event data, custom parameters, purchase information, search queries, button text, form metadata, or identifiers that can be matched to user profiles. Some tools allow “advanced matching,” which may use hashed email addresses, phone numbers, names, or other identifiers to improve ad attribution. Some platforms offer limited data use settings, restricted processing options, automatic advanced matching controls, or mechanisms to suppress sensitive fields. A compliance review should not simply ask whether a pixel exists. It should ask what data the pixel collects, when it fires, where the data goes, how the recipient may use it, how long it is retained, and whether the user had a legally meaningful choice before the transfer occurred.
Healthcare, financial, children’s, and other sensitive-content websites face heightened concerns even when the claim is not brought under a sector-specific statute. A visitor’s interaction with a page about a medical condition, debt relief service, addiction treatment option, fertility service, legal problem, or employment issue may feel more private than an ordinary retail page view. Plaintiffs can use that context to support common-law privacy claims or to argue that consent disclosures were inadequate. Even if a website is not a covered entity under HIPAA or a financial institution under the Gramm-Leach-Bliley Act, the sensitivity of the subject matter can influence how a court views the reasonableness of the data practice. For that reason, businesses operating in sensitive areas should consider disabling advertising pixels on sensitive pages or adopting stricter consent and data minimization practices.
A strong compliance program begins with a technical inventory. The business should identify every cookie, pixel, tag, script, SDK, embedded frame, chat tool, analytics service, and session replay product operating on the site. The inventory should include tools loaded through tag managers and tools loaded indirectly by other vendors. It should also identify which tools fire before consent, after consent, after login, during checkout, on video pages, and on sensitive-content pages. This process often reveals legacy tags that no one actively uses, duplicate pixels installed by past marketing campaigns, or vendor scripts that collect more information than expected. Removing unnecessary tags is one of the simplest and most effective ways to reduce litigation risk.
After inventory comes classification. The business should classify technologies as strictly necessary, functional, analytics, advertising, personalization, session replay, or social media. The classification should match both the user-facing disclosure and the technical behavior of the tool. A tag used for targeted advertising should not be described merely as “site improvement.” A session replay tool that records user interactions should not be hidden under a generic analytics label if it captures more detailed behavioral data. A video-page tracker should be reviewed under VPPA principles, not merely under general cookie law. Clear classification helps align the consent banner, privacy policy, vendor contracts, and technical settings.
Data minimization should be treated as a litigation defense strategy, not only a regulatory principle. If a business does not need a particular data field, it should not transmit it. If it does not need advertising pixels on video pages, it should suppress them. If it does not need advanced matching, it should disable it. If it does not need session replay on forms collecting sensitive information, it should turn it off or mask the fields. If it does need a tool, it should configure the tool to avoid collecting sensitive text, keystrokes, hidden form fields, authentication information, and unnecessary identifiers. These steps can reduce the factual basis for a lawsuit and improve the business’s position if litigation occurs.
Vendor contracts should also be revisited. A contract with an analytics or advertising provider should address the provider’s role, permitted uses of data, restrictions on independent use, data retention, security, subprocessors, compliance with law, assistance with consumer requests, and deletion or de-identification obligations. Where possible, the business should use settings and contract terms that characterize the vendor as a service provider or processor rather than an independent third party using the data for its own advertising ecosystem. That distinction may matter in privacy litigation because plaintiffs often portray the vendor as an outside eavesdropper or unauthorized recipient of private information. The more the vendor uses data for its own purposes, the harder it may be to defend the transfer as a routine internal service function.
Arbitration agreements and class action waivers can also affect risk, although they are not substitutes for compliance. Many pixel cases are brought as class actions because statutory damages become powerful when multiplied across large visitor populations. A properly drafted and enforceable arbitration agreement may reduce class exposure for registered users, purchasers, or subscribers. However, arbitration clauses may not apply to anonymous website visitors, and they can create mass arbitration risk if many claimants file individual demands. Businesses should therefore review dispute resolution provisions as part of a broader privacy litigation strategy, but they should not rely on arbitration alone to solve a technical tracking problem.
When a demand letter or complaint arrives, the first response should be factual preservation and technical investigation. The business should preserve the website code, tag manager history, consent banner configurations, privacy policies, terms of use, vendor contracts, and relevant analytics settings for the period at issue. It should determine what pixels were active, what pages they fired on, what data was transmitted, whether users were logged in, whether video pages were involved, whether consent was obtained, and whether opt-outs were honored. A quick but careful technical report can shape the entire defense strategy. Without that factual record, the business may be forced to litigate based on assumptions about how the website worked.
The defense strategy will depend on the claim. In a VPPA case, defense counsel will usually examine whether the defendant is a video tape service provider, whether the plaintiff is a renter, purchaser, or subscriber, whether the alleged disclosure involved specific video materials, whether the data was personally identifiable information, whether the disclosure was knowing, and whether statutory consent was obtained. ¹ ⁴ ⁵ In a wiretap case, counsel will examine whether there was an interception, whether the information was the contents of a communication, whether the website or vendor was a party to the communication, whether consent existed, and whether any statutory exception applies. ² In a CIPA case, counsel will examine California-specific doctrine, the role of the third-party vendor, consent, and whether the alleged conduct resembles eavesdropping within the meaning of the statute. ³ In common-law privacy claims, counsel will focus on reasonable expectations of privacy, offensiveness, disclosure, injury, causation, and the accuracy of the website’s public-facing statements.
The broader lesson is that website privacy litigation is no longer limited to technology companies. Ordinary business websites now sit at the intersection of advertising technology, consumer privacy statutes, and class action economics. A business may never sell data in the ordinary sense and may still be accused of unlawfully disclosing it. A business may never think of itself as a video provider and may still face a VPPA claim because it embedded product videos or webinars. A business may believe that its vendors are merely helping it understand website traffic and may still face a wiretap theory alleging that those vendors intercepted user communications. The gap between business expectations and litigation theories is exactly why proactive review is necessary.
The best risk-reduction measures are practical. Businesses should inventory tracking technologies, remove unnecessary tags, suppress advertising pixels on sensitive and video pages when appropriate, improve consent flows, test whether opt-outs work, update privacy policies to match actual practices, review vendor contracts, disable unnecessary matching features, and document governance decisions. These steps do not guarantee immunity, particularly in a legal landscape that remains unsettled. They do, however, make the business a less attractive target and create better defenses if a claim is filed. In this area, compliance is not simply about avoiding regulatory scrutiny. It is about being able to explain, with technical accuracy and legal clarity, what the website collected, why it collected it, who received it, what the user was told, and what choices the user had.
Website pixel litigation is likely to continue because it offers plaintiffs a compelling narrative: invisible code allegedly sharing personal activity with powerful third-party platforms. Businesses need an equally clear response grounded in transparency, consent, minimization, and documentation. The websites most vulnerable to these claims are not necessarily the ones using the most sophisticated technology. They are often the ones using ordinary technology without understanding it. For ordinary business websites, the question is no longer whether pixels and analytics tools are common. They are. The question is whether the business can show that its use of those tools was disclosed, consented to where required, technically controlled, legally reviewed, and proportionate to a legitimate business purpose.
Contact Tishkoff
Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).
Sources:
1- Video Privacy Protection Act, 18 U.S.C. § 2710. https://www.law.cornell.edu/uscode/text/18/2710
2- Electronic Communications Privacy Act and Federal Wiretap Act, 18 U.S.C. §§ 2510–2523. https://bja.ojp.gov/program/it/privacy-civil-liberties/authorities/statutes/1285
3- California Invasion of Privacy Act, Cal. Penal Code § 631. https://codes.findlaw.com/ca/penal-code/pen-sect-631/
4- Salazar v. National Basketball Association, 118 F.4th 533 (2d Cir. 2024). https://cdn.lawreportgroup.com/acuris/files/Cybersecurity-New/Salazar%20v%20National%20Basketball%20Association.pdf
5- Solomon v. Flipps Media, Inc., 136 F.4th 41 (2d Cir. 2025). https://law.justia.com/cases/federal/appellate-courts/ca2/23-7597/23-7597-2025-05-01.html
