California Legislature Halts Class Actions Alleging That Common Website Advertising Technologies Are Pen Registers And Trap And Trace Devices

By Gerald L. Maatman, Jr., Justin R. Donoho, and Hayley Ryan

Duane Morris Takeaways:  On September 30, 2026, California Governor Newsome signed Senate Bill 690, which amends the California Invasion of Privacy Act (“CIPA”) to eliminate the private right of action under California Penal Code § 638.51 for pen register and trap-and-trace device claims arising from website, online application, and mobile application activity. Under the amended statute, only the California Attorney General may bring such claims against private actors. The law takes effect on January 1, 2027, and it applies retroactively to any pending claim in an action commenced within two years before that date. For the thousands of companies now facing CIPA § 638.51 class actions and demand letters over the use of pixels, cookies, and similar website advertising technologies (“adtech”), Senate Bill 690 offers significant and fast relief. It is not, however, the end of CIPA litigation. The wiretapping provision (§ 631) and the eavesdropping provision (§ 632), which plaintiffs have also used in adtech cases, are untouched.

The bill’s final form is much narrower than the version first introduced. As introduced, Senate Bill 690 would have exempted all processing of personal information for a “commercial business purpose” as defined by the California Consumer Privacy Act (“CCPA”) from civil and criminal liability under all three sections of the CIPA. See Assembly Committee On Privacy And Consumer Protection Committee Report (July 1 , 2026) (“Committee Report”) at 6-7. The analysis in our blog post covers the legal landscape that led to the bill, the scope and mechanics of the enacted statute, how the bill narrowed during the legislative process, and what corporate counsel and class action practitioners should do now.

Background

The CIPA was adopted in 1967 to criminalize wiretapping, eavesdropping, interception, and recording of telephone communications without court authorization. Section 637.2 confers a private right of action to any person injured by a violation of the CIPA. Available relief includes statutory damages of $5,000 per violation, three times the actual damages suffered by the plaintiff, if any, and injunctive relief. Section 637.2(c) specifically provides that plaintiffs do not need to show actual damages. The Assembly Committee on Privacy and Consumer Protection observed that, in the adtech context, these violations “can stack up rapidly, causing defendants to face potentially devastating liability.” See Committee Report at 7.

Recent adtech litigation has relied on three CIPA provisions: § 631 (wiretapping), § 632 (recording confidential communications), and § 638.51 (pen registers and trap-and-trace devices). Section 638.51 was added only in 2015, and according to the Assembly Committee on Privacy and Consumer Protection, the Legislature gave “little, if any, thought” to how it would apply online or interact with the CIPA’s private right of action. See Committee Report at 1. The Committee called the pen register and trap and trace device statute “a poster child for abusive lawsuits,” explaining that “[b]ecause the potential liability can be staggering, businesses generally settle this litigation hastily, encouraging vexatious litigants to continue blasting out demand letters.” See id. at 1.

The case law gave businesses little certainty.  For example, federal district courts in California are split as to whether third-party collection of website-user information may constitute a trap and trace device or pen register under § 638.51.  California state trial courts, by contrast, have mostly dismissed these claims, as in Licea v. Hickory Farms LLC, No. 23STCV26148, 2024 WL 1698147 (Cal. Super. Ct. Mar. 13, 2024), Casillas v. Transitions Optical, Inc., No. 23STCV30742, 2024 WL 4873370 (Cal. Super. Ct. Sep. 9, 2024), and Sanchez v. Cars.com Inc., No. 24STCV13201, 2025 WL 487194 (Cal. Super. Ct. Jan. 27, 2025). The Committee noted that there is no published California appellate authority applying § 638.51 to software. See Committee Report at 16. According to the bill’s sponsors, § 638.51 lawsuits rose from about 600 to nearly 4,000 after SB 690 was introduced, and tens of thousands of businesses received demand letters. See id. at 7.

What Does SB 690 Change?

SB 690 amends only § 637.2, the CIPA’s civil remedies provision. Its main features are as follows:

  • AG-Only Enforcement For Online Pen Register And Trap-And-Trace Claims. An action against a private actor for a violation of § 638.51 “alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.”
  • The Private Right Of Action Otherwise Remains. Subdivisions (a) and (b) of section 637.2 still authorize private suits for statutory damages, treble damages, and injunctive relief for all other CIPA violations, now subject only to the new subdivision (d) exception. The no-actual-damages provision in subdivision (c) also remains.
  • Retroactivity. The amendments “apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.” The Committee explained that this provision is meant to relieve defendants in pen register lawsuits filed within the two-year period before January 1, 2027. It also stated that the amendments would not affect any case in which final judgment has been entered.
  • Severability. The Committee explained that a severability clause was added “in view of possible constitutional challenges to the retroactivity provisions.” See Committee Reportat 25.

Who And What Is Covered?

The carve-out is narrow and depends on four elements. First, it applies only to claims under § 638.51. Second, it applies only to actions against a “private actor.” Third, the claim must be “alleged to arise from conduct occurring on” a website, online application, or mobile application. Fourth, it removes only private standing. The underlying prohibition in § 638.51 remains, and the Attorney General may pursue violations using the remedies the CIPA already provides.

SB 690 does not define “private actor,” and it does not explain when conduct “arise[s] from conduct occurring on” a website or app. Defendants should expect plaintiffs to test those terms. Possible targets include back-end service providers to websites and apps, such as companies that provide payroll, shipping logistics, cybersecurity and antifraud technology, cloud storage, HR, and analytics and advertising tools, which the bill’s sponsors noted had also been sued.

How Did The Bill Change During The Legislative Process?

The introduced and enacted versions of SB 690 differ significantly. As introduced, the bill would have exempted any “commercial business purpose,” as defined by the CCPA, from both civil and criminal liability under the CIPA. The enacted version does much less: it removes private standing only for certain § 638.51 claims. The introduced bill would have changed CIPA §§ 631, 632, 632.7, and 638.51. The Committee’s amendments struck all changes to §§ 631, 632, 632.7, and 638.50, so the enacted law amends only § 637.2, the CIPA’s civil remedies provision. See Committee Report at 25-26.

The two versions also differ in reach. The original bill applied to all civil and criminal violations, was not limited to website activity, and could have covered any recording or interception of a confidential communication made for a commercial business purpose. Id. at 15. The enacted bill leaves criminal liability unchanged, focuses only on the civil private right of action against private actors, and is limited to conduct occurring on an internet website, online application, or mobile application. Further, the original bill did not provide for public enforcement, while the enacted version gives the California Attorney General standing to pursue these pen register and trap-and-trace violations using the remedies the CIPA already provides. The enacted version also adds two provisions the original bill did not have: retroactive application to pending claims in actions commenced within two years before the operative date, and a severability clause added in view of possible constitutional challenges to that retroactivity.

The Committee called the original bill “too blunt” and warned that the bill could “unintentionally shield wiretapping violations that involve highly offensive intrusions.” See Committee Report at 2, 25. The Committee also treated the trap and trace device and pen register statute differently from the other provisions, noting that trap and trace device and pen register cases usually involve “seemingly innocuous technical violations arising from ordinary operation of websites.” Id. at 2. By contrast, it found that §§ 631 and 632 cases often involve “highly offensive intrusions on users’ reasonable expectations of privacy, although they are not immune from abuse.” Id.  The narrowed bill passed the Legislature unanimously in late August 2026.

What SB 690 Does Not Do

Claims under Sections 631 (wiretapping) and 632 (eavesdropping), which carry the same $5,000 per-violation exposure, remain available to private plaintiffs in class action litigation. The Committee acknowledged that § 631 “continues to be challenging for courts to apply” to conduct occurring on websites. See Committee Report at 2. It concluded that targeted reform of § 631 “appears warranted, albeit not as urgent as reforms to the pen register statute.” Id. at 24. The Committee also noted that plaintiffs have moved toward other theories, including claims under California’s Comprehensive Computer Data Access and Fraud Act and the federal Electronic Communications Privacy Act. Id. at 25. In his signing message, Governor Newsom noted that “additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants,” and “urge[d] the Legislature to take this on next year to ensure a fair balance between protecting private information and preventing rapacious litigation.”

Implications For Companies

SB 690 should sharply reduce the volume of § 638.51 class actions and demand letters. In the short term, however, the plaintiffs’ bar may shift its claims rather than abandon them. Companies with any online presence, including websites, mobile applications, and online forms and applications, should consider the following steps.

  • Assess Pending § 638.51 Matters Now. For cases filed within the two-year retroactivity window, defendants should consider motions for judgment on the pleadings or dismissal once the law becomes operative on January 1, 2027, and should consider seeking stays in the meantime. Defendants should also reconsider their settlement posture on pen register-only demands.
  • Expect The Retroactivity Provision To Be Challenged. The Legislature added the severability clause because it anticipated constitutional challenges. Defendants should be prepared to defend retroactive application.
  • Expect Claims To Be Repleaded Under §§ 631 and 632. Plaintiffs asserting trap and trace device and pen register claims under § 638.51 are likely to recast adtech, claims as wiretapping or eavesdropping claims, particularly where descriptive URLs, search terms, or health information are involved, as adtech plaintiffs typically argue that such items constitute “contents” of a communication under § 631 and that transmission of such items to adtech companies constitutes “eavesdropping” or aiding and abetting eavesdropping under § 632. These claims still carry $5,000 per-violation statutory damages and remain suitable for class treatment.  Of course, adtech plaintiffs will continue to face numerous significant legal challenges regarding the merits and certifiability of their §§ 631 and 632 claims, as we blogged about here, here, and here.
  • Continue Auditing Website Advertising Technologies. The relief provided by SB 690 fails to limit exposure not only under the CIPA §§ 631 and 632 but also under the Electronic Communications Privacy Act (ECPA), the Video Privacy Protection Act (VPPA), the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), the Florida Security of Communications Act (FSCA), and other state and federal privacy statutes. Companies should continue to review and evaluate their adtech, data practices, consent mechanisms, and privacy notices, in light of rapidly evolving legal precedent regarding whether these old statutes apply to adtech, to ensure compliance with these other privacy laws.
  • Watch The 2027 Legislative Session. Given the Governor’s call for further reform, additional CIPA amendments are a realistic possibility.

Companies should consider Senate Bill 690 as a narrow solution providing limited relief to adtech defendants rather than a comprehensive reform. Companies that treat it that way will be better positioned for the next phase of CIPA class action litigation.

Ohio Federal Court Grants Conditional Certification Of A Wide Collective Action Against The Cleveland Clinic Foundation

By Gerald L. Maatman, Jr., Kathryn Brown, and Olga A. Romadin

Duane Morris Takeaways: On September 24, 2026, Judge Christopher A. Boyko of the U.S. District Court for the Northern District of Ohio granted Plaintiff’s motion for conditional certification of a proposed collective of workers alleging that time-rounding practices resulted in overtime violations in Garner v. Cleveland Clinic Foundation, Case No. 23-CV-2258 (N.D. Ohio Sept. 24, 2026).  Judge Boyko found that Plaintiff had met her burden to show a strong likelihood that workers were similarly situated because she provided testimony, declarations, and an expert opinion that demonstrated that workers across multiple positions and facilities were all subject to the same non-neutral rounding policy. The opinion should be required reading for companies defending wage & hour claims in courts within the Sixth Circuit.

Case Background

Plaintiff Deborah Garner brought a putative class and collective action on behalf of herself and all other similarly situated on November 21, 2023.  Plaintiff, a patient registrar and patient access specialist employed by Defendant, the Cleveland Clinic Foundation (“CCF”), alleged that CCF failed to pay non-exempt employees overtime at the statutory rate for all hours worked over forty, in violation of the Fair Labor Standards Act (“FLSA”) as well as Ohio’s wage and hour laws.  Plaintiff additionally claimed that CCF failed to pay all wages owed to workers due to improper rounding and/or editing of hours worked in Defendant’s timekeeping software, and failed to keep accurate time records.  Id. at 1-2. 

On January 5, 2024, Plaintiff filed an amended complaint as well as a motion asking the Court to facilitate notice to other similarly-situated potential plaintiffs, and the Court granted the motion after striking Plaintiff’s class claims.

The Court’s Ruling

Judge Boyko granted Plaintiff’s motion to facilitate notice to putative collective members on determining that there was a strong likelihood that the proposed collective members are similarly situated because the plaintiffs had met their burden to show that non-exempt hourly employees were all subject to the same rounding policies.  Id. at 1.  Plaintiffs provided declarations of 5 opt-in plaintiffs, deposition testimony, and an expert opinion regarding CCF’s rounding policies and practices. Id. at 1-2. Plaintiff’s expert testified that CCF’s “rounding practices worked against the employees nearly 80 percent of the time.”  Id. at 20. 

Defendant argued that the scope of the proposed class and the variety of positions involved gave rise to individualized questions and issues, but the Court was unconvinced. Id. The Court determined that this evidence was enough to have “shown the rounding practice applied broadly to all the non-exempt employees” and was in line with the U.S. Supreme Court’s express determination that representative evidence in collective actions is permissible. Id.

However, the Court, citing to Plaintiff’s evidence, which showed that about 17% of employees suffered no injury, concluded that they lacked standing and were not similarly situated because they could claim no injury under the FLSA.  Id. at 21.

Defendants further argued that approximately 4.5% of CCF’s non-exempt hourly employees were subject to “flex rounding” or “quarter rounding” policies and were therefore not similarly situated because they were not subject to the general rounding policy at issue. The Court found that Defendant’s argument only supported Plaintiff’s argument that CCF had a system-wide rounding policy, and that it was not applied to “select employees or departments.”  Id. at 22.  The Court concluded that the evidence showed “a consistent, systemwide policy of rounding and that rounding heavily favored Defendant,” and therefore that Plaintiffs met their burden to show the putative collective was similarly situated, and granted Garner’s motion for a Court-facilitated notice.

Implications for Companies

In light of the opinion in Garner, companies with a workforce of non-exempt employees are well-advised to take stock of their timekeeping policies and practices, particularly when they operate multiple facilities and utilize timekeeping systems with rounding features.  Federal courts in the Sixth Circuit scrutinize any such policies to determine whether putative collective action members are subject to the same practices, and the likelihood of plaintiffs meeting the “strong likelihood” standard is greater when such policies are generally applicable across the employer’s sites and positions. A strong defense often features a showing that a company’s timekeeping policies and practices vary by position, department, and facility, and may be pointed to in arguing that putative collective members are not similarly situated enough to warrant collective-wide treatment.

California Federal Court Denies TikTok’s Motion To Dismiss Children’s Privacy Claims Based on Prior Class Action Settlements

By Gerald L. Maatman, Jr., Justin R. Donoho, and Hayley Ryan

Duane Morris Takeaways:  On September 23, 2026, in the case of In Re TikTok, Inc., Minor Privacy Litigation, No. MDL 25-3144, ECF No. 414 (C.D. Cal. Sept. 23, 2026), Judge George H. Wu of the U.S. District Court for the Central District of California issued a tentative ruling (adopted as final on September 24, 2026) denying TikTok’s motion to dismiss the Second Amended Consolidated Class Action Complaint in a multidistrict litigation brought by minors alleging that TikTok collected, shared, and exploited their personal information without parental consent in violation of the Children’s Online Privacy Protection Act (“COPPA”) and related state laws.

The ruling is significant because it rejected TikTok’s argument that two prior nationwide class action settlements – totaling over $93 million combined – barred the plaintiffs’ claims, holding that the record at the pleadings stage did not establish the named plaintiffs’ membership in those prior settlement classes.  For companies that have previously settled class actions, the decision underscores the risk that broad settlement releases may not foreclose subsequent litigation where class membership is not clearly established on the face of the pleadings.

Background

This case is one of a series of privacy class actions targeting TikTok and its parent companies, ByteDance Inc. and ByteDance Ltd.  The plaintiffs are minors who allege that while under the age of 13, their personal information was collected, shared, and exploited by TikTok without the parental notice and consent COPPA requires for children under 13. The plaintiffs seek to impose liability stretching back to March 28, 2019.

Two prior nationwide settlements form the backdrop of the dispute.  The first, T.K. v. Bytedance Technology Co., No. 1:19-CV-07915 (N.D. Ill.), followed the FTC’s 2019 enforcement action concerning COPPA violations by Musical.ly, TikTok’s predecessor, and settled for $1.1 million on behalf of approximately 6 million individuals who used Musical.ly or TikTok before August 22, 2022, while under the age of 13. The settlement included a broad release but no injunctive relief.  The second, In Re TikTok, Inc., Consumer Privacy Litigation, No. 1:20-CV-04699 (N.D. Ill.) (the “Privacy MDL”), consolidated lawsuits focused on TikTok’s use of algorithms, facial recognition, and other technologies to collect and transfer personally identifiable user data to servers in China, and settled for $92 million with broad injunctive relief.

In April 2025, the U.S. Judicial Panel on Multidistrict Litigation ordered the transfer of the present actions to the Central District of California.  After an initial partial dismissal of claims brought under laws of states without a domiciled plaintiff, the plaintiffs amended, and the defendants moved to dismiss the Second Amended Consolidated Class Action Complaint (“Complaint”), arguing that the T.K. and Privacy MDL settlements barred claims for conduct occurring before August 22, 2022, the cutoff date defining the later T.K. settlement class.  The dispositive question was therefore whether the pleadings themselves established that the named plaintiffs fell within those prior settlement classes.

The Court’s Decision

The Court denied TikTok’s motion to dismiss, finding that the defendants failed to establish, on the record available at the pleadings stage, that the named plaintiffs were members of the T.K. class. ECF No. 414 at 8-9.

At the heart of the ruling was a straightforward factual gap.  The T.K. settlement class included individuals who used TikTok or Musical.ly before August 22, 2022, while under the age of 13.  Id.  However, the Complaint did not allege the birth dates or first-use dates of any of the named plaintiffs – it alleged only that the plaintiffs were under 13 and used TikTok during the Class Period, defined as March 28, 2019, to the present.  Id. at 9.  The Court held that these allegations did not establish when within that period the plaintiffs used TikTok, and the judicially noticed materials likewise did not supply that information.  Id.

Even assuming none of the plaintiffs opted out of the prior settlements, the Court found that the defendants still had not shown the plaintiffs belonged to the prior classes in the first place.  Id.  As the Court stated, “[a] person need not opt out of a class to which that person never belonged.”  Id.

The Court also rejected TikTok’s argument that plaintiffs should not be allowed to avoid res judicata simply by “artfully pleading around” the relevant facts.  Id.  Because a plaintiff’s failure to anticipate and plead around an affirmative defense is not a pleading deficiency, as the Supreme Court explained in Jones v. Bock, 549 U.S. 199 (2007), the Court concluded that even plaintiffs who knew these defenses were coming, and knew their own ages and use histories, were not required to plead around TikTok’s affirmative defenses of release and preclusion, provided they otherwise sufficiently pleaded their causes of action. Id. at 10.

The Court further rejected TikTok’s alternative argument that, regardless of membership in the prior classes, plaintiffs either were precluded from, or lacked Article III standing to pursue, claims for the pre-August 2022 period.  Id.  TikTok reasoned that uncertainty about whether the named plaintiffs were under 13 and used TikTok before August 22, 2022, does not prevent dismissal because plaintiffs who meet those criteria are bound by the prior settlements, while plaintiffs who did not use TikTok during the relevant period cannot recover for that period and lack standing to represent those who did.  Id.  The Court disagreed.  The Court held that once a named plaintiff establishes individual standing, differences in injuries between the named plaintiffs and absent class members go to class certification rather than standing, the distinction drawn by the Ninth Circuit in Melendres v. Arpaio, 784 F.3d 1254 (9th Cir. 2015).  Id. at 11.  As the Court explained, “[w]hether Plaintiffs can represent class members who experienced that conduct earlier in the proposed Class Period concerns their representative capacity under Rule 23, and the possibility that Plaintiffs used TikTok only after August 22, 2022, does not defeat their standing to pursue the alleged claims.”  Id.  The Court likewise declined to redefine the class period at the pleading stage, holding that the issue is more appropriately addressed at class certification.  Id.

After oral argument on September 24, 2026, the Court adopted its tentative ruling as the final ruling.  See ECF No. 416.

Implications For Companies

This decision provides important guidance for any company facing follow-on privacy and/or adtech class action litigation after a prior settlement, by showing that broad settlement releases cannot be enforced at the motion-to-dismiss stage unless the defendant can demonstrate from the pleadings alone that the current plaintiffs were members of the prior class.  That is a high bar where the operative complaint does not specify individual plaintiffs’ ages or first-use dates, or other identifying information necessary to determine membership.

Of course, preclusion based on prior settlements is just one tool in a defendant’s kit for defeating class certification in privacy and adtech cases.  For example, in the related case of In Re TikTok, Inc., Consumer Privacy Litigation, 713 F. Supp. 3d 470 (N.D. Ill. 2024), the court declined to dismiss in-app browser claims on the basis of the prior $92 million settlement but left the door open to a different result upon further discovery.  Id. at 501-02.  There, the court observed that “the unusual and as-yet-undisclosed manner and method of the Original Plaintiffs’ post-settlement investigation leaves open the possibility that further information might alter this conclusion — for example, evidence that they recognized both the in-app browser’s risks and the potential to use them as the basis for a wiretapping theory of liability, but deliberately chose not to pursue this opportunity,” adding that “[s]uch evidence would be worth further attention, if not a different result.”  Id. at 501.  The court reinforced this point by noting that the original plaintiffs’ source code expert had been given “free rein to probe TikTok’s relevant technology” during confirmatory discovery.  Id. at 499.  Defendants facing successive adtech class actions should accordingly pursue targeted discovery into prior expert analyses and internal communications reflecting awareness of the privacy risks at issue — evidence that, under the court’s reasoning in In Re TikTok, Inc., Consumer Privacy Litigation, could compel preclusion of theories that were available but not pursued in the earlier proceeding.

Ninth Circuit Signals That Strong Merits Defenses And Post-Suit Remediation May Not Be Enough To Defeat Class Certification

By Gerald L. Maatman, Jennifer A. Riley, Katherine L. Alphonso, and Caitlin Capriotti

Duane Morris Takeaways: On September 24, 2026, in Alicia Nolen v. PeopleConnect, Inc., No. 24-3894, 2026 U.S. App. LEXIS 29276 (9th Cir. Sept. 24, 2026), a panel for the Ninth Circuit, via an opinion written by Judge Marsha S. Berzon, affirmed an order of the U.S. District Court for the Northern District of California that granted certification of injunctive and damages classes as satisfying both the requirements of predominance and adequacy.  Predominance can be established by showing that reasonable inferences based on practical assumptions preclude the need for individualized inquiries. Predominance does not require courts to determine an administratively feasible way to identify class members to satisfy class certification. Furthermore, the Ninth Circuit reiterated that class certification issues must be evaluated separately from merits issues. As to adequacy, the Ninth Circuit held that a defendant cannot undermine adequacy by remedying a named plaintiff’s injury after a lawsuit is filed.

Case Background

PeopleConnect, Inc. (“PeopleConnect”) owns and operates Classmates.com, an online library of more than 450,000 digitized yearbooks. Id. at *5.  PeopleConnect built its collection by purchasing copies and accepting yearbook donations from individuals and schools.  Id.  PeopleConnect then scans each page of these acquired yearbooks, making all text searchable, and uploads a copy to Classmates.com, where users can search for and connect with former classmates and/or others.  Id. at *5-6.  Notably, individuals who donate yearbooks they own fill out a form authorizing PeopleConnect to use their likeness on Classmates.com.  Id. at *5. 

The lead plaintiff in this case, Alicia Nolen (“Nolen”), is a California resident whose name and photo was featured in at least one yearbook on Classmates.com.  Id. at *8.  Nolen contends PeopleConnect violated California’s statutory right of publicity, codified in Cal. Civ. Code § 3344, by using individuals’ names, without consent, to advertise paid subscriptions to Classmates.com.  Id. at *8-9.  At the core of Nolen’s substantive claims is the sequence of subscription advertisements shown to Classmates.com subscribers, wherein visitors do not initially see subscription advertisements when browsing or searching yearbooks, but if a visitor searches for a particular name and clicks on the resulting thumbnail, the website prompts the visitor to register for a free account.  Id. at *7.  Once the visitor registers, they will immediately receive an advertisement encouraging them to purchase a subscription.  Id.  Nolen argues that PeopleConnect violated the statute by using name-search results to drive account registrations and subscriptions sales.  Id. at *9.  In other words, PeopleConnect “commercially used” individuals’ likeness, requiring consent under the statute, when a name and/or thumbnail image became a publicly accessible part of its advertising workflow.  Id. at *9-10.

Nolen moved to certify injunctive and damages classes under Fed. Rule of Civ. Proc. 23(b)(2) and 23(b)(3).  Id. at *10.  The district court certified the classes, and PeopleConnect appealed under Fed. Rule of Civ. Proc. 23(f), arguing questions of law or fact common to class members do not predominate over those common to individual members, and Nolen is not an adequate representative for the purported class.  Id. at *10-11.

The Ninth Circuit’s Analysis

Predominance

PeopleConnect argued predominance was not satisfied for three reasons; the Ninth Circuit disagreed on all three grounds.  Id. at *13.

First, PeopleConnect argued that the district court misconstrued section 3344 as allowing claims based on the searchability of an individual on the website, whether or not a search has actually been conducted.  Id. at *13.  It urged the Ninth Circuit to construe section 3344 as only permitting recovery for claimants who have actually been searched, which requires an individualized showing of evidence.  Id.  The Ninth Circuit held that this issue goes to the merits of the section 3344 claims, not to whether the class can be certified.  Id. at *14.

Second, PeopleConnect argued that the district court further misconstrued section 3344 as allowing claimants to obtain a minimum award of statutory damages without presenting individualized evidence of mental anguish or actual economic harm.  Id. at *13.  The Ninth Circuit disagreed with PeopleConnect, stating that whether class members suffered an economic injury can be determined on a class wide basis based on reasonable inferences from the practical circumstances.  Id. at * 24.  It is reasonable to assume that PeopleConnect’s use of the name shows that the name has economic value.  Id. at * 22-25.  It is also reasonable to assume that a person whose likeness a company seeks to use in connection with advertising could negotiate at least a nominal licensing fee for such use.  Id.  Thus, a plaintiff deprived of such compensation, no matter how small, has suffered an economic injury.  Id.

Finally, PeopleConnect argued that the district court did not identify an adequate “winnowing plan” to exclude claimants ineligible for relief. Id. at *13.  Specifically, the district court did not come up with a manageable method to weed out individuals who consented to PeopleConnect’s use of their names by registering as Classmates.com members or donating a yearbook, and those whose names are not searchable on the website.  Id. at *25-26.  However, the Ninth Circuit rejected this argument, finding no basis to reverse certification on predominance or manageability grounds.  Id. at *40.

Adequacy

PeopleConnect challenged Nolen’s adequacy as a class representative on the following grounds: (1) her decision to proceed with a “searchable theory of liability” argument would create intraclass conflict by “sacrificing” potentially stronger claims from other purported class members, and (2) Nolen is not similarly situated to other class members because her name is no longer searchable on Classmates.com.  Id. at *41.  As to the first argument, the Ninth Circuit refused to rule as it was not properly raised on appeal.  Id. at *48.  The Ninth Circuit did, however, provide guidance should the issue be appropriately raised in the district court.  Id. at *41-48.  As to the second argument, the Ninth Circuit rejected PeopleConnect contention, explaining, inter alia, it could not “pick off” and moot Nolen’s claims by remediating her injury after she filed suit.  Id. at *49-50.

Implications for Employers

This decision underscores the distinction between class certification and merits evaluation—that potentially strong merits defenses may not be enough to defeat class certification when common issues can be resolved through reasonable, class-wide inferences.  Each of PeopleConnect’s defense arguments raised interesting issues on the merits but ultimately had no bearing on class certification.  Employers should therefore evaluate class-certification exposure independently from the ultimate merits, maintain clear records of consent and authorization for commercial uses of names or likenesses, and assess early whether uniform practices could support class-wide proof.  This decision also cautions that post-suit remediation directed at the named plaintiff generally will not defeat adequacy or moot the action, making proactive compliance and early risk assessment critical.

Michigan Federal Court Drives Back Auto Manufacturing Employees’ Collective Action Efforts

By Gerald L. Maatman, Jr., Shannon Noelle, and Olga A. Romadin

Duane Morris Takeaways: In Glidwell v. Autoneum N. Am., Inc., Case No. 2:24-CV-12805, 2026 WL 2621157 (E.D. Mich. Sept. 4, 2026), in a decision issued on September 4, 2026, Judge Robert J. White of the U.S. District Court for the Eastern District of Michigan denied Plaintiffs’ motion for court-facilitated notice to be distributed in a collective action alleging unpaid pre-shift and post-shift work in violation of the FLSA.  Judge White found that Plaintiffs’ evidentiary basis — namely, 6 declarations, including from one of the named plaintiffs and 5 from opt-ins — were insufficient to demonstrate “a strong likelihood” that thousands of employees across four states were similarly situated.

Case Background

Plaintiffs Roger Glidwell, Jr. and Amy Kelly brought an action against Autoneum North America, Inc. (“Autoneum”), an automobile parts manufacturer, asserting state law and FLSA claims alleging that the Company violated applicable wage and hour laws by failing to compensate employees across six plants in four different states for pre-shift and post-shift work.  Plaintiffs claimed that employees were required to clock in using Autoneum’s timekeeping system and to then do pre-shift work, including donning personal protective equipment (“PPE”) and attend meetings, and to do post-shift work by waiting for the next round of workers to start their shifts before clocking out.  Id. 1031-33, 1040.Plaintiffs alleged that “Autoneum would round, edit and otherwise manipulate the Plaintiffs’ start and stop times despite using a timekeeping system that records exactly when employees punch in and out each day.”  Id. at 1033.  The Court dismissed Plaintiffs’ state law claims and only the FLSA claim remained at the time the Court was considering Plaintiffs’ Motion for Court-Facilitated Notice to Potential Opt-In Plaintiffs.  Id.

The District Court’s Ruling

Judge White denied Plaintiffs’ motion finding that the 6 declarations submitted fell short of meeting the “strong likelihood” evidentiary standard for demonstrating that potential opt-ins are similarly situated and, finding further, that to approve notice — to thousands of employees across six plants in four different states — without such an evidentiary showing would be unfair.  Judge White offered three bases for his decision to deny Plaintiffs’ motion. 

First, the Court found that Plaintiffs did not meet their required evidentiary showing for court-approval of the notice because the 6 declarations (one from named Plaintiff Kelly and the rest from 5 opt-ins) did not rebut assertions made in the Complaint and in the Company’s opposition demonstrating a lack of uniformity in policies amongst the plants regarding time recording and overtime pay and as to collective bargaining agreement (“CBA”) and non-CBA facilities subject to different grievance procedures.  Though the Court agreed with Plaintiffs that declarations alone could potentially carry Plaintiffs’ burden, in the present case, it determined that the substance of the declarations could not overcome assertions in the Complaint and opposition briefing indicating that each plant used a different handbook or set calculation of work hours based on a CBA.  The Court noted that the named Plaintiffs “offered little evidence to rebut that each facility had its own system for calculating time worked” and, as such, there was no “strong likelihood that the underpayment was attributable to a companywide policy.”  Id. at 1038.  Because of the evidence showing that each plant had different handbooks and work hour calculations and indicating that some were governed by CBAs while others were not, the Court also found that the Plaintiffs were subject to differing individualized defenses as well.  Id.  In sum, Plaintiffs’ declarations could not overcome other evidence in the record showing differences amongst employees at the plants proposed to make-up the collective action at issue.

Second, turning to the issue of fairness with respect to distribution of the notice, and citing Clark v. A&L Homecare and Training Ctr., LLC, 68 F.4th 1003 (6th Cir. 2023), for the principle that sending notice can easily expand the “ranks” of a collective action “a hundredfold” and “forc[e] a defendant to settle,” the Court concluded that approving dissemination of the notice also would be unfair on such a sparse evidentiary showing.  Id. at 1040.  The Court observed that “[h]ere, there are thousands of employees across six plants in four different states that would receive notice” which could “amount[] to solicitation of those employees to bring suits of their own” if such employees are not eligible to join the lawsuit.  Id.  From that observation, the Court concluded that, given the size and scope of the potential collective and the “the impact notice might have on the ranks of th[e] collective action,” further evidence” was needed “to show that potential opt-ins are similarly situated.” Id.

Third, and finally, the Court found that not only was named Plaintiffs’ evidence insufficient and sparse, but also it had notable shortcomings.  Id. at 1041.  Two of the declarants had ended their employment over three years before the complaint was filed, putting their claims outside the statute of limitations period, and rendering their declarations irrelevant to the action at hand.  Id.  Further, one of the declarants was an opt-in plaintiff in a different FLSA action based on similar claims against the Company as to its Oregon, Ohio factory and, therefore, the declarant could not participate in the action rendering her declaration irrelevant as well.  Id. at 1041-42.In light of these additional deficiencies, the Court noted that it “only has four declarations across the six identified plants to rely on” which “further weaken[ed]” Plaintiffs’ position.  Id. at 1042. 

Implications for Companies

In defending FLSA collective actions, Companies should prioritize identifying evidence of differences amongst its locations or departments demonstrating different wage and hour computations or grievance processes early and often throughout the lifespan of the litigation.  Though the conditional certification and notice authorization stages of court review are thought to be more lenient and preliminary, the Glidwell decision shows that the evidentiary showing is not a cursory one, at least in the Sixth Circuit, and provides fertile ground for employers to make an evidentiary showing of their own to take putative plaintiffs to task.

California Federal Court Denies Class Certification In Adtech Case Due To Lack Of Article III Standing

By Gerald L. Maatman, Jr., Justin R. Donoho, and Hayley Ryan

Duane Morris Takeaways:  On September 21, 2026, in Smith, et al. v. Rack Room Shoes, Inc., No. 24-CV-6709 (N.D. Cal. Sept. 21, 2026), Judge Rita F. Lin of the U.S. District Court for the Northern District of California denied class certification in a case brought by consumers against an online shoe store company alleging that the company’s use of website advertising technology (“adtech”) violated the California Invasion of Privacy Act (“CIPA”) and Electronic Communications Privacy Act (“ECPA”).  The ruling is significant as it shows that before any class can be certified in the hundreds of adtech class actions filed in federal courts across the nation alleging that adtech violates privacy laws, plaintiffs not only bear the burden to establish, by the preponderance of the evidence, that they have suffered an Article III injury, but also cannot meet this burden by showing merely that they visited the defendant’s website at a time when adtech was installed on the website.

Background

This case is one of a legion of class actions that plaintiffs have filed nationwide alleging that third-party technology captured plaintiffs’ information and used it to facilitate targeted advertising. 

This software, often called advertising technologies or “adtech,” is a common feature of millions of consumer products and websites in operation today.  In adtech class actions, the key issue is often a claim brought under a the CIPA, the ECPA, or a variety of other statutes providing for statutory damages regardless of whether any actual injury occurred, because plaintiffs often seek millions (and sometimes even billions) of dollars, even from midsize companies, on the theory that hundreds of thousands of consumers or website visitors, times $5,000 per claimant in statutory damages under the CIPA and $10,000 per claimant in statutory damages under the ECPA, for example, equals a huge amount of damages.  Plaintiffs have filed the bulk of these types of lawsuits to date against healthcare providers, but they have filed suits against companies that span nearly every industry including retailers, consumer products, universities, and the adtech companies themselves.  Several of these cases have resulted in multimillion-dollar settlements, several have been dismissed, and the vast majority remain undecided. 

In Smith, the plaintiffs brought suit against Rack Room Shoes, Inc., an online shoe store company, alleging that in 2024, during their online web visits to purchase shoes from the company, the company had embedded on its website adtech supplied by Meta and other adtech companies that covertly intercepted the plaintiffs’ identities and interactions with the website, including the items the plaintiffs viewed, added to the their cart, and purchased, in alleged violation of the CIPA and the ECPA. 

The company answered the complaint, and the parties engaged in discovery, including the depositions of the plaintiffs and plaintiffs’ subpoenas to the adtech companies. 

Based on this discovery, the record reflected that in 2021 to 2023, the Meta pixel installed on the company’s website captured activities from devices and browsers that were signed into the plaintiffs’ accounts.  However, the plaintiffs provided no evidence that these 2021-2023 incidents involved their own web activities as opposed to activities of their family members using the same devices and browsers, that Meta captured any activity from the plaintiffs’ devices and browsers during their own sole 2024 visits, or that the other adtech installed on the company’s website captured any activities at all.

The plaintiffs moved for class certification, arguing that they had standing to bring their claims and that they satisfied Rule 23.

The Court’s Decision

The Court disagreed that the plaintiffs established standing and denied class certification on that basis without addressing or needing to address any of the parties’ arguments under Rule 23.

In their motion for class certification, the plaintiffs proffered two theories of injury in support of their argument that they had standing to bring their claims: one based on the actual interception of their information, and one based on the attempt to intercept their information.  (Slip Op. at 5.)

On the plaintiffs’ interception injury theory, the Court found no evidence that the Meta pixel embedded on the company’s website collected any data from the plaintiffs’ 2024 website visits, and no evidence that the activity that was recorded by Meta 2021-2023 was the plaintiffs’ own browsing activity.  Further, the Court rejected the plaintiffs’ argument that the company’s general use of the Meta pixel during 2024 was circumstantial evidence of actual tracking.  As the Court explained, citing the company’s expert testimony, the ability of adtech to collect and transmit data in a manner that can be linked to the website user “is impacted by many factors, including the browser being used, whether the browser and device are signed in to a social media account, and what cookie blocking features are enabled.”  (Id. at 7.)  In sum, the Court found that plaintiffs failed to present evidence from which a reasonable jury could find that any adtech installed on the company’s website collected any data attributable to the plaintiffs.

On the plaintiffs’ attempt injury theory, the Court found that the mere presence of active adtech on a company’s website does not bear the requisite close relationship to the type of harm traditionally at issue in intrusion upon seclusion and which type of harm the plaintiffs argued was the historical analog to the type of injury they suffered and thus sufficient to confer Article III standing.  On this point, the Court’s opinion turned on its finding that the plaintiffs presented no evidence that the adtech on the company’s website attempted to collect any “embarrassing, invasive, or otherwise private information.”  (Id. at 8.)  Further the Court found that the plaintiffs had no reasonable expectation of privacy in their web-browsing data due to the company’s privacy policy because the plaintiffs did not read it and the policy also did not create an expectation of privacy from adtech transmissions, and that even if plaintiffs had had a reasonable expectation of privacy, the plaintiffs failed to show that the mere presence of adtech was highly offensive.  (Id. at 9.)  In short, the Court held that “[t]he mere presence of active tracking software … on a website involving objectively non-sensitive information” does not bear a close relationship to the type of harm traditionally at issue in intrusion upon seclusion and, therefore, was insufficient to confer Article III standing.

Implications For Companies

Smith provides powerful precedent for any company opposing adtech class action claims where plaintiffs lack evidence from which a reasonable jury could find that any adtech installed on the company’s website actually collected any data attributable to the plaintiffs, by showing that any number of issues could have prevented such collection, such as the browser being used, whether the browser and device are signed in to a social media account, and what cookie blocking features are enabled.

Of course, Smith is just one tool in a defendant’s kit for defeating class certification in adtech cases.  Another is that even when named plaintiffs can establish that adtech collected data attributable to themselves (unlike in Smith), the same factors identified in Smith — browser type, social media account login status, cookie blocking features — are individualized issues that prevent named plaintiffs from establishing the defendant’s liability to alleged class members under Rule 23, as we blogged about here.

“Farm A Versus Farm B”: California Federal Court Rejects Class Certification Where Meal Period Claims Require Individualized Inquiries

By: Gerald L. Maatman, Jr, Daniel D. Spencer, Jamar D. Davis, and Kenny T. Tran

Duane Morris Takeaways: On September 18, 2026, in Sara Reyes v. Grow Smart Labor, Inc., No. 1:24-CV-00028, 2026 U.S. Dist. LEXIS 213967 (E.D. Cal. Sep. 18, 2026), Judge Jennifer L. Thurston of the U.S. District Court for the Eastern District of California denied class certification in a California wage-and-hour action after concluding that, although Plaintiff could identify a common question concerning whether the Donohue meal period presumption arose from Defendant’s timekeeping data, the rebuttal of that presumption would require extensive individualized farm-by-farm, crew-by-crew and day-by-day inquiries, demonstrating that individualized inquiries dominated over common questions.

Case Background

The case arose from Plaintiff Sara Reyes’ employment with Defendant Grow Smart Labor, a farm labor contractor that supplies agricultural workers to third-party farms. Id. at *1. Grow Smart’s workforce was anything but uniform: employees were assigned to different crops, locations, supervisors, and jobs; some were paid hourly while others were paid on a piece-rate basis; and the company used different timekeeping systems, including crew timecards and individual timecards. Id. at *8. Grow Smart presented evidence that its operations and timekeeping practices varied substantially by assignment, such that “farm-by-farm” or “crew-by-crew” investigation regarding meal breaks would ensue. Id. at *8-9.

The Court’s Reasoning

The meal period analysis was the centerpiece of the decision. The District Court recognized that under Donohue v. AMN Services, LLC, 11 Cal. 5th 58 (2021), time records showing missed, short, or delayed meal periods without corresponding compensation can create a rebuttable presumption that the employer violated California law. Id. at *4. But the Court emphasized that the Donohue presumption does not eliminate the separate requirements imposed by Federal Rule of Civil Procedure 23. Id. at *6.

Reyes’ expert provided class-wide evidence by analyzing Grow Smart’s timekeeping data, finding that almost none of Grow Smart’s records included entries that showed when employee meal breaks began or ended. Id. at *7. Grow Smart did not challenge the expert’s experience or qualifications, nor did it offer any contrary analysis of its own data or any rebuttal expert opinions. Id. at *7-8.The District Court concluded that Reyes had demonstrated a common question of law and fact concerning whether the class’s timekeeping data could trigger the Donohue presumption. Id. at *8.

However, Grow Smart successfully argued, to which the magistrate judge agreed to and found, that Reyes had not demonstrated that common questions are likely to predominate the rebuttal portion of the case: the degree of individualized inquiries needed to assess meal period compliance across all of Grow Smart’s California operations. Id. Grow Smart employees worked at different farms under different supervisors, some worked in crews while others had individualized timekeeping, and records varied from assignment to assignment. Id. Most importantly, Grow Smart presented evidence that whether meal periods were required to be recorded could depend on whether operations “ceased” during the relevant meal period. Id. at *8-9.The Court therefore anticipated that a class trial would devolve into “a long series of back-and-forth debates” concerning “what happened on Farm A versus Farm B or under the leadership of Supervisor 1 versus Supervisor 2.” Id. at *9.

The individualized nature of those inquiries also affected Reyes’ proposed class under Rule 23(b)(2). The Magistrate Judge found that a class action cannot be certified under 23(b)(2) when “each class member would be entitled to an individual award of monetary damages” and “a different injunction or declaratory judgment”, which Reyes did not object to.  Id. at *9-10. Since Reyes no longer worked for Grow Smart or cited any plans to return, she had not demonstrated that she could pursue prospective relief on behalf of a class of current employees, which is a prerequisite to seek such relief on behalf of a class of current employees. Id. at *10.

Takeaways and Implications for Employers

For employers defending wage-and-hour class actions, Reyes underscores an important distinction between identifying a statistical pattern and proving a class-wide violation. A plaintiff may be able to point to a common data anomaly, such as missing meal punches or apparent deductions, but the defense can still defeat certification by demonstrating that the meaning of those records depends on operational context. Here, the significance of a missing punch could not be evaluated in a vacuum because the company’s vast agricultural operations used different recordkeeping practices, including crew-level records that did not necessarily apply uniformly across business functions.

The decision also highlights the value of developing a factual record demonstrating operational variation before the certification stage. Employers should preserve and present evidence concerning different worksites, supervisors, scheduling practices, timekeeping systems, compensation methods, written policies, policy changes, and the actual practices followed in the field. Reyes shows how those facts can transform an apparently simple “missing meal punch” case into a series of individualized factual inquiries that plaintiffs cannot readily resolve through a single database or expert model. The result is a defense-friendly application of Rule 23’s predominance requirement: common data may establish a common issue, but it does not necessarily establish a common answer to the ultimate liability question.

You’re Invited: Year-End Review Of EEOC Litigation And Strategy 2026

By Gerald L. Maatman, Jr, Jennifer A. Riley, and Daniel D. Spencer

Mark your calendars for our bi-annual program analyzing the latest EEOC developments: Wednesday, October 14, 2026 from 11:00 a.m. to 11:30 a.m. Central. Reserve your virtual seat for the program here.

Join Duane Morris partners Gerald L. Maatman, Jr., Jennifer A. Riley and Daniel D. Spencer for a live panel discussion analyzing the latest impact of enforcement litigation at the U.S. Equal Employment Opportunity Commission, including its new National Enforcement Plan and strategic priorities established in fiscal year 2026 and the enforcement lawsuits filed over the past 12 months. Our virtual program will empower corporate counsel, human resource professionals and business leaders with key insights into the EEOC’s latest enforcement initiatives and provide strategies designed to minimize the risk of drawing the agency’s scrutiny.

Presenters

Gerald Maatman

Gerald L. Maatman Jr.

Jennifer A. Riley

Daniel D. Spencer

Daniel D. Spencer

Florida Federal Court Holds That The TCPA’s Do-Not-Call Provisions Do Not Apply To Cell Phone Users

By Gerald L. Maatman, Jr., Jennifer A. Riley, and Ryan T. Garippo

Duane Morris Takeaways: On September 11, 2026, in Anthony, et al. v. Brian Marketing Group, No. 24-CV-80800, 2026 WL 2685650 (S.D. Fla. Sept. 11, 2026), Judge Aileen M. Cannon of the U.S. District Court for the Southern District of Florida denied a plaintiff’s motion for default judgment on a Telephone Consumer Protection Act (“TCPA”) class action claim and held that cell phone users are not “residential telephone subscribers” entitled to sue under the TCPA’s do-not-call provisions. The decision is premised on the conclusion that a prior Federal Communications Commission’s (“FCC”) order was outside the scope of the agency’s statutory authority under 47 U.S.C. § 227(c).  If this decision is widely adopted, it has the potential to upend TCPA litigation nationwide.

Case Background

In June 2024, Plaintiff Michael Anthony (“Plaintiff” or “Anthony”) filed a putative class action against Brian Marketing Group (“BMG”) in the U.S. District Court for the Southern District of Florida for alleged violations of the TCPA and its implementing regulations.  He claimed that he received five unsolicited text messages to his personal cellphone over a twelve-month span even though he registered his cell phone number on the national do-not-call registry.  The text messages were identical and stated:

“Our records show that you or a loved one reached out for drug or alcohol treatment.  We have immediate availability!”

Because Anthony had never used drugs or alcohol, or never heard of BMG, he claims these text messages were unsolicited and violated the TCPA.  To that end, Anthony brought a single claim under § 227(c)(5) of the TCPA and its implementing regulations’ prohibition on unlawful communications to individuals who registered their phone numbers on the national do-not-call registry.  47 C.F.R. § 64.1200(c).

In September 2025, following proper service, the Clerk of Court entered default against BMG for failing to appear or respond.  As a result, Anthony filed a motion for default judgment seeking declaratory relief and $2,500 in statutory damages.

The Court’s Decision

In a thorough 25-page opinion, Judge Cannon walked through the text, structure, and history of the TCPA to conclude that the FCC’s Report and Order, In Re Rules & Regulations Implementing the Telephone Consumer Protection Act of 1991 (the “2003 Order”) exceeded the agency’s statutory authority.  The FCC could not lawfully include cell phone users within the definition of the term “residential telephone subscriber.”  As a result, Anthony could not state a claim under § 227(c)(5) of the TCPA.

“The TCPA consists of two parts: § 227(b) imposes ‘restrictions on [the] use of automated telephone equipment,’ and § 227(c) protects ‘subscriber privacy rights’ and is colloquially known as the ‘do-not-call provision.’”  Anthony, 2026 WL 2685650,at *2 (quotations omitted).  The authority to promulgate the regulations to enforce the do-not-call provision come from an express delegation from the U.S. Congress and were designed “to protect residential telephone subscribers’ privacy rights [and] to avoid receiving telephone solicitations to which they object.”  47 U.S.C. § 227(c)(1).

Although Congress did not define the term “residential telephone subscriber,” the FCC’s implementing regulations – which created the national do-not-call registry adopted that language – when defining the individuals who have a private right of action under the statute.  47 C.F.R. § 64.1200(c)(2) (“No person or entity shall initiate any telephone solicitation to . . . [a] residential telephone subscriber who has registered his or her telephone number on the national do-not-call registry of persons”) (emphasis added); see also 47 C.F.R. § 64.1200(c)(1) (“No person or entity shall initiate any telephone solicitation to . . . [a]ny residential telephone subscriber before the hour of 8 a.m. or after 9 p.m.”) (emphasis added). From 1991 (when the TCPA was passed) to 2003 (when the 2003 Order was issued), there was no indication that the term residential telephone subscriber included calls to cell phones.

But, in 2023, the FCC issued the 2003 Order which purported to extend the national do-not-call registry’s protections to cell phone users because it was “more consistent with the overall intent of the TCPA to allow wireless subscribers to benefit from the full range of TCPA protections.”  Anthony, 2026 WL 2685650,at *4 (quotations omitted).  Judge Cannon, however, concluded that the FCC lacked the authority to decide this issue in the 2003 Order and therefore Anthony failed to state a claim as a matter of law.  Judge Cannon’s analysis followed four primary steps.

First, Judge Cannon examined the plain meaning of “residential telephone subscriber” as used in § 227(c).  Because the TCPA does not define the term, Judge Cannon looked to the dictionary definitions in existence at the time of enactment.  “At the time the TCPA was enacted in 1991, dictionaries defined ‘residential’ as 1) ‘of or connected with residence,’ 2) ‘of, characterized by, or suitable for, residences or homes,’ and 3) ‘chiefly for residents rather than transients.’” Id. at *7 (quotations omitted).  She, therefore, reasoned that the term “residential telephone subscriber” meant “at the very least . . . a person who pays intermittently to receive telephone services that are connected to his or her home.“  Id.  Cell phones, however, were not connected to an individual’s residence in 1991 and therefore would not have been captured by the scope of that term at the time.

Second, Judge Cannon explained that the structure of the TCPA confirmed this interpretation as well.  In § 227(b), Congress demonstrated its ability to extend protections to “cellular telephone service” subscribers.  47 U.S.C. § 227(b)(1)(A)(iii).  It also included a separate section prohibiting the use of the above-mentioned regulated technologies to residential telephone subscribers.  47 U.S.C. § 227(b)(1)(B).  Other sections of the TCPA confirmed that interpretation.  See Anthony, 2026 WL 2685650, at *9-10.  If the term “residential” was synonymous with “cellular,” then Judge Cannon reasoned that § 227(b)(1)(B) would violate the cannon against surplusage because Congress would have regulated the same conduct twice.  “In sum, it is clear that Congress knew how to differentiate between cellular and residential when it wished to.”  Id. at *10.

Third, Judge Cannon reasoned that the history of the statute confirmed this interpretation.  “From the date of enactment of the TCPA through 2003,” no one thought that cell phone numbers were considered residential telephone lines.  Anthony, 2026 WL 2685650, at *9-10.  Indeed, the FCC even sought additional authority from Congress in order to promulgate such rules prior to 2003.  “Nevertheless, in 2003, and without the previously contemplated additional authority from Congress, the FCC promulgated new implementing regulations . . . to bring wireless subscribers within the orbit of residential subscribers.”  Id. at *11.   In short, “[a]gencies may play the sorcerer’s apprentice but not the sorcerer himself” – and in the absence of an express delegation from Congress to allow the FCC to promulgate rules to protect cell phone users– the extension of § 227(c) to cell phones was improper.  Id. at *11 (quoting Facebook, Inc. v. Duguid, 592 U.S. 395, 409 (2021)). 

Finally, Judge Cannon opined on the ongoing circuit split related to whether text messages constitute calls and determined that “the private right of action in § 227(c)(5) . . . does not [authorize] suits by cell phone users based on unwanted text messages (rather than calls)” and noted that this authority was an additional basis to enter judgment for BMG.  Anthony, 2026 WL 2685650, at *12.

Implications For Companies

If the reasoning of Anthony is widely adopted, this decision has the potential to eviscerate TCPA litigation for companies across the nation.  Indeed, if the call in question is made to a cell phone, this decision essentially holds that there is no cause of action under § 227(c)(5) generally and specifically there is no protections afforded to such users under 47 C.F.R. § 64.1200(c)(1), 47 C.F.R. § 64.1200(c)(2), and 47 C.F.R. § 64.1200(d).  It also represents yet another decision to hold that text messages are not calls within the meaning of § 227(c)(5).

That said, one of the more ironic elements of this decision is that it does not categorically foreclose 47 C.F.R. § 64.1601(e) claims – for failure to provide proper caller identification information – which a minority of courts have recently shoehorned into § 227(c)(5)’s private right of action.  Despite the numerous other problems with such claims, § 64.1601(e) claims do not purport to hinge on an individual’s residential telephone subscriber status.  This decision also does not eliminate TCPA liability under § 227(b)(3) for making calls using regulated technology but it would carve off a substantial chunk of TCPA liability if widely adopted.

While this decision is undoubtedly a positive development for corporate counsel, we are not yet at the stage where companies can take such liability off the table.  This decision represents one decision, from one federal judge, and is certainly the minority view.  Nonetheless, companies should continue to preserve this argument by raising it as the law continues to develop and monitor this blog to stay on top of this new potential trend in TCPA law.

Show Your Work: California Federal Court Denies Preliminary Approval Of Data Breach Class Action Settlement

By Gerald L. Maatman, Jr., Anna Sheridan, and Olga Romadin

Duane Morris Takeaways: On September 16, 2026, in Jimenez, Jr., et al. v. OE Federal Credit Union, Case No. 24-CV-02746 (N.D. Cal. Sept. 16, 2026), U.S. District Judge Jon S. Tigar of the U.S. District Court for the Northern District of California denied plaintiffs’ motion for preliminary approval of a class action settlement in a data breach case involving over 220,000 individuals. The decision is a significant reminder that courts will scrutinize class action settlements for obvious deficiencies, and that plaintiffs seeking preliminary approval must “show their work” by providing detailed information about the relative value of their claims and the strengths and weaknesses of their case.

Case Background

Plaintiffs Daniel Jimenez Jr., Mark Hendren, and Erica Jaramillo are current or former customers of OE Federal Credit Union (“OEFCU”), which is described as “the country’s largest labor-based credit union.” Order at 1. OEFCU possessed its customers’ personally identifiable information (“PII”) and protected health information (“PHI”), including full names, Social Security numbers, dates of birth, bank and financial account information, driver’s license numbers, medical procedure information, and health insurance information. Id. Sometime between August 19, 2023 and October 29, 2023, OEFCU suffered a ransomware attack and data breach resulting in unauthorized access to the PII/PHI of the named plaintiffs and the putative class.

Plaintiffs filed suit alleging claims for negligence, breach of implied contract, invasion of privacy, unjust enrichment, violation of the California Unfair Competition Law, violation of the California Consumer Privacy Act, violation of the California Customer Records Act, and declaratory relief. They brought claims on behalf of themselves and a class of all persons identified as being impacted by the data breach. After OEFCU moved to dismiss, the Court granted the motion in part and denied it in part, dismissing several claims with leave to amend and the declaratory relief claim with prejudice.

The parties subsequently engaged in mediation and reached a proposed class settlement. Under the proposed settlement, OEFCU agreed to establish a non-reversionary settlement fund of $2,300,000. Id. at 3.  Each class member could submit a claim of up to $5,000 for reimbursement of out-of-pocket losses traceable to the data incident. Settlement class members were also entitled to submit a claim for a pro rata cash payment from the net settlement fund, estimated at approximately $50 per claimant. California class members could claim an additional $75, subject to reduction based on the total number of claimants. The settlement agreement proposed to deduct $766,666.66 in attorney’s fees (one-third of the common fund), $5,000 each to the three class representatives as service awards, and undetermined amounts for litigation costs and settlement administration costs.  Id.

The Court’s Decision

Judge Tigar denied the motion for preliminary approval, identifying seven deficiencies that collectively prevented a finding that the settlement fell “within the range of possible approval” under Rule 23(e)(2). See In Re Tableware Antitrust Litig., 484 F. Supp. 2d 1078, 1079 (N.D. Cal. 2007).

Adequacy of Relief — Rule 23(e)(2)

The first four deficiencies all bore on whether the proposed settlement provided adequate relief to the class. The Court began by questioning the use of a claims-made distribution process, noting that because OEFCU could readily identify class members from its own records, requiring them to submit claims was unnecessary and would predictably depress the actual payout — “[t]he effect of not simply distributing relief to the known class members is that the defendant will likely pay out much less than it would if there were no claiming process.” Order at 6. The Court noted that claims-made settlements are appropriate when it is the best or only option available, as is often the case with consumer class actions. Id. The Court faulted Plaintiffs for providing no information about the maximum potential recovery at trial, offering instead only boilerplate that the settlement “provides significant relief” and “is well within the range of other data breach settlements.” Relatedly, Plaintiffs supplied only generic statements about the “high level of risk, expense, and complexity” of continued litigation rather than a careful analysis of the claims and defenses — falling short of the Court’s requirement that movants “show their work by explaining the relative value of their claims in significant detail.” Order at 7–8 (quoting Haralson, 383 F. Supp. 3d at 970). Finally, the Court observed that the estimated $50 per-member pro rata payment was unsupported by evidence. Order at 8. After subtracting attorney’s fees alone, the actual per-member recovery was closer to $6, and would decline further once administration costs, incentive awards, and out-of-pocket reimbursement claims were accounted for — the Court noted that if just over 300 claimants sought the full $5,000 reimbursement, the pro rata share could dwindle to nothing for remaining class members. Order at 8.

Equitable Treatment — Rule 23(e)(2)(D)

The fifth deficiency concerned the settlement’s differential treatment of class members. The settlement provided California class members a higher recovery than non-California members, yet Plaintiffs identified no California subclass with distinct claims that might justify the disparity. Order at 8–9. The Court emphasized that unexplained disparate treatment “increases the likelihood that the settlement agreement does not meet the Rule 23(e) standard.” Id. at 9 (quoting Ferrington v. McAfee, Inc., No. 10-CV-01455, 2012 WL 1156399, at *8 (N.D. Cal. Apr. 6, 2012)).

Accuracy and Procedural Compliance

The final two deficiencies concerned the quality of the submission itself. The Court identified a material discrepancy between the motion’s description of the timing of payments to class members and the actual terms of the settlement agreement. Order at 9–10. The Court also found that the motion failed to comply with the Northern District of California’s Procedural Guidelines for Class Action Settlements — including the requirements to explain anticipated versus maximum class recovery, to identify the settlement administration process and its costs, and to provide information about comparable settlements. Id. at 10; see also Bakhtiar v. Info. Res., Inc., No. 17-CV-04559, 2020 WL 11421997, at *8 (N.D. Cal. Jan. 30, 2020) (“A movant’s failure to address the issues discussed in the Guidelines is a proper ground for denying a motion for preliminary or final approval of a class action settlement.”).

The Court denied the motion without prejudice to Plaintiffs’ filing a revised motion, which it ordered due by November 4, 2026. The Court also reminded the parties that the Ninth Circuit benchmark for attorney’s fees in a successful class action is 25% of the common fund, and that Plaintiffs should justify any deviation from that benchmark. Id.

Implications For Companies

The Jimenez decision is a reminder that courts will closely scrutinize class action settlements at the preliminary approval stage, particularly in data breach litigation impacting consumers. The decision underscores several key points for corporate counsel. Most importantly, parties should closely follow the Court’s Procedural Guidelines for Class Action Settlements as failure to heed those Guidelines can serve as an independent basis for denying preliminary approval.

On a more granular level, the Jimenez decision offers other relevant practice pointers for class action settlements. First, claims-made settlement structures may be disfavored where the class members are readily identifiable from the defendant’s records. Second, plaintiffs seeking preliminary approval must do more than offer boilerplate language about the risks of litigation — they must provide concrete information about the maximum potential recovery and a detailed analysis of the strengths and weaknesses of their claims. Third, settlements that provide differential treatment to subsets of class members without explanation may face heightened scrutiny under Rule 23(e)(2)(D).  Companies facing data breach class actions should work closely with counsel to ensure that any settlement submissions provide the level of detail and analysis that courts increasingly require before granting preliminary approval.

© 2009- Duane Morris LLP. Duane Morris is a registered service mark of Duane Morris LLP.

The opinions expressed on this blog are those of the author and are not to be construed as legal advice.

Proudly powered by WordPress