California Federal Court Denies TikTok’s Motion To Dismiss Children’s Privacy Claims Based on Prior Class Action Settlements

By Gerald L. Maatman, Jr., Justin R. Donoho, and Hayley Ryan

Duane Morris Takeaways:  On September 23, 2026, in the case of In Re TikTok, Inc., Minor Privacy Litigation, No. MDL 25-3144, ECF No. 414 (C.D. Cal. Sept. 23, 2026), Judge George H. Wu of the U.S. District Court for the Central District of California issued a tentative ruling (adopted as final on September 24, 2026) denying TikTok’s motion to dismiss the Second Amended Consolidated Class Action Complaint in a multidistrict litigation brought by minors alleging that TikTok collected, shared, and exploited their personal information without parental consent in violation of the Children’s Online Privacy Protection Act (“COPPA”) and related state laws.

The ruling is significant because it rejected TikTok’s argument that two prior nationwide class action settlements – totaling over $93 million combined – barred the plaintiffs’ claims, holding that the record at the pleadings stage did not establish the named plaintiffs’ membership in those prior settlement classes.  For companies that have previously settled class actions, the decision underscores the risk that broad settlement releases may not foreclose subsequent litigation where class membership is not clearly established on the face of the pleadings.

Background

This case is one of a series of privacy class actions targeting TikTok and its parent companies, ByteDance Inc. and ByteDance Ltd.  The plaintiffs are minors who allege that while under the age of 13, their personal information was collected, shared, and exploited by TikTok without the parental notice and consent COPPA requires for children under 13. The plaintiffs seek to impose liability stretching back to March 28, 2019.

Two prior nationwide settlements form the backdrop of the dispute.  The first, T.K. v. Bytedance Technology Co., No. 1:19-CV-07915 (N.D. Ill.), followed the FTC’s 2019 enforcement action concerning COPPA violations by Musical.ly, TikTok’s predecessor, and settled for $1.1 million on behalf of approximately 6 million individuals who used Musical.ly or TikTok before August 22, 2022, while under the age of 13. The settlement included a broad release but no injunctive relief.  The second, In Re TikTok, Inc., Consumer Privacy Litigation, No. 1:20-CV-04699 (N.D. Ill.) (the “Privacy MDL”), consolidated lawsuits focused on TikTok’s use of algorithms, facial recognition, and other technologies to collect and transfer personally identifiable user data to servers in China, and settled for $92 million with broad injunctive relief.

In April 2025, the U.S. Judicial Panel on Multidistrict Litigation ordered the transfer of the present actions to the Central District of California.  After an initial partial dismissal of claims brought under laws of states without a domiciled plaintiff, the plaintiffs amended, and the defendants moved to dismiss the Second Amended Consolidated Class Action Complaint (“Complaint”), arguing that the T.K. and Privacy MDL settlements barred claims for conduct occurring before August 22, 2022, the cutoff date defining the later T.K. settlement class.  The dispositive question was therefore whether the pleadings themselves established that the named plaintiffs fell within those prior settlement classes.

The Court’s Decision

The Court denied TikTok’s motion to dismiss, finding that the defendants failed to establish, on the record available at the pleadings stage, that the named plaintiffs were members of the T.K. class. ECF No. 414 at 8-9.

At the heart of the ruling was a straightforward factual gap.  The T.K. settlement class included individuals who used TikTok or Musical.ly before August 22, 2022, while under the age of 13.  Id.  However, the Complaint did not allege the birth dates or first-use dates of any of the named plaintiffs – it alleged only that the plaintiffs were under 13 and used TikTok during the Class Period, defined as March 28, 2019, to the present.  Id. at 9.  The Court held that these allegations did not establish when within that period the plaintiffs used TikTok, and the judicially noticed materials likewise did not supply that information.  Id.

Even assuming none of the plaintiffs opted out of the prior settlements, the Court found that the defendants still had not shown the plaintiffs belonged to the prior classes in the first place.  Id.  As the Court stated, “[a] person need not opt out of a class to which that person never belonged.”  Id.

The Court also rejected TikTok’s argument that plaintiffs should not be allowed to avoid res judicata simply by “artfully pleading around” the relevant facts.  Id.  Because a plaintiff’s failure to anticipate and plead around an affirmative defense is not a pleading deficiency, as the Supreme Court explained in Jones v. Bock, 549 U.S. 199 (2007), the Court concluded that even plaintiffs who knew these defenses were coming, and knew their own ages and use histories, were not required to plead around TikTok’s affirmative defenses of release and preclusion, provided they otherwise sufficiently pleaded their causes of action. Id. at 10.

The Court further rejected TikTok’s alternative argument that, regardless of membership in the prior classes, plaintiffs either were precluded from, or lacked Article III standing to pursue, claims for the pre-August 2022 period.  Id.  TikTok reasoned that uncertainty about whether the named plaintiffs were under 13 and used TikTok before August 22, 2022, does not prevent dismissal because plaintiffs who meet those criteria are bound by the prior settlements, while plaintiffs who did not use TikTok during the relevant period cannot recover for that period and lack standing to represent those who did.  Id.  The Court disagreed.  The Court held that once a named plaintiff establishes individual standing, differences in injuries between the named plaintiffs and absent class members go to class certification rather than standing, the distinction drawn by the Ninth Circuit in Melendres v. Arpaio, 784 F.3d 1254 (9th Cir. 2015).  Id. at 11.  As the Court explained, “[w]hether Plaintiffs can represent class members who experienced that conduct earlier in the proposed Class Period concerns their representative capacity under Rule 23, and the possibility that Plaintiffs used TikTok only after August 22, 2022, does not defeat their standing to pursue the alleged claims.”  Id.  The Court likewise declined to redefine the class period at the pleading stage, holding that the issue is more appropriately addressed at class certification.  Id.

After oral argument on September 24, 2026, the Court adopted its tentative ruling as the final ruling.  See ECF No. 416.

Implications For Companies

This decision provides important guidance for any company facing follow-on privacy and/or adtech class action litigation after a prior settlement, by showing that broad settlement releases cannot be enforced at the motion-to-dismiss stage unless the defendant can demonstrate from the pleadings alone that the current plaintiffs were members of the prior class.  That is a high bar where the operative complaint does not specify individual plaintiffs’ ages or first-use dates, or other identifying information necessary to determine membership.

Of course, preclusion based on prior settlements is just one tool in a defendant’s kit for defeating class certification in privacy and adtech cases.  For example, in the related case of In Re TikTok, Inc., Consumer Privacy Litigation, 713 F. Supp. 3d 470 (N.D. Ill. 2024), the court declined to dismiss in-app browser claims on the basis of the prior $92 million settlement but left the door open to a different result upon further discovery.  Id. at 501-02.  There, the court observed that “the unusual and as-yet-undisclosed manner and method of the Original Plaintiffs’ post-settlement investigation leaves open the possibility that further information might alter this conclusion — for example, evidence that they recognized both the in-app browser’s risks and the potential to use them as the basis for a wiretapping theory of liability, but deliberately chose not to pursue this opportunity,” adding that “[s]uch evidence would be worth further attention, if not a different result.”  Id. at 501.  The court reinforced this point by noting that the original plaintiffs’ source code expert had been given “free rein to probe TikTok’s relevant technology” during confirmatory discovery.  Id. at 499.  Defendants facing successive adtech class actions should accordingly pursue targeted discovery into prior expert analyses and internal communications reflecting awareness of the privacy risks at issue — evidence that, under the court’s reasoning in In Re TikTok, Inc., Consumer Privacy Litigation, could compel preclusion of theories that were available but not pursued in the earlier proceeding.

California Federal Court Denies Class Certification In Adtech Case Due To Lack Of Article III Standing

By Gerald L. Maatman, Jr., Justin R. Donoho, and Hayley Ryan

Duane Morris Takeaways:  On September 21, 2026, in Smith, et al. v. Rack Room Shoes, Inc., No. 24-CV-6709 (N.D. Cal. Sept. 21, 2026), Judge Rita F. Lin of the U.S. District Court for the Northern District of California denied class certification in a case brought by consumers against an online shoe store company alleging that the company’s use of website advertising technology (“adtech”) violated the California Invasion of Privacy Act (“CIPA”) and Electronic Communications Privacy Act (“ECPA”).  The ruling is significant as it shows that before any class can be certified in the hundreds of adtech class actions filed in federal courts across the nation alleging that adtech violates privacy laws, plaintiffs not only bear the burden to establish, by the preponderance of the evidence, that they have suffered an Article III injury, but also cannot meet this burden by showing merely that they visited the defendant’s website at a time when adtech was installed on the website.

Background

This case is one of a legion of class actions that plaintiffs have filed nationwide alleging that third-party technology captured plaintiffs’ information and used it to facilitate targeted advertising. 

This software, often called advertising technologies or “adtech,” is a common feature of millions of consumer products and websites in operation today.  In adtech class actions, the key issue is often a claim brought under a the CIPA, the ECPA, or a variety of other statutes providing for statutory damages regardless of whether any actual injury occurred, because plaintiffs often seek millions (and sometimes even billions) of dollars, even from midsize companies, on the theory that hundreds of thousands of consumers or website visitors, times $5,000 per claimant in statutory damages under the CIPA and $10,000 per claimant in statutory damages under the ECPA, for example, equals a huge amount of damages.  Plaintiffs have filed the bulk of these types of lawsuits to date against healthcare providers, but they have filed suits against companies that span nearly every industry including retailers, consumer products, universities, and the adtech companies themselves.  Several of these cases have resulted in multimillion-dollar settlements, several have been dismissed, and the vast majority remain undecided. 

In Smith, the plaintiffs brought suit against Rack Room Shoes, Inc., an online shoe store company, alleging that in 2024, during their online web visits to purchase shoes from the company, the company had embedded on its website adtech supplied by Meta and other adtech companies that covertly intercepted the plaintiffs’ identities and interactions with the website, including the items the plaintiffs viewed, added to the their cart, and purchased, in alleged violation of the CIPA and the ECPA. 

The company answered the complaint, and the parties engaged in discovery, including the depositions of the plaintiffs and plaintiffs’ subpoenas to the adtech companies. 

Based on this discovery, the record reflected that in 2021 to 2023, the Meta pixel installed on the company’s website captured activities from devices and browsers that were signed into the plaintiffs’ accounts.  However, the plaintiffs provided no evidence that these 2021-2023 incidents involved their own web activities as opposed to activities of their family members using the same devices and browsers, that Meta captured any activity from the plaintiffs’ devices and browsers during their own sole 2024 visits, or that the other adtech installed on the company’s website captured any activities at all.

The plaintiffs moved for class certification, arguing that they had standing to bring their claims and that they satisfied Rule 23.

The Court’s Decision

The Court disagreed that the plaintiffs established standing and denied class certification on that basis without addressing or needing to address any of the parties’ arguments under Rule 23.

In their motion for class certification, the plaintiffs proffered two theories of injury in support of their argument that they had standing to bring their claims: one based on the actual interception of their information, and one based on the attempt to intercept their information.  (Slip Op. at 5.)

On the plaintiffs’ interception injury theory, the Court found no evidence that the Meta pixel embedded on the company’s website collected any data from the plaintiffs’ 2024 website visits, and no evidence that the activity that was recorded by Meta 2021-2023 was the plaintiffs’ own browsing activity.  Further, the Court rejected the plaintiffs’ argument that the company’s general use of the Meta pixel during 2024 was circumstantial evidence of actual tracking.  As the Court explained, citing the company’s expert testimony, the ability of adtech to collect and transmit data in a manner that can be linked to the website user “is impacted by many factors, including the browser being used, whether the browser and device are signed in to a social media account, and what cookie blocking features are enabled.”  (Id. at 7.)  In sum, the Court found that plaintiffs failed to present evidence from which a reasonable jury could find that any adtech installed on the company’s website collected any data attributable to the plaintiffs.

On the plaintiffs’ attempt injury theory, the Court found that the mere presence of active adtech on a company’s website does not bear the requisite close relationship to the type of harm traditionally at issue in intrusion upon seclusion and which type of harm the plaintiffs argued was the historical analog to the type of injury they suffered and thus sufficient to confer Article III standing.  On this point, the Court’s opinion turned on its finding that the plaintiffs presented no evidence that the adtech on the company’s website attempted to collect any “embarrassing, invasive, or otherwise private information.”  (Id. at 8.)  Further the Court found that the plaintiffs had no reasonable expectation of privacy in their web-browsing data due to the company’s privacy policy because the plaintiffs did not read it and the policy also did not create an expectation of privacy from adtech transmissions, and that even if plaintiffs had had a reasonable expectation of privacy, the plaintiffs failed to show that the mere presence of adtech was highly offensive.  (Id. at 9.)  In short, the Court held that “[t]he mere presence of active tracking software … on a website involving objectively non-sensitive information” does not bear a close relationship to the type of harm traditionally at issue in intrusion upon seclusion and, therefore, was insufficient to confer Article III standing.

Implications For Companies

Smith provides powerful precedent for any company opposing adtech class action claims where plaintiffs lack evidence from which a reasonable jury could find that any adtech installed on the company’s website actually collected any data attributable to the plaintiffs, by showing that any number of issues could have prevented such collection, such as the browser being used, whether the browser and device are signed in to a social media account, and what cookie blocking features are enabled.

Of course, Smith is just one tool in a defendant’s kit for defeating class certification in adtech cases.  Another is that even when named plaintiffs can establish that adtech collected data attributable to themselves (unlike in Smith), the same factors identified in Smith — browser type, social media account login status, cookie blocking features — are individualized issues that prevent named plaintiffs from establishing the defendant’s liability to alleged class members under Rule 23, as we blogged about here.

Colorado’s Proposed Rules Require Meaningful Human Review And Reconsideration Of Employment Decisions Materially Influenced by AI

By Gerald L. Maatman, Jr., Justin Donoho, and Hayley Ryan

Duane Morris Takeaways:  On August 11, 2026, the Colorado Department of Law released a set of proposed rules intended to govern the implementation of Colorado’s Automated Decision-Making Technology Act (“ADMT Act”) and Conversational Artificial Intelligence Service Operator Requirements (the “Chatbot Safety Act”). Both laws, and the proposed rules (to the extent they become final, following a notice and comment period), take effect January 1, 2027.

The proposed rules under the ADMT Act would add additional layers of regulatory burdens on companies using AI-based tools to make consequential automated decisions affecting a consumer’s access to, eligibility for, or terms of employment, education, housing, lending, financial services, insurance, health care, essential government services, and public benefits. 

Take AI employment tools, for example — if Colorado’s ADMT rules were to become final, they would require companies using AI employment tools to make available and readily accessible to job candidates and employees:

  1. the make, model, and version number of any AI tool whose outputs were used or will be used to materially influence a consequential employment decision such as in candidate screening, interviewing, hiring, firing, and other consequential employment decisions;
  2. the types and categories of personal data input to the model;
  3. the sources of these input data, including the identities of intermediary and original sources; and
  4. to the recipients of any adverse outcomes materially influenced by the AI tool:
    1. within 30 days, notifications of the adverse outcome setting forth the decision, purpose of the AI tool, the reasoning and primary factors relied upon by the AI tool to produce the output, and the relative roles of the AI tool and human reviewers in the decision — such as whether the employer followed the human best practices to mitigate the risk of AI hiring tool noncompliance with antidiscrimination statutes that we identified in our blog (here); and
    2. within 45 days after receipt of a request for review, complete a meaningful human review and reconsideration of any adverse outcome, to the extent commercially reasonable.

The proposed rules under the Chatbot Safety Act would add age-assurance, disclosure, privacy, minor-protection, crisis-response, and reporting requirements on companies using AI-based chatbots.

The analysis in our blog post focuses on the “meaningful human review and reconsideration” component of the ADMT Act and its corresponding proposed rules, in the context of adverse employment decisions (number 4(b), above), to assist companies in preparing for compliance by January 1, 2027, and in commenting on the proposed rules before the comment period closes on October 26, 2027, as may be appropriate for their businesses. 

Organizations evaluating and seeking to comply with the proposed rules should continue monitoring the rulemaking process, as key provisions, including those discussed below, may change before the rules become effective.

Background

Colorado’s ADMT Act (Colo. Rev. Stat. § 6-1-1701, et seq.) was enacted May 14, 2026, and will become effective January 1, 2027.  It provides, among other things, that when an employee or job applicant experiences an adverse outcome resulting from a consequential decision that was materially influenced by AMDT such as an AI employment tool, then the employee or job applicant may request, and the employer must provide (i) instructions for requesting personal data and correcting factually  incorrect or materially inaccurate personal data used in the decision; and (ii) “an opportunity for meaningful review and reconsideration of the consequential decision, to the extent commercially reasonable.”  Id. § 6-1-1705. 

“Meaningful Human Review,” as defined under the ADMT Act, requires the employer to designate an individual who has authority to approve, modify, or override a consequential decision to perform the review.  Id. § 6-1-1701(15).  Further, in conducting the review, the designated individual must consider relevant, available primary evidence, must be trained to conduct the review, must not default to the system output, and must have access to sufficient information to understand (i) the output’s intended use, material limitations, and categories of inputs; and (i) the principal factors used to generate the output, without requiring disclosure of proprietary source code, model weights, or other trade secrets.  Id.

The ADMT Act also provides that, on or before January 1, 2027, Colorado’s Attorney General shall adopt rules to clarify and implement these requirements.  Id.

On August 11, 2026, the Colorado Department of Law released a set of proposed rules under the ADMT Act and Chatbot Safety Act that, among other things, would clarify and implement rules regarding reviewer standards, commercial reasonableness, response requirements, and documentation requirements, as discussed below.

Who Can Perform A Meaningful Human Review?

The proposed rules provide that an individual who conducts a meaningful human review must meet the following criteria:

  • Independence – The reviewer must be an independent reviewer who did not make the original decision and who is not a subordinate of the original decision-maker, whenever feasible.
  • Subject matter understanding – The reviewer must have a level of subject matter understanding that is commensurate with the nature of, and negative consequences resulting from, the adverse outcome of the consequential decision being reviewed.
  • Sufficient training – The reviewer must be trained regarding (a) accuracy and objectivity in decision-making; (b) information considered by the AI employment tool; (c) the output’s intended use, material limitations, and categories of inputs; and (d) the subject matter at issue at a level that would enable the reviewer to identify whether review of additional available primary evidence would be valuable, and to review and understand that evidence.
  • Sufficient authority – The reviewer must not be subject to steering by the upper management that would influence the reviewer’s decision, and they must be shielded from potential retaliation.
  • Unassisted by AI – The reviewer may not use any ADMT in conducting his or her review.

When Is Meaningful Human Review Commercially Reasonable?

Under the ADMT Act, employers receiving requests to review adverse outcomes materially influenced by an AI employment tool must conduct a meaningful human review and reconsideration of such outcome “to the extent commercially reasonable.” 

The proposed rules provide that an employer bears the burden of demonstrating that meaningful human review is not commercially reasonable.

To meet this burden, employers must use specific evidence, and consider the following factors, weighed together, with no single factor being dispositive:

  • type of review required — i.e., either (a) if the circumstances and request indicate that the AI tool may have malfunctioned, then correcting and re-performing the decision-making process; or (b) if additional evidence is submitted by the employee or job applicant, then considering whether that evidence changes the adverse outcome;
  • magnitude of harm resulting from the adverse outcome;
  • reversibility of the adverse outcome;
  • value provided by the review of available primary evidence;
  • employer size and capacity;
  • marginal cost and technical feasibility of the review; and
  • availability of qualified reviewers.

When the harm to an employee or job applicant resulting from an adverse outcome is a severe and irreversible denial of a basic human need, meaningful human review is presumed to be commercially reasonable.  This presumption of commercial reasonableness can be rebutted by evidence showing that the review is technically or financially impossible or could not change the adverse outcome of the consequential decision.

When And How Must An Employer Respond To A Request For Review?

Within 10 days after receiving a request for review of an adverse outcome of a consequential decision meaningfully influenced by an AI employment tool, the employer must confirm receipt of the request and provide information about how the employer will process the request.

Within 45 days of receiving the request, meaningful human review must be completed, and a response must be provided to the employee or job candidate.  The response must include the reviewer’s decision to confirm or override the consequential decision, the type of review conducted, the factors considered in making that decision, and the reasons the reviewer decided to confirm or override the consequential decision.  Reasons provided must be specific to the evidence provided, and not a recitation of the AI tool’s general logic. 

Where possible, an adverse outcome must be stayed pending meaningful human review.

What Documentation Of Meaningful Human Reviews Must Be Retained?

When a meaningful human review is conducted, the employer must retain a record showing:

  • the reviewer identity, authority, and relevant training;
  • review timestamps;
  • primary evidence available to the reviewer, including information provided by the employee or job candidate;
  • the reviewer’s access to the AI tool’s intended use, limitations, inputs and principal factors;
  • whether the reviewer approved, modified, or overrode the output; and
  • a written justification for the reviewer’s decision to approve, modify, or override the output.

Implications For Companies

Colorado’s ADMT Act and Chatbot Safety Act and their corresponding proposed rules add significant operational obligations and compliance burdens for companies using automated decision-making technology to meaningfully influence consequential decisions, and using chatbots, respectively. 

This blog post identified one component of these multifaceted burdens relating to one type of ADMT – meaningful human review and consideration of employment decisions materially influenced by AI employment tools.

Although the ADMT Act and Chatbot Safety Act do not provide a private right of action, violations may be prosecuted by the Colorado Attorney General and are treated as a deceptive trade practice under the Colorado Consumer Protection Act, carrying civil penalties of up to $20,000 per violation.

Companies using or considering using ADMT or chatbots should consider whether to comment on the proposed rules before the comment period closes on October 26, 2027, should continue to monitor the content of the rules as they may evolve during the notice and comment period, and should prepare for complying with the rules by the time they are scheduled to come into effect on January 1, 2027.

Third Circuit Affirms Dismissal Of Session Replay Code Class Action Because The Collection Of Anonymized Information Does Not Constitute A Concrete Injury Necessary To Confer Article III Standing

By Gerald L. Maatman, Jr., Justin Donoho, and Hayley Ryan

Duane Morris Takeaways:  On May 26, 2026, in Smidga, et al. v. Spirit Airlines, Inc., No. 24-1757, 2026 WL 1470137 (3d Cir. May 26, 2026), the U.S. Court of Appeals for the Third Circuit affirmed a federal district court’s dismissal of a class action alleging that the defendant’s use of session replay code, a form of website analytics technology, violated federal and state privacy laws.  Relying on its prior decision in Cook v. GameStop, Inc., 148 F.4th 153 (3d Cir. 2025), the Third Circuit held that the three named plaintiffs lacked standing because there were no allegations of embarrassment or humiliation, plaintiffs voluntarily provided the information on the defendant’s website, the information allegedly collected was anonymized, and, in any event, most people “understand that what we do on the Internet is not completely private.” Id. at *2. Accordingly, the Third Circuit concluded that plaintiffs failed to allege a concrete injury to their privacy interests sufficient to confer Article III standing. Id. at *1.

This ruling reinforces the growing trend among federal courts requiring plaintiffs to plausibly allege that the collected data was personally identifiable and obtained without authorization in order to establish a concrete privacy injury.

Background

Many companies embed session replay code and other similar software, such as Google Analytics and the Meta Pixel, into their websites to conduct website analytics and/or targeted advertising.  All of these various technologies capture users’ browsing behaviors and cryptographically transmit this data to algorithms residing on the software providers’ servers.  Upon entry into the algorithm, this data is typically anonymized, aggregated, and not alleged to have been viewed or accessible by any human.  Plaintiffs across the country have filed multitudes of class actions challenging these various website analytics and advertising practices under federal and state privacy laws, targeting companies in virtually every industry, including healthcare, retail, education, and consumer products.  Some cases have resulted in multimillion-dollar settlements, others have been dismissed, and the vast majority remain undecided.  In these session replay and other data privacy class actions, the central question is often whether the specific data captured is sufficiently sensitive or personally identifying to establish a cognizable legal injury.

In Smidga, three named plaintiffs sued the defendant airline, alleging that session replay code embedded on its website recorded users’ interactions with the website in real time, including “text entries, mouse clicks, and geolocation.” Id. at *1.  Plaintiffs asserted claims under the Pennsylvania and Maryland Wiretap Acts, the California Invasion of Privacy Act, California’s Unfair Competition Law, and several other state and common law causes of action. Id. at *1 n.2.

All three plaintiffs visited defendant’s website to browse flights. Only one plaintiff ultimately purchased tickets and entered the names, addresses, and ages of herself and her children while doing so.  Id. at *1.

The defendant moved to dismiss for lack of Article III standing under Federal Rule of Civil Procedure 12(b)(1) or, alternatively, for failure to state a claim under Federal Rule of Civil Procedure 12(b)(6).  In support of its Rule 12(b)(1) arguments, the defendant submitted a declaration from its Senior Vice President and Chief Information Officer disputing plaintiffs’ allegations that the session replay code collected personal information and explaining that any data collected was “not traceable to any specific [w]ebsite user.”  Id. at *1.

The District Court granted the motion to dismiss for lack of standing, finding that the plaintiffs failed to establish an injury-in-fact sufficient to confer Article III standing, while also granting plaintiffs leave to seek jurisdictional discovery and amend the complaint again. Id. When plaintiffs took no further action, the District Court dismissed the complaint with prejudice, and plaintiffs appealed.

The Third Circuit’s Decision

The Third Circuit affirmed dismissal of the complaint but modified the District Court’s order so that the dismissal would be without prejudice. Id.

After observing that its recent decision in Cook v. GameStop, Inc., 148 F.4th 153 (3d Cir. 2025), “plainly resolve[d]” plaintiffs’ standing challenge, the Third Circuit “briefly explain[ed]” why plaintiffs failed to establish a concrete injury sufficient to confer Article III standing. Id. at *2.

First, the Third Circuit held that the alleged harm did not share a “close relationship” to the comparator torts of disclosure of private information or intrusion upon seclusion. Id.  With respect to public disclosure of private information, the Third Circuit explained that the two non-purchasing plaintiffsdid not allege that the defendant collected any personal information. Although the purchasing plaintiff entered personal information while using the website, the Third Circuit noted that the tort of public disclosure of private facts requires allegations of resulting embarrassment or humiliation, which were absent from the complaint.  Id. 

The Third Circuit similarly concluded that plaintiffs failed to state an analogous intrusion upon seclusion injury. Such a claim requires allegations that the defendant intentionally intruded upon plaintiffs’ “private affairs or concerns.” Id. The Third Circuit determined that standard was not satisfied because plaintiffs voluntarily provided the information, the allegedly collected information was anonymized, and, in any event, most people “understand that what we do on the Internet is not completely private.” Id.

Second, the Third Circuit rejected plaintiffs’ argument that bare violations alone confer standing, concluding that the argument misconstrued Third Circuit precedent and the U.S. Supreme Court’s holding in TransUnion LLC v. Ramirez, 594 U.S. 413, 426–27 (2021). Id. at *2.

Third, the Third Circuit reasoned that it was “hard-pressed to find that a de facto invasion of privacy exists where a website makes no express promise to refrain from collecting site visitors’ information.” Id. at *3. As explained in Cook, “there is a material difference between an allegation that a website merely failed to ask for visitors’ consent to data collection and an allegation that a website expressly promised it would not collect information but secretly did so anyway.” Id. The complaint contained no allegations that the defendant made such a promise.

The Third Circuit also rejected plaintiffs’ challenge to the District Court’s consideration of the declaration submitted in support of the defendant’s Rule 12(b)(1) motion to dismiss. The Third Circuit emphasized that plaintiffs failed to request discovery to respond to the defendant’s factual challenge despite being given the opportunity to do so, and it agreed that plaintiffs’ “boilerplate averments” alone could not rebut the defendant’s external evidence. Id. at *3.

Accordingly, the Third Circuit affirmed the District Court’s dismissal order for lack of Article III standing but modified the dismissal to be without prejudice.

Implications For Companies

Smidga reinforces that plaintiffs challenging the use of common website analytics and advertising technology must, at a minimum, plausibly allege that the technology collected and disclosed personally identifying information, rather than anonymized, aggregated web-browsing data cryptographically transmitted to software providers’ servers and not viewable or accessible by any human.  Moreover, alleging the collection and disclosure of PII via functionally internal session replay technology may or may not confer standing, depending on the jurisdiction one is in, as we blogged about earlier this month (here).

For companies facing session replay and other data privacy class actions in federal court, Article III standing remains a significant threshold defense that should be evaluated throughout the litigation, while balancing the possibility that claims may continue in state court.

Third Circuit Holds That Unauthorized Collection Of Credit Card Information Via Session Replay Code Confers Article III Standing, Creating Split Of Authority

By Gerald L. Maatman, Jr., Justin Donoho, and Hayley Ryan

Duane Morris Takeaways: On May 11, 2026, in In Re BPS Direct, LLC; Cabela’s, LLC Wiretapping Litigation, No. 23-3235, 2026 WL 1280969 (3d Cir. May 11, 2026), the U.S. Court of Appeals for the Third Circuit reversed a federal district court’s dismissal of a class action alleging that defendants’ use of session replay code, a form of website analytics technology, violated federal and state privacy laws. The Third Circuit held that two plaintiffs who made purchases on the defendants’ websites had standing to sue because the session replay code collected their credit card information without consent, an alleged injury the Third Circuit deemed analogous to the common law tort intrusion upon seclusion. Id. at *6-7.

This ruling is significant in that it shows that in class actions seeking millions (or billions) in dollars in statutory damages under federal and state data privacy laws for alleged use of session replay code, the Third Circuit has distinguished itself from California District Courts, which have held that there is no reasonable expectation of privacy in credit card information collected by session replay code.  Companies operating in the Third Circuit should take note as the legal risk of session replay code has meaningfully shifted in that jurisdiction. 

Background

Many companies embed their websites with session replay code and other similar software such as Google Analytics and the Meta Pixel in order to perform website analytics and/or targeted advertising. All of these various technologies capture users’ browsing behaviors and cryptographically transmit this data to algorithms residing on the software providers’ servers.  Upon entry into the algorithm, this data is typically anonymized, aggregated, and not alleged to have been viewed or accessible by any human.  In addition, session replay code (unlike other website analytics and advertising technologies) is typically alleged to record and store “videos” of “all mouse movements, clicks, scrolls, zooms, window resizes, keystrokes, [and] text entries,” so that the session replay provider can provide that information back to the company “in a format that [the company] can use for its business purposes.” Id. at *1, 5. Plaintiffs across the country have filed multitudes of class actions challenging these various website analytics and advertising practices under federal and state privacy laws, targeting companies in virtually every industry, including healthcare, retail, education, and consumer products.  Some cases have resulted in multimillion-dollar settlements, others have been dismissed, and the vast majority remain undecided.  In these session replay and other data privacy class actions, the central question is often whether the specific data captured is sufficiently sensitive or personally identifying to establish a cognizable legal injury.

In In re BPS Direct, LLC, eight named plaintiffs sued the defendant retailers, alleging that session replay code embedded on their websites captured users’ interactions, including “mouse clicks and movements, keystrokes, search terms, substantive information inputted …, pages and content viewed …, scroll movement[s], and copy and paste actions.” Id. at *2.  Plaintiffs asserted claims under the federal Wiretap Act, 18 U.S.C. § 2510 et seq., and the Computer Fraud and Abuse Act, 18 U.S.C. § 1030 et seq., along with several state and common law causes of action. Id.

The plaintiffs fell into two groups. Two plaintiffs made purchases on the defendants’ websites and entered his or her “name, address, and payment and billing information” into text fields. Id. The remaining six plaintiffs browsed the websites without making purchases and did not enter any personally identifying information while browsing the websites.  Id.

Defendants moved to dismiss for lack of Article III standing under Federal Rule of Civil Procedure 12(b)(1) and for failure to state a claim under Federal Rule of Civil Procedure 12(b)(6).  The District Court granted the motion, dismissing the non-purchasing plaintiffs’ claims with prejudice, finding that, after two attempts, they could not establish concrete harm “because they did not make purchases on the Websites or engage in any activity prompting their browsers to send highly sensitive personal information such as medical diagnosis information or financial data from banks or credit cards.” 705 F. Supp. 3d 333, 367 (E.D. Pa. 2023).  The claims of the two purchasing plaintiffs were dismissed without prejudice. Id. Rather than amend, those two plaintiffs filed a notice of intent to stand on their allegations, and all eight plaintiffs appealed.  2026 WL 1280969, at *2-3.

The Third Circuit’s Decision

The Third Circuit reversed the dismissal of the purchasing plaintiffs’ claims and modified the dismissal of the non-purchasing plaintiffs’ claims from with prejudice to without prejudice.  Id. at *1. 

The Third Circuit analyzed standing under two analogous common law torts: (1) public disclosure of private facts, and (2) intrusion upon seclusion. It held that none of the plaintiffs had standing under the first theory.  As to the non-purchasing plaintiffs, their browsing data was neither sensitive nor personally identifiable. As to the purchasing plaintiffs, their information was not publicly disclosed.  Id. at *4-5.

The Third Circuit held that only the two purchasing plaintiffs had standing under the intrusion upon seclusion theory. Id. at *3.  Under that common law tort, “[o]ne who intentionally intrudes, physically or otherwise, upon the solitude or seclusion of another or his private affairs or concerns, is subject to liability to the other for invasion of his privacy, if the intrusion would be highly offensive to a reasonable person.” Id. at *5 (citing Restatement (Second) of Torts § 652B (1977)). The Third Circuit concluded that the two purchasing plaintiffs had entered “personal or sensitive” information – specifically their “complete credit card or debit card numbers” – when making purchases on the defendants’ websites. Id. at *7. The Third Circuit reasoned that “[j]ust as media consumption is sensitive and historically private, so is a person’s complete credit card or debit card number.” Id.

Accordingly, the Third Circuit held that these two plaintiffs had standing based on their allegations that defendants embedded session replay code in their websites, allowing third-party adtech providers to “surreptitiously record their billing and payment information absent consent.” Id.

Implications For Companies

This ruling puts the Third Circuit at odds with California District Courts, which have reached the opposite conclusion in two session replay cases. See Thomas v. Papa Johns Int’l, Inc., 2024 WL 2060140, at *5 (S.D. Cal. May 8, 2024) (plaintiff’s “name, address, credit card number(s), and billing information” collected via session replay is “not information over which society is prepared to recognize a reasonable expectation of privacy”); Saleh v. Nike, Inc., 562 F. Supp. 3d 503, 525 (C.D. Cal. 2021) (collection via session replay of a website user’s “payment card information, including card number, expiration date, and CCV code” without consent was insufficient to constitute an invasion of privacy).

In the Third Circuit, session replay is no longer just an analytics tool – it carries significant legal risk for website operators.  Companies facing session replay class actions in the Third Circuit should shift their litigation strategy accordingly and consider moving beyond standing arguments, including demonstrating that plaintiffs cannot meet their burden of proof on the elements of the claims asserted.

Given the volume of session replay and similar litigation pending nationwide and the significant statutory damages at stake, this decision warrants close attention from any company whose website uses session replay code or similar technologies.

Data Security and Privacy Liability – Takeaways From The Sedona Conference Working Group 11 Annual Meeting in Kansas City, MO

By Justin R. Donoho

Duane Morris Takeaways: Data privacy and data breach class action litigation continue to explode.  At the Sedona Conference Working Group 11 on Data Security and Privacy Liability, in Kansas City, Missouri, on May 5-6, 2025, Justin Donoho of the Duane Morris Class Action Defense Group served as a dialogue leader for two panel discussions, “Privacy and Data Security Litigation Update” and “Legislative Drafting Considerations: Lessons from Colorado’s Privacy and AI Law Intersection.”  The working group meeting, which spanned two days and had over 50 participants, produced excellent dialogues on these topics and others including unique procedural aspects of data breach class actions, data privacy primer, onward transfer of consumer PII in M&A and bankruptcy contexts, privacy and data security state regulator roundtable, and application of attorney-client privilege in the cybersecurity context.

The Conference’s robust agenda featured over 30 dialogue leaders from a wide array of backgrounds, including federal and state regulators and governmental officials, data security industry experts, in-house attorneys, cyberlaw professors, plaintiffs’ attorneys, and defense attorneys.  In a masterful way, the agenda provided valuable insights for participants toward this working group’s mission, which is to identify and comment on trends in data security and privacy law, in an effort to help organizations prepare for and respond to data breaches, and to assist attorneys and judicial officers in resolving questions of legal liability and damages.

Justin had the privilege of speaking about current trends in data privacy class actions and lessons from the intersection of the Colorado Privacy Act (CPA) and Colorado AI Act (CAIA) and how these lessons might guide future legislatures when drafting AI and data privacy statutes.  Highlights from his presentations included two recent cases resulting in helpful precedent for defendants facing cases alleging privacy violations for their uses of website advertising technologies (adtech), including a case that disposed of a claim under the California Invasion of Privacy Act under the rule of lenity (see here), and a case that dismissed an adtech class action due to failure to allege highly offensive conduct (see here).

Finally, one of the greatest joys of participating in Sedona Conference meetings is the opportunity to draw on the wisdom of fellow presenters and other participants from around the globe.  Highlights included:

  1. Litigators from both sides of the “v.” and a neutral debating early case procedural rules and practices, choice of law, and discovery mechanisms in the context of data breach class actions, with an unprompted shoutout to the Duane Morris Class Action Review for supplying statistics.
  2. Sedona Conference veterans discussing Sedona’s latest version of a data privacy primer and the proper level of detail to include in this document ten years in the making in order to keep it reasonably current to account for the rapid evolution of data privacy laws and related developments in artificial intelligence.
  3. Panelists with different backgrounds discussing the law regarding when a company that has obtained personal data with consent can and cannot transfer the data in M&A and bankruptcy contexts.
  4. A lively dialogue among some of my panelists and other participants regarding trends in decisions regarding mass arbitration protocols and whether a company’s use of website advertising technology is highly offensive to a reasonable person.
  5. Federal and state regulators discussing enforcement priorities and issuances of advisory opinions in the contexts of data breaches, alleged data privacy violations, and concerns regarding national security.
  6. Data breach litigators discussing factors to consider when conducting dual track investigations following a cybersecurity incident in order to segregate and maintain confidentiality over attorney work product and attorney-client communications.
  7. A lively dialogue among some of my panelists and other participants regarding whether compliance with AI and antidiscrimination statutes should provide a safe harbor for compliance with data privacy statutes including, for example, the heavily litigated California Invasion of Privacy Act.

Thank you to the Sedona Conference Working Group 11 and its incredible team, the fellow dialogue leaders, the engaging participants, and all others who helped make this meeting in Redmond, Washington, an informative and unforgettable experience.

Finally, I want to thank to share the exciting news that I have been selected as a new steering committee member of Working Group 11.  Thank you Sedona!  In this role, I will help lead the identification of cutting-edge issues and oversee development of principles, guidelines, commentaries and other projects representing the work product of the Sedona Conference.

For more information on the Duane Morris Class Action Group, including its Data Privacy Class Action Review e-book, and Data Breach Class Action Review e-book, please click the links here and here.

New York Federal Court Certifies Crypto Class Action With Modifications And Reserves Causation Question For Summary Judgment Proceedings

By Gerald L. Maatman, Jr. and Justin R. Donoho

Duane Morris Takeaways:  On March 6, 2025, Judge Katherine Polk Failla of the U.S. District Court for the Southern District of New York granted class certification with modifications in a case involving a stablecoin issuer’s alleged issuance of unbacked or debased stablecoins in furtherance of an alleged scheme to manipulate the market prices for crypto commodities and futures in the litigation captioned In Re Tether & Bitfinex Crypto Asset Litigation, No. 19 Civ. 9236, 2026 WL 629826 (S.D.N.Y. Mar. 6, 2026).  The ruling is significant as it shows that while crypto purchasers who file class action complaints alleging violations of the Sherman Act and Commodities Exchange Act may be able to satisfy Rule 23 so long as they offer reliable expert models on class-wide causation and damages and limit their proposed classes to purchasers who used fiat currency or stablecoins to make their purchases on domestic or stateless exchanges, such class actions may also be subject to dismissal based on summary judgment on the question of whether the defendants’ alleged provision of unbacked or debased stablecoins caused an increase in price of crypto commodities and futures. 

Background

In the litigation captioned In Re Tether & Bitfinex Cryto Asset Litigation, the plaintiffs, four purchasers of Bitcoin, Bitcoin futures, and other crypto assets, brought a class action against various entities and individuals associated with the issuer of a stablecoin and the stablecoin issuer’s sister company, a crypto asset exchange, alleging that the defendants artificially inflated the prices of the plaintiffs’ crypto asset purchases by engaging in market manipulation under the Commodities Exchange Act and monopolization and restraint of trade under the Sherman Act.  Id. at *2, 26. 

According to the plaintiffs, the stablecoin issuer issued hundreds of millions of unbacked or debased stablecoins while telling the market that these stablecoins were fully backed by U.S. dollars whereas actually they were backed only by the sister crypto exchange’s accounts receivables and inaccessible funds.  Id. at *2-3.  Further according to plaintiffs, the defendants used an anonymous trader to engage in cross-exchange arbitrage by purchasing “massive” amounts of crypto commodities on other exchanges with the debased stablecoin, selling them on the defendant exchange for U.S. dollars, and withdrawing those funds as the stablecoin.  Id. at *4.  All these activities were allegedly performed by the defendants with knowledge and intent to inflate crypto commodity and futures prices and allegedly resulted in artificially inflated prices of crypto assets purchased by the plaintiffs.  Id.

The plaintiffs moved for class certification under Rule 23, seeking to certify classes of acquirers in the United States during the class period of crypto commodities and futures, respectively.  Id. at *5.  In support, the plaintiffs submitted a report from an antitrust and economics expert that included an event study purporting to show that the issuance of the unbacked or debased stablecoin caused the price of Bitcoin to increase, a regression analysis that purported to model how a change in the outstanding volume of the stablecoin affects Bitcoin prices, and an overcharge model that purported to quantify the artificial inflation of Bitcoin based on the extent to which the stablecoin was debased or unbacked.  Id. at *6.

The defendants moved to exclude the plaintiff’s expert and opposed class certification by challenging only adequacy and predominance (not any of the other Rule 23 requirements).  On adequacy, the defendants argued that adequacy was not satisfied due to two sources of potential intraclass conflict – intraclass trading and plaintiffs’ alternative models for showing debasement and inflation.   On predominance, the defendants argued that individual questions would predominate when resolving questions of class-wide impact, injury, and extraterritoriality.

The Court’s Decision

The Court began its analysis by excluding the plaintiffs’ expert’s event study purporting to show that the issuance of the unbacked or debased stablecoin caused the price of Bitcoin to increase.  As the Court explained, the event study was unreliable because the “t-test” model it employed violated the key assumption of the model “that the values within in each tested group are independent, meaning that they are not correlated with each other..  Id. at *6 n.5, 12-13.  However, the court denied exclusion of the expert’s regression model, overcharge model, and other opinions.  Id. at *14-19.

Turning next to the defendants’ two adequacy challenges, the Court rejected both.  First, the Court found that intraclass trading did not create any conflicts because the alleged classes included only buyers alleging only price inflation.  Id. at *23-24.  Second, the Court found that there were also no intraclass conflicts based on plaintiffs’ alternative methods for showing stablecoin debasement because the methods differed only “in the extent of the debasement they show on certain days, but they are not diametrically opposed. In fact, the debasement is, by default, one-directional.”  Id. at *25.

Turning to defendants’ challenges to predominance, the court found that common evidence would be used “to establish that Defendants engaged in certain conduct, such as issuing debased or unbacked [stablecoins], misrepresenting that [the stablecoins were] always backed one-to-one by USD held in reserve by [the defendant crypto exchange], disseminating debased [stablecoins] through the Anonymous Trader, and conspiring with the Anonymous Trader to increase cryptocommodity prices.”  Id. at *27.  The court also found that common evidence would be used for the elements relating to the defendants’ scienter or intent.  Id. at *27.  In sum, the Court found that common questions predominated as to “issues related to defendants’ anticompetitive conduct.”  Id.  However, as the Court explained, “the elements of antitrust and CEA cases that pertain to Defendants’ conduct almost always present a common question that predominates … Because of this, class certification in CEA and antitrust cases often turns on whether common issues predominate in establishing injury, causation, or damages.”  Id. at *26-27 (emphasis added). 

Next the Court found that the plaintiffs could demonstrate class-wide impact or causation through plaintiffs’ expert’s regression analysis, although the Court found this to be a “closer question.”  Id. at *28.  Although the defendants did not provide a sufficient reason to exclude the regression analysis such as the expert’s failure to account for a key variable, the Court found nevertheless that the defendants called into question the plaintiffs’ ability with its regression model to establish “the fact of causation.”  Id. at *28-30.  However, as the Court explained, “That type of challenge sounds more in summary judgment than in Rule 23(b)(3). Indeed, the Supreme Court has warned that when ‘the concern about the proposed class is not that it exhibits some fatal dissimilarity but, rather, a fatal similarity — [an alleged] failure of proof as to an element of the plaintiffs’ cause of action — courts should engage that question as a matter of summary judgment, not class certification.’”  Id. (quoting Tyson Foods, Inc. v. Bouaphakeo, 577 U.S. 442, 457 (2016)). 

Further, the Court found that the plaintiffs could measure damages on a class-wide basis using Plaintiffs’ overcharge model.  Id. at *31.

Finally, as to the defendants’ remaining challenges to predominance, the Court rejected them as to the predominance finding but embraced them for purposes of narrowing the Plaintiffs’ proposed class definitions in two ways. 

First, on the question of injury, the Court found that whether common issues predominate turns on whether injury occurs “(i) when a Class Member purchases an artificially inflated cryptocommodity, or (ii) when that Class Member experiences economic loss flowing from their purchase of that cryptocommodity.”  Id. at *31.  As the Court explained, whereas the defendants argued “that economic loss is required for Class Members to establish injury — like in the securities context,” Plaintiffs argued “that the magnitude of loss only matters for the calculation of damages — like in the antitrust context.”  Finding this issue “close,” the Court ruled for the plaintiffs, reasoning as follows: “The [d]efendants are correct that the Class Assets share more in common with securities than commodities such as olive oil, especially given that purchasers of cryptocommodities often sell them later, either at a loss or gain … But the Court ultimately sides with Plaintiffs because, at its core, this is an antitrust case, not a securities action. And unlike in securities cases, antitrust injury flows from the overcharge itself.”  Id. at *32.  The Court “remain[ed] concerned, however, that the initial harm that is required to establish an antitrust injury is not as clearcut for Class Members who purchased cryptocommodities with other cryptocommodities” because “whether that purchaser has incurred the required initial overcharge would depend on whether the purchasing cryptocommodity was more or less inflated than the purchased cryptocommodity.”  Id. at *33.  In addition, the court found no injury for any alleged class members who acquired class assets only by engaging in mining, using a crypto fork, or receiving them as gifts.  Id. at *33.  Thus, the Court limited the proposed classes of crypto commodity and futures acquirers to purchasers who used fiat currency or stablecoins.  Id.

Second, on the question of extraterritoriality, the Court found that “[o]n Plaintiffs’ CEA [Commodities Exchange Act] cause of action, individual questions predominate regarding futures trades on foreign exchanges” because “the domesticity of transactions on foreign exchanges is too fact-specific for class certification,” including “facts concerning the formation of the contracts, the placement of purchase orders, the passing of title, or the exchange of money.”  Id. at *34-36.  Foreign exchanges aside, the Court found that there are no individualized questions as to domesticity for futures transactions executed on domestic exchanges.”  Id.  Lastly, on the remaining question of whether stateless exchanges “are governed by the domestic exchange rule or foreign exchange rule,” which question the Court found “especially important in the context of the crypto-economy,” the Court held that this inquiry satisfied predominance because it “can be determined on an exchange-by-exchange, rather than person-to-person, basis.”  Id. at *35.  Accordingly, the Court limited the futures subclass to all purchasers of crypto commodity futures with fiat currency or stablecoins in the United states during the class period so long as they purchased futures on either U.S.-based exchanges or stateless exchanges “that either (a) matched trades on servers in the United States or (b) prohibited buyers from revoking their orders once placed.”  Id. at *38.

For these reasons, the Court granted the plaintiffs’ motion for class certification and narrowed the plaintiffs’ proposed class definitions.

Implications For Companies

The In Re Bitfinex class certification ruling is an instructive one for litigants on either side of crypto class actions alleging antitrust and commodities violations.  For plaintiffs, it shows that table stakes for achieving class certification of such claims include (a) proffering reliable models regarding class-wide causation and damages and (b) limiting class definitions to transactions that can use common evidence to satisfy the injury element and escape the extraterritoriality defense.  For defendants, it shows that if their challenges to plaintiffs’ causation and damages models are ineffective, then summary judgment remains as a vehicle to show the absence of sufficient evidence for the plaintiff to demonstrate causation of any purported antitrust or commodities injury due to defendants’ alleged conduct.

Massachusetts Federal Court Dismisses Adtech ECPA Class Action For Failure To Allege Defendants Purposefully Committed A Criminal Act, Furthering Split Of Authority

By Gerald L. Maatman, Jr., Justin Donoho, and Hayley Ryan

Duane Morris Takeaways: On March 6, 2026, in Progin v. UMass Memorial Health Care, Inc., No. 25-CV-40003, 2026 U.S. Dist. LEXIS 46522 (D. Mass. Mar. 6, 2026), Judge Allison D. Burroughs of the U.S. District Court for the District of Massachusetts granted a motion to dismiss a class action complaint brought by website users against Massachusetts health care and hospital entities. Plaintiffs alleged that the defendants’ use of website advertising technology (“adtech”) violated the federal Wiretap Act, also known as the Electronic Communications Privacy Act (“ECPA”).  Following another similar ruling in the same court,  see Goulart v. Cape Cod Healthcare, Inc., 2025 U.S. Dist. LEXIS 119435 (D. Mass. June 24, 2025),  the decision is significant because it reflects the Massachusetts Federal court’s alignment with other federal courts (including the U.S. District Court for the Southern District of Texas, as we blogged about here) that have interpreted the ECPA in a defense-friendly manner. In contrast, courts in other jurisdictions (including Illinois Federal courts, as we blogged about here) have adopted more plaintiff-friendly interpretations, further deepening the emerging split of authority in adtech privacy litigation.

Background

Progin is one of a legion of class actions that plaintiffs have filed nationwide alleging that Meta Pixel, Google Analytics, and other similar software embedded in websites secretly captured plaintiffs’ web-browsing data and transmitted that data to Meta, Google, and other online advertising agencies and data analytics companies.

In these adtech and similar internet-based technology class actions, plaintiffs frequently rely on the ECPA’s statutory damages provision. Their theory is simple: multiply the number of website visitors – potentially hundreds of thousands – by $10,000 in statutory damages per claimant to produce enormous potential exposure. Although plaintiffs have filed a majority of these lawsuits to date against healthcare providers, they have filed suits against companies that span nearly every industry including education, retailers, and consumer products. Some of these cases have resulted in multimillion-dollar settlements, while others have been dismissed at the pleading stage (as we blogged about here) or the summary judgment stage (as we blogged about here), and the vast majority remain undecided.

In Progin, the plaintiffs sued a group of health care and hospital entities, seeking to represent a class of patients whose personal health information was allegedly disclosed by the Meta Pixel installed on defendants’ websites. The plaintiffs claimed that these alleged transmissions constituted an “interception” by defendants in violation of the ECPA.

Under the ECPA, a “party to the communication” generally cannot be sued unless it intercepted the communication “for the purpose of committing any criminal or tortious act.” 18 U.S.C. § 2511(2)(d). This provision is commonly referred to as the “crime-tort exception.”

Plaintiffs argued that alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) served as the predicate crime to trigger this exception. Specifically, plaintiffs argued that defendants were liable under the crime-tort exception because they intercepted and disclosed plaintiffs’ communications and personal information to third parties without consent in violation of HIPAA. 2026 U.S. Dist. LEXIS 46522, at *11.

The defendants moved to dismiss, arguing that the crime-tort exception did not apply because they did not install the Meta Pixel “for the distinct purpose of violating HIPAA or perpetrating a tort.” Id. at *11-12.

The Court’s Decision

The Court agreed with defendants and granted their motion to dismiss, holding that the amended complaint’s allegations “do not support the inference that Defendants purposefully committed the ‘criminal and tortious acts’ specified by Plaintiffs.” Id. at *13-14.

As the Court explained, based on the alleged predicate acts, plaintiffs were required to plausibly allege that defendants “purposefully used or caused to be used” plaintiffs’ unique health identifiers without authorization; “purposefully disclosed” plaintiffs’ individually identifiable health information to Facebook or Google without authorization; or “purposefully invaded” plaintiffs’ privacy.  Id. at *12-13.

Importantly, the Court emphasized that merely alleging that defendants knowingly committed such acts is insufficient because “‘purpose’ is an essential element of ECPA, distinct from the minimal intent [of knowingness] required under HIPAA.” Id. at *13 (quoting Doe v. Lawrence Gen. Hosp., 2025 U.S. Dist. LEXIS 195964, at *32 (D. Mass. Aug. 29, 2025)). The Court further explained that “[i]t is not enough that a crime or tort [may have been] a . . . side effect of the interception.” Id. at *14 (quoting Doe, 2025 U.S. Dist. LEXIS 195964, at *30).

Implications For Companies

The decision in Progin is a big win for healthcare providers and other defendants facing adtech class actions. This ruling reinforces a critical principle in ECPA and other privacy-based litigation: the defendants’ state of mind matters.

Under the ECPA’s HIPAA-based crime-tort exception, as well as under similar privacy statutes such as the Video Privacy Protection Act (“VPPA”), liability depends on the defendant’s knowledge and purpose. Where a defendant lacks knowledge that transmitted data is tied to specific individuals, or lacks the purpose to disclose identifiable information, the statutory requirements for liability may not be satisfied.

Accordingly, Progin provides strong authority for defendants to argue that routine adtech data transmissions cannot satisfy the purposeful intent requirements of the ECPA’s HIPAA-based crime-tort exception or similarly worded privacy statutes – a position that may prove critical as courts continue to confront the growing wave of adtech privacy class actions.

California Federal Court Orders Disclosure Of Side Deals In Connection With Class Action Settlement

By Gerald L. Maatman, Jr. and Justin R. Donoho

Duane Morris Takeaways:  On December 23, 2025, Judge William Alsup of the U.S. District Court for the Northern District of California entered an order in Bartz, et al. v. Anthropic PBC, Case No. 24-CV-5417 (N.D. Cal. Dec. 23, 2025), requiring five law firms seeking a fee award in connection with a class action settlement to file a declaration setting forth the full extent of any of the firms’ actual or proposed fee-sharing agreements and the extent to which any arrangement may result in some class members receiving a sweeter recovery than other class members.  Judge Alsup also ordered preservation of all communications and other documents relating to such side deals. 

The ruling is significant because it shows that only appointed class counsel may be eligible to receive a fee award in connection with a class action settlement, and may not outsource its responsibilities to non-appointed counsel or seek any other arrangements that may favor some class members to the detriment of other class members.  Furthermore, the ruling shows that any such side deals must be disclosed publicly prior to any final approval of a class action settlement.

Background

This case is one of several class actions that plaintiffs have filed alleging that developers of generative artificial intelligence  (“gen AI”) violated copyright laws by generating infringing outputs and/or by using unauthorized copies of copyrighted works as inputs to train the developer’s models. 

Many of these gen AI class actions are “bet-the-company” lawsuits, even for the world’s largest companies. Plaintiffs in gen AI class actions typically invoke the Copyright Act in order to seek millions — and sometimes even billions — of dollars on the theory that thousands or millions of unauthorized copies of copyrighted works, times up to $150,000 per copyrighted work for willful infringement, equals a crushing, settlement-inspiring number. 

In Bartz, the parties reached a $1.5 billion settlement, which the Court preliminary approved, and which we blogged about previously here and here.

Following preliminary approval, two law firms appointed as class counsel and three additional non-appointed firms filed a petition for fees to be awarded in connection with the class action settlement.  The fee petition sought $225 million for class counsel and $75 million for the non-appointed law firms.  Id. at 3, 7.  These three non-appointed firms had agreed to gather contact information for the class list and to provide input on the claim form and claims process, two for the publisher class members (“Publishers’ Coordination Counsel”), and one for the author class members (“Authors’ Coordination Counsel”).  Id. at 3.

The Court’s Decision

The Court declined to rule on the fee petition, ordering that a number of disclosures and preservation efforts be made first in order “to set the record straight” concerning aspects of the fee petition.  Id. at 1.  Such was necessary, according to the Court, because it appeared that counsel may have entered into one or more “side deals.”  Id. at 3.

As the Court explained, “[t]wo and only two law firms were ever appointed class counsel.”  Id. at 1.  Moreover, “preliminary approval and the class notices confirmed that only two firms were approved to serve the class … Those firms never proposed a fee splitting scheme, and none was ever even preliminarily approved.”  Id. at 7. 

As to the three non-appointed law firms, the Court found that they “cannot appoint [themselves] class counsel by showing up.  Nor can class counsel appoint someone else to do its work.”  Id. at 2.  As the Court further explained, it had not had a chance to vet the non-appointed counsel for conflicts, or to prevent duplication of effort by overlapping law firms.  Id. at 8.  In addition, the Court found it concerning that “we do not yet know whether ‘Publishers’ Coordination Counsel’ will share any part of their bonanza with one or more publishers so as to give those publishers a premium to not opt out … and thereby avoid triggering [the defendant]’s right to about the settlement.”  Id.  Furthermore, the class notice “never alerted class members that still other lawyers would come out of the woodwork to seek a third again whatever their class counsel would seek for its work.”  Id. (emphasis added).

For these reasons, the Court ordered that, within one week, all law firms who filed fee petitions or on whose behalf fee petitions were filed, must publicly file a declaration (not under seal) setting forth the “full extent” to which such firm agreed or made a proposal “to share any portion(s) of any fee award in this class action or in any other class action (putative or certified) involving any party (or class member) herein,” and stating as to each such agreement or proposal its date, terms, the extent to which it is verbal and the extent to which it is in writing (or in an email or text or other message), and the parties and the names of all persons who made the agreement.  Id. at 10.  The Court also ordered public disclosure in a declaration of the “full extent to which any arrangement has been made or proposed by which any class member would receive a sweeter recovery than other class members.”  Id. at 10-11.  Finally, the Court further ordered that “[a]ll emails, messages, and written materials relating to any of the above shall be preserved for future potential discovery.”  Id. at 11.

Implications For Companies

The Bartz fee petition order is as extraordinary as it is unique. It offers strong precedent for any company defending a large class action and preparing to enter into a class action settlement.  Specifically, Bartz shows that plaintiffs’ firms seeking any portion of a fee award in connection with such a settlement will need to publicly disclose any side deals prior to any final settlement approval.  Therefore, settling defendants should consider seeking to discover any side-deal information before entering into such settlement.  That way, any obstacles to final settlement approval such as that presented by the Bartz fee petition order might be considered before the parties reach any settlement.

Executive Order Signals A Push Toward A Single, Federal “AI Rulebook” And A Retreat From The State Patchwork

By Gerald L. Maatman, Jr., Justin R. Donoho, and Hayley Ryan

Duane Morris Takeaways:  On December 11, 2025, President Donald J. Trump signed Executive Order 14365 titled “Ensuring a National Policy Framework for Artificial Intelligence.” The Order targets what it characterizes as a “patchwork” of State-by-State AI regulation and directs federal agencies to pursue a more uniform, national framework. Rather than serving as a technical AI governance roadmap, the Order focuses on limiting State AI laws through federal funding leverage, potential preemption, and expanded use of FTC enforcement authority. The discussion below highlights the Order’s core objectives and key implications for companies and employers. The Executive Order is required reading for any organizations deploying AI or thinking of doing so.

The Executive Order’s Core Objectives

Reduce State AI Regulation By Framing It As A Competitiveness Problem

The Order emphasizes U.S. leadership in artificial intelligence and asserts that divergent State regulatory regimes increase compliance costs, especially for startups, and may impede innovation and deployment. It also raises concerns that certain State approaches could pressure companies to embed “ideological” requirements into AI systems.

Create Leverage Through Federal Funding: BEAD Broadband Money As The “Carrot And Stick”

Within 90 days, the Secretary of Commerce is directed to issue a policy notice describing the circumstances under which States may be deemed ineligible for certain broadband deployment funding under the Broadband Equity Access and Deployment (BEAD) program if they impose specified AI-related requirements. The notice is also intended to explain how fragmented State AI laws could undermine broadband deployment and high-speed connectivity goals.

Move Toward A Federal Reporting And Disclosure Standard

Within 90 days after the Order’s State-law “identification” process (discussed below), the Federal Communications Commission (FCC), in consultation with a Special Advisor for AI and Crypto, is instructed to consider whether to initiate a proceeding to adopt a federal reporting and disclosure standard for AI models that would preempt conflicting State requirements.

Use The FTC Act As An Enforcement Anchor And Tee Up Preemption Arguments

Within 90 days, the Federal Trade Commission (FTC) is directed, in consultation with other federal agencies, to issue a policy statement addressing how the FTC Act’s prohibition on unfair or deceptive acts or practices applies to AI models, with the express objective of preempting conflicting State laws.

Establish A Federal AI Litigation Task Force To Challenge State AI Laws

The Executive Order goes beyond policy statements and funding leverage by directing the Attorney General, within 30 days, to establish an AI Litigation Task Force dedicated exclusively to challenging State AI laws that conflict with the Order’s national policy objectives. The Task Force is authorized to pursue constitutional and preemption-based challenges, signaling an intent to bring coordinated, affirmative litigation against State AI regimes.

That enforcement effort is reinforced by a parallel State-law triage process. Within 90 days, the Secretary of Commerce must publish an evaluation identifying “onerous” State AI laws for potential challenge, particularly those that require AI systems to alter truthful outputs or compel disclosures that may implicate First Amendment or other constitutional concerns. Together, these provisions signal an intent to move quickly from policy articulation to test cases aimed at curbing State-level AI regulation.

Implications For Companies

Compliance Strategy May Shift, But Uncertainty Rises First

Although companies may welcome relief from conflicting State AI mandates, the Executive Order is likely to increase near-term uncertainty. Preemption disputes are likely, and the Order directs agency action rather than establishing a comprehensive statutory framework. Companies should avoid scaling back State-law compliance prematurely and should assume any federal override will be contested until resolved through rulemaking and litigation.

Class Action Exposure Will Shift, Not Disappear

Even if State AI laws are narrowed, plaintiffs’ lawyers are likely to pursue claims under more traditional theories, including consumer protection (particularly AI marketing and disclosure claims), employment discrimination, privacy and biometrics statutes, and contract or misrepresentation theories. The Order’s emphasis on FTC unfair and deceptive practices enforcement suggests that federal consumer protection standards may become the new focal point for both regulatory scrutiny and follow-on civil litigation.

Employment Risk Remains

Employers should expect ongoing scrutiny of AI use in hiring, promotion, and performance management, including disparate impact claims, vendor-liability arguments, and discovery disputes over model documentation, adverse impact analyses, and validation. Defensible governance, testing, and documentation remain critical.

Federal Contracting And Funding May Come With New AI Representations

If federal agencies adopt standardized AI disclosures, companies operating in regulated industries or participating in broadband initiatives may face new contract provisions governing AI use, along with enhanced reporting and audit obligations.

What Companies Should Do Now

Companies should begin by identifying where and how AI tools are being deployed, particularly in consumer-facing and employment-related contexts, and evaluating those uses under existing disclosure, privacy, and anti-discrimination laws. Public-facing statements about AI capabilities should be reviewed to ensure they are accurate and defensible, as increased regulatory and litigation focus on unfair or deceptive practices is likely to heighten scrutiny of AI-related claims. Companies should also review vendor relationships to confirm that contracts clearly address testing and validation obligations, incident response, audit rights, and appropriate allocation of risk for privacy and discrimination claims. Finally, organizations should remain prepared for continued regulatory change by maintaining State-law compliance readiness while monitoring federal agency actions that may shape a national AI framework.

Bottom Line

This Executive Order is a significant policy signal. The federal government is positioning itself to reduce State-by-State AI regulation and replace it with a framework centered on federal disclosure requirements and consumer protection enforcement. Companies should view the Order as an opportunity to prepare for a likely federal compliance baseline, without assuming State-law exposure will disappear in the near term.

© 2009- Duane Morris LLP. Duane Morris is a registered service mark of Duane Morris LLP.

The opinions expressed on this blog are those of the author and are not to be construed as legal advice.

Proudly powered by WordPress