In recent years, private plaintiffs have leveraged the California Invasion of Privacy Act (CIPA) against companies over customer service call recordings, transcription services, and website monitoring. These lawsuits allege that businesses violate CIPA by disclosing or allowing third parties to monitor private communications. Even though many cases are dismissed or settled before trial, defending a
California Invasion of Privacy Act
Notetaker App in Litigation Crosshairs
On August 15, 2025, notetaker app Otter.ai, Inc. was named a defendant in litigation alleging that its artificial intelligence-powered meeting assistant called Otter Notetaker, which “engages in real-time transcription of Google Meet, Zoom, and Microsoft Teams meetings for Otter accountholders and other users…records, accesses and records the contents of private conversations between Otter accountholders who…
What a 1988 Statute Signals in the New England Patriots’ Privacy Class Action Settlement
This post was co-authored by Mark Abou Naoum, Summer Associate. Mark is not admitted to practice law.
The 1988 Video Privacy Protection Act (VVPA) prohibits the disclosure of VHS rental history; now, in a recent class action where the VPPA was invoked by the plaintiffs, the parties’ voluntary settlement signals developments related to this outdated…
California’s SB 690: A Game-Changer for Website Privacy Lawsuits Pushes Forward
On June 3, 2025, the California Senate unanimously passed Senate Bill 690 (SB 690) in a 35-0 vote, a strong show of support for reining in a flood of lawsuits that have taken many companies by surprise over the last few years. The bill now heads to the California Assembly, where it will face further…
Video Game Developer’s Website Privacy Policy Disclosure and Cookie Banner Consent Defeat Wiretap Class Action
Video game developer Ubisoft, Inc. came out on top earlier this month in the Northern District of California when a judge dismissed, with prejudice, a class action claiming that the company’s use of third-party website pixels violated privacy laws. The judge concluded that the “issue of consent defeat[ed] all of Plaintiffs’ claims.” Lakes v. Ubisoft…
Judge Rules “Tester” Plaintiffs Cannot Bring Wiretap Claims under California Invasion of Privacy Act
In a big win for businesses, a California federal court just held that a “tester” plaintiff—someone who visits websites to initiate litigation—cannot bring a claim under the California Invasion of Privacy Act (CIPA). Rodriguez v. Autotrader.com, Inc., No. 2:24-cv-08735, 2025 WL 65409 (C.D. Cal. 1.8.25). Tester plaintiffs have started to focus on consumer protection…
Yahoo ConnectID Faces Class Action Over Email Address Tracking as Alleged Wiretap Violation
Yahoo’s ConnectID is a cookieless identity solution that allows advertisers and publishers to personalize, measure, and perform ad campaigns by leveraging first-party data and 1-to-1 consumer relationships. ConnectID uses consumer email addresses (instead of third-party tracking cookies) to produce and monetize consumer data. A lawsuit filed in the U.S. District Court for the Southern District…
Crumbl Sued for Disclosing Data to Stripe Without Consent
In the latest surge of lawsuits against retailers for embedding tracking technology into websites, yummy cookie company Crumbl was sued on May 1, 2024, for allegedly embedding web-tracking technology allowing third-party processing company Stripe to obtain, without consumer consent, customers’ names, email and delivery addresses, geographic locations, IP addresses, and payment information when consumers surf…