Website tracking technologies: why are businesses being sued for using them?

Laws in other states, including in New Hampshire, are being used to hold businesses liable for their use of website tracking technologies

Businesses commonly embed in their websites tracking technologies, like Meta Pixel, Google Analytics, or LinkedIn Insight. These plugins analyze website visitor activities and facilitate advertising for the business on social media sites and Internet browsers. In 2024, businesses that use them started being sued by plaintiff’s lawyers under the California Invasion of Privacy Act or CIPA. Now, however, similar laws in other States, including in New Hampshire, are being used to hold businesses liable for their use of website tracking technologies.

The laws being leveraged to create liability are called wiretap statutes, which were intended to prevent the unconsented interception of electronic communications. Plaintiff’s lawyers claim that tracking technologies violate wiretap statutes by intercepting electronic communications between the website operator and its visitors, such as clicks, page views, and keystrokes, and then by transmitting that data to the tracking technology provider. Even if the business cannot identify its website visitors, the tracking provider can do so using data from a cookie that it previously placed on the devices of the website visitors.

Plaintiff’s lawyers are not suing the tracking technology providers, like Meta, Google and LinkedIn. Doing so would pick a fight with an enormous adversary, involve expensive litigation, and potentially result in court rulings determining that wiretap statutes do not apply in this context. If that were to occur, it might put an end to this lucrative litany of lawsuits.

Instead, these lawyers find an individual who has visited the website of a small or medium sized business, and then send a demand letter or file a lawsuit asserting a putative class-action claim against the business for aiding and abetting the violations of wiretap statutes by the tracking technology providers. When doing so, they seek statutory damages, which are commonly about $5,000 per website visit by the name-plaintiff, resulting in settlement demands ranging from $50,00 to $200,000, and ultimate settlements of 10% to 25% of the initial demand. For small to mid-sized business, settling a claim is far cheaper than litigating it, which is the precise outcome desired by the lawyers asserting these claims in the first place.

What should businesses do to avoid liability?

  • Audit your website to determine if you are using tracking technologies.
  • Update your privacy policy to state that the website uses tracking technologies that forward information about visitors to third parties, such as Meta, Google or LinkedIn, and that those third-parties will use that information to advertise to those individuals.
  • Reset your website cookie banner to require all visitors the next time they visit the site to reject all, accept all, or select which cookies they permit on your site. Require website visitors when making the cookie selection to consent to the new version of the privacy policy discussed above, and log that consent for potential future use.
  • Do not transmit information to tracking technology providers unless and until a website visitor has consented to such transfers via the cookie banner and new privacy policy.
  • Honor privacy rights requests of website visitors, including their cookie selections and their right to limit how the business uses their personal information.

Plaintiff’s lawyers are relentless, targeting unaware and unprepared businesses with class-action claims designed to leverage moderate settlements to avoid expensive litigation. Take action now to ensure that your business does not become their next victim.

Cam Shilling founded and chairs McLane Middleton’s Cybersecurity and Privacy Group. The group of six attorneys and one paralegal assist businesses and private clients to improve their security, privacy and AI compliance, and address any incidents or breaches that occur.

Categories: Cybersecurity