California’s Unfair Competition Law (Business & Professions Code § 17200), commonly known as the UCL, has become one of the most powerful tools in modern data privacy litigation. What began as a flexible consumer-protection statute is now routinely layered onto claims under the California Invasion of Privacy Act (CIPA), the California Consumer Privacy Act (CCPA/CPRA), and related statutes. The result is a significant expansion of both liability with new claims with plaintiff law firms coming up with creative theories to increase their settlement demands which leads to higher potential damages.
Plaintiffs are no longer limited to CIPA’s $5,000 statutory damages or the more constrained remedies under the CCPA. By pleading UCL claims, they seek restitution of advertising technology (AdTech) revenues, broad injunctive relief, and a pathway to keep cases alive even when pure privacy standing is challenged as we may see CIPA claims disappear but as soon as that happens we will start to see a surge in litigation with UCL Data Privacy claims start popping up and these claims will not stop until a solution like Captain Compliance is in place that allows users to opt-out and remove trackers when requested.
If your company operating websites, apps, or platforms that collect or share personal data, understanding how UCL is being weaponized in data privacy lawsuits is now essential risk management.
How UCL Is Expanding Liability Beyond CIPA and CCPA
The UCL prohibits any “unlawful, unfair or fraudulent business act or practice.” Its breadth is both its strength and its danger. Unlike many privacy statutes that require concrete injury or specific statutory elements, the UCL’s three prongs allow creative pleading that can survive early motions to dismiss and open the door to discovery of internal practices, revenue data, and vendor relationships.
In the privacy context, the statute is most often used in three ways:
- As a vehicle to convert a CIPA or CCPA violation into a claim for restitution of profits derived from the alleged misconduct.
- As a standalone claim when plaintiffs allege that a consent mechanism, privacy policy, or data practice is deceptive or unfair even if a pure privacy statute claim faces standing hurdles.
- As a mechanism to obtain broader injunctive relief that can force changes to website architecture, consent flows, and third-party data sharing.
This combination has made UCL claims a standard feature in recent CIPA “broken banner” cases and in broader data-broker and tracking litigation.
The Three Prongs Explained in the Privacy Context
1. The Unlawful Prong
Under the unlawful prong, any violation of another law can serve as a predicate for UCL liability. In privacy cases this is most commonly a CIPA violation (Penal Code §§ 631 or 638.51), a CCPA violation, or a breach of the Consumers Legal Remedies Act (CLRA). Once the underlying violation is established, the UCL allows plaintiffs to seek restitution and injunctive relief in addition to whatever remedies the predicate statute provides.
Courts have repeatedly held that a CIPA violation can support an unlawful-prong UCL claim. This linkage is particularly powerful because it converts a statutory-damages claim into one that can reach the defendant’s AdTech-related revenues.
2. The Fraudulent Prong
The fraudulent prong focuses on whether members of the public are likely to be deceived. In website cases, this is frequently tied to consent banners and privacy disclosures. Plaintiffs allege that a banner promising users the ability to opt out of data sharing is fraudulent when AdTech scripts have already executed and transmitted data before the user ever sees or interacts with the banner.
This theory does not require proof that any particular plaintiff was actually deceived—only that the practice is likely to deceive the public. The presence of a non-functional or “broken” consent management platform therefore becomes both the privacy violation and the deceptive business practice.
3. The Unfair Prong
The unfair prong is the most flexible. Courts apply various tests, but in consumer cases they often examine whether the practice offends public policy, is immoral or unethical, or causes substantial injury that is not outweighed by countervailing benefits. Plaintiffs argue that collecting and monetizing data in a manner inconsistent with a website’s own privacy policy or consent representations is inherently unfair.
When companies continue operating a known defective consent mechanism, the unfairness claim is strengthened by evidence of knowledge and continued revenue generation from the practice.
Case Spotlight: Pflaumer v. Ace Hardware and the Broken-Banner Theory
The litigation in Pflaumer v. Ace Hardware provides a clear illustration of how these theories are combined. Plaintiffs allege that AdTech scripts on the Ace Hardware website executed and shared user data with third-party advertising partners before the consent banner was presented to the user. By the time a visitor could opt out, the data had already been transmitted.
Plaintiffs plead CIPA as the core privacy violation and then layer UCL claims under all three prongs:
- Unlawful: The CIPA violation itself.
- Fraudulent: The banner represented that opt-out functionality existed and would be honored.
- Unfair: Data was collected and monetized in breach of the disclosed privacy practices and user expectations.
This pleading strategy is no longer novel. It has become part of the standard template in website tracking and consent-banner cases. Similar theories appear in actions involving e-commerce platforms, media sites, and any organization that monetizes user data through advertising technology while displaying a consent interface.
How UCL Expands Damages and Settlement Leverage
The most significant practical impact of UCL claims is the expansion of remedies. Pure CIPA claims are largely limited to statutory damages of $5,000 per violation (or three times actual damages). UCL restitution claims, by contrast, seek the return of money obtained through the allegedly unlawful or unfair practice.
In the AdTech context this can include revenues attributable to the use of the plaintiff’s data in targeted advertising, measurement, or other monetization activities. While courts carefully scrutinize restitution calculations and require a causal link, the mere possibility of reaching advertising revenues changes settlement dynamics and increases the stakes of discovery.
When the website involves consumer transactions, plaintiffs frequently add CLRA claims, which can bring actual damages, punitive damages, and attorney fees. The combination of UCL restitution and CLRA remedies creates a multi-layered damages theory that is far more threatening than CIPA alone.
UCL Privacy Claims Over Web Tracking
UCL claims are not limited to CIPA website cases. They appear in data-broker litigation, employee-monitoring disputes, and actions challenging the handling of sensitive personal information. Regulators and private plaintiffs both use the statute’s flexibility to address practices that may not fit neatly into narrower privacy statutes.
Key patterns emerging include:
- Increased pairing of UCL with CIPA “pen register” and wiretap theories.
- Focus on consent mechanisms that fail in practice even if they appear compliant on the surface.
- Discovery pressure on internal communications about consent-management deficiencies and AdTech revenue.
- Use of UCL to seek forward-looking injunctive relief that forces architectural changes to websites and apps.
These trends mean that companies can no longer treat consent banners as a check-the-box compliance exercise. Technical implementation failures are now being reframed as unfair or fraudulent business practices with significant financial consequences.
Practical Compliance and Defense Recommendations
Organizations that want to reduce UCL exposure in privacy litigation should focus on both technical and legal controls:
- Validate Order of Operations — Conduct regular traffic-capture testing to confirm that AdTech scripts do not execute before consent is obtained or after an opt-out is recorded. Document the results.
- Align Disclosures with Reality — Ensure that privacy policies, cookie banners, and just-in-time notices accurately describe what happens to user data. Inconsistencies create both fraudulent-prong and unfair-prong exposure.
- Segment and Control AdTech Loading — Configure tag managers and consent platforms so that non-essential scripts are blocked until affirmative consent is recorded.
- Preserve Testing and Change-Management Records — Maintain evidence of ongoing monitoring. These records can be critical in demonstrating good-faith efforts and defeating claims of knowing misconduct.
- Review Vendor Contracts — Ensure that agreements with AdTech providers and consent-management vendors contain appropriate representations, audit rights, and indemnification language.
- Evaluate Insurance and Reserves — Confirm that cyber and media liability policies respond to UCL restitution and related privacy claims, and consider whether additional reserves are warranted given the expanded damages theories.
- Prepare for Discovery — Assume that internal communications about consent failures, revenue attributable to tracking, and remediation efforts will be sought. Privilege and work-product protections should be applied carefully from the outset of any investigation.
Proactive remediation is almost always less expensive than defending multi-prong UCL litigation after a demand letter or complaint is filed.
FAQs: Unfair Competition Law and Data Privacy Lawsuits
Q: Can a UCL claim succeed even if a pure CIPA or CCPA claim is dismissed?
A: In some circumstances yes. The fraudulent and unfair prongs can sometimes stand independently if the plaintiff adequately alleges a deceptive or unfair business practice, although courts scrutinize standing and the required link to the plaintiff’s injury.
Q: What is the biggest practical risk of receiving a UCL claim?
A: Restitution of AdTech or other data-related revenues, plus broader injunctive relief that can force costly website and operational changes. Settlement leverage increases significantly.
Q: Does every website with a consent banner face this risk?
A: Risk is highest where the banner is there but it doesn’t work. Non-functional in practice (scripts fire before consent) or where disclosures are inconsistent with actual data flows. Proper technical validation substantially reduces exposure.
Q: How should companies respond to a UCL + privacy demand letter?
A: First get your website compliant with a high quality privacy software tool like Captain Compliance. Talk to your insurance company and engage experienced counsel immediately, preserve relevant technical and communications evidence, conduct a rapid audit of the consent mechanism, and evaluate both the merits and the potential restitution exposure before responding.
Q: Is this only a California issue?
A: Primary exposure is under California law but this targets businesses all over the country but the plaintiff is going to be California based.
UCL is One of Many Privacy Lawsuit Landmines to Avoid
California’s Unfair Competition Law is no longer a secondary afterthought in data privacy lawsuits. It has become a central vehicle for expanding remedies, increasing settlement pressure, and converting technical consent failures into claims of unlawful, unfair, and fraudulent business practices. Cases such as Pflaumer v. Ace Hardware demonstrate how plaintiffs are successfully combining CIPA with UCL theories to reach beyond statutory damages and into the heart of a company’s advertising revenue model.
For compliance, legal, and technical teams, the message is clear: surface-level implementation of consent banners is insufficient. Organizations must verify that the technical sequence of events matches the promises made to users, document those efforts, and treat ongoing testing as a core compliance control. Failure to do so creates not only privacy risk but also significant unfair-competition exposure.
At Captain Compliance, we help organizations identify and close these gaps. Our services include consent-mechanism audits, AdTech data-flow mapping, UCL risk assessments, remediation roadmaps, and ongoing monitoring programs designed to reduce both regulatory and private-litigation exposure.
Is your organization prepared for the expanded liability that Unfair Competition Law claims bring to data privacy lawsuits? Contact Captain Compliance today for a confidential evaluation of your consent practices, privacy disclosures, and overall litigation risk profile.
Stay informed on evolving privacy litigation trends, enforcement actions, and practical compliance strategies with Captain Compliance — your partner in building resilient, defensible privacy programs.