Wrongful collection has quietly become one of the most expensive phrases in American privacy law. It describes the gathering of personal information without the legally required notice, consent, or authority to do so, and it now sits at the center of three converging storms: a wave of wiretapping and biometric class actions targeting everyday website technology, a hardening cyber insurance market that is rewriting policies to escape those claims, and a renewed federal crackdown on data harvested from children through connected toys and apps. Compliance officers who treat wrongful collection as an abstract underwriting term are learning, one demand letter at a time, that it is the operative theory behind most of the privacy litigation filling federal and state dockets today.
This guide explains what wrongful collection means in practice, walks through real-world examples drawn from active litigation, unpacks how cyber insurance policies treat wrongful collection claims (and where carriers are cutting coverage), and decodes the “not liable for data collection” disclaimers appearing on toys and consumer products.
What Is Wrongful Collection?
Wrongful collection via pixel tracking is the acquisition of personal data in a manner that violates a statute, a regulation, a contractual promise, or the collector’s own published privacy policy. The term originated in insurance drafting, where cyber and technology errors and omissions policies needed language to describe privacy claims that did not stem from a breach or hack. Unlike a ransomware event, nothing is stolen in a wrongful collection scenario. The company itself gathers the data, and the gathering is the injury.
That distinction matters enormously. Traditional cyber coverage was built around third-party intrusions: a criminal breaks in, records are exfiltrated, and the insured is a victim responding to the event. Wrongful collection inverts the posture. The insured is the accused actor, the plaintiff is a consumer or employee whose data was captured, and the alleged harm flows from ordinary business tooling such as analytics pixels, session replay software, chatbots, fingerprint time clocks, and voice assistants.
The statutes most commonly invoked in wrongful collection claims include:
- The California Invasion of Privacy Act (CIPA), which carries $5,000 in statutory damages per violation for unlawful interception or pen register use
- The Illinois Biometric Information Privacy Act (BIPA), with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation
- The federal Video Privacy Protection Act (VPPA), providing $2,500 per violation for disclosure of video viewing data
- The Children’s Online Privacy Protection Act (COPPA), enforced by the FTC with civil penalties that now exceed $53,000 per violation
- The federal Wiretap Act and its state analogs in Pennsylvania, Massachusetts, Florida, Maryland, and Washington
- Comprehensive state privacy laws such as the CCPA/CPRA, which impose notice-at-collection and purpose-limitation duties
Because most of these statutes award damages per violation rather than per plaintiff, and because a busy ecommerce site can log millions of sessions per year, wrongful collection exposure scales in a way few other legal risks do.

Wrongful Collection Examples
Wrongful collection is not hypothetical. Each of the following patterns is drawn from filed litigation or regulatory enforcement, and most of them involve technology that marketing teams installed without ever consulting legal.
Session Replay and Tracking Pixel Wiretapping
The largest single category of wrongful collection claims today alleges that session replay tools, chat widgets, and advertising pixels intercept website communications in real time without visitor consent, violating CIPA Section 631 and similar two-party consent statutes. Plaintiffs’ firms have filed thousands of these suits and arbitration demands against retailers, healthcare systems, and financial institutions. A visitor types a search query or health condition into a website; a third-party script transmits that keystroke data to an analytics or advertising vendor before the visitor ever clicks submit. Under the wiretapping theory, the vendor is an eavesdropper and the website operator aided the interception.
Pen Register and Trap-and-Trace Claims
A newer CIPA theory, built on Section 638.51, alleges that tracking scripts which capture IP addresses and device identifiers operate as unauthorized pen registers. Because the theory targets nearly universal technology such as analytics cookies and fraud-detection scripts, it has generated an extraordinary volume of demand letters from serial claimants, often seeking fast settlements below the cost of a motion to dismiss.
Biometric Capture Without Consent
BIPA litigation established the template for wrongful collection class actions. Employers using fingerprint or face-scan time clocks, retailers deploying virtual try-on tools, and platforms tagging photos with facial recognition have all faced claims for collecting biometric identifiers without the written release BIPA requires. Facebook paid $650 million to settle its BIPA photo-tagging case, and the Illinois Supreme Court’s decision in Cothron v. White Castle confirmed that claims accrue with each scan, a holding so severe that the Illinois legislature amended the statute in 2024 to limit recovery to one violation per person per collection method.
Video Viewing Data Disclosure
VPPA suits allege that websites hosting video content wrongfully collect and share viewing histories with Meta and other ad platforms via pixels, tying identifiable users to the specific videos they watched. Media companies, sports leagues, and even hospital systems with video libraries have been named.
Geolocation and Sensitive Data Harvesting
Regulators have pursued wrongful collection theories against data brokers and app publishers that gathered precise geolocation revealing visits to health clinics, places of worship, and shelters. The FTC’s cases against location data brokers and the Texas Attorney General’s suits over vehicle telematics data both rest on collection that exceeded consumer consent.
Children’s Data Collected Through Apps and Toys
COPPA enforcement supplies some of the starkest examples: Epic Games paid $275 million for collecting children’s data through Fortnite without parental consent, Amazon paid $25 million over Alexa’s indefinite retention of children’s voice recordings, and connected toy maker VTech settled FTC charges after collecting data from hundreds of thousands of children without proper notice. Each case is wrongful collection in its purest form, since the products worked exactly as designed and the design itself was the violation.
Wrongful Collection Cyber Insurance
For a decade, policyholders assumed privacy class actions would land inside their cyber towers. That assumption is collapsing, and understanding why requires a look at how carriers define and now exclude wrongful collection.
How Cyber Policies Define Wrongful Collection
Many cyber forms include wrongful collection as an enumerated peril within the privacy liability insuring agreement, typically phrased as coverage for claims alleging improper collection of personally identifiable information, or collection in violation of the insured’s privacy policy or applicable privacy law. Where that language appears without a countervailing exclusion, it is the natural home for CIPA, BIPA, VPPA, and pixel litigation defense costs and settlements.
Where Carriers Are Cutting Back
The claims wave changed underwriting behavior quickly. Compliance and risk teams should watch for four developments in current renewals:
- Biometric exclusions. After BIPA verdicts and settlements ran into nine figures, many carriers attached exclusions for claims arising from biometric data. Courts have not always enforced them as written; in Citizens Insurance Co. of America v. Wynndalco Enterprises, the Seventh Circuit found a broad statutory-violation exclusion so sweeping it would swallow the policy’s own privacy coverage, and construed it against the insurer.
- Wiretapping and unlawful collection exclusions. Newer forms add exclusions for claims alleging wiretapping, eavesdropping, pen registers, or the intentional collection of data in violation of law, aimed squarely at CIPA and pixel litigation.
- Unlawful data collection carve-outs in general liability. Insurers have also litigated whether GL policies’ personal and advertising injury coverage reaches privacy statutes. The Illinois Supreme Court’s West Bend v. Krishna Schaumburg Tan decision found a duty to defend a BIPA claim under a GL policy, which accelerated the carriers’ push to add explicit exclusions.
- Underwriting interrogation of tracking technology. Cyber applications increasingly ask whether the insured deploys session replay, pixels on pages collecting health data, chatbots, or a consent management platform, and whether consent is obtained before trackers fire. Misstatements on these questions can support rescission arguments later.
What Risk Managers Should Do
- Read the wrongful collection language in both the insuring agreement and the exclusions, and ask the broker to reconcile any conflict in writing
- Negotiate affirmative coverage or sublimits for wiretapping, biometric, and unlawful collection claims rather than relying on silence
- Document the consent management program, because demonstrating prior express consent is both a litigation defense and an underwriting asset
- Confirm whether regulatory investigations, arbitration demands, and pre-suit CIPA letters trigger the policy’s definition of a claim, since much of this exposure arrives before a complaint is ever filed
What Does “Not Liable for Data Collection” Mean on Toys?
Parents shopping for connected toys, tablets, and smart devices increasingly encounter packaging, quick-start guides, or online listings stating that the manufacturer or seller is not liable for data collection. The phrase generally appears in one of three contexts:
- A disclaimer that the toy connects to a third-party app or platform, and that data collected through that app is governed by the app developer’s privacy policy rather than the toy maker’s
- A terms-of-use provision attempting to limit the manufacturer’s liability for how voice recordings, camera images, gameplay data, or account information are collected and used
- A marketplace seller’s boilerplate attempting to push privacy responsibility onto the brand or the platform
The practical translation is that the toy likely does collect data, often audio, video, location, or behavioral information, and someone in the supply chain is trying to point the legal responsibility elsewhere. Smart toys have earned that suspicion honestly. The My Friend Cayla doll was banned in Germany as an illegal surveillance device after researchers showed its microphone could be exploited, and VTech’s connected toy platform exposed the data of millions of children before its FTC settlement.
Critically, a disclaimer on a box does not do what buyers might fear or what sellers might hope. COPPA obligations attach to any operator that collects personal information from children under 13, and the FTC’s updated COPPA Rule, which took effect in 2025, tightened requirements around third-party disclosures, retention, and targeted advertising. A manufacturer cannot contract its way out of a statutory duty owed to children, and parents cannot waive their children’s COPPA protections by opening the packaging. If a company is collecting children’s data, verifiable parental consent and compliant notice are required regardless of what the label says.
Not Liable for Data Collection Meaning
Outside the toy aisle, “not liable for data collection” language shows up in website terms, SaaS agreements, vendor contracts, and product disclaimers. Its meaning depends entirely on who is disclaiming what, and its enforceability is far narrower than the drafting suggests.
What the Language Is Trying to Accomplish
- Allocating responsibility between parties, such as a platform stating it is not liable for data its merchants collect, or a hardware maker disclaiming the conduct of bundled third-party software
- Limiting contractual damages if a user later claims their data was mishandled
- Signaling that a separate entity is the data controller, which is a meaningful legal distinction under GDPR-style frameworks and state privacy laws
Why the Disclaimer Rarely Ends the Analysis
Statutory privacy liability is generally non-waivable through unilateral disclaimers. A business that actually determines the purposes and means of collection remains a controller with notice and consent duties under state privacy laws no matter what its terms recite. Wiretapping statutes such as CIPA turn on whether consent was obtained before interception, not on whether a liability limitation exists somewhere in the terms of service. Courts also scrutinize whether consumers had meaningful notice of buried disclaimers at all, and regulators have treated privacy promises that conflict with actual practices as deceptive acts in themselves.
The honest reading of any “not liable for data collection” statement is therefore a prompt for diligence rather than reassurance: identify what data the product or service actually collects, which entity receives it, what legal basis and consent mechanism supports the collection, and whether the disclaiming party is genuinely outside the data flow or merely wishes to be.
How to Prevent Wrongful Collection Claims
Every wrongful collection theory shares the same vulnerability for plaintiffs: valid, provable, prior consent defeats the claim. That makes prevention an engineering problem as much as a legal one.
- Inventory every tracking technology, pixel, session replay tool, chatbot, and SDK running on your web and mobile properties, including those injected by tag managers
- Deploy a consent management platform that blocks trackers before consent and fires them only after an affirmative choice, with consent records preserved as litigation evidence
- Honor Global Privacy Control signals and state-specific opt-out requirements automatically
- Purge biometric, children’s, and sensitive data collection paths unless a documented compliance basis exists, including written releases where BIPA-style statutes apply
- Align privacy policy disclosures with actual data flows, since the gap between the two is itself a wrongful collection allegation
- Bring insurance into the program by disclosing your consent architecture accurately at renewal and pressure-testing exclusions before a demand letter arrives
Captain Compliance gives businesses the infrastructure to shut down wrongful collection exposure at the source: a certified consent management platform that gates trackers until consent is captured, automatic Global Privacy Control honoring, dynamic privacy policies that stay synchronized with your actual data practices, and continuous website scanning that flags new pixels and scripts before a plaintiff’s firm finds them. If session replay lawsuits, CIPA demand letters, or biometric consent requirements are on your radar, get in touch with our team for a compliance assessment and see exactly what your website is collecting today.