Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Home› Editorial› Where There’s Smoke: Hinton v. Planned Parenthood and…
DATA

Where There’s Smoke: Hinton v. Planned Parenthood and the “Linkage” Proof Gap in CIPA Pixel Class Actions

For more than three years, plaintiffs have filed California Invasion of Privacy Act (CIPA) claims against nearly every type of organization with a public website, alleging that the Meta Pixel, Google Analytics, and similar tools “intercept” visitors’ communications.

Oct 8, 2026 10 min read

Know what’s on your site before a plaintiff’s firm does

A free privacy audit shows which cookies, pixels and trackers are running — and which ones commonly appear in privacy claims.

Get My Free Audit

For more than three years, plaintiffs have filed California Invasion of Privacy Act (CIPA) claims against nearly every type of organization with a public website, alleging that the Meta Pixel, Google Analytics, and similar tools “intercept” visitors’ communications. Many of these suits never get past the pleadings. The more important question is what happens to the ones that do: whether a plaintiff can turn an individual pixel claim into a certified class action carrying CIPA’s $5,000 per-violation statutory damages.

On September 30, 2026, Judge James Donato of the Northern District of California issued a significant answer. In Hinton v. Planned Parenthood Federation of America, Inc., No. 23-cv-04529-JD, 2026 WL 2959993 (N.D. Cal. Sept. 30, 2026), the court denied certification of both a damages class and an injunctive relief class of California visitors to Planned Parenthood’s website, reasoning the plaintiffs had offered “speculation and conjecture in lieu of facts” to show that Meta and Google linked visitors’ reproductive health searches to their identities.

Why it Matters: For companies that use third-party tracking technologies, Hinton matters for three reasons. First, it shows that plaintiffs’ own framing of their theory can become a certification liability. Second, it confirms that arguments based on how AdTech business models work cannot substitute for classwide proof of what actually happened to each class member’s data. Third, it arrived on the same day California enacted SB 690, which will push plaintiffs toward exactly the CIPA § 631 interception theory that Hinton rejected for class treatment.

The Claims & Proposed Classes

After a partial dismissal, the plaintiffs’ first amended complaint asserted a single claim under CIPA § 631’s wiretapping prohibition, Cal. Penal Code § 631, “on an aiding-and-abetting theory only.” The plaintiffs alleged that Planned Parenthood embedded “tracking codes” supplied by Google, Meta, and others, and that this code allowed those third parties to intercept “confidential and private healthcare information and other sensitive personally identifiable information” of website visitors. According to the operative pleading, the disclosures revealed “the exact identity” of users along with information about “their inherently private and personal sexual and reproductive healthcare.”

The plaintiffs proposed two classes with identical definitions: all persons who, between September 1, 2022, and July 6, 2023, while in California, either searched the plannedparenthood.org site for abortion, STD testing, birth control, pregnancy testing, hormone therapy, or emergency contraception, or visited one of seven enumerated service pages on those topics. They sought certification of a “Damages Class” under Rule 23(b)(3) and an “Injunctive Relief Class” under Rule 23(b)(2).

The Court’s Analysis

Skipping Rule 23(a)

The court departed from the usual sequence. Instead of working through numerosity, commonality, typicality, and adequacy, Judge Donato went directly to Rule 23(b), explaining that the plaintiffs had “manifestly failed to meet their burden” there and that this failure “alone warranted denial of certification.”

Predominance: The Plaintiffs’ Theory Became Their Burden

The predominance analysis turned on the case the plaintiffs had chosen to bring. Citing the principle that plaintiffs are “the master[s] of [their] complaint,” the court paid “close attention” to how they framed their claim. In their certification reply, the plaintiffs had committed to proving “with common evidence that Meta and Google actually linked class members’ PPFA Website searches and page views concerning private healthcare concerns like birth control, emergency contraception or STD testing to their specific identities, including their name, email address and other information provided to Google or Meta when creating an account” (emphasis in original).

The record did not support that commitment. The plaintiffs’ main argument was an inference from business purpose. Because “[t]he whole purpose of tracking technologies is, in Meta’s words, ‘to personalize content,’” they said, it would be “preposterous” to think Meta and Google could deliver personalization “without first matching online actions to actors.” The court rejected that reasoning:

This is not evidence. It is an inference based on generalities and speculation. In effect, plaintiffs say where there’s smoke, there must be fire. That is not a basis to certify a class under Rule 23.

The court analogized to Wal-Mart Stores, Inc. v. Dukes, 564 U.S. 338 (2011), in which the Supreme Court rejected an expert’s “social framework” testimony that Wal-Mart’s corporate culture made it “vulnerable” to gender bias because the expert could not determine “with any specificity” how often stereotypes affected actual employment decisions. The Hinton plaintiffs’ “generalized evidence about Meta and Google’s business goals and promises” had the same defect. It described what the technology is designed to do, but it did not provide common proof of what, in fact, happened to class members’ data.

The “Off Meta Activity” Problem

The decision’s most useful practical lesson involves the plaintiffs’ evidence from Meta itself. The plaintiffs cited “Off Meta Activity reports and data produced by Meta,” but acknowledged that those materials “cut against their case” because they did not show that Meta tracked and linked the plaintiffs’ activity on the Planned Parenthood website. The plaintiffs tried to minimize the reports as “not a complete record.” The court found that approach self-defeating: “marginalizing the Off Meta Activity reports, which is one of the scant few items of concrete, potentially classwide evidence plaintiffs cited, is not a step forward in establishing the availability of classwide proof based on common evidence.”

The plaintiffs’ final argument—their own testimony that they used the website to research reproductive health concerns—did not help. That kind of testimony is “exactly the opposite of classwide, common proof,” and Rule 23(b)(3) does not allow certification when claims must be determined “one claim at a time.” Van v. LLR, Inc., 61 F.4th 1053, 1067 n.11 (9th Cir. 2023); Bowerman v. Field Asset Servs., Inc., 60 F.4th 459, 469-70 (9th Cir. 2023).

The Injunctive Relief Class

The plaintiffs’ Rule 23(b)(2) request failed for two independent reasons. First, the plaintiffs presented it “in barebones fashion in less than one page,” and the same lack of evidence that defeated predominance meant they could not show a “pattern or practice that is generally applicable to the class as a whole.” Second, the primary relief sought was monetary, not injunctive or declaratory, with the complaint itself demanding “statutory damages of $5,000 per violation.” See Rodriguez v. Hayes, 591 F.3d 1105, 1125 (9th Cir. 2010).

What Comes Next

The court directed the parties to resume ADR “on an individual, non-class basis,” administratively terminated the pending summary judgment and Daubert motions, asked the parties to consider whether those motions should be re-briefed in light of the ruling, and set a status conference for December 10, 2026.

Analysis & Takeaways

Framing the Theory Has Consequences

Hinton does not hold that every § 631 pixel plaintiff must prove identity linkage. It holds that these plaintiffs, having made linkage central to their case, had to prove it with common evidence. Ambitious theories increase settlement demands, but they can become serious certification problems. Defense counsel should identify and lock in the plaintiffs’ theory early, in interrogatory responses, expert disclosures, and the certification briefing itself, and then test whether the record can support it on a classwide basis.

Business Model Inferences Are Not Classwide Proof

Pixel complaints routinely argue that AdTech companies monetize data by matching it to users, so matching must have occurred. Hinton reflects growing judicial skepticism of that reasoning at the evidentiary stage. It follows In re Meta Pixel Tax Filing Cases, 826 F. Supp. 3d 1217 (N.D. Cal. 2026), where Judge P. Casey Pitts denied certification in part because determining whose tax filing data Meta actually received would require individualized inquiries, and Ingraham v. Capital One Financial Corp., No. 24-cv-05985-TLT, 2026 WL 1759155 (N.D. Cal. June 16, 2026), where variation in browser settings, user behavior, and disclosures defeated predominance. Courts increasingly expect evidence of what happened to each class member’s data, not descriptions of what the technology is built to do.

Vendor-Side Data Can Help the Defense

The Off Meta Activity reports, produced by Meta in discovery, damaged the plaintiffs’ case. Website operators defending aiding-and-abetting claims should make obtaining vendor-side data a priority, because the absence of linkage in the vendor’s own records may be the most persuasive classwide evidence available—and it favors the defense.

Sensitivity Does Not Reduce the Burden

Few categories of website data are more sensitive than searches about abortion, STD testing, and hormone therapy, and those facts appear throughout the operative Hinton complaint. They did not change the Rule 23 analysis. Sensitivity may matter on the merits and to a jury, but does not substitute for common proof.

Certification is Not Dead—and the Record Decides

Hinton should not be read as a categorical bar. In Doe v. Adventist Health System/West, 2026 WL 2474859 (Cal. Ct. App. July 24, 2026), the California Court of Appeal reversed denial of certification for a hospital’s health risk assessment subclass, finding that whether pixel transmissions disclosed “content” was subject to common proof where the hospital’s records identified authenticated users and the tracked interactions were standardized. Frasco v. Flo Health, Inc., 349 F.R.D. 557 (N.D. Cal. 2025), likewise certified classes based on a uniform app experience and identifiable users. The lesson is that a defendant’s own data architecture, including logged-in portals, authenticated sessions, and user level records, can supply the common proof that the Hinton plaintiffs lacked.

SB 690 Makes CIPA § 631 the Primary Battleground

On the same day Hinton was decided, Governor Newsom signed SB 690, which, effective January 1, 2027, limits CIPA § 638.51 pen register and trap and trace claims arising from website and app conduct to the California Attorney General, with retroactive effect on pending claims filed on or after January 1, 2025. SB 690 leaves CIPA § 631 private claims untouched. As pen register filings decline, expect the plaintiff’s bar to shift toward § 631 interception and aiding-and-abetting theories like the one in Hinton. That makes the certification defense Hinton illustrates more valuable.

Practical Tips & Strategies

Compliance Teams

For compliance teams, the aim is to reduce both merits exposure and the conditions that make a class certifiable:

  1. Map the tracking environment. Inventory every pixel, tag, software development kit (SDK), and session replay tool across websites and apps, including site search functions, and document what each one transmits, to whom, and on which pages.
  2. Treat sensitive pages differently. Consider removing third-party advertising pixels from health, financial, and similarly sensitive pages and search results, or reconfigure them (for example, through server-side tagging with parameter stripping) so that URLs and search terms revealing sensitive topics are not transmitted.
  3. Make consent mean something. Use a consent management platform that actually blocks non-essential tags until the user consents, honor Global Privacy Control signals, and confirm through periodic testing that the banner works as represented.
  4. Watch authenticated environments. Patient portals, account dashboards, and logged-in experiences are where the common proof found in Adventist comes from. Tracking in those environments warrants the strictest review.
  5. Tighten vendor terms. Contractually restrict vendors’ independent use of data, require data sharing configurations that minimize identifiers, and allocate risk through indemnification.
  6. Keep disclosures consistent. Make privacy notices and consent flows uniform and accurate. Inconsistent disclosures can create individualized consent questions, but they also create merits risk.

Litigation Teams

For litigation teams defending pixel suits, the steps are:

  1. Lock in the plaintiffs’ theory through early discovery and hold them to it at certification.
  2.  Subpoena vendor-side data (including Off Meta Activity reports and comparable Google records) to test whether interception or linkage can be shown on a classwide basis.
  3. Develop expert evidence on variability, including how browser settings, ad blockers, consent choices, logged-in status, and device type affect what each user transmitted.
  4. Challenge (b)(2) classes directly, where the complaint’s demand for $5,000 per violation shows that monetary relief predominates.

The Final Word: Involve Experienced Counsel Early

Hinton is a meaningful defense win, but it was won on the evidentiary record after nearly three years of litigation. The more cost-effective approach is to configure tracking technologies so that sensitive data is never transmitted and to design consent and vendor programs that hold up under review. Organizations should engage experienced privacy counsel early, both to audit and remediate tracking practices before a demand letter or putative class complaint arrives and, when litigation comes, to build the certification defense from the first day of the case.

About the Author

David J. Oberly is a tech-savvy attorney and recognized thought leader in the privacy space. David provides strategic advice and counseling on all types of privacy and technology matters that arise when doing business in today’s digital world, and guides companies in navigating the full spectrum of regulatory, product, and risk management issues that impact the use of personal data. He also represents companies in the defense of privacy and technology class actions, with deep experience litigating class claims brought under the California Invasion of Privacy Act (CIPA) and similar state wiretapping laws, Electronic Communications Privacy Act (ECPA), Video Privacy Protection Act (VPPA), California Consumer Privacy Act (CCPA), and California’s Unfair Competition Law (UCL) and analogous state unfair and deceptive practices (UDAP) statutes, among others. David can be reached at doberly@bakerdonelson.com.

Put this into practice

Turn privacy guidance into working controls.

Captain Compliance helps teams discover tracking technologies, enforce consent, manage privacy requests and document the evidence behind every decision.

Book a demo Run a free scan