Rodriguez v. Sacramento CDJR LLC (C.D. Cal.): Browsewrap Arbitration Fails, ECPA One-Party Consent Holds, and Crime-Tort Exception Narrowed

Table of Contents

Rodriguez v. Sacramento CDJR LLC Privacy Lawsuit
On August 12, 2026, the Central District of California issued a notable order in Rodriguez v. Sacramento CDJR LLC (a case removed from Los Angeles County Superior Court). The decision addresses a familiar pattern in California privacy litigation: a tester plaintiff asserting claims under the Electronic Communications Privacy Act (ECPA) and related state-law theories (typically CIPA) against a car dealership’s website. Plaintiff Rebeka Rodriguez, represented by Pacific Trial Attorneys, is a high-volume tester plaintiff associated with a large number of similar suits. The court denied the defendant’s motion to compel arbitration, granted the motion to dismiss the ECPA claim with leave to amend, and deferred ruling on the remaining state-law claims.

Arbitration Denied: Browsewrap Is Not Enough

The court refused to compel arbitration because the arbitration terms appeared only through a browsewrap link. Users were not required to take any affirmative step acknowledging or agreeing to the terms before accessing the site. This outcome aligns with longstanding case law requiring clear notice and assent for online contracts to be enforceable.

The practical lesson is straightforward and one we have repeatedly advised clients to implement: rely on a conspicuous gatekeeper (or “clickwrap”) banner or interstitial that blocks further access to the site unless the user affirmatively consents to the terms of use (including any arbitration provision). Passive links in a footer or privacy policy, without more, remain vulnerable.

ECPA Claim Dismissed: One-Party Consent Controls; Crime-Tort Exception Requires an Independent Act

The court granted the motion to dismiss the federal ECPA claim with leave to amend. The core holding turns on the federal one-party consent rule. Under the Wiretap Act (the relevant portion of ECPA), interception is generally lawful if one party to the communication consents. California’s all-party consent regime under CIPA does not automatically override this federal baseline for the federal claim.

Plaintiff attempted to invoke the crime-tort exception to one-party consent. The court rejected that argument on a threshold ground: the alleged interception itself cannot supply the required criminal or tortious purpose. To rely on the exception, a plaintiff must plead an independent act—separate from the interception—that was undertaken for a criminal or tortious purpose. The court did not reach the secondary question of whether any such purpose was the “primary” purpose of the interception. This is a significant clarification. Many recent complaints treat the mere act of deploying tracking technology (or the collection that results) as self-sufficient to trigger the exception. Rodriguez rejects that circular approach.

State Claims Deferred; Jurisdictional Caution

Because the sole federal claim was dismissed (with leave to amend), the court deferred any ruling on the state-law claims. If plaintiff successfully amends and maintains a viable federal claim, the court will then address the state claims. If the federal claim ultimately fails, the court indicated the matter would be remanded to state court. This is a standard and prudent exercise of supplemental jurisdiction discretion.

Broader Context: Parallel Developments in CIPA and ECPA Litigation

The Rodriguez order arrives amid a crowded and still-unsettled landscape of website-tracking litigation under CIPA and related federal theories. In recent months, California courts have continued to split on whether routine analytics, pixels, and similar tools can qualify as pen registers or trap-and-trace devices under Penal Code § 638.51. Some state-court decisions have dismissed these claims with prejudice on the ground that the statute was aimed at telephonic surveillance rather than ordinary commercial website operations, while other courts have allowed similar theories to proceed past the pleading stage. Federal courts have likewise produced mixed results, with several recent rulings emphasizing Article III standing requirements and rejecting bare statutory violations as sufficient injury.

Class-certification efforts have also faced headwinds. Multiple Central District decisions in 2026 have denied certification in CIPA tracking cases after applying the Ninth Circuit’s standing framework from Popa v. Microsoft, finding that individualized inquiries into whether each putative class member suffered a concrete injury would predominate. Standing dismissals of serial plaintiffs, including orders designating certain frequent filers as vexatious litigants, further illustrate judicial impatience with tester-driven litigation that generates volume without corresponding individualized harm.

On the legislative front, Senate Bill 690 continues to move through the California Assembly. In its current form, the bill would eliminate the private right of action for website-based pen-register and trap-and-trace claims under § 638.51, reserving enforcement to the Attorney General and applying retroactively to many pending cases. While the measure does not address the full range of CIPA theories (including traditional wiretapping claims under § 631), its progress reflects growing legislative recognition that the volume of demand letters and suits targeting ordinary website tools has strained both businesses and the courts. Whether the bill reaches the Governor’s desk this session remains an open question, but its narrowed scope and bipartisan support signal a possible partial recalibration of private enforcement in this area.

Settlements continue to close out some of the larger matters even as new complaints are filed. The mid-2026 final approval of a multi-million-dollar class settlement involving the Los Angeles Times and certain third-party trackers stands as one recent data point, while other cases have been dismissed at the pleadings stage or pruned through targeted motions on standing, jurisdiction, or the crime-tort exception. Appellate guidance is still limited; pending Court of Appeal matters addressing the reach of § 638.51 to website technologies could eventually supply more uniform direction, but trial-level decisions remain the primary source of day-to-day guidance for the time being.

What the Order Signals for Defense Strategy and Website Design

Arbitration language needs real assent. Browsewrap alone is a weak foundation. Implement a blocking consent mechanism that requires affirmative acceptance of terms before users proceed.

ECPA remains a higher bar than CIPA for many tracking claims. One-party consent continues to provide a meaningful defense on the federal claim. Plaintiffs cannot bootstrap the crime-tort exception simply by alleging that the interception was itself wrongful.

Tester-plaintiff dynamics remain relevant. Courts continue to see high-volume serial filers. While standing and injury analyses were not the focus of this particular order, the overall posture of these cases continues to invite close scrutiny of the allegations and the plaintiff’s relationship to the challenged conduct.

Leave to amend keeps the case alive for now. Defendants should expect amended pleadings that attempt to allege an independent criminal or tortious purpose. Plaintiffs will likely try to plead additional facts around data monetization, secondary uses, or other downstream conduct.

This decision is one of several CIPA/ECPA rulings issued the same week. It reinforces two practical priorities: obtain clear, affirmative consent to website terms when arbitration or other contractual defenses matter, and structure data practices with the federal one-party consent framework and the limits of the crime-tort exception in mind.

Businesses operating consumer-facing websites in California should treat this as another data point in the ongoing evolution of website-tracking litigation. Clear notice-and-consent architecture, careful review of third-party tools, and documentation of legitimate business purposes remain the most effective risk-reduction measures.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.