The Arizona Consumer Fraud Act (ACFA): The New Vehicle for Pixel Tracking Litigation

Table of Contents

When the Arizona Court of Appeals killed the “spy pixel” theory under the Telephone, Utility and Communication Service Records Act (TUCSRA) in November 2025, it didn’t end Arizona’s role in pixel litigation — it just ended one specific theory. Plaintiffs’ firms had already found the next vehicle, and it’s a much older, much broader statute: the Arizona Consumer Fraud Act (ACFA), A.R.S. § 44-1521 et seq. In August 2026, mental health provider LifeStance Health Group agreed to pay $3,027,874.44 to settle claims that its website tracking pixels violated the ACFA. It wasn’t the only one — Banner Health settled a nearly identical, multi-state consolidated action months earlier.

This piece is the companion to our TUCSRA breakdown: it covers exactly what the ACFA says, why it works as a pixel-litigation vehicle where TUCSRA didn’t, every significant case we can identify, and how this fits into the broader national pattern of “consumer fraud” and “little FTC Act” statutes being stacked onto wiretap claims in states from Colorado to California.

At a glance

  • The ACFA (A.R.S. § 44-1521 et seq.) was signed into law in March 1967 as House Bill 114, and broadly prohibits deception, false pretenses, misrepresentation, and concealment or omission of material facts in the sale or advertisement of “merchandise” — a term defined to include goods, services, and even real estate.
  • The pixel theory: if a company’s privacy policy says it doesn’t share visitor data, but tracking pixels are quietly sending that data to Meta or Google anyway, the contradiction itself is pled as a deceptive act — independent of whether any wiretap or records statute applies.
  • In August 2026, LifeStance Health Group agreed to a $3.02 million settlement (Strong et al. v. LifeStance Health Group Inc., D. Ariz.) resolving HIPAA and ACFA claims over pixel data sent to Google and Meta.
  • Banner Health settled a consolidated, multi-state action (McCulley et al. v. Banner Health, filed in Colorado) that stacked the ACFA alongside CIPA, ECPA, California’s Confidentiality of Medical Information Act, California’s Unfair Competition Law, and the Colorado Consumer Protection Act — all in a single complaint.
  • This “stack every applicable consumer-protection and wiretap statute into one complaint” pattern is becoming the standard architecture for pixel litigation nationally, not just an Arizona quirk.
  • The ACFA succeeds as a pixel vehicle for exactly the opposite reason TUCSRA failed: its operative terms (“deception,” “misrepresentation,” “concealment”) are broad and not tied to any specific industry, so they don’t require a court to stretch carrier-specific language to reach a marketing pixel.

What the Arizona Consumer Fraud Act actually says

The ACFA was introduced as House Bill 114 by then-Arizona House Republican majority leader D. Delos Ellsworth, introduced January 26, 1967, and signed into law by Governor Jack Williams on March 13, 1967. Its core prohibition, at A.R.S. § 44-1522(A), is broad by design:

The act, use or employment by any person of any deception, deceptive
act or practice, fraud, false pretense, false promise, misrepresentation,
or concealment, suppression or omission of any material fact with intent
that others rely upon such concealment, suppression or omission, in
connection with the sale or advertisement of any merchandise ... is
declared to be an unlawful practice.

A few structural features matter enormously for how this statute gets used against tracking technology:

  • “Merchandise” is defined broadly under A.R.S. § 44-1521 to include “objects, wares, goods, commodities, intangibles, real estate, or services” — meaning the ACFA reaches service transactions (like signing up for a healthcare portal or booking an appointment online) just as easily as it reaches the sale of a used car.
  • The Act covers both affirmative deception and silent omission. A company doesn’t need to make an explicit false statement; concealing or omitting a material fact “with intent that others rely” on that silence is independently actionable.
  • Private right of action. Established since Sellinger v. Freeway Mobile Home Sales, Inc., 110 Ariz. 573 (1974), individual consumers — not just the Arizona Attorney General — can sue directly, though private claims carry a short, one-year statute of limitations under A.R.S. § 12-541.
  • Remedies include actual damages and punitive damages for private plaintiffs; the Attorney General can separately seek civil penalties of up to $10,000 per willful violation under A.R.S. § 44-1531.
Arizona Consumer Fraud Act Privacy Lawsuit Financials

The pixel theory: privacy policy contradiction as deception

The ACFA theory doesn’t require proving a pixel “intercepted” anything or that data collected qualifies as some statutorily defined “record” — the arguments that sank TUCSRA. It requires something much simpler and much harder to engineer around: showing that what a company said about its data practices doesn’t match what its website actually does.

The template looks like this:

  1. A company’s privacy policy states, in some form, that it doesn’t sell or share visitor data with third parties, or that data is used only for specified, limited purposes.
  2. Independent of that stated policy, the company’s website runs tracking pixels (Meta Pixel, Google Analytics, Google Ads conversion tracking, and similar tools) that transmit visitor behavior — and, on sensitive sites, specific health, financial, or personal details — to those third-party platforms.
  3. Plaintiffs plead that the gap between the stated policy and the actual data flow is itself the “deception,” “misrepresentation,” or “concealment” the ACFA prohibits — with the pixel serving as the evidentiary mechanism proving the contradiction, not as the legal violation itself.
  4. Because reliance on a privacy policy in choosing to use a service (particularly a healthcare or mental health service) is a plausible theory of consumer reliance, and because damages can be framed around the value of the improperly disclosed data or the service fees paid, plaintiffs can plead both elements the ACFA requires.

This is precisely why the ACFA has proven durable where TUCSRA collapsed: it doesn’t ask a court to decide whether a pixel is a “communication service record.” It asks whether a company’s own words about its data practices were true.

AZ Privacy litigation contradictions

Case studies

Strong et al. v. LifeStance Health Group Inc. — $3.02 million settlement

Filed as Case No. 2:23-cv-00682 in the U.S. District Court for the District of Arizona, this class action targeted LifeStance Health Group, a mental health and psychiatric services provider with locations nationwide. Plaintiffs alleged that LifeStance’s website used tracking pixels that allowed third parties — specifically named as Google and Facebook — to collect and store sensitive patient information without consent, and pled both a federal HIPAA-adjacent theory and a violation of the Arizona Consumer Fraud Act.

  • Settlement amount: $3,027,874.44, split across two subclass funds ($1.2 million and $1.8 million).
  • Class period: March 1, 2020 through April 30, 2023.
  • Subclasses: Subclass 1 covers patients who booked at least one session through LifeStance’s online booking tool; Subclass 2 covers the remainder of LifeStance’s patient population during the class period.
  • Class counsel: Zimmerman Reed LLP and Almeida Law Group LLC.
  • Status: Final approval hearing scheduled for October 16, 2026; LifeStance has not admitted wrongdoing.

McCulley et al. v. Banner Health — consolidated multi-state action

Banner Health, a large nonprofit health system headquartered in Phoenix, faced multiple class actions over pixels embedded on its website and patient portal (formerly “MyBanner”) that allegedly transmitted protected health information to Meta and Google without consent. The cases were consolidated into a single action in the District Court for Weld County, Colorado, naming eight class representatives.

What makes this case especially useful as a national case study is how many statutes plaintiffs stacked into one complaint:

  • Breach of confidence
  • Electronic Communications Privacy Act (unauthorized interception, use, and disclosure)
  • Invasion of privacy — intrusion upon seclusion
  • Unjust enrichment
  • Arizona Consumer Fraud Act
  • California Invasion of Privacy Act (CIPA)
  • California Confidentiality of Medical Information Act (CMIA)
  • California Unfair Competition Law (UCL)
  • Colorado Consumer Protection Act
  • Class period: June 1, 2020 through November 22, 2023.
  • Preliminary approval: May 5, 2026.
  • Settlement structure: Attorneys’ fees and expenses up to $3,750,000, plus settlement administration costs and $2,500 service awards to each of the 8 class representatives.
  • Status: Banner Health denies any wrongdoing or liability.

Arizona v. Google — $85 million ACFA enforcement settlement

Not every ACFA data-privacy case involves pixels specifically, and this one is worth including because it shows the statute’s reach and establishes the state’s own enforcement posture. In 2022, then-Arizona Attorney General Mark Brnovich settled a lawsuit against Google for $85 million, alleging that Google’s location-tracking practices were “willfully deceptive and unfair” in violation of the ACFA. The AG’s office argued Google made it “exceedingly hard for users to understand what is going on with their location information,” and functionally impossible for users to meaningfully opt out despite Google’s public statements about user control over location history. The theory — a gap between what a company says about user control over data and what its systems actually allow — is structurally identical to the privacy-policy-contradiction theory now being used against pixels, just brought by the state rather than private class plaintiffs.

Why the ACFA succeeds where TUCSRA failed

This is the direct continuation of the lesson from our TUCSRA piece, and it’s worth stating explicitly: the outcome in each case tracks the elasticity of the statute’s operative language, not how old the law is or how large its damages figure looks on paper.

  TUCSRA ACFA
Core term “Communication service record,” “access logs” — carrier-specific “Deception,” “misrepresentation,” “concealment” — industry-neutral
Who’s regulated Communication service providers only Any person selling or advertising merchandise, goods, or services
What plaintiff must show The specific data collected fits a technical statutory definition A statement or omission was misleading and a consumer relied on it
Court’s flexibility to extend it Very limited — bound by carrier-specific statutory history Very broad — deception doctrine applies to virtually any representation
Outcome so far Rejected on appeal, Nov. 2025 Multiple settlements: LifeStance ($3.02M), Banner Health, Google ($85M)

In effect, plaintiffs’ firms in Arizona learned the same lesson defense counsel did: don’t fight a definitional battle over whether a pixel is a “record” when you can instead fight a much more favorable, fact-intensive battle over whether a company’s privacy policy told the truth.

The national pattern: “little FTC Acts” as the new wiretap co-counts

The ACFA is Arizona’s version of a “little FTC Act” — a state consumer protection statute modeled on the same “unfair or deceptive acts or practices” (UDAP) concept that underlies Section 5 of the federal FTC Act. Virtually every state has some version of this statute (California’s Unfair Competition Law, Colorado’s Consumer Protection Act, and dozens of others), and the same privacy-policy-contradiction theory that’s driving Arizona settlements is the direct state-law cousin of the FTC’s own enforcement theory in cases like its actions against GoodRx and BetterHelp, where the federal agency alleged that health and wellness platforms shared sensitive user data with advertising platforms in ways that contradicted their own privacy representations.

McCulley v. Banner Health is the clearest illustration of where this is heading nationally: rather than picking one theory, plaintiffs’ firms are now routinely stacking a wiretap-style claim (CIPA, ECPA), a records-based claim where available, a healthcare-specific claim (CMIA), and a UDAP-style consumer fraud claim (ACFA, Colorado’s CPA) into a single complaint spanning multiple states’ laws — regardless of which single state’s courthouse the case is actually filed in. A business’s tracking-technology exposure is no longer usefully analyzed one statute at a time; it has to be evaluated as a bundle.

Elements a plaintiff must plead under the ACFA

  1. A deceptive act, false statement, misrepresentation, or a material omission made with intent that the consumer rely on it — here, typically a privacy policy statement that doesn’t match actual data practices.
  2. Connection to the sale or advertisement of merchandise, services, or real estate — satisfied easily where the deceptive statement appears on a commercial website or in connection with signing up for a paid service.
  3. Consumer reliance — plaintiffs typically plead that they would have made different choices (declined to use the service, sought a different provider) had they known the true data practices.
  4. Damages — often framed around the value of the service paid for, the value of the improperly disclosed data, or the cost of remediation (credit monitoring, and similar).

Defenses businesses have available

  • Accurate, specific disclosure. A privacy policy that accurately and specifically discloses the use of analytics and advertising pixels — rather than a blanket “we don’t share your data” statement — substantially undercuts the core contradiction theory.
  • No reasonable reliance. Where a policy did disclose third-party tracking in reasonably conspicuous terms, defendants can argue no reasonable consumer could have relied on a contrary understanding.
  • One-year statute of limitations. Private ACFA claims must be brought within one year of when the claim accrued, which is considerably shorter than many other consumer-protection statutes and can bar older claims outright.
  • Lack of concrete damages. As in wiretap litigation, defendants often challenge whether plaintiffs can show actual, quantifiable harm rather than a bare statutory or theoretical injury.

Six-statute comparison: TUCSRA, ACFA, CIPA, WESCA, FSCA, and ECPA

  TUCSRA (AZ) ACFA (AZ) CIPA (CA) WESCA (PA) FSCA (FL) ECPA (Federal)
Enacted 2006 1967 1967 1978 1969 1986
Theory Unauthorized records procurement Deceptive/unfair practice Wiretap/pen register All-party wiretap All-party wiretap Wiretap, party exception
Pixel-litigation status Rejected on appeal (2025) Active, multiple settlements (2026) Large, mature wave (3,900+ cases) Rising post-Popa Rising, jury trial pending Nov. 2026 Usually paired with state claims
Key case Smith v. Target Strong v. LifeStance; McCulley v. Banner Health Numerous Popa v. Harriet Carter Gifts W.W. v. Orlando Health; Magenheim v. Nike Foundational statute

What businesses should do now

  1. Audit your privacy policy against your actual tag inventory. Every absolute statement (“we do not sell or share your information”) needs to be checked against every pixel, tag, and third-party script actually running on the site — not just the ones marketing remembers adding.
  2. Replace blanket non-sharing statements with accurate, specific disclosures naming the categories of third parties (advertising, analytics) that receive data, and for what purpose.
  3. Treat healthcare, mental health, and other sensitive-data websites as highest priority. Every settlement referenced in this piece involves a healthcare or mental-health provider — sensitivity of the underlying data drives both plausibility of harm and settlement value.
  4. Expect multi-statute complaints, not single-theory ones. Build compliance programs that address wiretap-style consent, records statutes, and deceptive-practices exposure together, since plaintiffs’ firms are already litigating them together.
  5. Re-audit after every privacy policy update. A policy that was accurate at launch can become misleading the moment a new pixel or vendor integration is added without a corresponding update.
  6. Document your consent-gating logic so that, if a pixel does fire, you can show it fired only after a user’s affirmative choice — not merely that a policy disclosing it existed somewhere on the page.

How Captain Compliance helps

The through-line across TUCSRA, ACFA, WESCA, FSCA, and CIPA is the same: the gap between what your privacy policy says and what your website actually does is where every one of these settlements originated. Captain Compliance continuously scans your site’s actual tag and pixel inventory, checks it against your stated disclosures, and keeps your privacy policy accurate as vendors and tracking technology change — backed by IAB TCF validator certification.

See how Captain Compliance audits your privacy policy against your actual tracking →

FAQs

What is the Arizona Consumer Fraud Act?

The ACFA (A.R.S. § 44-1521 et seq.) is a 1967 Arizona law prohibiting deception, misrepresentation, false pretenses, and material omissions in connection with the sale or advertisement of merchandise, services, or real estate. It includes a private right of action with a one-year statute of limitations, and allows the Arizona Attorney General to seek civil penalties up to $10,000 per willful violation.

How does the ACFA apply to website tracking pixels?

Plaintiffs argue that when a company’s privacy policy states it doesn’t share visitor data with third parties, but tracking pixels actually transmit that data to platforms like Meta or Google, the contradiction itself constitutes a deceptive act or practice under the ACFA — independent of any wiretap or records-statute theory.

What is the LifeStance Health Group settlement?

LifeStance Health Group agreed to a $3,027,874.44 class action settlement (Strong et al. v. LifeStance Health Group Inc., D. Ariz.) resolving claims that tracking pixels on its website transmitted patient data to Google and Meta without consent, in violation of HIPAA and the Arizona Consumer Fraud Act, covering a class period from March 1, 2020 through April 30, 2023.

Why did the ACFA succeed as a pixel litigation vehicle when TUCSRA failed?

TUCSRA’s key terms are narrowly defined around communication service providers and carrier records, which courts held did not reach marketing pixels. The ACFA’s core terms, deception and misrepresentation, are broad and industry-neutral, applying to any business’s statements about its practices, which is why courts and settling defendants have not needed to resolve a definitional dispute the way TUCSRA required.

Are ACFA pixel claims usually filed alone or combined with other laws?

Usually combined. Recent cases like McCulley v. Banner Health have stacked ACFA claims alongside the federal Electronic Communications Privacy Act, California’s Invasion of Privacy Act, California’s Confidentiality of Medical Information Act, California’s Unfair Competition Law, and Colorado’s Consumer Protection Act in a single multi-state complaint.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.