CDAFA Web Tracking Litigation Wave – How To Protect Your Business

Table of Contents

California’s web tracking litigation trend is rapidly shifting across the AI and legal tech space. Plaintiffs’ attorneys are increasingly moving away from explicit consumer privacy statutes toward older state laws originally targeting criminal computer trespass, wiretapping, and unfair trade practices—making CDAFA claims the new CIPA. Here is how these technical mechanics work, and how targeted data privacy software protects businesses from costly nuisance lawsuits
When plaintiffs’ firms file class actions over tracking pixels, Meta/Google ad scripts, and session replay software, they routinely layer multiple statutory claims over the same core technical event: the unauthorized execution of code that transmits user data to a third party.
A review of recent complaints highlights how plaintiffs build these claims, why the California Comprehensive Computer Data Access and Fraud Act (CDAFA) has become a focal point, and where state regulators like the Department of Financial Protection and Innovation (DFPI) enter the picture.

Schedule a 15-minute Demo with a Data Privacy Expert

CDAFA and the Threshold of “Without Permission”

Plaintiffs frequently bring claims under California Penal Code § 502, the California Comprehensive Computer Data Access and Fraud Act (CDAFA). Section 502(c)(7) penalizes anyone who knowingly accesses, or causes to be accessed, any computer, computer system, or computer network without permission.
In traditional cybersecurity contexts, CDAFA targets network intrusions or system breaches. In web-tracking litigation, plaintiffs reframe the statute’s language around code execution.
The mechanics depend on how tracking scripts operate:
  1. A user navigates to a webpage.
  2. The site’s HTML contains embedded third-party JavaScript (e.g., Meta Pixel, Google Tag Manager).
  3. The visitor’s browser automatically executes the script, reading local device data (IP addresses, device fingerprints, form field entries) and transmitting HTTP POST requests to third-party endpoints.

Unlike federal anti-hacking statutes like the Computer Fraud and Abuse Act (CFAA), which often require bypassing a technical barrier or “breaking in,” CDAFA § 502 merely requires showing that a party knowingly accessed a computer system and took, copied, or used data “without permission.”

Here is an example of what a data broker in the USA received as a CDAFA privacy lawsuit: 
Databroker CCCDAFA Privacy Suit Information

Plaintiffs argue that if a website loads tracking scripts that collect personal data before a visitor receives notice or grants affirmative consent, that execution constitutes taking data without permission under state law.
The defense against a CDAFA claim typically turns on two elements:
  • The nature of the data: Federal courts sitting in California have repeatedly thrown out CDAFA web-tracking claims where the collected data consists only of generic, unauthenticated browsing logs (such as clicking a public FAQ page). When the script captures sensitive data—medical intake entries, loan application progress, or account credentials—the claim becomes viable.
  • Prior authorization: If a site’s Consent Management Platform (CMP) holds third-party scripts back until the user clicks “Accept,” the “without permission” element collapses. If the scripts execute silently in the background upon initial page load, the defense loses its primary factual shield.

The Core Statutory Claims: CIPA, UCL, FAL, and Constitutional Privacy

Plaintiffs rarely file CDAFA claims in isolation. They build multi-pronged complaints designed to maximize statutory penalties across state law.

California Invasion of Privacy Act (CIPA) § 631

Originally drafted in 1967 to target wiretaps on landline telephones, CIPA § 631 penalizes anyone who intentionally taps or makes an unauthorized connection with any telegraph or telephone wire, or who attempts to read or learn the contents of a communication “in transit.”
In the web-tracking context, complaints allege that when a website embeds a third-party pixel, that pixel acts as a digital wiretap. The third-party vendor (such as Meta or a session replay provider) is framed as an unauthorized eavesdropper intercepting consumer communications as they travel between the user’s browser and the host server.

Unfair Competition Law (UCL) & False Advertising Law (FAL)

California Business and Professions Code § 17200 (UCL) and § 17500 (FAL) provide statutory penalties of up to $2,500 per violation.
In tracking lawsuits, these claims are anchored directly to the website’s written privacy policy. Complaints regularly quote standard corporate language promising “appropriate, reasonable, and industry-standard security practices” or claiming that “we respect your privacy and do not share your data without consent.”
Plaintiffs allege that these statements are affirmative misrepresentations under the FAL and fraudulent business practices under the UCL. The core theory is that a reasonable consumer reads those assurances and forms a reasonable expectation of privacy. When undisclosed tracking pixels silently exfiltrate user interactions to third-party ad networks in spite of those promises, the discrepancy creates both statutory false advertising and an invasion of the constitutional right to privacy under Article I, Section 1 of the California Constitution.

Regulatory Oversight: The DFPI and Privacy Compliance

Beyond civil class actions, regulatory agencies in California have expanded their scrutiny of digital data handling, specifically within financial services.
The California Department of Financial Protection and Innovation (DFPI)—which regulates state-chartered banks, credit unions, money transmitters, lending platforms, and fintechs—operates under the California Financial Consumer Protection Law (CFCPL). Under California Financial Code § 90003, the DFPI holds broad statutory authority to target “unlawful, unfair, deceptive, or abusive acts or practices” (UADAP) committed by covered financial entities.
While general consumer privacy enforcement is led by the California Privacy Protection Agency (CPPA) and the California Attorney General, the DFPI evaluates data collection through the lens of financial consumer harm:
  • Fintech Data Leakage: When fintech platforms or consumer lenders integrate ad-tech tracking pixels on loan application pages or account portals, unencrypted financial indicators (such as credit application progress, pre-approval status, or debt figures) can bleed out to third-party marketing networks.
  • Deceptive Disclosures as UADAP Violations: If a financial institution licensed by the DFPI assures borrowers that their personal and financial information remains confidential, but quietly permits third-party scripts to harvest user behavioral data for targeted advertising, the DFPI can deem those deceptive omissions a direct violation of state financial protection laws.
  • Enforcement Ramifications: Unlike private litigation that relies on court judgments and class settlements, the DFPI has administrative power to issue cease-and-desist orders, suspend operating licenses, and impose administrative penalties directly against non-compliant entities.

Technical Defensibility

For companies operating websites accessible in California, defending against this statutory framework requires aligning marketing technology setups with explicit legal disclosures:
  1. Client-Side Auto-Blocking: Ensuring that third-party scripts, tracking pixels, and session replay tools do not execute at the code level until a user provides affirmative opt-in consent.
  2. Data-Layer Segmentation: Stripping all analytics tags and ad pixels from sensitive user journeys, such as health intake forms, login screens, and financial application pages.
  3. Auditable Consent Logs: Maintaining cryptographically verified logs showing that script execution occurred strictly after receiving a positive consent signal from the user.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.