Arizona’s Telephone, Utility and Communication Service Records Act (TUCSRA): The Complete Guide to the “Spy Pixel” Litigation Wave

Table of Contents

The TUCSRA which we detail below is not a threat but the Arizona Consumer Fraud Act (ACFA) is and there was just a multi-million dollar banner health settlement with LifeStance that we covered around this new threat. 

For about eighteen months, a 2007 Arizona records-privacy statute nobody outside telecom compliance had ever heard of became the basis for at least 20 class action lawsuits against retailers, filed not just in Arizona but as far away as Washington and New York. Then, on November 11, 2025, the Arizona Court of Appeals shut the theory down — unanimously, and about as thoroughly as an appellate court can. That makes Arizona’s Telephone, Utility and Communication Service Records Act (TUCSRA) a genuinely useful case study: a real-time example of how a CIPA-style litigation wave gets built, tested, and in this instance, dismantled by the actual statutory text but this may not stop pro-se plaintiffs from sending out demand letters alleging violations and attempting to take TUCSRA cases to arbitration. If you’ve received an Arizona demand letter over a privacy violation reach out to the Captain Compliance team for a free privacy audit to understand your risks.  

This guide covers exactly what TUCSRA says, every significant case filed under it that we can identify, how the Arizona Court of Appeals reasoned its way to dismissal in Smith v. Target Corp., and — because no privacy litigation trend exists in isolation — how TUCSRA’s trajectory compares to Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA), Florida’s Security of Communications Act (FSCA), California’s Invasion of Privacy Act (CIPA), and the federal Electronic Communications Privacy Act (ECPA) that sits underneath all of them.

At a glance

  • TUCSRA (A.R.S. § 44-1376 et seq.) was enacted in 2006 and amended in 2007, modeled on the federal Telephone Records and Privacy Protection Act of 2006 — both were written to stop “pretexting”: fraudulently posing as a customer to obtain that customer’s phone or account records from a carrier.
  • Starting around 2023–2024, plaintiffs’ firms began arguing that email marketing “spy pixels” — the tiny embedded trackers that report when an email is opened — create a “communication service record” or “access log” under TUCSRA, and filed at least 20 class actions on that theory within about 18 months.
  • TUCSRA carries a private right of action and economic damages of at least $1,000 per violation, the same statutory-damages structure that makes CIPA, WESCA, and FSCA attractive to plaintiffs’ firms.
  • At least five courts rejected the pixel theory, culminating in the Arizona Court of Appeals’ November 11, 2025 decision in Smith v. Target Corp., which held that an email marketer is not the kind of entity TUCSRA regulates and that a tracking pixel is not a “communication service record.”
  • That outcome puts Arizona on a different trajectory than Pennsylvania and Florida, where nearly identical “old wiretap statute meets modern tracking tech” theories have had far more success surviving motions to dismiss.

What TUCSRA actually says

TUCSRA, codified at A.R.S. § 44-1376 et seq., grew out of two earlier Arizona statutes enacted in 2000 and 2006, all aimed at the same underlying problem: “pretexting,” where someone impersonates a customer to fraudulently extract that customer’s phone, utility, or account records from the company that actually provides the service. The core prohibition, at A.R.S. § 44-1376.01(A)(1), bars a person from knowingly procuring, attempting to procure, soliciting, or conspiring to procure an Arizona resident’s “telephone record” or “communication service record”:

  • Without the authorization of the person to whom the record pertains, or
  • By fraudulent, deceptive, or false means.

The statute separately prohibits knowingly selling or attempting to sell such a record without consent. Critically, the definitions section, A.R.S. § 44-1376(1), defines “communication service record” broadly on its face:

"Communication service record" includes subscriber information, including
name, billing or installation address, length of service, payment method,
telephone number, electronic account identification and associated screen
names, toll bills or access logs, records of the path of an electronic
communication between the point of origin and the point of delivery, and
the nature of the communication service provided, such as caller
identification, automatic number identification, voice mail, electronic
mail, paging or other service features.

TUCSRA includes a private right of action, allowing individual consumers — not just the Arizona Attorney General — to sue for violations, with economic damages of at least $1,000 per violation. That combination (a broad-sounding definition, plus a private right of action, plus per-violation statutory damages) is exactly the profile that made CIPA and WESCA attractive to the plaintiffs’ bar, and it’s exactly why TUCSRA became the next target once those other theories had been thoroughly tested.

The theory: are email tracking pixels a “communication service record”?

Email tracking pixels (sometimes called “spy pixels” in these complaints) are tiny, typically invisible 1×1 images embedded in marketing emails. When a recipient opens the email, the pixel loads from a remote server, which lets the sender know the email was opened, when, how many times, from what kind of device or email client, and sometimes whether it was forwarded or printed.

Plaintiffs’ theory was straightforward on its face: if a spy pixel logs “when a recipient accessed the email,” doesn’t that create an “access log” — a term that appears directly in TUCSRA’s definition of “communication service record”? If so, argued plaintiffs, a retailer sending marketing emails with embedded pixels is “procuring” a communication service record without the recipient’s authorization, triggering statutory damages for every email sent to every class member.

TUCSRA Pixel Litigation Timeline

Case timeline: how the TUCSRA wave rose and fell

  1. 2023–early 2024: The first handful of spy-pixel cases appear in Arizona, some pleading TUCSRA alone and others pleading TUCSRA alongside CIPA, borrowing directly from the playbook already running in California.
  2. Home Depot, Inc. v. Validity, Inc. class action: Home Depot and email-deliverability vendor Validity are sued in a putative class action alleging TUCSRA violations tied to embedded email trackers — one of the earlier, higher-profile filings that helped establish the template other firms would copy.
  3. Mid-to-late 2024: The pace accelerates. By the time defense firms start tracking the trend systematically, plaintiffs have filed at least 20 TUCSRA cases in roughly 18 months — not confined to Arizona courts, but also filed in Washington and New York on behalf of Arizona-resident class members.
  4. Carbajal v. Home Depot U.S.A., Inc., No. CV-24-00730-PHX-DGC (D. Ariz. Dec. 16, 2024): The U.S. District Court for the District of Arizona dismisses a TUCSRA pixel claim, reasoning that “sending marketing emails and collecting information about how recipients interact with them” is not the conduct TUCSRA was written to reach. This decision becomes the analytical template later adopted at the appellate level.
  5. Pacific Sunwear (PacSun) decision: The District of Arizona dismisses a similar claim against PacSun over its email tracking pixels, becoming one of several federal decisions holding TUCSRA doesn’t reach email marketers — part of what defense counsel describe as a “handful of recent decisions” solidifying the trend.
  6. Smith v. Target Corp., filed May 7, 2024: Kiloh Smith files a class action (removed to federal court under the Class Action Fairness Act, then proceeding on the TUCSRA claim) alleging Target embedded spy pixels in marketing emails to track when he opened, and whether he forwarded, those emails. The case is later dismissed with prejudice at the superior court level.
  7. Smith appeals; Arizona Court of Appeals, Division One affirms — November 11, 2025: In a published opinion, the court holds that TUCSRA’s “communication service record” definition, read in context, refers to records held by an actual communication service provider (a carrier) about its subscribers — not marketing engagement metrics collected by a retailer about its email recipients. The court explicitly rejects the argument that a pixel’s “access log” of email opens qualifies under the statute.

Inside the Smith v. Target decision

The Arizona Court of Appeals’ reasoning is worth walking through in detail, because it’s the clearest statement yet of why TUCSRA doesn’t reach this fact pattern — and it’s a useful lens for evaluating whether similar “old law, new technology” theories will succeed elsewhere.

  1. Statutory history and purpose. The court traced TUCSRA back through its 2000 and 2006 predecessor statutes and found all three were “clearly intended to regulate ‘public utility records, telephone records, communication service records’ controlled by service providers that send or receive oral, wire, or electronic communications or computer services” — in other words, carriers and utilities, not retailers sending marketing emails.
  2. Who the statute regulates. The court held that an email sender like Target “is not the kind of person or entity that TUCSRA seeks to regulate.” The statute is aimed at communication service providers themselves (or those who fraudulently extract records from them) — not at any business that happens to send email and track engagement.
  3. What “access logs” actually means. This is the crux of the ruling. The court held the term “access logs,” read in its statutory context, refers to “records of when a subscriber accesses the communication services” provided by their carrier — not, in the court’s words, “marketing metrics collected by retailers about email engagement.” Reading “access logs” as broadly as plaintiffs proposed would stretch the term well beyond what the surrounding statutory language supports.
  4. The specific data points pleaded didn’t fit the definition. The court walked through the categories of data actually collected by the pixel — email access logs, associated email addresses, email client types, email path data, recipient locations, IP addresses, forwarding data, and device information — and held that none of it qualifies as “access logs” or “records of the path of an electronic communication between the point of origin and the point of delivery” as those terms are used in the statute.
  5. No need to reach standing. Because the claim failed on the merits (failure to state a claim under Rule 12(b)(6)), the court didn’t need to separately resolve whether Smith had Article III standing — though standing challenges had been a live issue in several of the underlying trial-court dismissals.

Other defenses raised across the broader wave of TUCSRA cases — not all reached in every decision — included lack of personal jurisdiction over out-of-state defendants, lack of Article III standing on the theory that email-open tracking doesn’t constitute the kind of concrete injury required for federal court, and preemption by the federal CAN-SPAM Act, which separately regulates commercial email.

Is TUCSRA litigation actually over?

Defense-side commentary following Smith v. Target has been fairly direct: this “should subside” the wave, since it’s now a published, precedential appellate decision that Arizona trial courts are bound to follow, and multiple federal district court decisions had already reached the same conclusion independently. That said, a few caveats are worth naming plainly:

  • A losing party can petition the Arizona Supreme Court for review, so the decision isn’t necessarily the final word procedurally, even if it’s unlikely to be disturbed given the consistency with prior federal rulings.
  • The ruling addresses the specific “spy pixel in marketing email” fact pattern. It doesn’t foreclose every conceivable TUCSRA theory — a case involving an actual communication service provider’s records, closer to the statute’s original pretexting purpose, would be evaluated differently.
  • Plaintiffs’ firms that built TUCSRA practices didn’t necessarily fold entirely — some of the same firms are active in parallel CIPA, WESCA, and FSCA litigation, and may simply reallocate effort toward jurisdictions where the theory is faring better.

How Arizona compares to Pennsylvania’s WESCA

Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA), enacted in 1978, prohibits the intentional interception, disclosure, or use of any wire, electronic, or oral communication without the consent of all parties — Pennsylvania is one of roughly a dozen all-party consent states. Unlike TUCSRA, which failed because its specific definitions didn’t stretch to cover marketing pixels, WESCA has succeeded in reaching website tracking precisely because its core prohibition — “interception” — is a more elastic, less specifically-defined term.

The pivotal decision is Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022), in which the Third Circuit held two things that plaintiffs now rely on throughout Pennsylvania litigation:

  • No blanket “direct party” exception. The court rejected the idea that a marketing vendor receiving a visitor’s browsing data directly is automatically exempt from WESCA merely because it’s a party to the communication, not an outside eavesdropper.
  • Interception occurs at the browser. The court held that interception happens where the signal originates — the visitor’s browser in Pennsylvania — not at an out-of-state vendor’s servers, keeping the conduct within Pennsylvania’s statutory reach regardless of where the receiving company is based.

Since Popa, WESCA cases have proceeded well past the pleading stage more often than not. A 2026 decision allowed a case to proceed on the theory that the Meta Pixel qualifies as an intercepting “device” under WESCA, and that the statute’s primary provision doesn’t even require pleading interception of communication “contents.” Dozens of class actions have been filed over session replay software, chat tools, and tracking pixels since 2022. That said, defendants have found some success too: one Pennsylvania federal court granted summary judgment where the defendant had posted a clearly labeled privacy disclosure at the bottom of the relevant webpage, finding implied consent as a matter of law — and courts have dismissed cases for lack of Article III standing where the tracked data (like “searches for drink flavors”) wasn’t sufficiently sensitive to establish real injury.

WESCA’s civil remedies allow recovery of actual damages or liquidated damages of $100 per day or $1,000 per violation (whichever is higher), plus punitive damages and attorney’s fees.

How Arizona compares to Florida’s FSCA

Florida’s Security of Communications Act (FSCA), Fla. Stat. Ch. 934, was passed in 1969, modeled on Title III of the federal Omnibus Crime Control and Safe Streets Act of 1968, and amended materially in 1988 and 2002. Like WESCA, it’s an all-party consent statute — Fla. Stat. § 934.03 generally makes it unlawful to intercept a wire, oral, or electronic communication unless every party has consented.

For years, FSCA was rarely applied to websites. That changed with W.W. v. Orlando Health, Inc., No. 6:24-cv-1068-JSS-RMU (M.D. Fla. Mar. 6, 2025), where a federal court let most claims proceed against a hospital system accused of using chatbots and tracking pixels that captured and shared patient communications with third parties without consent. The court found the alleged data collection could plausibly involve the “contents” of communications — not merely metadata — which matters because FSCA’s core protection is specifically for communication contents. The case itself never reached a merits verdict; the parties jointly dismissed it in February 2026. But the ruling on the motion to dismiss remains influential and has been cited in subsequent Florida decisions, giving plaintiffs a roadmap even without a final judgment.

Within 90 days of that ruling, plaintiffs’ firms reportedly sent hundreds of new demand letters, and litigation spread from healthcare targets to general consumer-facing websites. Magenheim v. Nike, filed in the Southern District of Florida, is scheduled for trial on November 2, 2026 — the first major FSCA pixel case expected to reach a jury, and a case widely watched as a bellwether: a plaintiff verdict would likely accelerate the Florida wave nationally, while a defense win or settlement could dampen it.

FSCA civil remedies under Fla. Stat. § 934.10 provide statutory damages of $1,000 per violation or $100 per day of violation, whichever is greater, plus actual damages, attorney’s fees, and potential punitive damages. Two defenses have shown some traction: the “contents” argument (trackers capturing only clicks and page views, not message content, may fall outside the statute — though Orlando Health narrowed this for pixels that transmit form inputs or search queries), and a 1988 statutory carve-out excluding devices that track “movement of a person or object,” which some courts have stretched to cover pure session-replay tools. Neither is a guaranteed win post-Orlando Health.

How Arizona compares to California’s CIPA

California’s Invasion of Privacy Act remains the largest and most mature of these litigation waves, with more than 3,900 cases filed statewide and settlements reaching into the millions of dollars — including a roughly $10 million settlement over website tracking technology nearly identical to what Arizona courts have now rejected under TUCSRA. CIPA is a one-party-consent-adjacent statute in the traditional wiretap sense but has been stretched by plaintiffs to reach “pen register” and “trap and trace” theories (Section 638.51) targeting pixels and IP-address collection, alongside more traditional wiretap theories (Sections 631 and 632). Unlike TUCSRA’s narrow, carrier-specific definitions, CIPA’s broader “interception” and “pen register” language has proven far more elastic in the hands of plaintiffs’ counsel — which is precisely why California’s wave hasn’t collapsed the way Arizona’s did.

The federal baseline: ECPA

Every one of these state statutes sits on top of, or alongside, the federal Electronic Communications Privacy Act (ECPA), which itself comprises the Wiretap Act (18 U.S.C. § 2510 et seq.) and the Stored Communications Act (18 U.S.C. § 2701 et seq.). ECPA generally prohibits the intentional interception of wire, oral, or electronic communications, but critically includes a party exception: it’s generally not unlawful for a party to the communication itself to intercept it, or to consent to someone else doing so — a much more permissive baseline than the all-party consent regimes in Pennsylvania, Florida, and (in a different statutory form) California.

This is exactly why plaintiffs’ firms have gravitated toward state statutes rather than ECPA claims alone: a website operator is typically a “party” to its own visitor’s communications, which would exempt it under federal law’s party exception. State all-party consent statutes without an equivalent broad party exception (like WESCA, per Popa) close that gap — which is also why the “contemporaneous interception” doctrine (whether data was captured in real time, during transmission, versus accessed later from storage) keeps surfacing as a contested issue across CIPA, WESCA, and FSCA cases alike. Courts applying that doctrine have reached inconsistent results even within the same state, which is a large part of why this area of law remains, as one commentator put it, “contested, inconsistent, and changing state by state.”

Comparison table: five statutes, one litigation pattern

  TUCSRA (AZ) WESCA (PA) FSCA (FL) CIPA (CA) ECPA (Federal)
Enacted 2006 (amended 2007) 1978 1969 (amended 1988, 2002) 1967 1986 (amending 1968 Wiretap Act)
Consent model N/A — records/pretexting statute All-party All-party Effectively all-party via pen register theory Party exception applies (one party’s consent generally suffices)
Statutory damages $1,000+ per violation Greater of $100/day or $1,000/violation Greater of $100/day or $1,000/violation Up to $5,000 per violation Actual or statutory damages, varies by provision
Pixel-litigation status Rejected by courts; appellate loss for plaintiffs (Nov. 2025) Mixed, trending plaintiff-favorable post-Popa Mixed, trending plaintiff-favorable post-Orlando Health; jury trial pending Nov. 2026 Large-scale, ongoing, most mature wave (3,900+ cases) Rarely pled alone; usually paired with a state claim
Key case Smith v. Target Corp. (Ariz. Ct. App. 2025) Popa v. Harriet Carter Gifts (3d Cir. 2022) W.W. v. Orlando Health (M.D. Fla. 2025); Magenheim v. Nike (trial Nov. 2026) Numerous; various pen register and wiretap rulings N/A — foundational statute

Arizona Wiretapping Lawsuits vs Other States

Why Arizona diverged: a lesson in statutory specificity

The single biggest reason TUCSRA collapsed while WESCA and FSCA are thriving comes down to how narrowly each statute’s key terms are drafted and how courts have chosen to read them. TUCSRA’s operative terms — “communication service record,” “access logs,” “communication service provider” — are specific, technical, telecom-industry terms tied by context to carriers and utilities. When the Arizona Court of Appeals looked at the statute’s history and structure, there was very little room to read those terms as reaching a retailer’s marketing email metrics.

WESCA and FSCA, by contrast, use a much more general operative term — “interception” — that isn’t tied to any particular industry or type of entity. That generality is precisely what let the Third Circuit in Popa and the district court in Orlando Health extend the statutes to website tracking technology that Pennsylvania’s and Florida’s legislatures plainly never contemplated in 1978 and 1969, respectively. The lesson for anyone tracking this space: a statute’s litigation potential against modern tracking technology depends far more on how abstractly its core prohibition is worded than on how old the statute is or how large its damages figure looks on paper.

What businesses should do now

  1. Don’t assume TUCSRA exposure is zero everywhere. Smith v. Target resolves the specific “email pixel as access log” theory. A business with an actual communication-service-provider relationship to Arizona residents should still evaluate TUCSRA on its original pretexting terms.
  2. Treat Pennsylvania and Florida as active, not theoretical, risk. If your site serves Pennsylvania or Florida visitors and runs third-party pixels, session replay, or chat widgets, the current judicial trend in both states favors plaintiffs surviving the pleading stage — meaning discovery costs and settlement pressure regardless of ultimate merits.
  3. Watch Magenheim v. Nike. Its November 2, 2026 trial date makes it the most important near-term data point for Florida litigation risk; a plaintiff verdict would likely accelerate filings against any consumer-facing website with common ad-tech tools.
  4. Audit for the “contents” distinction. Pixels or session-replay tools that capture form inputs, search queries, or other substantive user-entered content face meaningfully higher exposure under FSCA and similar statutes than tools capturing only clicks and page views.
  5. Post clear, conspicuous tracking disclosures — not just a buried privacy policy link. Implied-consent defenses have succeeded in Pennsylvania specifically where disclosure was clearly labeled and visible on the page.
  6. Gate non-essential pixels behind actual consent rather than relying on a statute’s specific definitional gaps to hold up in every jurisdiction — Arizona’s outcome was a product of that state’s unusually narrow statutory language, not a guarantee that the same tracking technology is safe elsewhere.

How Captain Compliance helps

The pattern across TUCSRA, WESCA, FSCA, and CIPA is the same: a business’s own vendor-added pixel or chat widget becomes the fact pattern in a lawsuit the business never saw coming. Captain Compliance continuously scans your site for every tracking technology actually firing — not just the ones your team remembers adding — and keeps consent gating and disclosures current across every state’s shifting legal landscape, backed by IAB TCF validator certification.

See how Captain Compliance audits your site’s tracking exposure →

FAQs

What is the Arizona Telephone, Utility and Communication Service Records Act?

TUCSRA (A.R.S. § 44-1376 et seq.) is a 2006 Arizona law, amended in 2007, that prohibits fraudulently or without authorization procuring or selling a person’s telephone, utility, or communication service records. It was written to stop “pretexting” — impersonating a customer to obtain their records from a carrier — and includes a private right of action with damages of at least $1,000 per violation.

Do email tracking pixels violate TUCSRA?

Based on the Arizona Court of Appeals’ November 2025 decision in Smith v. Target Corp., no — the court held that an email marketer is not the type of entity TUCSRA regulates and that data collected by a tracking pixel, including when an email was opened, does not qualify as a “communication service record” or “access log” under the statute.

Is TUCSRA pixel litigation completely finished?

The specific “email pixel as access log” theory has been rejected by at least five courts and one appellate decision, which strongly suggests the wave will subside. A petition for review to the Arizona Supreme Court remains procedurally possible, and TUCSRA’s original pretexting application (against or by actual communication service providers) is unaffected by this ruling.

How is Florida’s FSCA different from Arizona’s TUCSRA?

FSCA is a general wiretapping statute prohibiting “interception” of communications without all-party consent — a broad, industry-neutral term that courts have extended to website tracking technology. TUCSRA’s key terms are narrowly defined around communication service providers and carrier records, which is why Arizona courts found the statute didn’t reach email marketing pixels while Florida courts have allowed similar tracking-technology claims to proceed under FSCA.

What is the federal ECPA, and how does it relate to these state laws?

The Electronic Communications Privacy Act (ECPA) is the federal wiretapping and stored-communications law that generally prohibits intercepting communications, but includes a party exception allowing a party to the communication (such as a website operator) to consent to interception. Because that exception often shields website operators under federal law, plaintiffs’ firms have relied primarily on state all-party-consent statutes like WESCA, FSCA, and CIPA, which don’t offer the same broad exception.


Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.