When plaintiff firms draft a California privacy complaint, the wiretapping counts get the headlines. CIPA Section 631 and 632.7 claims against session replay tools, chatbots, and tracking pixels dominate the docket volume. But buried a few counts down in a growing share of those complaints sits a statute that should worry defendants far more than any per-violation wiretap penalty: the Consumers Legal Remedies Act, California Civil Code Section 1750 and following.
The reason is simple economics. California’s other consumer protection workhorse, the Unfair Competition Law, limits plaintiffs to restitution and injunctive relief. The CLRA hands them actual damages, punitive damages, and mandatory attorney’s fees, plus a jury trial. When a privacy class action survives on a CLRA count, the settlement calculus changes completely. Defense counsel know it, plaintiff counsel know it, and the pleading patterns over the last several years reflect it: wherever a privacy plaintiff can identify a purchase transaction, a CLRA count follows.
What the CLRA Prohibits, and Why It Reaches Privacy Practices
The CLRA prohibits a list of roughly two dozen “unfair methods of competition and unfair or deceptive acts or practices” undertaken in a transaction intended to result, or that results, in the sale or lease of goods or services to a consumer. On its face it reads like a garden-variety false advertising statute. Nothing in the text mentions data, tracking, cookies, or security.
Privacy plaintiffs get there through the misrepresentation prongs. The provisions that appear most often in data privacy complaints include:
- Section 1770(a)(5) — representing that goods or services have characteristics, uses, or benefits they do not have. A privacy policy promising that data is “never sold” or “protected by industry-leading security” is a representation about the characteristics of the service.
- Section 1770(a)(7) — representing that goods or services are of a particular standard or quality when they are of another. Security-practice misrepresentations in data breach cases are routinely pled under this prong.
- Section 1770(a)(9) — advertising goods or services with intent not to sell them as advertised.
- Section 1770(a)(14) — representing that a transaction confers rights or obligations it does not, which plaintiffs invoke against consent flows and terms that misstate what users actually agreed to.
Critically, courts have long held that the CLRA reaches not just affirmative misstatements but material omissions where the defendant had a duty to disclose. In privacy litigation, that omission theory is often the sharper edge. In the Vizio smart TV litigation, plaintiffs did not need Vizio to have promised anywhere that its televisions would refrain from tracking viewing habits. The claim that survived was built on the omission: Vizio sold a physical product while failing to disclose that the product was continuously collecting and monetizing viewing data, a fact a reasonable consumer would consider material to the purchase.
That framing should get the attention of every company shipping connected hardware, and increasingly every company selling a paid app or subscription. The question is not only “did our privacy policy say anything false” but “did we fail to tell buyers something about our data practices that would have mattered to the purchase decision.”
The Remedies Gap: Why Plaintiffs Stack CLRA on Top of the UCL
Nearly every complaint that pleads a CLRA count also pleads the UCL, and the pairing is strategic rather than redundant. The UCL’s “unlawful” prong lets plaintiffs borrow violations of other statutes, and its standing requirements differ. But the UCL is an equitable statute. A prevailing UCL plaintiff gets restitution and an injunction. No compensatory damages. No punitive damages. No statutory fee entitlement.
The CLRA fills every one of those gaps:
- Actual damages, with a statutory floor of $1,000 in total damages for class actions.
- Punitive damages, which fundamentally change settlement leverage in cases involving allegedly knowing misrepresentations about data practices.
- Mandatory attorney’s fees to a prevailing plaintiff under Section 1780(e). This is not discretionary. It is one of the reasons plaintiff firms will fight hard to keep a CLRA count alive even when the wiretapping claims are the centerpiece of the complaint.
- An additional award of up to $5,000 for senior citizens or disabled persons in qualifying cases.
- A jury trial on the damages claims, which the equitable UCL does not provide.
The statute also contains an anti-waiver provision in Section 1751: any purported waiver of CLRA rights is void as contrary to public policy. Companies cannot draft their way out of the statute through terms of service, although arbitration clauses with class action waivers remain the principal structural defense and continue to be enforced under the Federal Arbitration Act.
The “Goods or Services” Battleground: Where Privacy CLRA Claims Live or Die
The CLRA’s biggest limitation, and the most heavily litigated issue in privacy cases, is its transactional scope. The statute only applies to transactions for the sale or lease of “goods or services.” Goods are defined as tangible chattels bought or leased for personal, family, or household purposes. Services means work, labor, and services for other than a commercial or business use. The California Supreme Court held in Fairbanks v. Superior Court that these definitions are to be applied as written, refusing to stretch “services” to cover life insurance, and that textualist approach governs how federal courts sitting in California analyze privacy claims today.
The case law has sorted into three rough categories:
Free services: CLRA claims usually fail
The foundational line of cases holds that users of free platforms are not “consumers” engaged in a covered transaction. In the early Facebook privacy litigation, the court dismissed CLRA claims because plaintiffs paid nothing for the service, and the theory that users “pay” with their personal data has repeatedly failed to satisfy the statute’s transactional requirement. Courts have continued to apply that logic to free apps, free browser features, and ad-supported platforms. More recently, the Ninth Circuit’s decision in Hammerling v. Google affirmed dismissal of CLRA claims premised on Google’s collection of third-party app activity data, reasoning that the plaintiffs had no qualifying purchase transaction with Google for the free services at issue.
Paid services: CLRA claims frequently survive
The analysis flips when money changes hands. In the Yahoo data breach litigation, the court allowed CLRA claims to proceed on behalf of users who paid for premium email services, while free-tier arguments faced the familiar obstacles. In Doe v. SuccessfulMatch.com, paying subscribers of a dating platform that allegedly shared sensitive profile information stated viable CLRA claims. The lesson for the current market is significant: as more consumer platforms shift from ad-supported to subscription models, they are simultaneously shifting themselves into CLRA territory. Every freemium conversion is also a standing conversion.
Hardware and connected products: the cleanest CLRA fit
A smart TV, a vehicle, a wearable, a smart speaker, a connected appliance — all are tangible chattels, and their sale is unambiguously a covered transaction. That is why the Vizio litigation is the template plaintiffs now follow for IoT privacy claims. When the data collection is embedded in a purchased physical product and was not adequately disclosed at the point of sale, the “goods” element is satisfied and the fight moves to materiality and reliance, which are far friendlier terrain for plaintiffs. Automakers facing claims over telematics data sharing, and consumer electronics companies facing claims over embedded tracking, should assume the CLRA applies to them.
The software gap
Standalone software occupies an unresolved middle ground. In the Adobe data breach litigation, the court held that software is not a tangible “good,” and courts have split on whether providing software amounts to a “service.” Plaintiffs respond by recharacterizing the transaction — framing a software purchase as a purchase of ongoing services, or pointing to bundled physical elements. Defendants litigating in this space should scrutinize exactly what was sold, because the characterization can be dispositive.
The 30-Day Notice Requirement: The Defense Opportunity Most Companies Waste
Before filing a CLRA claim for damages, a plaintiff must send the prospective defendant a notice letter by certified or registered mail at least 30 days before suit, identifying the alleged violations and demanding correction. Section 1782 then gives the defendant a genuine off-ramp: in a class context, if the company identifies the affected consumers, notifies them, and provides or agrees to provide the appropriate correction, repair, or replacement within that window, damages claims are barred.
Two practical realities follow. First, plaintiffs can and do file for injunctive relief immediately without notice, then amend to add damages after 30 days, so receiving a complaint without a damages prayer is not a reprieve — it is a countdown. Second, most companies treat the CLRA notice letter as routine pre-litigation noise routed to outside counsel for a form response. That is a mistake. The notice period is the single cheapest moment in the entire lifecycle of a CLRA privacy claim to change the outcome, and a substantive correction response — fixing the disclosure, remediating the practice, offering appropriate relief — can strip the damages engine out of the case before it is ever pled.
Defendants should also remember the venue affidavit requirement in Section 1780(d): plaintiffs must file an affidavit establishing proper venue, and failure to do so is grounds for dismissal. It is a technical point, but privacy complaints churned out at volume by serial filers sometimes miss it.
How CLRA Counts Fit the Modern Privacy Complaint
The contemporary California privacy complaint follows a recognizable stacking pattern. CIPA wiretapping and pen register claims target the tracking technology itself. UCL claims borrow statutory violations and sweep in “unfair” conduct. The CLRA count then attaches wherever a purchase exists, converting the case from an equitable dispute into a damages-and-fees case. Data breach complaints follow the same architecture, pairing negligence and contract theories with CLRA misrepresentation claims aimed at the company’s pre-breach security promises, as in the Sony PlayStation Network litigation, where representations about “reasonable security” became actionable when the network was compromised.
For defendants, the takeaway is that privacy compliance and advertising compliance have merged. Your privacy policy, your cookie banner, your product packaging, your checkout flow disclosures, and your marketing claims about security and data handling are all “representations” in the CLRA sense, and any purchased product or paid tier gives a plaintiff the transaction hook the statute requires.
A Seven-Step CLRA Exposure Audit for Privacy Teams
- Map every purchase transaction you offer. Physical products, paid subscriptions, premium tiers, in-app purchases, bundled hardware. Each one is a potential CLRA transaction. If you are migrating free users to paid plans, recognize that you are expanding your CLRA-eligible class with every conversion.
- Inventory your privacy representations. Pull every affirmative statement about data collection, sale, sharing, security, and retention from your privacy policy, cookie banner, product pages, packaging, onboarding screens, and ad copy. These are the statements a complaint will quote back at you.
- Reconcile representations against actual data flows. This is where most exposure lives. Run a technical scan of the trackers, pixels, SDKs, and server-side integrations actually firing on your properties and compare the results against what your disclosures claim. “We do not sell your data” paired with an unconfigured advertising pixel is a Section 1770(a)(5) claim waiting for a filing fee.
- Audit for material omissions, not just false statements. Ask the Vizio question: is there anything about our data practices that a reasonable buyer of this product would want to know before purchasing, that we have not disclosed at or before the point of sale? Connected product companies should answer this at the packaging and setup-flow level, not just in a linked policy.
- Kill the puffery-adjacent security claims. “Bank-level security,” “military-grade encryption,” and “your privacy is our top priority” read as marketing until a breach or a tracking revelation converts them into quality-and-standard misrepresentations. Every security claim should be specific, current, and provable, or removed.
- Build a CLRA notice-letter response protocol. Route Section 1782 letters to a defined owner with a mandate to evaluate substantive correction within the 30-day window, not just to acknowledge receipt. Pre-plan what a compliant correction offer would look like for your highest-probability claims.
- Institute continuous monitoring. Representations drift and tag managers change weekly. A disclosure that was accurate at your last annual review is not a defense to what your website was doing on the date a plaintiff’s forensic tool captured it. Continuous scanning of your actual tracking behavior against your published disclosures is the only way to keep the two aligned.
Frequently Asked Questions
What is the Consumers Legal Remedies Act?
The CLRA, California Civil Code Section 1750 et seq., is a consumer protection statute prohibiting a defined list of unfair and deceptive practices in transactions for the sale or lease of goods or services to consumers. In privacy litigation, it is used to attack misrepresentations and material omissions about data collection, data sharing, and security practices.
How is the CLRA different from the UCL in privacy cases?
The UCL provides only restitution and injunctive relief. The CLRA provides actual damages, punitive damages, mandatory attorney’s fees to a prevailing plaintiff, and a jury trial. Plaintiffs typically plead both, but the CLRA count is what transforms a privacy case into a damages case.
Can users of free websites and apps bring CLRA claims?
Generally no. Courts have consistently held that free services do not involve a qualifying sale of goods or services, and the theory that consumers “pay” with their personal data has not satisfied the statute’s transactional requirement. Paid subscriptions, premium tiers, and purchased hardware are a different story, and claims by paying customers regularly survive dismissal.
Does the CLRA apply to smart devices and connected products?
Yes. Physical products are tangible goods squarely within the statute, and the Vizio smart TV litigation established the template: undisclosed data collection embedded in a purchased device can support a CLRA omission claim even without any false statement.
What is the CLRA 30-day notice requirement?
Before seeking damages, a plaintiff must send a notice letter by certified or registered mail at least 30 days before suit, demanding correction of the alleged violations. A defendant that provides an appropriate correction or remedy within that window can bar class damages claims, making the notice period a critical and frequently underused defense opportunity.
How can companies reduce CLRA exposure from their privacy practices?
Reconcile every public representation about data and security against actual technical behavior, disclose material data practices at or before the point of sale for paid products, eliminate unprovable security claims, respond substantively to Section 1782 notice letters, and continuously monitor website and product tracking so disclosures never drift from reality.
Keep Your Representations and Your Reality in Sync
CLRA privacy claims are ultimately gap claims: the gap between what your privacy policy, cookie banner, and marketing say and what your website, app, and products actually do. Captain Compliance closes that gap. Our platform continuously scans your properties for the trackers, pixels, and data flows actually running, keeps your privacy policy dynamically aligned with real practices, manages consent through an IAB TCF-validated CMP, and gives you the audit trail to prove your disclosures matched your behavior on any given date. Before a Section 1782 letter shows up in your mailroom.