IAPP 2026 Privacy Litigation Report: U.S. Privacy Lawsuits Surge

Table of Contents

The number of privacy lawsuits being filed in the United States is accelerating, plaintiffs are finding new ways to apply decades-old statutes to modern tracking technologies, and the line between privacy compliance and litigation defense is becoming increasingly difficult to separate.

That is the larger message emerging from the International Association of Privacy Professionals’ newly released U.S. Data Privacy Litigation Report 2026.

Published August 17, the IAPP report examines eight major areas of U.S. privacy litigation: breach of contract and warranty claims, the California Invasion of Privacy Act, the federal Wiretap Act, the Video Privacy Protection Act, the California Consumer Privacy Act’s private right of action, biometric and consumer health data laws, New Jersey’s Daniel’s Law and shareholder litigation arising from privacy incidents.

Taken together, these are not eight isolated legal problems.

They show a fundamental change in privacy risk.

Privacy Litigation Is Surging: How the IAPP’s 2026 U.S. Data Privacy Litigation Report Correlates With What Captain Compliance Has Been Warning About

Companies are increasingly being sued not simply because regulators believe they violated a privacy statute, but because plaintiffs can examine what happened technically, compare it with what the company promised publicly, identify a statute carrying a private right of action or common-law remedy, and attempt to convert that discrepancy into individual or class-wide damages.

Number of data privacy dockets filed
in state and federal courts

The numbers explain why this matters.

IAPP reports that private settlements in the data privacy arena have exceeded $2.5 billion over the past three years, while acknowledging the actual figure could be substantially higher. The largest 50 settlements across five privacy and security categories totaled approximately $1.59 billion in 2025, following $2.93 billion in 2024 and $2.187 billion in 2023.

Settlement totals may have fallen from their 2024 peak, but litigation itself is moving in the opposite direction.

Westlaw Edge Litigation Analytics data cited by IAPP shows 1,799 privacy cases filed in 2022, 2,420 in 2023, 2,565 in 2024 and 3,414 in 2025.

That represents almost a 90% increase in annual case volume in only three years.

The IAPP expects the upward trajectory to continue through 2026.

For businesses, that may be the most important statistic in the entire report.

Privacy litigation is no longer an edge-case risk reserved for companies that experience catastrophic data breaches. The litigation theories now extend to cookie banners, analytics software, session replay, Meta Pixel, web forms, chat tools, video viewing, biometric technologies, location information, customer databases, security configurations and even statements contained in privacy policies.

The new privacy question is no longer simply whether an organization has a privacy program.

It is whether that privacy program will survive contact with a plaintiff’s lawyer.

Privacy Law Is Becoming “Living Law”

One of IAPP’s most useful observations is that U.S. privacy law is developing through litigation itself.

Unlike a regulatory framework where businesses can read one statute and one set of implementing regulations, privacy litigation is producing fragmented decisions across federal district courts, state courts and appellate courts.

Those decisions do not all carry the same precedential weight. Nor do they always agree with one another.

The report warns that many of the cases it analyzes never reached final judgment. They instead ended through settlements, dismissals or summary judgment. Nevertheless, those decisions are shaping which allegations survive, which defenses succeed and what companies must be prepared to prove.

This is particularly important for businesses using modern digital technology.

A company can deploy the exact same tracking technology on the exact same website and encounter materially different litigation risk depending upon what data it transmits, when the transmission occurs, the jurisdiction, how its disclosures are written, whether the user consented beforehand and what the vendor receiving the information is permitted to do with it.

That is why static privacy compliance is becoming increasingly inadequate.

Your Privacy Policy Can Become Evidence Against You

The report begins with something deceptively simple: breach of contract.

Privacy professionals tend to think of privacy policies primarily as compliance disclosures. Plaintiffs increasingly treat them as potential promises.

A company that tells customers it will keep information confidential, restrict third-party sharing or employ particular security practices may later face an argument that those representations created an express or implied contractual obligation.

The IAPP highlights cases where employers collecting personal information as a condition of employment were alleged to have entered an implied contract to protect that information.

It also discusses BetterHelp litigation in which plaintiffs successfully identified privacy assurances that allegedly promised customer information would remain confidential despite purported disclosures to advertising and other third parties.

This changes how organizations should think about privacy-policy drafting.

The goal cannot simply be to make the policy sound reassuring.

Every statement should be evaluated against actual technical behavior.

A company promising that it does not “share” certain information while its website transmits that information through third-party code may have created more than a regulatory disclosure problem. Depending on the circumstances, it may have created evidence for a contract claim.

The opposite can also be true.

Carefully drafted terms, limitations of liability, arbitration provisions and sufficiently conspicuous disclosures have helped defendants defeat or limit privacy lawsuits.

IAPP’s review repeatedly demonstrates that the wording, placement and presentation of digital agreements matter.

The distinction between browsewrap and clickwrap remains particularly important. Clickwrap requires affirmative assent. Browsewrap attempts to infer agreement from continued website use and consequently demands much greater conspicuousness.

The report points to the Federal Trade Commission’s familiar “4Ps” — prominence, presentation, placement and proximity — as useful factors for analyzing whether disclosures are sufficiently conspicuous.

This produces an important operational lesson.

Privacy lawyers should not draft policies in isolation from product, engineering and marketing teams.

The policy describes the system.

The website implements the system.

Litigation tests whether those two versions of reality match.

CIPA Has Become Ground Zero for Website Privacy Litigation

Nowhere is the collision between old statutes and new technology more obvious than under the California Invasion of Privacy Act.

CIPA was enacted in 1967 during an era dominated by concerns about telephone wiretapping and electronic eavesdropping.

Today, plaintiffs are applying it to session-replay technologies, advertising pixels, analytics tools, web forms, chat software and other website technologies.

IAPP calls out Sections 631, 632, 632.7 and 638.51 as areas generating modern privacy litigation.

Section 631(a) has become particularly important.

The litigation increasingly centers around whether a third party has intercepted or attempted to read the contents of an electronic communication while the communication is in transit and without the necessary consent.

Each part of that sentence can become its own lawsuit.

Was there consent?

Was the vendor actually a third party?

Was it merely providing technology on behalf of the website?

Did it have the ability to use the information for itself?

Was the information “content,” or merely routing and record information?

Did the vendor actually read or learn the communication?

Was it intercepted while in transit or only processed after reaching its intended destination?

The answers are highly technical.

Consent Before Collection Is Becoming Critical

Javier v. Assurance IQ remains foundational to the modern CIPA litigation landscape.

There, the Ninth Circuit concluded that prior consent matters when website communications are allegedly intercepted by a third party.

The sequencing is critical.

A disclosure presented after a technology has already activated may be too late.

The IAPP report discusses this distinction extensively, including the fact that consent to a website’s own collection does not necessarily transfer to an undisclosed third-party tracker operating before the consumer sees or accepts the privacy terms.

Similarly, Rodriguez v. Autotrader.com illustrates why the mere existence of a banner does not automatically resolve litigation. Whether the banner was sufficiently conspicuous and whether it sufficiently described the processing can itself become a factual dispute unsuitable for resolution at the earliest pleading stage.

That difference has enormous implications for consent-management architecture.

A banner that appears while third-party trackers have already fired may provide substantially less protection than a consent system technically preventing the relevant technologies from activating until the required choice has been obtained.

In other words, consent cannot merely be displayed.

It has to control execution.

The “Tape Recorder Versus Friend” Test Shows Why Vendor Contracts Matter

One of the stranger analogies in modern digital privacy law comes from old California eavesdropping cases.

Courts attempting to determine whether a software provider is an independent third-party eavesdropper sometimes ask whether it resembles a tape recorder or a friend secretly listening to the conversation.

A tape recorder merely records information for the communicating party.

A friend can hear the communication and potentially use the information for their own purposes.

Modern courts have adapted that distinction to software providers.

Some have found that vendors merely storing information on behalf of their customers are analogous to tape recorders and therefore are not independent eavesdroppers.

Others have focused on whether the vendor has the capability to access or use the information for its own purposes.

IAPP highlights cases involving ActiveProspect, advertising companies, AI voice technology and website chat systems where the vendor’s independent capabilities became significant to the analysis.

This means vendor contracts and technical permissions can affect litigation exposure.

A processor prohibited from independently using customer information and technically restricted from doing so presents a different factual record than a provider that can use collected information to improve its own products, refine algorithms, create profiles or monetize data.

Vendor governance is therefore becoming part of CIPA defense.

What Is “Content” on a Website?

Another major CIPA dispute concerns the difference between the contents of a communication and record information.

IAPP uses the analogy of a physical letter.

The words written inside the letter are its contents.

The destination and routing information written on the envelope are record information.

The internet makes that distinction considerably more complicated.

Some courts have treated information entered into forms, substantive search queries, hotel reservation information and URLs revealing highly specific health interests as content.

Other courts have concluded that timestamps, browser types, device information, geolocation, IP addresses and similar metadata do not necessarily constitute contents.

Context can transform the analysis.

An email address existing simply as routing information can look very different from an email address deliberately typed into a form as part of a substantive communication.

Likewise, a URL identifying a generic homepage may be less revealing than a URL indicating that someone accessed an anorexia self-assessment or a specific medical-treatment page.

The report’s cases demonstrate why simply producing a list of cookies is not enough for sophisticated privacy analysis.

Businesses increasingly need to understand exactly what values are being transmitted through each technology.

Timing Matters: Was the Communication Actually Intercepted?

Section 631 litigation also depends heavily on sequence.

An alleged eavesdropper generally must acquire the relevant communication while it is in transit.

Receiving information after it reaches its intended destination can produce a different result.

IAPP reviews cases reaching opposite conclusions based on these technical details.

Real-time event listeners capturing user inputs before they reach the webpage can support an interception theory.

Information processed by a tracking vendor only after reaching the intended website may not.

Session-replay information reconstructed later on a vendor’s servers presents yet another scenario.

The distinction can turn on milliseconds of technical behavior, but legally those milliseconds matter.

This is one of the reasons forensic website scanning has become important.

A privacy policy alone cannot establish transmission sequence.

Network behavior can.

The Pen Register Fight Is Moving Even Faster Than the IAPP Report

Section 638.51 represents one of the fastest-developing areas covered by IAPP.

The statute regulates unauthorized use of pen registers and trap-and-trace devices.

Plaintiffs have increasingly argued that modern website tracking software can fit those definitions because the statute refers to a “device or process” capturing routing, addressing or signaling information.

The report describes sharply conflicting trial-level decisions.

Some courts have rejected the proposition that ordinary internet-connected technologies collecting IP addresses become pen registers.

Others have allowed allegations involving modern tracking software or device fingerprinting to continue.

At the time IAPP completed the report, it specifically identified Variety Media v. Superior Court as the pending California appellate proceeding that might provide definitive guidance.

And almost immediately after publication, that landscape moved again.

On August 21, the California Court of Appeal issued a tentative ruling in Variety Media. The court tentatively rejected the argument that CIPA’s pen-register definition is limited solely to telephone communications, potentially allowing Section 638.51 to reach internet communications.

But it also tentatively concluded that the plaintiff’s existing complaint failed because the visitor’s IP address identifies the source of the communication, while a pen register concerns destination-identifying information. Oral argument occurred August 25, and as of August 26 the appellate docket still lists the matter as pending rather than completed.

That development could hardly illustrate IAPP’s “living law” concept more clearly.

The report was published August 17.

Four days later, one of the major unresolved CIPA questions discussed in the report received a tentative appellate answer.

And other federal cases are already waiting for the final Variety decision before proceeding with their own Section 638.51 disputes.

Privacy compliance cannot be a once-a-year exercise in that environment.

The Federal Wiretap Act Creates Similar Risks — But Different Defenses

The federal Wiretap Act presents another example of an older surveillance statute being applied to modern data technologies.

The law prohibits intentional interception of wire, oral or electronic communications, but it differs from CIPA in several important ways.

The Ninth Circuit has interpreted interception narrowly, generally requiring acquisition while the communication is in transmission rather than after it enters electronic storage.

Additionally, the federal statute operates under a one-party consent framework.

That can be enormously important.

If one party to the communication consents, liability may be defeated.

The IAPP report describes cases where websites’ disclosures and cookie notices were sufficient to establish consent and others where generalized disclosures failed because they did not adequately reveal the processing at issue.

The key lesson is that specificity matters, but perfect granularity is not necessarily required.

The statute also contains a party exemption.

An intended participant in the communication generally cannot be directly liable for intercepting its own communication.

But that seemingly straightforward defense leads directly into one of the most unsettled questions in federal tracking litigation: the crime-tort exception.

The Crime-Tort Exception Is Producing a Major Court Split

The Wiretap Act’s party and consent protections may disappear when a communication is intercepted for the purpose of committing a criminal or tortious act.

Courts agree on some principles.

The unlawful purpose generally must exist at the time of interception.

And the separate crime or tort generally must be distinct from the interception itself.

Beyond that, agreement breaks down.

One major dispute concerns commercial purpose.

Some courts have reasoned that a company using tracking technology for advertising, analytics or another legitimate commercial purpose did not intercept communications for the purpose of committing a tort, even if the resulting conduct ultimately violated another law.

Other courts reject that logic.

One court summarized the problem with the defense through a bank-robbery analogy: saying the purpose was financial gain does not necessarily mean the conduct was not also criminal.

The result is a genuine judicial split over whether commercial motivation can protect conduct that otherwise results in a crime or tort.

For companies, that uncertainty reinforces the value of minimizing unnecessary processing.

The broader the collection and the more independent purposes attached to the data, the harder it may become to characterize the activity as merely necessary technical processing.

The VPPA Has Escaped the Video Store

The Video Privacy Protection Act may be the clearest example of a statute being pulled dramatically beyond the technological environment Congress originally envisioned.

Congress enacted the VPPA after Judge Robert Bork’s video-rental history was published during his 1987 Supreme Court confirmation battle.

It was written for a world of video cassette tapes.

Today, plaintiffs are using it against websites, streaming services, education platforms and businesses that embed video alongside technologies such as Meta Pixel.

The financial stakes are substantial because the VPPA provides statutory damages of at least $2,500 per violation, along with potential punitive damages, attorneys’ fees and equitable relief.

Three questions dominate modern VPPA litigation:

Who qualifies as a video tape service provider?

Who qualifies as a consumer?

What qualifies as personally identifiable information revealing someone’s video viewing?

Courts do not consistently agree.

You Do Not Have to Be Netflix to Face VPPA Risk

One mistake businesses can make is assuming the VPPA only applies to streaming companies.

The case law reviewed by IAPP is considerably broader.

Courts have rejected VPPA claims against movie theaters whose primary business is showing films in physical theaters rather than delivering audiovisual materials online.

But courts have found potential video tape service providers in less obvious circumstances.

LinkedIn faced claims involving videos on LinkedIn Learning.

Hillsdale College faced litigation involving videos used in education, marketing and fundraising.

An online asset marketplace offering a large library of prerecorded videos was also treated as potentially within scope.

IAPP’s analysis suggests that video delivery does not necessarily need to be the company’s primary business.

That matters for publishers, healthcare providers, educational organizations, retailers, nonprofits and other businesses that increasingly use substantial video libraries as part of their digital operations.

The Supreme Court Is Poised to Address Who Counts as a VPPA Consumer

The definition of “consumer” has produced a particularly significant circuit split.

Some courts have taken a narrow approach, requiring the plaintiff’s subscription, rental or purchase relationship to relate specifically to video or audiovisual products.

Others have taken a broader approach.

Under that interpretation, someone may qualify as a consumer if they subscribe to another product or service from an entity that also qualifies as a video provider.

Money is not necessarily required.

Providing an email address, personal information or some other valuable consideration in exchange for an account or access can potentially create the necessary subscription relationship.

IAPP notes that the Supreme Court is expected to address the issue in Salazar v. Paramount Global during its October 2026 term.

That decision could materially expand or contract a substantial category of pixel-related privacy litigation.

VPPA Consent Is Its Own Standard

Companies also cannot assume that generic cookie consent automatically satisfies the VPPA.

The statute requires informed written consent that is distinct and separate from other legal or financial obligations.

Consent can last no more than two years, and the consumer must receive a clear and conspicuous way to withdraw from the disclosures.

In Lakes v. Ubisoft, IAPP notes that a cookie preference interface allowing users to individually permit or decline categories of cookies helped support the defendant’s consent argument.

By contrast, generalized descriptions of advertising and user activity were considered inadequate in another case.

The takeaway is that VPPA compliance may require more careful consent architecture than simply placing references to “cookies and partners” somewhere inside a lengthy privacy policy.

The CCPA Private Right of Action May Be Expanding Beyond Traditional Breaches

The California Consumer Privacy Act presents a different problem.

Unlike most comprehensive state privacy statutes, the CCPA contains a limited private right of action.

Traditionally, that right has been understood to concern security breaches involving specified categories of unencrypted or unredacted personal information.

Several courts have reinforced that limitation.

But the IAPP report identifies an emerging line of cases testing whether Section 1798.150 can also reach unauthorized disclosure through website tracking.

In Shah v. Capital One, for example, the court allowed a claim involving alleged collection, use and sale of personal information through website trackers to proceed despite the absence of a conventional hacker-driven data breach.

Other cases involving analytics code and allegedly exposed health information have followed similar reasoning.

IAPP identifies this as an extremely important development to watch because it could broaden the circumstances capable of generating CCPA private litigation.

That should matter to any business that has historically treated its CCPA private-action exposure exclusively as a cybersecurity problem.

“Reasonable Security” Is Becoming a Litigation Standard

When traditional breach claims do arise, plaintiffs must generally connect the incident to a failure to implement and maintain reasonable security procedures appropriate to the information.

What constitutes reasonable security remains fact-dependent.

IAPP identifies cases involving failures to encrypt information, employ multifactor authentication, maintain adequate email filtering, train employees, patch systems, monitor suspicious behavior or delete information that was no longer needed.

At the same time, courts have rejected bare allegations that security was inadequate simply because a breach occurred.

This means companies increasingly need evidence of their controls rather than a generalized assertion that their security was reasonable.

The CCPA settlements discussed in the report reinforce the point.

The first CCPA class settlement involving Hanna Andersson included not merely monetary compensation but commitments to risk assessments, multifactor authentication and additional technical staffing.

The California Pizza Kitchen settlement also included remedial security measures and multifactor authentication.

The T-Mobile settlement was on a different scale: a $350 million settlement fund plus a commitment to spend at least $150 million beyond its existing budget on data security and related technology.

Privacy litigation therefore increasingly changes corporate systems, not merely corporate bank balances.

Biometrics Remain One of the Highest-Risk Privacy Categories

Illinois’ Biometric Information Privacy Act remains one of the most consequential privacy statutes with a private right of action.

BIPA regulates the collection, retention, disclosure, protection and destruction of biometric identifiers and biometric information.

It requires written notice concerning collection and purpose, disclosure of retention periods and a written release from the individual.

It also restricts disclosures and prohibits companies from selling, leasing, trading or otherwise profiting from biometric information.

The stakes are substantial: negligent violations can carry $1,000 in liquidated damages and intentional or reckless violations can carry $5,000, along with attorneys’ fees and injunctive relief.

Illinois has since limited the potentially enormous per-scan exposure that resulted from earlier interpretations of BIPA.

Following Cothron v. White Castle, the legislature amended the law so repeated collections of the same biometric information no longer necessarily create a new statutory claim every time. The Seventh Circuit subsequently held that the amendment applies retroactively.

But BIPA remains formidable.

The report discusses a $92 million TikTok settlement, a $100 million Google settlement involving face templates, Meta’s $650 million facial-recognition settlement, the BNSF fingerprint litigation that initially produced a $228 million award before ultimately moving toward a $75 million settlement, and Clearview AI’s unusual settlement providing the class with a 23% stake in the business.

That history explains why biometric technologies require privacy review before deployment rather than after litigation begins.

AI Is Entering the Biometric Litigation Picture

One particularly important BIPA case discussed by IAPP involved AI-based facial scanning.

Plaintiffs in Melzer v. Johnson & Johnson alleged that technology designed to analyze facial geometry in connection with skin-health products collected biometric information without proper consent.

The company argued that a healthcare exemption applied.

The court rejected dismissal on that basis, reasoning that the experience lacked involvement by a medical professional and looked more like marketing than healthcare treatment.

The case illustrates a broader AI-governance problem.

Labeling technology “health,” “wellness” or “AI-powered” does not determine which privacy rules apply.

What matters is what the system actually does.

If software scans a face, records a voice, infers health information, creates a template or converts physical characteristics into an identifier, organizations need to analyze the data processing itself.

AI governance and privacy governance increasingly overlap.

Washington’s My Health My Data Act Opens Another Frontier

The report also examines Washington’s My Health My Data Act.

Unlike HIPAA, which is tied largely to covered healthcare entities and their business associates, Washington’s law can regulate consumer health information in a much broader range of commercial settings.

IAPP notes that private plaintiffs face a meaningful hurdle because they must establish actual damages and actual injury connected to the alleged data sharing.

Nevertheless, litigation has begun.

The report identifies a February 2025 class action against Amazon as the first MHMDA class action, centered on allegations that location information collected through an SDK embedded in third-party applications could reveal sensitive health information.

This represents another important trend.

Privacy statutes increasingly protect information because of what can be inferred from it, not merely because the field itself is labeled “health data.”

Location near a treatment center may reveal health information.

A search query may reveal health information.

A URL may reveal health information.

Browsing behavior may reveal health information.

Privacy programs built only around obvious database fields such as “diagnosis” or “medical record” can therefore miss substantial risk.

Daniel’s Law Demonstrates How a Narrow Privacy Law Can Create Mass Litigation

One of the less widely discussed sections of the IAPP report may be one of its most instructive.

New Jersey’s Daniel’s Law protects judges, prosecutors, law-enforcement officers and certain family members by allowing them to demand removal of home addresses and unpublished phone numbers.

A 2023 amendment allowed covered individuals to assign their claims to third parties.

That change helped produce hundreds of lawsuits against data brokers, real estate websites, consumer reporting services, enterprise software companies and other businesses.

IAPP reports that Atlas Data Privacy Corporation had become the assignee of nearly 20,000 covered individuals by May 2024.

The statute carries $1,000 in liquidated damages per violation.

This should sound familiar to businesses that have watched other privacy statutes evolve into high-volume demand-letter and litigation ecosystems.

A seemingly narrow statute can produce substantial commercial exposure when it combines:

a private enforcement mechanism,

statutory or liquidated damages,

large numbers of potential claimants,

assignable claims,

and information that can be tested at scale.

Daniel’s Law also contains an unforgiving operational requirement: covered information generally must be removed within 10 days following a proper request.

IAPP consequently recommends data mapping, clear internal ownership, vendor management, data-disposal procedures and retention of evidence showing compliance with takedown requests.

Those controls are strikingly similar to those required for modern DSAR programs.

Privacy Failures Are Becoming Board-Level Litigation

The final section of the IAPP report expands privacy exposure beyond consumers entirely.

Shareholders can also sue.

Privacy incidents can reduce market capitalization, generate regulatory penalties, create remediation expenses, damage brands and expose companies to other litigation.

That gives investors a basis to argue that directors and executives failed to perform their fiduciary obligations or misled the market about privacy and cybersecurity risks.

IAPP discusses the Equifax breach as an example of a shareholder action resulting in corporate governance reforms, enhanced cybersecurity, stricter board oversight and leadership changes.

It also points to litigation arising from Facebook and Cambridge Analytica, which resulted in a $190 million settlement and governance changes involving privacy, whistleblower protections and compliance.

The report then discusses Alphabet litigation arising from the Google+ API incident. After the Ninth Circuit revived claims concerning allegedly misleading public statements, the case ultimately settled for $350 million.

The significance goes beyond those dollar figures.

Privacy is becoming a corporate governance obligation.

A chief privacy officer’s inability to explain a data flow may eventually become a board problem.

A board’s inability to demonstrate oversight may eventually become a securities problem.

And a company’s inaccurate public description of a known privacy issue may become substantially more expensive than the original technical problem.

The Common Thread Across the Entire IAPP Report

At first glance, CIPA, BIPA, the VPPA, Daniel’s Law and shareholder derivative litigation have very little in common.

Read together, they have a great deal in common.

The disputes repeatedly return to the same operational questions.

What information was collected?

Why was it collected?

What technology collected it?

When did that technology activate?

Where did the information go?

Was a third party involved?

Could that third party use the information independently?

Was the information sensitive?

What did the consumer see before collection occurred?

What did the consumer agree to?

Can the company prove that consent?

Did the technical system honor rejection or withdrawal?

How long was the information retained?

Was old information deleted?

Were reasonable security controls actually implemented?

Did the company’s public disclosures accurately describe those practices?

Can the company reconstruct what happened when challenged months or years later?

Those are not simply legal questions.

They are technical and operational questions.

And that may be the most significant takeaway from the IAPP’s 2026 report.

A Privacy Policy Is No Longer a Privacy Program

For years, many organizations treated privacy largely as a documentation exercise.

Draft the privacy policy.

Add a cookie banner.

Insert provisions into vendor contracts.

Maintain a data processing addendum.

Respond to consumer requests.

Those things remain important.

But the litigation described throughout IAPP’s report demonstrates why they are no longer sufficient.

A privacy policy cannot prevent an advertising pixel from firing before consent.

A data processing agreement cannot prove what a vendor actually received.

A cookie banner cannot protect a company if “Reject” is recorded but the relevant technologies continue transmitting information.

A vendor questionnaire cannot establish whether that vendor independently uses collected information.

A breach response plan cannot establish that reasonable security existed before the attack.

And a statement saying data was deleted is not the same thing as evidence showing deletion actually occurred.

Privacy compliance is becoming execution plus evidence.

Businesses Need to Start Thinking Like Future Defendants

That does not mean every company should operate under constant fear of litigation.

It means privacy programs should be designed so that the organization can answer predictable questions before a plaintiff asks them.

A defensible program should provide visibility into website technologies, data flows, consent states, third-party processing, sensitive information, consumer requests, assessments, retention practices and security controls.

It should also preserve evidence.

Consent logs matter.

Configuration histories matter.

Scan results matter.

Vendor agreements matter.

Data maps matter.

Privacy assessments matter.

Records showing remediation matter.

Documentation showing why a technology was necessary can matter.

The ability to establish that a tracker was blocked until consent may matter enormously.

This is particularly important because so many privacy cases are decided at the pleading and early discovery stages.

The organization that can quickly determine what actually happened is in a fundamentally different position from one that needs engineers, lawyers and vendors to reconstruct a website configuration from two years earlier.

Continuous Monitoring Is Becoming More Important Than Annual Compliance

The IAPP report also exposes a fundamental weakness in point-in-time privacy assessments.

Digital environments change constantly.

Marketing installs new tags.

Developers release new code.

Vendors update SDKs.

Pixels change behavior.

Consent configurations are modified.

New campaigns launch.

AI tools gain access to additional data.

Customer-support platforms integrate with new systems.

A privacy review conducted six months earlier may accurately describe a website that no longer exists.

That is why continuous monitoring is becoming increasingly important.

The question is no longer merely:

“What trackers did we approve?”

It is:

“What is operating right now?”

For companies facing litigation under laws like CIPA, VPPA or state consumer-health statutes, that distinction can determine whether the organization discovers a problem itself or learns about it in a demand letter.

Privacy Litigation Is Becoming Its Own Form of Enforcement

Regulators remain central to American privacy law.

But IAPP’s report demonstrates that they no longer have a monopoly on enforcement.

Private plaintiffs are increasingly functioning as a parallel enforcement mechanism.

Sometimes the legislature explicitly created that mechanism, as with BIPA.

Sometimes plaintiffs rely on a limited statutory private right, as under the CCPA.

Sometimes an old wiretapping statute is repurposed for modern website technologies, as with CIPA.

Sometimes a video-rental law becomes a pixel lawsuit.

Sometimes a privacy promise becomes a breach-of-contract action.

Sometimes public officials assign removal claims to another company.

Sometimes shareholders sue corporate leadership after the privacy incident is already over.

Different legal theories lead to the same result:

Privacy failures can create private financial exposure even when no regulator has taken action.

That changes how organizations should calculate privacy risk.

What the IAPP Report Means for Privacy Teams in 2026

The 2026 U.S. Data Privacy Litigation Report should not be read merely as a case-law reference guide.

It is a warning about where privacy risk is moving.

The growth from 1,799 privacy cases in 2022 to 3,414 in 2025 is occurring while businesses are deploying more tracking technology, more third-party integrations, more AI systems and more data-driven personalization than ever before.

At the same time, plaintiffs are becoming more sophisticated about the technical facts underlying those systems.

The next generation of privacy disputes will increasingly be fought over network requests, JavaScript execution, consent sequencing, SDK behavior, vendor permissions, device identifiers, URL parameters, AI inference, authentication records and data retention.

Legal departments therefore need technical visibility.

Engineering teams need privacy requirements they can actually implement.

Marketing teams need controls around the tools they deploy.

Security teams need to understand that data minimization can reduce privacy liability as well as breach severity.

Boards need visibility into material privacy risk.

And companies need documentation showing that their privacy controls did what they were supposed to do.

From Compliance to Defensibility

The distinction between being compliant and being defensible is becoming increasingly important.

Compliance asks whether an organization has implemented the required policies and controls.

Defensibility asks whether the organization can prove it.

A company may believe its cookie banner blocks tracking.

Can it demonstrate that?

A company may believe a vendor acts only as a service provider.

Does the contract say so, and does the technical implementation support it?

A company may believe users consented.

Can it produce the consent record and show which technologies were permitted at that moment?

A company may believe it practices data minimization.

Can it identify what information each technology collects and explain why it is necessary?

A company may believe it deleted data.

Can it demonstrate when and where deletion occurred?

Those questions are increasingly what stand between an allegation and a defensible response.

Where Captain Compliance Fits Into the Litigation Era of Privacy

The litigation landscape documented by IAPP reinforces why modern privacy technology must do more than generate policies.

Captain Compliance is built around the operational side of these risks: identifying tracking technologies, continuously monitoring websites, detecting cookies and pixels, controlling technologies based on consent, maintaining consent evidence, mapping privacy risks and helping organizations understand what their websites are actually transmitting.

For businesses concerned about CIPA, ECPA, VPPA, state privacy laws and the growing wave of website-tracking claims, visibility is the starting point.

You cannot block a tracker you do not know exists.

You cannot accurately disclose a data flow you have never identified.

You cannot prove consent if you did not retain the record.

And you cannot remediate a privacy risk that no one is monitoring.

The objective is not to promise that litigation will disappear.

It is to make the organization substantially harder to successfully target.

The Privacy Litigation Era Has Arrived

The IAPP’s 2026 U.S. Data Privacy Litigation Report captures a U.S. privacy environment undergoing a significant transformation.

Private privacy litigation is at an all-time high.

Old statutes are being applied to new technologies.

New statutes are creating new private rights.

Courts are disagreeing about fundamental definitions.

Tracking technologies are becoming evidence.

Consent implementation is becoming a defense.

Security failures are becoming CCPA claims.

Biometric technologies are producing multimillion-dollar exposure.

Consumer-health data is generating an emerging class of litigation.

Narrow state laws can create mass-claim ecosystems.

And privacy failures can ultimately reach corporate directors and shareholders.

There is no single statute that businesses can comply with to eliminate this risk.

The more durable strategy is to build a privacy program around visibility, minimization, consent, control, documentation and continuous monitoring.

Because the direction identified by IAPP is difficult to ignore.

Privacy litigation is not slowing down.

It is becoming more technical, more creative and more deeply embedded in how American privacy law is actually enforced.

And in that environment, the organizations in the strongest position will not simply be those that can say they take privacy seriously.

They will be the ones that can prove what actually happened.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.