NFL Privacy Lawsuit Alleges Tracking Continued After Users Opted Out

Table of Contents

A newly filed privacy lawsuit against NFL Enterprises alleges that hundreds of tracking technologies operated on NFL.com before visitors made a privacy choice—and continued operating after visitors attempted to opt out.

The proposed class action is notable not simply because it targets one of the largest sports organizations in the world. It raises a more consequential question for every company using the company that the NFL is using as their consent management platform especially after regulators said this week they are targeting broken cookie banners on websites as one of the low hanging fruits:

Does the website actually enforce the privacy choice presented by its cookie banner?

NFL.com currently uses privacy infrastructure associated with a privacy software company called OneTrust, one of the largest privacy software providers in the market. The NFL’s consumer privacy request portals are hosted through OneTrust, and its website consent experience appears to use OneTrust technology.

That does not mean in any way that OneTrust has been found responsible for the conduct alleged in the lawsuit. OneTrust is not named as a defendant in this case but is named as one in another one filed by prolific privacy attorney Scott Ferrel of Pacific Trial Attorneys, the claims are directed against NFL Enterprises, and a consent platform’s effectiveness depends heavily on how the website owner configures its tags, categories, blocking rules and integrations.

But the allegations expose an uncomfortable reality for companies relying on OneTrust and other consent management platforms: displaying a recognizable privacy banner does not establish that tracking has been stopped, preferences have been honored or consent has been properly enforced. The old saying of nobody gets fired for hiring IBM is going right out the window in the privacy world.

What Does the NFL Privacy Lawsuit Allege?

The case, Kimmons v. NFL Enterprises LLC, was filed in Alameda County Superior Court on July 6, 2026. The plaintiff is a California resident who alleges that she visited NFL.com to view football scores, schedules and related content.

According to the complaint and published reporting, forensic testing allegedly identified 182 third-party trackers operating before a visitor had an opportunity to interact with NFL.com’s privacy controls.

The complaint alleges that the pre-choice activity included:

  • Twenty-four cookies
  • Four canvas fingerprinting scripts
  • A session-recording technology
  • Advertising and analytics requests
  • Device and browser identification
  • Real-time transmission of browsing activity to third parties

The plaintiff further alleges that selecting the website’s opt-out option did not stop the tracking environment.

According to the forensic results cited in the complaint, 186 trackers were allegedly detected after the visitor opted out, including 25 cookies, the same four canvas fingerprinting scripts and the same session-recording tool.

These remain allegations. NFL Enterprises has not been found liable, and the tracker counts, technical methodology and legal characterization may be disputed as the case proceeds.

NFL.com Uses OneTrust Privacy Infrastructure

The NFL currently uses OneTrust-hosted portals for consumer privacy requests, including its United States fan privacy choices portal and its portal for authorized agents.

The privacy and consent experience associated with NFL.com also appears to use OneTrust technology. OneTrust is one of the most widely deployed consent management platforms and markets tools for website scanning, cookie classification, consent banners, preference centers, automated blocking and consent records.

The NFL lawsuit does not name OneTrust as a defendant and does not establish that the OneTrust platform itself caused the alleged conduct.

That distinction matters.

A consent management platform supplies the controls used to collect and communicate a visitor’s preference. The website operator generally remains responsible for configuring the platform, categorizing technologies, integrating the CMP with the tag manager and ensuring that scripts respond correctly to consent signals.

OneTrust can provide the banner while the website’s underlying implementation determines whether a particular pixel, script or tracker is actually blocked.

This case therefore should not be reduced to whether NFL.com had a OneTrust banner. The more important question is whether NFL’s OneTrust implementation allegedly controlled the technologies operating behind it.

This Lawsuit Makes it Clear That A OneTrust Cookie Banner Is Not Automatic Protection

Many enterprises treat the purchase and deployment of privacy software solutions like OneTrust as evidence that website consent has been addressed.

That assumption can create substantial risk.

A company can display a OneTrust banner and still experience technical failures involving:

  • Advertising pixels firing before consent
  • Tags that are missing the correct consent category
  • Scripts deployed outside the CMP’s blocking logic
  • Google Tag Manager triggers that ignore consent status
  • Session replay tools classified as strictly necessary
  • Fingerprinting technologies that do not rely on cookies
  • Previously loaded scripts continuing after an opt-out
  • Regional rules that apply the wrong consent model
  • New tags added after the original implementation
  • Global Privacy Control signals that are recorded but not enforced

The banner is the visible interface. Compliance depends on the less visible infrastructure operating underneath it.

Even a properly configured consent banner cannot control a technology that the organization has not identified, categorized or connected to its consent framework.

The NFL Lawsuit Is About More Than Cookies

The lawsuit also illustrates why the phrase “cookie compliance” no longer captures the full scope of website tracking risk.

The complaint reportedly identifies canvas fingerprinting and session-recording technology in addition to conventional browser cookies.

Canvas fingerprinting can use characteristics of a visitor’s browser, graphics environment and device to generate an identifier. Unlike an ordinary cookie, the technique may not require storing a traditional tracking file in the visitor’s browser.

The session-recording technology identified in the complaint allegedly captured interactions such as:

  • Mouse movements
  • Clicks
  • Scrolling behavior
  • Navigation paths
  • Search-field keystrokes
  • Other interactions with NFL.com

A consent implementation focused only on deleting or blocking cookies may therefore leave other technologies untouched.

This distinction is particularly important when a website tells visitors they have opted out of tracking, targeted advertising or the sale or sharing of personal information. A visitor is unlikely to understand that the opt-out may affect cookies while leaving fingerprinting scripts, server-side tracking or session-recording technology active.

Which Privacy Laws Does the NFL Lawsuit Invoke?

The plaintiff asserts claims under several federal and California laws, including:

  • The California Invasion of Privacy Act
  • The federal Electronic Communications Privacy Act
  • The California Computer Data Access and Fraud Act
  • The California Constitution’s right to privacy
  • The California Unfair Competition Law

The California Invasion of Privacy Act, commonly called CIPA, has become one of the most frequently invoked statutes in website tracking litigation.

Plaintiffs have attempted to apply the law’s wiretapping, pen-register and trap-and-trace provisions to advertising pixels, analytics tools, chat software, session replay products and other common website technologies.

Courts continue to evaluate how statutes written for older communications systems apply to modern websites. The legal theories remain contested, and outcomes often depend on the specific technology, the information transmitted, the role of the third-party vendor and the timing of the alleged interception.

The Opt-Out Allegations Create the Greatest Compliance Concern

The most consequential allegation is not simply that trackers operated before the plaintiff interacted with the banner.

It is that more trackers allegedly operated after the plaintiff opted out.

A website may have different legal bases for operating certain technologies before a visitor makes a selection. Strictly necessary technologies, security controls, load-balancing tools and basic functionality may not always require the same form of consent as advertising or behavioral tracking.

But when a website expressly offers an opt-out, the resulting preference must be translated into technical action.

The system should determine:

  • Which technologies are covered by the visitor’s choice
  • Which tags must be prevented from firing
  • Which previously stored identifiers should be removed
  • Which vendors must receive the updated signal
  • Whether server-side data transmission must stop
  • Whether the preference applies across pages, domains and sessions

Saving an opt-out value in the consent platform is not enough when the website continues behaving as though the visitor consented.

Why OneTrust Implementations Can Fall Out of Alignment

Enterprise websites rarely remain technically static.

Marketing teams add campaign pixels. Advertising agencies publish tags through Google Tag Manager. Product teams introduce analytics platforms. Developers embed video players. Fraud teams deploy device-identification tools. Vendors update their scripts and endpoints.

Each change can alter the website’s tracking environment without changing the visible OneTrust banner.

A company may initially launch a well-configured consent program and gradually lose control as:

  • New tags are added without privacy review
  • Existing tags are assigned to the wrong category
  • Scripts are hard-coded outside the tag manager
  • Regional geolocation rules are changed
  • Vendor code is updated
  • Pages are migrated to a new platform
  • Consent Mode settings are modified
  • Additional domains or subdomains are launched

The result is configuration drift: the consent program documented by the privacy team no longer matches the website experienced by the visitor.

Consent Management Requires More Than a Banner

A defensible consent program requires several technical components to work together.

Website Scanning

The organization must identify cookies, pixels, scripts, beacons, fingerprinting methods, session replay tools, embedded content and third-party network requests across the website.

A scan should replicate the visitor experience from relevant jurisdictions and evaluate behavior both before and after a consent selection.

Accurate Classification

Each technology must be placed into the correct category based on what it actually does—not simply the category recommended by a vendor or listed in a generic cookie database.

A marketing or behavioral analytics technology should not be labeled strictly necessary merely because blocking it creates an inconvenience for the business.

Prior Blocking

Where affirmative consent is required, non-essential technologies should remain blocked until the visitor has made the necessary selection.

The consent interface should not appear after advertising pixels have already collected and transmitted the visitor’s information.

Opt-Out Enforcement

When a visitor rejects tracking or opts out of sale, sharing or targeted advertising, the website must apply that preference to the appropriate technologies.

That enforcement should extend beyond ordinary cookies to pixels, SDKs, session replay, fingerprinting, server-side events and other covered data flows.

Consent Records

The company should maintain evidence of the preference presented, the choice made, the applicable jurisdiction, the banner version, the technologies covered and the consent status transmitted to downstream systems.

Continuous Monitoring

A periodic spreadsheet or annual cookie audit cannot reliably govern a frequently changing enterprise website.

Organizations need recurring or continuous testing capable of detecting when a newly added or modified technology begins operating outside the consent rules.

A CMP Vendor Cannot Fix Every Website Implementation Problem

Companies sometimes blame the consent platform when tracking continues after an opt-out. In other cases, the organization assumes the platform vendor is responsible for preventing every unauthorized tag from loading.

Neither assumption is necessarily correct.

The division of responsibility depends on the implementation. OneTrust may provide scanning, classification, banner and blocking functionality, but the customer and its implementation partners may control:

  • Which domains are scanned
  • How frequently scans occur
  • How technologies are categorized
  • Which scripts are connected to blocking controls
  • How Google Tag Manager is configured
  • Whether custom code circumvents the CMP
  • Whether identified changes are remediated

The NFL lawsuit is therefore not proof that every OneTrust deployment is ineffective. It is a warning that buying a leading CMP does not transfer the website operator’s compliance responsibility to the software provider.

What Companies Using OneTrust Should Test Now

Organizations using OneTrust should conduct independent testing rather than relying exclusively on the platform’s administrative dashboard.

The review should answer several direct questions:

  • What network requests occur before the banner appears?
  • Which cookies and identifiers are created before consent?
  • Do advertising tags remain blocked after the visitor rejects them?
  • Do session replay tools activate before consent?
  • Are canvas or device-fingerprinting scripts operating?
  • Does Global Privacy Control alter website behavior?
  • Are tags deployed outside OneTrust’s blocking framework?
  • Does the preference persist across pages and subdomains?
  • Are server-side events governed by the same choice?
  • Can the organization produce an audit trail for a specific visit?

Testing should be conducted from the browser and network layer. A green status indicator inside a CMP dashboard does not establish that every website request complied with the visitor’s selection.

How To Reduce Exposure to an NFL-Style Privacy Lawsuit

No consent platform can guarantee that a company will never receive a privacy demand letter or lawsuit. Companies can, however, reduce preventable exposure by strengthening the connection between their privacy controls and website behavior.

Run Pre-Consent and Post-Opt-Out Tests

Test the website in a fresh browser before interacting with the banner. Then repeat the test after rejecting non-essential tracking.

Compare cookies, storage objects, scripts and outbound network requests between the two sessions.

Review Google Tag Manager

Identify every tag, trigger and custom HTML script deployed through the container. Confirm that relevant tags use consent-aware triggers and cannot fire before the required consent state is established.

Audit Technologies That Do Not Depend on Cookies

Fingerprinting, session replay, server-side tracking and certain fraud or identity tools may continue operating even when optional cookies are disabled.

These technologies require separate technical and legal analysis.

Remove Stale and Unnecessary Tags

Old campaign pixels and abandoned vendor scripts create legal and security risk without necessarily delivering current business value.

Data minimization should apply to the website’s technology stack as well as the data stored in internal systems.

Reconcile the Website With the Privacy Notice

The privacy policy, notice at collection, cookie disclosures and consent categories should describe the website’s actual data practices.

Disclosures should be updated when new vendors or tracking purposes are introduced.

Test Every Material Website Release

Privacy testing should be incorporated into deployment and change-management processes. Major redesigns, tag-manager changes, new marketing integrations and platform migrations should trigger a new review.

The NFL lawsuit demonstrates why companies need more than a recognizable consent banner.

Organizations using OneTrust can also conduct an independent technical assessment to determine whether their current implementation is blocking the technologies it claims to control.

The NFL Privacy Lawsuit Is a Warning for Every Website Operator

The NFL case remains at an early stage, and its allegations may be challenged or rejected. It nevertheless captures a central weakness in many enterprise privacy programs.

The organization has a privacy policy. It has a cookie banner. It offers an opt-out. It uses a prominent privacy technology provider.

Yet the plaintiff alleges that the underlying tracking continued.

That is the compliance gap businesses must address.

A consent banner is not the final product. The final product is a website that changes its behavior based on the visitor’s lawful privacy choice—and produces evidence showing that the choice was respected.

Frequently Asked Questions

What is the NFL privacy lawsuit?

Kimmons v. NFL Enterprises LLC is a proposed class action filed in California alleging that NFL.com deployed third-party tracking, fingerprinting and session-recording technologies before visitors made a privacy choice and after they attempted to opt out.

How many trackers were allegedly found on NFL.com?

The complaint reportedly alleges that forensic testing detected 182 third-party trackers before a visitor interacted with the consent interface and 186 after the visitor opted out.

Does NFL.com use OneTrust?

The NFL currently uses OneTrust-hosted privacy request portals, and its website privacy and consent infrastructure appears to include OneTrust technology. OneTrust is not named as a defendant in the lawsuit.

Is OneTrust responsible for the alleged tracking?

No court has made that finding. Consent management platforms require implementation and configuration by the website operator and its technical partners. Tracking can continue when tags are misclassified, deployed outside blocking controls or improperly connected to the consent system.

Can a company be sued even when it has a cookie banner?

Yes. A banner does not prevent a lawsuit, particularly when a claimant alleges that tracking occurred before consent or continued after an opt-out.

What is canvas fingerprinting?

Canvas fingerprinting is a technique that uses characteristics of a browser, device and graphics environment to help generate a distinctive identifier. It may operate without relying on a conventional tracking cookie.

How should companies test their consent management platforms?

Companies should independently examine browser storage, scripts and network traffic before consent, after acceptance, after rejection and while Global Privacy Control is enabled. Testing should be repeated as websites and marketing technologies change.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.