We warned about the California Invasion of Privacy Act (CIPA) cookie banner cases and now the entire privacy and legal community is paying attention to our warnings about the high costs associated with using a broken cookie banner on your site because it can get really expensive and according to Bloomberg news can come down to milliseconds.
This trend has defined much of this year’s digital privacy docket, the decisive issue is rarely whether a company posted a consent banner. It is whether tracking technologies fired in the instant before a user could make any choice—or continued firing after the user clicked “Reject All.” That split-second gap has transformed the banner from a compliance artifact into plaintiffs’ Exhibit A. Courts are treating a malfunctioning or incomplete consent management platform (CMP) as evidence of deception rather than proof of compliance. The plaintiff’s bar has grown markedly more sophisticated at pleading the precise sequence of script loads, pixel fires, and cookie drops relative to the user’s interaction with the banner. The result is a fast-developing body of case law that rewards technical precision in both pleading and website architecture.
Three recent decisions illustrate the through-line with particular clarity: D’Antonio v. Smith & Wesson Inc., De Ayora v. Inspire Brands, Inc., and Camplisson v. Adidas Am., Inc. Together they show courts willing to let claims proceed where the consent architecture is missing, delayed, or ineffective, while still enforcing traditional pleading rigor under Rule 9(b) and requiring plaintiffs to allege concrete interactions with the site.
D’Antonio v. Smith & Wesson Inc., 820 F. Supp. 3d 928 (N.D. Cal. 2026)
In February 2026, Judge P. Casey Pitts of the Northern District of California issued a mixed ruling that has become a frequent citation in both plaintiff and defense briefs. Plaintiffs Tony D’Antonio, Thomas Thayer, and Reina Cuevas Garcia alleged that Smith & Wesson’s website presented a popup cookie consent banner offering “Accept Cookies,” “Reject All,” or “Manage Privacy Preferences.” The banner stated that the site used cookies to enhance experience and analyze performance, that information was shared with social media, advertising, and analytics partners, and that any detected “opt-out preference” would be honored. Plaintiffs claimed they each clicked “Reject All”—D’Antonio around February 2025, Thayer around November 2024, and Garcia sometime in 2024—yet the site still placed first-party and third-party cookies and allowed Google, X Corp., Listrak, Digioh, and others to collect browsing history, website interactions, demographic data, shopping behaviors, device information, referring URLs, session data, user identifiers, and geolocation information.
The court allowed the intrusion-upon-seclusion, invasion-of-privacy, common-law fraud (as to D’Antonio and Thayer), and unjust-enrichment claims to proceed. It found the “deceit-plus” factor—affirmative representations that opt-outs would be honored, followed by continued tracking—sufficient to render the intrusion highly offensive at the pleading stage. The court also accepted that Smith & Wesson could be liable for facilitating third-party intrusions by embedding the trackers pursuant to commercial agreements.
CIPA claims fared differently. The wiretapping claim under Penal Code § 631 was dismissed (with leave to amend) because plaintiffs failed to allege that they themselves engaged in any communications with the website whose contents could have been intercepted; general allegations that the site enabled interception of user communications were insufficient. The pen-register claim under § 638.51 met a similar fate. The court rejected Smith & Wesson’s argument that the statute is limited to telephones, noting the absence of any such textual limitation and the privacy-protective purpose of CIPA. Nevertheless, the claim was dismissed because plaintiffs did not allege specific interactions or identify the particular “dialing, routing, addressing, or signaling information” captured from their visits. Breach-of-contract, implied-covenant, and trespass-to-chattels claims were also dismissed for lack of consideration and measurable device harm, respectively. Garcia’s fraud claim failed Rule 9(b) specificity because “in or around 2024” did not give adequate notice of the time and circumstances.
The decision is notable for two reasons. First, it confirms that a non-functional “Reject All” button can support traditional privacy and fraud theories even when CIPA claims require more granular pleading of personal communications. Second, it signals that courts will not stretch CIPA to cover every allegation of cookie placement without some showing that the plaintiff actually interacted with the site in a way that generated the protected information.
De Ayora v. Inspire Brands, Inc., 2025 WL 3707561 (N.D. Cal. Dec. 22, 2025) and subsequent proceedings
The De Ayora litigation, involving Inspire Brands and its portfolio of restaurant websites (Arby’s, Jimmy John’s, Sonic, Dunkin’/Baskin-Robbins), has produced multiple orders that underscore the continued importance of Rule 9(b). Plaintiffs alleged that cookie banners on the various brand sites promised users the ability to reject tracking, yet trackers continued to operate after users declined. Early proceedings focused heavily on standing (particularly as to the parent Inspire Brands), equitable tolling of CIPA claims, and the heightened pleading standard for fraud-based theories.
In the December 2025 order, the court scrutinized whether plaintiffs had adequately alleged the who, what, when, where, and how of the alleged deception. Claims sounding in fraud were held to Rule 9(b)’s particularity requirement; conclusory assertions that banners were false, without specifying the precise representations, the timing of the plaintiff’s visits, the specific brands interacted with, and the reliance and resulting harm, were insufficient. CIPA wiretapping, pen-register, federal Wiretap Act, invasion-of-privacy, and unjust-enrichment claims were dismissed or trimmed on these and related grounds in the initial rounds. Later orders (including a June 2026 ruling on a second amended complaint) allowed certain fraud and remaining privacy claims to proceed while continuing to dismiss or limit wiretapping theories that failed to allege interception of the contents of communications in transit, and while applying statute-of-limitations and tolling analysis carefully to individual plaintiffs and brands.
The case illustrates that even when the underlying technical story—banner promises versus continued tracking—is compelling, federal courts still demand particularized pleading. Plaintiffs who treat the cookie banner as a generic “false statement” without tying it to specific user experiences risk early dismissal. At the same time, once those details are supplied, courts have shown willingness to let fraud and certain privacy claims survive, treating the mismatch between the banner’s promise and the site’s actual behavior as a classic deception.
Camplisson v. Adidas Am., Inc., 809 F. Supp. 3d 1095 (S.D. Cal. 2025)
Perhaps the most plaintiff-friendly of the three, Camplisson (decided November 18, 2025, by Judge Gonzalo P. Curiel) denied Adidas’s motion to dismiss a putative class action alleging CIPA § 638.51 pen-register violations based on the TikTok Pixel and Microsoft Bing trackers. Plaintiffs claimed the pixels were installed on visitors’ browsers without consent and collected IP addresses, browser information, unique identifiers, and other personally identifiable information, including through device-fingerprinting techniques that correlated data across sessions.
Adidas argued that the trackers did not meet the statutory definition of a pen register because they did not capture all outgoing information and because some of the collected data was substantive rather than pure routing or addressing information. The court rejected both arguments. Relying on CIPA’s intentionally broad language, it held that a narrow reading limited to tools capturing every piece of outgoing data would undermine the statute’s privacy purpose and render it underinclusive. It further noted that most courts in the district and elsewhere had recognized that website-based trackers can plausibly constitute pen registers. Allegations that the trackers recorded PII, including information contained in IP addresses, were therefore sufficient at the pleading stage.
On consent, the court found Adidas’s disclosures inadequate. Visitors allegedly had to scroll to the footer to locate links to the terms and privacy policy; the site did not present a pop-up or similar mechanism requiring affirmative assent before the pixels fired. Footer-only notice, without a pre-tracking affirmative consent step, did not establish consent as a matter of law. The decision has been widely cited for the proposition that standard marketing pixels can survive a motion to dismiss on pen-register theories and that the practical path to notice and the timing of script execution relative to any user choice are central to the consent analysis.
The through-line and the compliance imperative
Across these cases, a consistent pattern emerges. Courts are receptive to claims where the consent architecture is missing, delayed, or ineffective—particularly where trackers fire before any choice is possible or continue after an explicit “Reject All.” At the same time, they continue to enforce traditional requirements: Rule 9(b) particularity for fraud theories, concrete allegations of personal interactions for certain CIPA claims, and careful distinction between the contents of communications and mere addressing or routing information.
The practical consequence is that a CMP that looks compliant on the surface but fails in the millisecond before or after the user’s click has become a liability. Plaintiffs’ counsel now routinely include technical appendices or detailed narrative of network requests, cookie timelines, and script-load order. Defense counsel respond with their own audits showing either that non-essential trackers were blocked or that consent was obtained in a manner courts have previously accepted.
For website operators, the lesson is straightforward and urgent. Do not wait for a demand letter, a lawsuit, or an enforcement inquiry to examine the actual behavior of your consent banner and tag-management system. Test whether non-essential cookies and pixels are blocked until affirmative consent is given. Confirm that “Reject All” actually clears or prevents the relevant trackers rather than merely recording a preference while scripts continue to fire. Ensure that any notice of terms or privacy practices is presented in a manner that courts are likely to find conspicuous and that consent is captured before tracking begins. Document the testing. Update vendor agreements to allocate risk around tracking technologies. Maintain a playbook for responding to the now-common pre-suit demand letters that cite these very decisions.
The case law is still evolving, and appellate clarification may eventually narrow some of the more expansive readings of CIPA’s pen-register provisions. Until then, the millisecond remains the critical unit of measurement. A banner that functions only after the fact, or that never fully honors the user’s choice, is no longer a shield. In the current litigation environment, it is evidence.