ConsentPixel – Privacy · Verified

CIPA Case Deep-Dive · Pen Register · Consent

Camplisson v. Adidas America, Inc.

A California federal judge refused to dismiss a CIPA pen-register class action over the TikTok and Microsoft Bing pixels on adidas.com — and delivered the lesson most sites still haven't learned: privacy-policy links buried in your footer are not consent. This is the case that makes a real cookie banner non-negotiable.

By The ConsentPixel Team Updated July 2026 13 min read
⚖️ Case snapshot
Court
U.S. District Court, S.D. Cal. (Judge Gonzalo P. Curiel)
Case No.
25-cv-603-GPC-KSC · 2025 WL 3228949
Filed
March 14, 2025
Status (as of Jul 2026)
Motion to dismiss DENIED Nov 18, 2025 — case proceeds
Tracking tech
TikTok Pixel · Microsoft Bing pixel · IP, device & fingerprint data
Defendant
Adidas America, Inc. (adidas.com/us) — retail

What the case is about

On March 14, 2025, three plaintiffs — Maeve Camplisson, David Sanchez, and a minor identified as S.D. (through legal guardian Elvis Diciero) — filed a putative class action against Adidas America over the tracking technology on adidas.com/us. The complaint alleges that Adidas installed and used two tracking pixels — the TikTok Pixel and the Microsoft Bing tracker — that fired on visitors' browsers and captured their personal information the moment they landed on the site, without consent.[1]

The data the pixels allegedly collected goes well beyond "which pages you clicked." According to the complaint, it included IP addresses, browser information, device details, unique identifiers, timestamps, and fingerprinting data — and, through a feature called AutoAdvanced Matching, could tie that browsing activity back to a visitor's actual name, birthday, and address.[2] The plaintiffs' framing was blunt: this is not retargeting, it is a map back to the real person.

Why a retail site is the story. Adidas isn't a healthcare portal or a bank — it's a shoe shop. The plaintiffs weren't doing anything sensitive; they were browsing sneakers. That's exactly what makes the case resonate: if the pixels on a mainstream e-commerce site create CIPA exposure, the same pixels on tens of thousands of ordinary online stores do too. Retail is not the quiet cousin of pixel litigation anymore.

The legal theory — pixels as a pen register

The plaintiffs brought their claim under California Penal Code § 638.51, CIPA's "pen register and trap and trace" provision, defining the device through § 638.50(b). Historically a pen register recorded the phone numbers dialed from a line — the routing and addressing information of a call, not its contents. Modern plaintiffs argue that website pixels do the digital equivalent: they capture the "dialing, routing, addressing, or signaling information" a browser emits, which § 638.51 forbids capturing without consent or a court order.[3]

Adidas moved to dismiss on two grounds: first, that pixels are not a "pen register" as a matter of law; second, that even if they were, the plaintiffs had consented. Judge Curiel rejected both.[1] On the definition, the court treated CIPA's language as intentionally broad and technology-neutral — not confined to old telephone equipment simply because that was the technology of 1967 — and declined to require the plaintiffs to allege that the pixels captured all outgoing communications.[4]

The IP-address holding that travels. This is the finding defendants fear most: the court held that even if the pixels collected only IP addresses, that alone plausibly alleges use of a pen register. The recording of personally identifiable information "including information contained in an IP address" was enough to survive dismissal. There is no minimum data threshold to clear — an IP address is enough to state the claim.[5]

"Even though the pixels on the sportswear company's website only collected IP addresses, the court also said the plaintiff successfully lodged a pen register claim."

— Fisher Phillips, on Camplisson v. Adidas Am., Inc., 2025 WL 3228949 (S.D. Cal. Nov. 18, 2025)

Here is what sets Camplisson apart from every other pen-register case in the tracker. The definitional fight over "is a pixel a pen register?" is being had in courtrooms across the country, with mixed results. But Camplisson turned decisively on the second question — consent — and that is the part every website operator should read twice.

Adidas's consent defense rested on the disclosures it did have: a privacy policy and terms-and-conditions, accessible through links. The problem was where those links lived. They appeared only in small font in the website footer — the classic "browsewrap" setup, where a site posts terms somewhere on the page and treats continued browsing as agreement. There was no consent banner, no pop-up, no affirmative opt-in of any kind before the pixels fired.[6]

The court applied the Ninth Circuit's browsewrap standard from Nguyen v. Barnes & Noble (2014): a user is only bound by terms they had a reasonable opportunity to notice. Whether that opportunity existed "depends on the design and content of the website." Buried footer links, the court found, did not put a reasonably prudent user on inquiry notice — and certainly did not obtain the affirmative consent CIPA's exception requires.[6]

✕ BROWSEWRAP (Adidas) Visitor lands on page Pixel fires immediately data sent — no action taken Terms sit in footer, small font. No notice. No consent. ✓ CLICKWRAP (compliant) Visitor lands on page Pixel BLOCKED — banner shown nothing fires yet User clicks Accept → pixel fires

The distinction the case turns on: browsewrap treats a page visit as agreement — but the pixel has already fired. Clickwrap blocks tracking until the visitor affirmatively consents.

Why the timing makes browsewrap fatal. Browsewrap rests on the idea that continued use equals agreement. But a pen-register claim frames the harm as immediate: the pixel fires, the data transmits, and the user never took a single affirmative step. By the time a visitor could theoretically scroll to a footer link and read it, the alleged violation has already happened. That sequence is why passive footer notice cannot rescue a tracking setup — the tracking beat the notice.[7]

Where it stands (as of July 2026)

On November 18, 2025, Judge Curiel denied Adidas's motion to dismiss in its entirety and granted the company's request for judicial notice (docket entry ECF No. 32). The motion had been fully briefed and argued at a hearing on November 14, 2025.[8] What the ruling means in practice:

  • The case is alive and moving into discovery. A denial of a motion to dismiss is not a finding that Adidas violated the law — it means the plaintiffs' allegations, taken as true, state a claim the court will let proceed.
  • Both of Adidas's core defenses failed at the pleading stage: pixels can plausibly be a pen register, and the buried-footer consent theory did not hold.
  • The IP-only holding is now a citable precedent plaintiffs will reuse — collection of an IP address alone is enough to plead a § 638.51 claim.
  • Statutory damages loom. Under Cal. Penal Code § 637.2, a CIPA plaintiff can recover the greater of $5,000 per violation or three times actual damages — and the proposed class covers California visitors to adidas.com.[5]
One caveat worth stating plainly. Fisher Phillips pointed out that the Camplisson court allowed the claim to proceed without addressing the contrary case law — the decisions from other courts holding that pixels are not pen registers, or that IP collection causes no cognizable harm. That doesn't weaken the ruling's force for anyone sued in the Southern District of California, but it is a reminder that this is a contested area, not settled law.[5]

How Camplisson fits the 2026 landscape

CIPA pen-register litigation is genuinely split, and Camplisson sits on the plaintiff-friendly side. Reading it against the cases going the other way is the only honest way to gauge your own risk — and the contrast with a case like Rounds v. DDI is stark.

CaseCourtWhat it held
Camplisson v. Adidas (this case)S.D. Cal. (federal)Pixels plausibly a § 638.51 pen register even if only IP is collected; buried-footer browsewrap isn't consent. MTD denied in full.
D'Antonio v. CNNS.D.N.Y. (federal)Adtech trackers can be a pen register; standing via intrusion upon seclusion. MTD denied — twice.
Rounds v. DDIC.D. Cal. (federal)Cookies aren't a § 638.51 device; no violation, so no jurisdiction over the out-of-state defendant. Dismissed, no leave.
L.A. Superior (session replay)State courtTrap-and-trace doesn't reach session replay; the CCPA/CPRA governs that data. Defense-friendly.
Read the split honestly. Camplisson is a motion-to-dismiss ruling from one federal judge — persuasive and citable, but not binding appellate precedent, and it declined to engage the contrary authority. Other courts have dismissed materially similar claims. Outcomes turn on the forum, the judge, the data pleaded, and — as Camplisson shows more sharply than any other case — whether the site obtained real consent before tracking. What you cannot do is treat "a pixel isn't a pen register" as a settled defense. Here it wasn't even close.

Why this case matters for website operators

Camplisson is arguably the most useful case in the entire tracker, because it isolates the one variable you fully control. Other cases argue about statutory definitions you can't change. Camplisson tells you exactly what a defensible consent posture looks like — by showing you one that failed.

  • The trackers are the ones everyone runs. TikTok Pixel and Microsoft Bing are mainstream marketing tools on a huge share of e-commerce sites. If they create exposure on adidas.com, they create it on yours.
  • An IP address is enough. You cannot argue your way out by saying "we only collect basic data." The court held IP collection alone states the claim.
  • Your privacy policy is not your consent mechanism. This is the misconception Camplisson demolishes. A policy tells people what you do; it does not obtain their agreement to do it. Those are different jobs, and a footer link does neither well.
  • "Continued use = consent" is dead for tracking. Browsewrap fails because the pixel fires before the user acts. Only an affirmative step — a click — creates the consent CIPA's exception needs.

What this means for your site

Camplisson converts neatly into a checklist, because the court essentially published the failure mode. If Adidas had done the opposite of each defect, the consent argument would have been far stronger. Here is the opposite:

  • Show a real consent banner — conspicuous, on entry, before any non-essential pixel fires. Not a footer link. Not fine print. An actual, visible request.
  • Block trackers until the visitor clicks. TikTok, Bing, Meta, GA4 and the rest must not fire on page load. The whole browsewrap problem is that tracking happened before any action — so make the action come first.
  • Use clickwrap, not browsewrap. Require an affirmative choice. It creates both the legal assent CIPA wants and a record you can produce later.
  • Log every consent decision — what was shown, what was chosen, and when — so you can prove tracking only began after agreement.
  • Match the disclosure to reality. If a pixel uses advanced matching that ties data to a real identity, your notice should reflect that, not describe vague "analytics."
The reassuring part. Every defect in Camplisson is a design choice, which means every one is fixable — and cheaply. Adidas's problem was never that pixels are illegal; it was that the pixels fired before anyone agreed, behind notice no one could reasonably find. A site that blocks non-essential trackers until a clear banner is accepted, and logs the choice, simply doesn't present the fact pattern that beat Adidas.

Worried your site has this exposure?

Scan free in about 10 seconds to see every tracker firing on your site — including the pixels loading before any consent, the exact defect in Camplisson. It's the same scan a plaintiff firm would run before drafting a complaint.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What is Camplisson v. Adidas about?
Maeve Camplisson, David Sanchez, and a minor identified as S.D. filed a class action against Adidas America in March 2025, alleging that the TikTok Pixel and Microsoft Bing tracker on adidas.com collected their personal information — IP addresses, device details, browser information, unique identifiers, timestamps, and fingerprinting data — without consent, in violation of the California Invasion of Privacy Act. They argued the pixels function as an unlawful "pen register" under Cal. Penal Code § 638.51. On November 18, 2025, Judge Gonzalo P. Curiel of the Southern District of California denied Adidas's motion to dismiss, allowing the case to proceed.
Did Adidas win or lose?
Adidas lost the round that mattered most so far. A motion to dismiss asks the court to throw a case out before discovery. Judge Curiel denied that motion in its entirety, meaning the plaintiffs' allegations were strong enough for the case to move forward. It is not a final ruling that Adidas violated the law — it is a finding that the plaintiffs stated a claim the law recognizes. Both of Adidas's main arguments failed: that pixels aren't pen registers, and that its footer disclosures established consent.
Why did Adidas's consent defense fail?
Because its only disclosures were privacy-policy and terms links buried in small font in the website footer — a "browsewrap" setup that treats continued browsing as agreement. There was no consent banner, no pop-up, and no affirmative opt-in before the pixels fired. Applying the Ninth Circuit's standard from Nguyen v. Barnes & Noble, the court found buried footer links did not put a reasonably prudent user on inquiry notice and did not obtain the affirmative consent CIPA's exception requires. The pixel fired before the user took any action at all, so passive footer notice couldn't rescue it.
Is collecting only an IP address enough to be a "pen register"?
In this court's view, yes — at least enough to survive a motion to dismiss. Judge Curiel held that even if the pixels collected only IP addresses, the plaintiffs plausibly alleged use of a pen register, because the recording of personally identifiable information "including information contained in an IP address" fits CIPA's broad, technology-neutral definition. That is the holding defendants find most alarming, because it removes the argument that minimal data collection is automatically safe. Note that other courts have disagreed, so this is not settled law.
How is this different from Rounds v. DDI, where the case was dismissed?
They point in opposite directions. In Rounds, a California federal court held that cookies are not a § 638.51 device, found no violation, and dismissed for lack of jurisdiction over the out-of-state defendant. In Camplisson, the court held that pixels can plausibly be a pen register, that IP collection alone suffices to plead the claim, and that buried-footer consent didn't hold — so the case proceeds. The split reflects genuine judicial disagreement. Outcomes depend heavily on the forum, the judge, the specific facts pleaded, and — uniquely highlighted in Camplisson — whether the site obtained real consent before tracking.
Does a privacy policy count as consent under CIPA?
Not on its own, and Camplisson is the cautionary tale. A privacy policy discloses what you do; consent is the visitor's agreement to let you do it. Those are different functions. When the policy sits behind a small footer link and the tracking fires on page load, the visitor never had a genuine opportunity to notice the terms or to agree before their data was collected. To rely on consent as a CIPA defense, you need conspicuous notice and an affirmative action — clickwrap, not browsewrap — captured before non-essential trackers run.
Does this case create risk for my website?
If your site loads marketing or analytics pixels — TikTok, Microsoft Bing, Meta, Google — before visitors affirmatively consent, and relies on a footer privacy link rather than a real banner, Camplisson describes your exact fact pattern. The trackers named are mainstream tools, the IP-only holding removes the "we collect very little" defense, and the consent analysis targets the setup most sites still use. The reliable fix is to block non-essential trackers until the visitor accepts a conspicuous consent banner, and to log that choice. A free tracker scan will show what currently fires before consent on your site.

Sources

  1. CourtListener — Docket, Camplisson v. Adidas America, Inc., No. 3:25-cv-00603 (S.D. Cal.). Confirms filing, parties, Judge Curiel, the Nov. 14, 2025 hearing, and the Nov. 18, 2025 order denying the motion to dismiss (ECF No. 32).
  2. CIPAWorld — "Pixel-Tracking Gets Its Third Stripe: Adidas Learns CIPA Isn't Optional" (Nov. 28, 2025). Details the trackers, AutoAdvanced Matching, and the browsewrap consent analysis.
  3. Casemine — Camplisson v. Adidas America, Inc., No. 25-603 (S.D. Cal.). Reproduces the court's recitation of the § 638.50(b) / § 638.51 pen-register theory and the browsewrap / Nguyen v. Barnes & Noble discussion.
  4. Traverse Legal — "CIPA Pen Register Claims After Camplisson v. Adidas" (Feb. 2026). Analyses the broad, technology-neutral reading and the browsewrap-vs-clickwrap distinction.
  5. Fisher Phillips — "Court Allows CIPA Claim Involving Third-Party Pixels to Proceed, Ignores Contrary Case Law" (Dec. 4, 2025). Confirms the IP-only holding, standing, and that the court didn't address conflicting authority.
  6. Consumer Finance + Privacy Counsel — "Court Upholds Privacy Claims Against Website Tracking: Finding Lack of Conspicuous or Affirmative Consent" (Nov. 29, 2025). Names Judge Curiel and details the footer / small-font disclosure findings.
  7. Fox Rothschild / FIC Law — "Pixels, Cookies, and Consent Have Become High Risk in California" (Mar. 2026). Covers § 637.2 statutory damages and the browsewrap weakness.
  8. National Law Review / Robinson+Cole — "What Camplisson v. Adidas Am., Inc. Means for Business Websites" (Jan. 2026). Summarises the ruling, the two grounds for dismissal, and the consent-pleading template.

Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the primary decision is reported at 2025 WL 3228949 (S.D. Cal. Nov. 18, 2025). Status is stated as of July 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.

Scroll to Top