ConsentPixel – Privacy · Verified

CIPA Case Deep-Dive · Pen Register

D'Antonio v. Cable News Network, Inc.

A New York federal judge refused to dismiss a CIPA pen-register class action over the adtech trackers on CNN.com — and it was the second time the same judge told CNN the case could proceed. Where Rounds v. DDI shows how these claims die, D'Antonio shows how they survive.

By The ConsentPixel Team Updated July 2026 13 min read
⚖️ Case snapshot
Court
U.S. District Court, S.D.N.Y. (Judge Victor Marrero)
Case No.
1:24-cv-03132 · 2026 WL 960032
Filed
April 24, 2024
Status (as of Jul 2026)
Motion to dismiss DENIED Apr 9, 2026 — case proceeds
Tracking tech
Third-party adtech trackers — Microsoft, PubMatic, OpenX · IP & device metadata
Defendant
Cable News Network, Inc. (CNN.com) — news publisher

What the case is about

Plaintiff Anthony D'Antonio sued Cable News Network over the tracking technology running on CNN.com. According to the operative complaint, when he visited the site, CNN had embedded third-party adtech code — from Microsoft, PubMatic, and OpenX — that prompted his browser to transmit identifying information to those companies without his consent. The trackers, the complaint alleges, collected his IP address and device metadata, then worked to match that data against existing profiles to deanonymize him and serve targeted advertising.[1]

The detail that makes the complaint concrete — and that most coverage seizes on — is an advertisement. D'Antonio alleges he was shown a banner for Jaguar Land Rover, and that the third-party tracker PubMatic had received a real-time bid response for that ad slot based on metadata harvested from him, without his knowledge or consent, while he was simply reading the news.[2] That is the ordinary machinery of programmatic advertising — real-time bidding, or RTB — described in the language of a wiretap statute.

Why a news site, of all things. CNN.com is not a fringe target — it is one of the most-trafficked publishers on the internet, running a standard adtech stack that looks like almost every ad-supported site on the web. That is precisely what makes the case matter: if the trackers on CNN.com create CIPA exposure, so do the identical trackers on tens of thousands of ordinary publisher and e-commerce sites.

This was CNN's second time defending the same theory

D'Antonio did not arrive out of nowhere. The same court, the same judge — Judge Victor Marrero — had already denied CNN's motion to dismiss an earlier version of essentially the same lawsuit roughly 14 months before, in a predecessor action (Lesh v. Cable News Network). A CIPA plaintiff targeted the same defendant, drew the same judge, and got the same answer: the claim can go forward.[3] When the D'Antonio ruling built directly on the reasoning from that earlier decision, it turned a one-off into a pattern.

The legal theory — the pen-register revival

D'Antonio's claim runs on California Penal Code § 638.51, the "pen register and trap and trace" provision of CIPA. Historically, a pen register was a device law enforcement attached to a phone line to record the numbers dialed — the routing and addressing information of a call, but not the words spoken. Modern plaintiffs argue that website trackers do the digital equivalent: they capture the "dialing, routing, addressing, or signaling information" that a browser emits, which is exactly what § 638.51 restricts.[4]

Marrero's ruling accepted, at the pleading stage, that the tracking code on CNN.com could fit CIPA's broad definition of a pen register, and that a visitor's IP address qualifies as "addressing information" within the meaning of the statute. Critically, the court read the definition as technology-neutral — not confined to legacy telephone equipment simply because that is what existed when the statute was written.[4]

Why § 638.51 is the plaintiff's favourite theory. Unlike the § 631 wiretapping theory — which requires showing a third party intercepted the contents of a communication in real time — the pen-register theory only requires capture of routing and addressing data. That is a much lower bar, and ordinary adtech trackers appear to clear it just by transmitting an IP address. The asymmetry is why so many 2026 CIPA complaints lead with § 638.51.[4]

Content vs. record: the line CNN tried to draw

CNN's cleverest argument targeted the seam in the statute. A pen register, by definition, captures routing and addressing information but not the contents of a communication. So CNN argued that D'Antonio had actually alleged the interception of content — which would place the conduct outside the pen-register definition and sink that theory.[5]

D'Antonio's answer was precise: the "fingerprint" data at issue — device and browser identifiers, IP address, technical metadata — is not the content of a communication. It is exactly the routing and addressing layer the statute covers. He cited decisions holding that trackers collecting digital fingerprint information do not thereby collect content.[5] Marrero was persuaded that dismissal was not warranted on that basis.

"…the aggregation of tracking data into comprehensive, non-anonymous user profiles bears a close enough relationship to the tort of intrusion upon seclusion to survive dismissal."

— Reporting on the court's standing analysis, D'Antonio v. Cable News Network, Inc., 2026 WL 960032 (S.D.N.Y. Apr. 9, 2026)

The hurdle most CIPA cases die on — and how D'Antonio cleared it

Many pen-register cases never reach the merits because the plaintiff cannot show Article III standing — a concrete injury, not a bare statutory violation. Collecting an IP address, several courts have held, is not "remotely similar" to a traditional privacy harm, and a "free-roaming privacy right" is not enough to get into federal court.[6]

D'Antonio cleared the bar by pleading harm in a specific shape. He argued his information was not merely collected but collected and sold in the online-advertising marketplace, and that aggregating his metadata into a comprehensive, identifiable profile was "highly offensive." Marrero held that this bore a close enough relationship to the common-law tort of intrusion upon seclusion to confer standing — echoing the reasoning from the earlier Lesh ruling.[6]

Visitor loads CNN.com Browser transmits IP + device metadata to Microsoft · PubMatic · OpenX Aggregated into identifiable profile Ad slot auctioned via real-time bidding — all before any consent — "Jaguar Land Rover" banner served

The mechanics D'Antonio alleged — the ordinary adtech pipeline, reframed as a pen register capturing addressing information without consent.

CNN's fallback: the service-provider exception

CNN had one more argument, and it is the one publishers everywhere were watching. Section 638.51(b) contains an exception: a provider of an electronic or wire communication service may use a pen register to operate or maintain its service. CNN argued it was exactly that — "a provider of wire communication service" — and that the device and browser metadata it collected "were required to properly operate and load the website," meeting the operation requirement in the statute.[7]

Marrero declined to resolve it. Relying on Garon v. Keleops USA, he held that whether the service-provider exception applied was a question of fact not suitable for resolution on a motion to dismiss — precisely because of the breadth of data alleged to have been tracked. Loading a webpage may need some metadata; harvesting IP addresses and device fingerprints to build sellable advertising profiles is a different thing, and telling the two apart requires a factual record.[7]

Why the exception didn't rescue CNN. The exception is written for data a service genuinely needs to function. The moment the same data flows out to third-party adtech companies for their own advertising and profiling purposes, the "necessary to operate the service" framing gets much harder to defend — and a court won't decide that on the pleadings. Publishers hoping the exception is a clean early exit did not get that comfort here.

Where it stands (as of July 2026)

On April 9, 2026, Judge Marrero denied CNN's motion to dismiss the Second Amended Complaint (docket entry 86, denying the motion at docket 73).[8] The practical meaning:

  • The case is alive and moving into discovery. A denial of a motion to dismiss is not a finding that CNN did anything wrong — it means D'Antonio's allegations, taken as true, state a claim the law recognises.
  • Three theories survived: the pen-register claim under § 638.51, Article III standing grounded in intrusion upon seclusion, and the rejection — for now — of the service-provider exception.
  • The service-provider question is deferred, not decided. CNN can raise it again on a full factual record at summary judgment.
  • This is the second denial. Combined with the predecessor Lesh ruling, the same judge has now twice held that CNN's adtech configuration can support a CIPA claim.

D'Antonio is represented by Bursor & Fisher PA, one of the most active plaintiff-side privacy firms in the country; CNN by Weil, Gotshal & Manges LLP.[2] With statutory damages of up to $5,000 per violation and a proposed class measured in the site's California visitors across millions of page views, the exposure math is what makes these cases settle.

How D'Antonio fits the 2026 landscape

The single most important thing to understand about CIPA pen-register litigation in 2026 is that the courts are split, and D'Antonio sits firmly on the plaintiff-friendly side of that split. Reading it next to the cases going the other way is the only honest way to gauge your risk.

CaseCourtWhat it held
D'Antonio v. CNN (this case)S.D.N.Y. (federal)Trackers can be a § 638.51 pen register; IP is addressing information; standing via intrusion upon seclusion. MTD denied — twice.
Krzyzek v. OpenXN.D. Cal. (federal)Near-total denial of MTD — CIPA § 631, § 638.51, ECPA and intrusion all survived against a data broker. Plaintiff-friendly.
Rounds v. DDIC.D. Cal. (federal)Cookies aren't a § 638.51 device; no violation, so no jurisdiction over the out-of-state defendant. Dismissed, no leave.
L.A. Superior (session replay)State courtTrap-and-trace doesn't reach session replay; the CCPA/CPRA governs that data. Defense-friendly.
Read the split honestly. D'Antonio is a motion-to-dismiss ruling from one federal judge in New York applying California law — persuasive, influential, and part of a real plaintiff-friendly line, but not binding appellate precedent. Other courts have dismissed materially similar claims. Outcomes turn on the forum, the judge, the specific data pleaded, and whether trackers fired before consent. What you cannot do is read Rounds and conclude the theory is dead — D'Antonio is the live proof that it is thriving.

Why this case matters for website operators

D'Antonio is not a niche ruling about a media company. It is a roadmap for suing any ad-supported website, and it lands on the exact tools most sites run:

  • The trackers named are ubiquitous. Microsoft advertising, PubMatic, OpenX — these are mainstream RTB and supply-side adtech vendors on a huge share of commercial sites. If they create exposure on CNN.com, they create it on yours.
  • The theory needs no "content." Because the pen-register claim only needs routing and addressing data, a plaintiff doesn't have to prove anyone read a private message. An IP address transmitted to a third party is the whole case.
  • Standing has a template now. "Collected and sold in the advertising marketplace" + "aggregated into an identifiable profile" + "highly offensive" is a pleading formula that cleared the standing hurdle twice. Expect to see it copied.
  • The service-provider exception is not a shield at the pleadings. Publishers hoping to exit early on that basis just watched CNN fail to.

And the through-line that connects D'Antonio to the defense-side wins is simple. The cases plaintiffs lose tend to involve narrow data or trackers that fired after consent. The cases plaintiffs win — like this one — involve rich data flowing to third parties before the visitor ever agreed to anything. That timing is the whole ballgame, and it is the one thing entirely within your control.

What this means for your site

Strip away the docket numbers and D'Antonio delivers one operational lesson: your third-party trackers must not fire until the visitor has consented. Every surviving CIPA claim in 2026 shares that fact pattern — data leaving the browser for an adtech third party before any agreement. Fix the timing and you remove yourself from the fact pattern.

Concretely, that means:

  • Inventory every third-party tag on your site — analytics, advertising, RTB, identity resolution, session replay. Most operators are shocked by how many load, and by how many fire on page load.
  • Block non-essential trackers by default until the visitor gives affirmative, informed consent. Not a banner that merely appears while the pixels fire behind it — actual technical blocking.
  • Log every consent decision — what was shown, what was chosen, and when — so you can prove the trackers only ran after agreement.
  • Re-check after every change, because a new ad partner or marketing tag can silently reintroduce exposure.
The comfort in the bad news. CIPA exposure is almost entirely a timing problem, and timing is fixable. CNN's defensible position was never "we don't use trackers" — it was going to be "our trackers respected consent." A site that blocks third-party tags until consent, and logs the choice, simply doesn't present the fact pattern D'Antonio is built on.

Worried your site has this exposure?

Scan free in about 10 seconds to see every tracker firing on your site — including the adtech tags loading before consent, the exact pattern behind D'Antonio. It's the same scan a plaintiff firm would run before drafting a complaint.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What is D'Antonio v. CNN about?
Anthony D'Antonio sued Cable News Network under the California Invasion of Privacy Act, alleging that third-party adtech trackers on CNN.com — from Microsoft, PubMatic, and OpenX — collected his IP address and device metadata without consent and used it to build an advertising profile and serve him targeted ads. He pointed to a Jaguar Land Rover banner he was shown, alleging PubMatic received a real-time bid response based on data harvested from him. On April 9, 2026, Judge Victor Marrero of the Southern District of New York denied CNN's motion to dismiss, allowing the case to proceed.
Did CNN win or lose?
Neither, yet — but CNN lost the round that matters most so far. A motion to dismiss asks the court to throw the case out before discovery. Judge Marrero denied that motion, meaning D'Antonio's allegations are strong enough for the case to move forward into discovery. It is not a finding that CNN violated the law; it is a finding that the plaintiff has stated a claim the law recognises. Notably, it was the second time the same judge denied CNN's motion to dismiss essentially the same theory, after an earlier predecessor case.
What is a "pen register" under CIPA, and how does it apply to a website?
Historically, a pen register was a device that recorded the phone numbers dialed from a telephone line — the routing information of a call, not its contents. California Penal Code § 638.51 restricts using one without a court order. Plaintiffs now argue that website trackers do the digital equivalent: they capture the "dialing, routing, addressing, or signaling information" a browser transmits, such as an IP address. In D'Antonio, the court accepted at the pleading stage that CNN's trackers could fit this broad, technology-neutral definition and that an IP address qualifies as "addressing information."
Why did the court reject CNN's service-provider exception?
It didn't reject it outright — it refused to decide it on a motion to dismiss. Section 638.51(b) lets a communication-service provider use a pen register to operate or maintain its service, and CNN argued the metadata it collected was needed to load the website. But relying on Garon v. Keleops, Judge Marrero held that whether the exception applied was a factual question unsuitable for early resolution, given the breadth of data alleged to have been tracked. CNN can raise the argument again later on a full record, but it was not an early exit.
How is this different from Rounds v. DDI, where the case was dismissed?
They are close to mirror images, which is why reading them together is useful. In Rounds, a California federal court held that cookies are not a § 638.51 trap-and-trace device, found no violation, and therefore no personal jurisdiction over the out-of-state defendant — dismissed with no leave to amend. In D'Antonio, a New York federal court held the opposite at the pleading stage: the trackers could be a pen register, the IP address is addressing information, and standing was adequately pleaded. The split reflects genuine judicial disagreement; outcomes depend heavily on the forum, the judge, and the specific facts pleaded.
Does this case create risk for my website?
If your site loads third-party advertising or analytics trackers before visitors consent, D'Antonio describes a fact pattern that a plaintiff could apply to you. The trackers named — Microsoft, PubMatic, OpenX — are mainstream tools found on a huge range of commercial sites, and the pen-register theory doesn't require proof that anyone read message contents. The most reliable protection is to block non-essential third-party tags until the visitor gives affirmative consent, and to keep a log proving they only fired afterward. A free tracker scan will show you what currently fires before consent on your site.

Sources

  1. National Law Review / Sheppard Mullin — "CNN's CIPA Tracking Case: Court Focuses on IP Addresses and Pen Registers" (Apr. 2026). Summarises the trackers, the pen-register holding, and the standing analysis.
  2. Bloomberg Law — "CNN Stuck With Suit Challenging Use of Online Tracking Tools" (Apr. 10, 2026). Confirms case number, counsel (Bursor & Fisher; Weil Gotshal), the content-vs-record argument, and the "highly offensive" standing finding.
  3. Privado — "CNN stuck with CIPA suit over alleged data-sharing with Microsoft and adtech partners" (Apr. 2026). Notes this was the second denial, 14 months after the first, and the fingerprint-vs-content distinction.
  4. CIPAWorld — "CNN's Motion to Dismiss Denied: How the Exception for Service Providers Is Taking Shape" (Apr. 17, 2026). Detailed analysis of the § 638.51 holding, the Jaguar Land Rover / PubMatic allegation, and the Garon v. Keleops reliance.
  5. Privacy Daily — "CNN Case Shows Publishers May Face CIPA Risks Without Disclosures" (Apr. 20, 2026). Covers CNN's service-provider / "required to load the website" argument.
  6. LegalClarity — "Trap and Trace Lawsuits: How CIPA Targets Website Tracking" (2026). Context on the standing split and the intrusion-upon-seclusion analysis.
  7. Fisher Phillips — "Courts Still Divided on Whether California Privacy Law Applies to Website Tracking" (Apr. 21, 2026). Places D'Antonio among four rulings in ten days and confirms the MTD denial.
  8. Justia — Docket, D'Antonio v. Cable News Network, Inc., No. 1:24-cv-03132 (S.D.N.Y.), Dkt. No. 86. The Decision and Order denying the motion to dismiss the Second Amended Complaint, signed by Judge Victor Marrero on April 9, 2026.

Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the primary decision is reported at 2026 WL 960032 (S.D.N.Y. Apr. 9, 2026). Status is stated as of July 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.

Scroll to Top