Camplisson v. Adidas America, Inc.
A California federal judge refused to dismiss a CIPA pen-register class action over the TikTok and Microsoft Bing pixels on adidas.com — and delivered the lesson most sites still haven't learned: privacy-policy links buried in your footer are not consent. This is the case that makes a real cookie banner non-negotiable.
What the case is about
On March 14, 2025, three plaintiffs — Maeve Camplisson, David Sanchez, and a minor identified as S.D. (through legal guardian Elvis Diciero) — filed a putative class action against Adidas America over the tracking technology on adidas.com/us. The complaint alleges that Adidas installed and used two tracking pixels — the TikTok Pixel and the Microsoft Bing tracker — that fired on visitors' browsers and captured their personal information the moment they landed on the site, without consent.[1]
The data the pixels allegedly collected goes well beyond "which pages you clicked." According to the complaint, it included IP addresses, browser information, device details, unique identifiers, timestamps, and fingerprinting data — and, through a feature called AutoAdvanced Matching, could tie that browsing activity back to a visitor's actual name, birthday, and address.[2] The plaintiffs' framing was blunt: this is not retargeting, it is a map back to the real person.
The legal theory — pixels as a pen register
The plaintiffs brought their claim under California Penal Code § 638.51, CIPA's "pen register and trap and trace" provision, defining the device through § 638.50(b). Historically a pen register recorded the phone numbers dialed from a line — the routing and addressing information of a call, not its contents. Modern plaintiffs argue that website pixels do the digital equivalent: they capture the "dialing, routing, addressing, or signaling information" a browser emits, which § 638.51 forbids capturing without consent or a court order.[3]
Adidas moved to dismiss on two grounds: first, that pixels are not a "pen register" as a matter of law; second, that even if they were, the plaintiffs had consented. Judge Curiel rejected both.[1] On the definition, the court treated CIPA's language as intentionally broad and technology-neutral — not confined to old telephone equipment simply because that was the technology of 1967 — and declined to require the plaintiffs to allege that the pixels captured all outgoing communications.[4]
"Even though the pixels on the sportswear company's website only collected IP addresses, the court also said the plaintiff successfully lodged a pen register claim."
— Fisher Phillips, on Camplisson v. Adidas Am., Inc., 2025 WL 3228949 (S.D. Cal. Nov. 18, 2025)The heart of the case: why "consent" failed
Here is what sets Camplisson apart from every other pen-register case in the tracker. The definitional fight over "is a pixel a pen register?" is being had in courtrooms across the country, with mixed results. But Camplisson turned decisively on the second question — consent — and that is the part every website operator should read twice.
Adidas's consent defense rested on the disclosures it did have: a privacy policy and terms-and-conditions, accessible through links. The problem was where those links lived. They appeared only in small font in the website footer — the classic "browsewrap" setup, where a site posts terms somewhere on the page and treats continued browsing as agreement. There was no consent banner, no pop-up, no affirmative opt-in of any kind before the pixels fired.[6]
The court applied the Ninth Circuit's browsewrap standard from Nguyen v. Barnes & Noble (2014): a user is only bound by terms they had a reasonable opportunity to notice. Whether that opportunity existed "depends on the design and content of the website." Buried footer links, the court found, did not put a reasonably prudent user on inquiry notice — and certainly did not obtain the affirmative consent CIPA's exception requires.[6]
The distinction the case turns on: browsewrap treats a page visit as agreement — but the pixel has already fired. Clickwrap blocks tracking until the visitor affirmatively consents.
Where it stands (as of July 2026)
On November 18, 2025, Judge Curiel denied Adidas's motion to dismiss in its entirety and granted the company's request for judicial notice (docket entry ECF No. 32). The motion had been fully briefed and argued at a hearing on November 14, 2025.[8] What the ruling means in practice:
- The case is alive and moving into discovery. A denial of a motion to dismiss is not a finding that Adidas violated the law — it means the plaintiffs' allegations, taken as true, state a claim the court will let proceed.
- Both of Adidas's core defenses failed at the pleading stage: pixels can plausibly be a pen register, and the buried-footer consent theory did not hold.
- The IP-only holding is now a citable precedent plaintiffs will reuse — collection of an IP address alone is enough to plead a § 638.51 claim.
- Statutory damages loom. Under Cal. Penal Code § 637.2, a CIPA plaintiff can recover the greater of $5,000 per violation or three times actual damages — and the proposed class covers California visitors to adidas.com.[5]
How Camplisson fits the 2026 landscape
CIPA pen-register litigation is genuinely split, and Camplisson sits on the plaintiff-friendly side. Reading it against the cases going the other way is the only honest way to gauge your own risk — and the contrast with a case like Rounds v. DDI is stark.
| Case | Court | What it held |
|---|---|---|
| Camplisson v. Adidas (this case) | S.D. Cal. (federal) | Pixels plausibly a § 638.51 pen register even if only IP is collected; buried-footer browsewrap isn't consent. MTD denied in full. |
| D'Antonio v. CNN | S.D.N.Y. (federal) | Adtech trackers can be a pen register; standing via intrusion upon seclusion. MTD denied — twice. |
| Rounds v. DDI | C.D. Cal. (federal) | Cookies aren't a § 638.51 device; no violation, so no jurisdiction over the out-of-state defendant. Dismissed, no leave. |
| L.A. Superior (session replay) | State court | Trap-and-trace doesn't reach session replay; the CCPA/CPRA governs that data. Defense-friendly. |
Why this case matters for website operators
Camplisson is arguably the most useful case in the entire tracker, because it isolates the one variable you fully control. Other cases argue about statutory definitions you can't change. Camplisson tells you exactly what a defensible consent posture looks like — by showing you one that failed.
- The trackers are the ones everyone runs. TikTok Pixel and Microsoft Bing are mainstream marketing tools on a huge share of e-commerce sites. If they create exposure on adidas.com, they create it on yours.
- An IP address is enough. You cannot argue your way out by saying "we only collect basic data." The court held IP collection alone states the claim.
- Your privacy policy is not your consent mechanism. This is the misconception Camplisson demolishes. A policy tells people what you do; it does not obtain their agreement to do it. Those are different jobs, and a footer link does neither well.
- "Continued use = consent" is dead for tracking. Browsewrap fails because the pixel fires before the user acts. Only an affirmative step — a click — creates the consent CIPA's exception needs.
What this means for your site
Camplisson converts neatly into a checklist, because the court essentially published the failure mode. If Adidas had done the opposite of each defect, the consent argument would have been far stronger. Here is the opposite:
- Show a real consent banner — conspicuous, on entry, before any non-essential pixel fires. Not a footer link. Not fine print. An actual, visible request.
- Block trackers until the visitor clicks. TikTok, Bing, Meta, GA4 and the rest must not fire on page load. The whole browsewrap problem is that tracking happened before any action — so make the action come first.
- Use clickwrap, not browsewrap. Require an affirmative choice. It creates both the legal assent CIPA wants and a record you can produce later.
- Log every consent decision — what was shown, what was chosen, and when — so you can prove tracking only began after agreement.
- Match the disclosure to reality. If a pixel uses advanced matching that ties data to a real identity, your notice should reflect that, not describe vague "analytics."
Worried your site has this exposure?
Scan free in about 10 seconds to see every tracker firing on your site — including the pixels loading before any consent, the exact defect in Camplisson. It's the same scan a plaintiff firm would run before drafting a complaint.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What is Camplisson v. Adidas about?
Did Adidas win or lose?
Why did Adidas's consent defense fail?
Is collecting only an IP address enough to be a "pen register"?
How is this different from Rounds v. DDI, where the case was dismissed?
Does a privacy policy count as consent under CIPA?
Does this case create risk for my website?
Related cases & reading
D'Antonio v. CNN: The CIPA Case That Survived Dismissal Another 2026 pen-register win — this time against a publisher's adtech stack. Rounds v. DDI: How a CIPA Pen-Register Claim Gets Dismissed The mirror image — where the same theory failed, and why. CIPA Lawsuit Tracker 2026: Every Website Wiretapping Case The running index of CIPA tracking suits, outcomes, and what they mean.Sources
- CourtListener — Docket, Camplisson v. Adidas America, Inc., No. 3:25-cv-00603 (S.D. Cal.). Confirms filing, parties, Judge Curiel, the Nov. 14, 2025 hearing, and the Nov. 18, 2025 order denying the motion to dismiss (ECF No. 32).
- CIPAWorld — "Pixel-Tracking Gets Its Third Stripe: Adidas Learns CIPA Isn't Optional" (Nov. 28, 2025). Details the trackers, AutoAdvanced Matching, and the browsewrap consent analysis.
- Casemine — Camplisson v. Adidas America, Inc., No. 25-603 (S.D. Cal.). Reproduces the court's recitation of the § 638.50(b) / § 638.51 pen-register theory and the browsewrap / Nguyen v. Barnes & Noble discussion.
- Traverse Legal — "CIPA Pen Register Claims After Camplisson v. Adidas" (Feb. 2026). Analyses the broad, technology-neutral reading and the browsewrap-vs-clickwrap distinction.
- Fisher Phillips — "Court Allows CIPA Claim Involving Third-Party Pixels to Proceed, Ignores Contrary Case Law" (Dec. 4, 2025). Confirms the IP-only holding, standing, and that the court didn't address conflicting authority.
- Consumer Finance + Privacy Counsel — "Court Upholds Privacy Claims Against Website Tracking: Finding Lack of Conspicuous or Affirmative Consent" (Nov. 29, 2025). Names Judge Curiel and details the footer / small-font disclosure findings.
- Fox Rothschild / FIC Law — "Pixels, Cookies, and Consent Have Become High Risk in California" (Mar. 2026). Covers § 637.2 statutory damages and the browsewrap weakness.
- National Law Review / Robinson+Cole — "What Camplisson v. Adidas Am., Inc. Means for Business Websites" (Jan. 2026). Summarises the ruling, the two grounds for dismissal, and the consent-pleading template.
Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the primary decision is reported at 2025 WL 3228949 (S.D. Cal. Nov. 18, 2025). Status is stated as of July 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.