ConsentPixel – Privacy · Verified

CIPA Case Watch · Issue 04 — September 2026

The Split Sharpens — And the Pixel Theory Goes National

Last cycle was about verdicts. This one is about division. A California federal court let some tracking claims against Wayfair proceed while tossing others in the same order; a $3.85M settlement won final approval — then drew an appeal; and the pen-register theory keeps winning for defendants in one courtroom while §631 wiretapping claims survive in the next. Meanwhile the tracking-pixel theory spread past California's borders — into a Colorado hospital suit and beauty retail. Here's the Good, the Bad, and the Ugly.

CP ConsentPixel Team September 2026 12 min read CIPA Case Watch · Issue 04
Split
Wayfair: §631 & trap-and-trace survive; pen register tossed — one order
$3.85M
LA Times settlement won final approval — now under appeal, payments stayed
Beauty
Ulta becomes the latest retail brand hit with a Meta-Pixel CIPA suit
National
The pixel theory surfaces in Colorado — beyond CIPA's California reach

The shift this cycle

If last cycle proved CIPA claims can reach a jury, this cycle proved how unevenly they land. The clearest example arrived on August 13, when a Central District of California judge ruled on Wayfair's motion to dismiss and split the difference cleanly: the pen-register theory was dismissed, but the §631 wiretapping claim and a trap-and-trace theory were allowed to proceed — all in the same order. That single ruling is the whole state of CIPA law in miniature.

Three threads define this cycle. First, the pen-register theory keeps losing for defendants who challenge it head-on — a genuine bright spot for operators. Second, the §631 "contents" theory keeps surviving, and it reached a new vertical: beauty retail, with a proposed class action against Ulta. Third, the pixel theory stopped being a California-only story — a Colorado hospital was sued over the same Meta Pixel fact pattern, on different legal grounds, showing the underlying argument travels even where CIPA can't.

We're not a law firm, and this is not legal advice. We track these decisions because each tells website operators something concrete about their exposure. This issue names the trend that matters — a hardening split that leaves the pre-consent firing problem exactly where it's always been: unprotected in every forum.

Three theories, one reminder. §631 (wiretapping) targets the contents of communications intercepted in transit; §638.51 (pen register / trap-and-trace) targets addressing and routing data. The pen-register theory is where defendants are winning; §631 is where plaintiffs keep surviving. No pending reform touches §631 — and the pre-consent firing gap loses under it in every forum.
🟢 The Good — the pen-register defense holds

The Good: the pen-register theory keeps failing

For operators, the most reliable defense trend of 2026 held firm this cycle: when defendants challenge the "pen register / trap-and-trace" theory directly, courts increasingly reject it. Two data points reinforced that.

Limas v. Wayfair LLC — pen-register claim dismissed

C.D. California Aug. 13, 2026 §638.51 pen register
✓ Pen-register theory dismissed (without leave to amend)
🛋️ Home goods · multi-platform tracking

In Limas v. Wayfair, the plaintiff alleged Wayfair ran tracking tools tied to TikTok, Meta, Pinterest, Snapchat, X, and Reddit, and argued those tools were both pen registers and trap-and-trace devices under §638.51. The court dismissed the pen-register half without leave to amend — the plaintiff didn't rebut Wayfair's argument that a recent state appellate decision, Smith v. LoanDepot.com (Cal. Ct. App., Apr. 2026), forecloses the theory.

That's the good news for operators: a growing line of authority now treats the pen-register label as a poor fit for ordinary website software. When a defendant makes the argument squarely, this theory is increasingly a loser.

✦ What this means for your site

The pen-register theory is the most defensible to fight — but notice what didn't get dismissed (see The Bad). A win on one theory in the same order that lets another proceed isn't a defense you'd choose to rely on. The reliable position is not presenting the fact pattern at all.

Smith v. LoanDepot.com — the appellate anchor

Cal. Court of Appeal Apr. 8, 2026 §638.51 pen register
✓ Appellate authority against the pen-register theory
⚖️ Precedent · cited in Wayfair

The reason Wayfair's pen-register claim fell is that defendants now have state appellate authority to point to. Smith v. LoanDepot.com is the decision courts are increasingly citing to foreclose the theory that everyday website trackers are "pen registers." Its value is durability: a Court of Appeal ruling carries far more weight than a single trial judge's order, and it's now doing exactly that work across new cases.

The caveat: California appellate courts are still preparing to rule on the broader question of whether CIPA reaches website tracking at all — with the closely watched Variety Media pen-register appeal drawing a tentative ruling in late August — tentative, not final, so the picture could shift again.

✦ What this means for your site

Your counsel now has real appellate footing against the pen-register theory — worth knowing if you face a §638.51 claim. But this authority does nothing for §631 wiretapping claims, which is where the real volume and the surviving cases sit.

SB 690 clears the legislature — the pen-register theory loses ground in Sacramento too

Passed both houses · awaiting the Governor

The defense trend wasn't only judicial this cycle. On the final days of the session (late August 2026), the California Legislature passed SB 690 — the first meaningful CIPA reform in years — and sent it to Governor Newsom, who has until roughly the end of September to sign or veto it. If signed, it would remove the private right of action for the pen-register / trap-and-trace theory (§638.51) on websites, leaving that claim enforceable only by the Attorney General, and would apply retroactively to certain pending §638.51 claims within a two-year window tied to a January 1, 2027 operative date.

Be precise about what it does not do, because the headlines overstate it: SB 690 leaves §631 wiretapping and §632 recording claims completely untouched — and §631 is the provision behind most Meta Pixel, session-replay, and chatbot suits. The likely result isn't fewer cases; it's the same cases reframed as §631 claims. As of publication SB 690 has passed but is not yet law — the Governor's decision is the thing to watch.

✦ What this means for your site

Don't deprioritize remediation on the strength of SB 690. Even if signed, it narrows one theory while the most expensive one — §631, at $5,000 per violation under Cal. Penal Code §637.2 — survives intact. Your exposure doesn't disappear; it moves.

A dismissal on one theory doesn't fix what fires on your site

Every surviving claim this cycle started with a tracker firing before consent. See what fires on your site before the banner renders — the same thing a plaintiff scanner looks for first. About 10 seconds, no account.

Scan your site free →
🔴 The Bad — §631 survives, and a new vertical joins

The Bad: the wiretapping theory keeps surviving

For every pen-register win, the §631 "contents" theory kept advancing — and this cycle it reached a mainstream consumer brand.

Limas v. Wayfair LLC — §631 & trap-and-trace survive

C.D. California Aug. 13, 2026 §631(a) / trap-and-trace
◐ Split ruling — key claims proceed
🛋️ Home goods · multi-platform tracking

The same Wayfair order that dismissed the pen-register claim let the §631(a) wiretapping claim and a trap-and-trace theory proceed. On trap-and-trace, Wayfair argued the device must capture incoming impulses while the trackers captured data outgoing from users — but the court said Wayfair was looking at the wrong recipient: the question wasn't whether the communication was incoming to Wayfair.

This is the pattern operators should internalise: the theories that survive are the ones about intercepting the contents and routing of a visitor's communications — and detailed allegations about multi-platform tracking are increasingly enough to clear a motion to dismiss.

✦ What this means for your site

Winning the pen-register argument doesn't end the case if §631 survives alongside it. A defendant running six ad-tech trackers still faces discovery and settlement pressure on the surviving claims. The trackers firing before consent are what generate every one of these theories.

Hartigan v. Ulta Beauty — Meta Pixel class action

N.D. California Filed Aug. 2026 §631 · ECPA · intrusion
✕ Newly filed — beauty retail joins the wave
💄 Beauty / retail · Meta Pixel

A proposed class action alleges Ulta's website deployed the Meta Pixel and related trackers that intercepted the contents of visitors' communications — full URL strings and the specific products and content viewed — and transmitted them to Meta and other third parties without consent. Filed by plaintiff Raeanon Hartigan for a class of California website visitors dating to June 2024, the complaint stacks CIPA §631, the ECPA, and California constitutional privacy and intrusion-upon-seclusion claims, and alleges Ulta aided Meta's interception. Notably, it's brought by Swigart Law Group and Shay Legal — among the most active CIPA filers. Separately, a distinct Ulta matter on session-replay tracking drew an August ruling that the company's privacy policy alone was not enough to establish CIPA consent — a reminder that passive "by continuing to browse" notice does not meet the affirmative-consent standard.

The allegations are unproven and Ulta has not been found liable. What makes the filing notable isn't novelty — it's the vertical: the pixel wave has moved firmly into mainstream beauty and retail, where the Meta Pixel is nearly universal.

✦ What this means for your site

If you run the Meta Pixel and serve California visitors, this is your fact pattern. The Ulta complaint isn't exotic — it's the standard §631 "contents" theory applied to a routine retail tracking setup. The differentiator between a defendant and a bystander is whether the pixel fires before consent. This is general information, not legal advice.

🟠 The Ugly — a win under appeal, and a theory without borders

The Ugly: the split gets messier, and the theory travels

The genuinely uncertain developments this cycle are the ones that resist a clean "good" or "bad" reading — a settlement that's approved but frozen, and a pixel suit in a state where CIPA doesn't even apply.

Mirmalek v. Los Angeles Times — $3.85M approved, then appealed

N.D. California Final approval Jun. 26, 2026 §638.51 pen register
◐ Settled ($3.85M) — approval under appeal
📰 Media / publishing · ad-tech trackers

The LA Times won final approval of a $3.85M class settlement over three ad-tech trackers (TripleLift, GumGum, Audiencerate) that allegedly collected visitor data without consent — brought, notably, on the pen-register theory. Then an appeal was filed, and payouts are stayed until it resolves.

Here's why it lands in the Ugly column: the settlement rewards the same §638.51 pen-register theory that defendants are successfully dismissing elsewhere (see Wayfair, LoanDepot). A company paid $3.85M to resolve a theory another company just defeated at the pleading stage weeks later. That's not a coherent risk signal — it's the split personified, and it means settlement math can't be reduced to "which theory is winning this month."

✦ What this means for your site

Don't read the pen-register dismissals as "you're safe." The LA Times shows a company can still pay millions on a theory that's losing in other courtrooms — because settlement pressure comes from cost and uncertainty, not from which way the last ruling went. The only stable variable you control is whether trackers fire before consent.

Miller v. UCHealth — the pixel theory crosses state lines

D. Colorado (Denver) Filed Aug. 2026 HIPAA / privacy (not CIPA)
✕ Newly filed — same pixel, different statute
🏥 Healthcare · Meta Pixel · "Find a Doctor"

A proposed class action alleges UCHealth deployed the Meta Pixel on its "Find a Doctor" feature and possibly its patient portal, capturing users' condition and symptom searches along with identifying details, and sending that to Meta without consent. Filed by Larimer County resident Patrick Miller in federal court in Denver, the complaint is built on HIPAA and privacy grounds — not CIPA (Colorado isn't a CIPA jurisdiction). As in several of these suits, Meta is not named; the website operator is the sole defendant.

We're including it here precisely because it isn't a CIPA case. It's the same Meta-Pixel-on-a-health-site fact pattern that drives the California wave — reproduced in a state with no wiretapping analog, on entirely different legal theories. The allegations are unproven and UCHealth has not been found liable.

✦ What this means for your site

"We don't have California traffic" is not the shield it used to be. The pixel-tracking theory is portable — it reappears under HIPAA, under other states' wiretap laws, and under consumer-protection statutes. The underlying trigger is identical everywhere: sensitive data sent to a third party before the visitor agreed. ConsentPixel — Privacy · Verified is the detection and state-law consent layer for that trigger; it is not a HIPAA product and does not make any site "HIPAA compliant." This is general information, not legal advice.

The patterns: what's changed, what hasn't

Strip away the individual rulings and three patterns define this cycle — two new, one stubbornly constant.

Development this cycleWhat it changesYour exposure
Pen-register theory keeps losing (Wayfair, LoanDepot)A defensible argument against §638.51 claims, now with appellate backingLower — if that's the only theory pled
§631 "contents" theory keeps surviving (Wayfair, Ulta)The high-volume theory clears motions to dismiss on detailed tracking allegationsUnchanged — the main risk
Settlement approved but appealed (LA Times $3.85M)Shows companies still pay on theories losing elsewhere; settlement ≠ meritsCost-driven, not theory-driven
Beauty/retail joins the wave (Ulta)Mainstream Meta-Pixel setups are now targets, not just healthcare/mediaHigher for retail operators
Theory goes national (UCHealth, Colorado)Same pixel fact pattern reappears under HIPAA / other states' lawsPortable beyond California
The pre-consent firing gapNothing — it's the trigger under every theory, in every forumThe constant across all cases
SB 690 passed the legislature (awaiting Governor)Would strip the private right of action for §638.51 pen-register claims — but only if signed, and §631 stays intactWatch — not yet law; §631 exposure unchanged
Defense also landed clean wins (Chrysler, food banks, UnitedHealthcare)Standing and party-exception dismissals show prepared defendants still prevailLower — with genuine consent architecture

The throughline is unchanged from every prior issue: whichever theory is winning this month, they all begin at the same place — a tracker that transmits a visitor's activity to a third party before the visitor consented. The pen-register defense might spare you one claim; it does nothing about the §631 claim filed alongside it, or the same fact pattern refiled in Colorado under HIPAA.

⚠ Don't over-read the pen-register wins
The dismissals are real, but they're narrow. They resolve one theory, often in one order that lets §631 proceed, and they don't stop a plaintiff from settling — or refiling the fact pattern in another state under another law. Treating "the pen-register theory is losing" as "tracking litigation is cooling" is the misread this cycle is designed to prevent.

What to do right now

None of this changes the practical playbook — it sharpens why it matters. Four steps, in order.

1

Find what fires before consent

Every surviving claim this cycle — Wayfair §631, Ulta, UCHealth — starts with a tracker transmitting before the visitor agreed. Scan your site to see exactly what loads pre-consent, the way a plaintiff scanner would.

2

Treat the Meta Pixel as the highest-risk tag

The Ulta and UCHealth suits both turn on it. If you run the Meta Pixel, confirm it doesn't fire — and doesn't transmit URL or form data — until consent. This is the single most-litigated tracker of 2026.

3

Don't rely on your jurisdiction

UCHealth shows the theory travels. Whether you have California traffic or not, block non-essential trackers until consent and honour opt-out signals — the standard that holds under CIPA, HIPAA-adjacent claims, and every state wiretap law.

4

Keep the proof

Settlements like the LA Times turn on what a site actually did. A timestamped, page-scoped consent log is what lets you show a tracker was gated — the evidence that a privacy policy alone can't provide.

The take

This cycle's headline isn't a verdict or a number — it's a widening split. The pen-register theory is losing; the §631 wiretapping theory is winning; a settlement got approved on a theory that's failing elsewhere; and the whole fact pattern jumped state lines into a jurisdiction where CIPA doesn't apply. If you're trying to time your risk to "which theory is ahead," this cycle is the argument against that entire approach.

Because underneath the divergence, every one of these cases — the survivor, the settlement, the out-of-state copy — traces to the same millisecond: a tracker firing before consent. That's the one variable you control, and it's the one that's dispositive in every forum.

We'll publish the next CIPA Case Watch covering October 2026 — including any ruling in the California appellate pen-register case, and whether the LA Times appeal moves. For the full, continuously updated case database, see our CIPA Lawsuit Tracker.

Is your site firing before consent?

No ruling, settlement, or bill fixes a tracker that fires before the banner renders. Run the same scan a plaintiff firm would — in about 10 seconds.

Free site scan →
CP

ConsentPixel Research Team

CIPA Litigation Research & Case Analysis

The ConsentPixel — Privacy · Verified research team monitors CIPA case filings, decisions, and settlements to translate legal developments into practical guidance for website owners. CIPA Case Watch publishes 2–3 times a month. All case summaries are sourced from public court records and legal reporting. This series does not constitute legal advice.

Legal disclaimer: This article is published for informational purposes only and does not constitute legal advice. Case summaries are based on publicly available court records and legal reporting, including analysis published by the National Law Review, Spencer Fane LLP, Law360, Loeb & Loeb LLP, Klein Moynihan Turco LLP, Top Class Actions, and the Denver Post (via HealthExec and Daily Hodl). Hartigan v. Ulta Beauty and Miller v. UCHealth are newly filed complaints; the allegations described are unproven and neither defendant has been found liable. Limas v. Wayfair is a motion-to-dismiss ruling, not a final judgment. The LA Times settlement was resolved without any admission of wrongdoing and is under appeal. The $5,000-per-violation figure, where referenced, reflects statutory damages under California Penal Code §637.2. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel; it is not a HIPAA product and does not make any website "HIPAA compliant." CIPA and website-tracking litigation are fact-specific and rapidly evolving; for advice on your situation, consult a qualified privacy attorney.

Scroll to Top