Ingraham v. Capital One Financial Corp.
The most important financial-data CIPA case of 2026 has two faces. The claims survived dismissal because the data at issue — credit outcomes, income, FICO segments — was genuinely sensitive. Then the class was denied because tracking harms are inherently individual. Here's the full breakdown, and why both halves matter for your site.
What the case is about
In August 2024, a group of Capital One customers and credit-card applicants — the case is captioned Shah v. Capital One on the docket, but is widely known by co-plaintiff Gary Ingraham's name — sued the bank over the tracking technology on its credit-card application and pre-approval website.[5] The allegation wasn't that Capital One suffered a data breach. It was that the bank had quietly built third-party tracking into the most sensitive pages a consumer can visit: the ones where you type in your income, your employment, and apply for credit.
According to the complaint, Capital One's application pages ran a deep stack of third-party tools — the Meta Pixel, Google Analytics, Adobe Analytics, DoubleClick, New Relic, Skai/Kenshoo, Snowplow, BioCatch, and Tealium — that did more than measure traffic. They allegedly transmitted, to outside advertising and analytics companies, information including employment status, bank account type, citizenship and dual-citizenship status, credit-card pre-approval and approval/denial outcomes, FICO score segments, income bands, names, email addresses, and phone numbers.[1]
The human detail that anchored the case: plaintiff Gary Ingraham allegedly applied for a Capital One card, was denied — and then began seeing credit-card ads from Discover, Chase, and Chime in his Facebook feed. Co-plaintiff Deia Williams described the same pattern, saying she was "constantly bombarded" with credit-card ads after her own denial.[4] To the plaintiffs, that was proof their financial circumstances had been broadcast to the ad-tech ecosystem. None of them, they said, had signed any authorization to send that data to third or fourth parties.
The legal theory — §631 and the "sensitive data" injury
The plaintiffs brought a stack of claims, but the ones that matter here are under the California Invasion of Privacy Act (CIPA) §631 — the wiretapping/interception provision — alongside the federal Electronic Communications Privacy Act (ECPA) and the California Consumer Privacy Act (CCPA). Unlike the pen-register theory driving many other 2026 cases, §631 targets the interception and unauthorized disclosure of the contents of a confidential communication to a third party.[7]
Capital One moved to dismiss on the arguments defendants usually win with: that visitors consented via the posted privacy policy, that no third party read anything "in transit," and that the plaintiffs hadn't suffered any concrete injury. The bank's strongest card was Article III standing — the doctrine that has quietly become the most powerful defense in tracking litigation. Courts increasingly refuse to treat the mere presence of a pixel as a real-world harm; a plaintiff has to show something private was actually disclosed and that a reasonable person would object.[3]
Across 2026, courts have drawn a sharp line between routine behavioural metadata (which pixels collect all the time, and which increasingly fails to establish a concrete injury) and genuinely sensitive data — medical, financial, or highly personal information — whose disclosure a reasonable user would find "highly offensive." Where a case falls on that line usually determines whether it survives.
Why the claims survived
On the motion to dismiss — decided in May 2026 — Judge Trina L. Thompson let the core privacy claims proceed. The CIPA §631, ECPA, CCPA, negligence, and unjust-enrichment claims all survived.[5] The reason was exactly the sensitivity point: this wasn't vague "we collected personal information" pleading. The plaintiffs identified specific, sensitive financial data — approval/denial outcomes, income bands, FICO segments — allegedly disclosed to advertisers. On the consent argument, the court followed the Javier v. Assurance IQ line, holding that whether visitors actually consented through a privacy policy is a fact question that can't be resolved on a motion to dismiss.[4]
"Courts are increasingly unwilling to treat every cookie, pixel, beacon, SDK, or session-replay tool as a constitutional injury. But Ingraham shows that the analysis changes when the alleged data involves financial eligibility, employment, citizenship, income, FICO segments, [or] application denial..."
— Security Boulevard analysis of the Ingraham dismissal orderThe one plaintiff who lost — and why
In the same order, the court delivered a sharp lesson in how standing actually works. It dismissed Gary Ingraham himself from the case — not because his data was less sensitive, but because of what he did after filing suit: he submitted two more credit-card applications on Capital One's website.[3] You cannot credibly claim a reasonable expectation of privacy in data you keep voluntarily handing to the same company you're suing. Co-plaintiff Deia Williams, who did not do this, retained standing and carried the case forward.[8]
The turning point: surviving dismissal isn't winning
Here is what makes Ingraham genuinely important, and why it's more than "another pixel case." Surviving a motion to dismiss is the stage most defendants fear — it's the point where settlement pressure becomes enormous, because a class-wide judgment in a financial-data wiretapping case can reach eight or nine figures.[6] Plaintiffs' firms bank on that pressure. But in June 2026, the case reached the next stage — class certification — and the story reversed.
On June 16, 2026, Judge Thompson denied class certification for both the proposed nationwide class and the California subclass.[2] To certify a class under Rule 23(b)(3), plaintiffs must show that common questions "predominate" over individual ones. In tracking cases, that is proving very hard to do — and the court identified three independent reasons the individual questions overwhelmed the common ones:
The deep irony is that the plaintiffs' claims survived dismissal because the questions of consent and sensitive-data disclosure were fact-specific — and then failed certification for the same reason: fact-specific questions can't be answered class-wide.[2] What helps a plaintiff at the pleading stage sinks them at certification.
Where it stands (as of July 2026)
As of July 2026, the litigation is in an unusual posture. The individual claims survive — named plaintiff Deia Williams cleared standing and her CIPA §631, ECPA, and CCPA claims against Capital One remain live. But there is no class: the June 16, 2026 order means the case can no longer be pursued on behalf of the thousands of applicants whose data was allegedly shared, only on behalf of the individual plaintiff(s) who remain.[2] That transforms the economics — from a potential nine-figure class exposure to an individual dispute.
How Ingraham fits the 2026 landscape
Ingraham sits at the intersection of two of the most important trends in 2026 tracking litigation. On the merits, it's the flagship "sensitive data changes everything" case — the clearest illustration that financial and eligibility data is treated very differently from routine browsing metadata. On procedure, it's now a leading example of the emerging "class certification firewall." Read alongside its siblings, the pattern is unmistakable:
| Case | Court | What it held |
|---|---|---|
| Ingraham v. Capital One (this case) | N.D. Cal. | Sensitive financial data kept CIPA §631 claims alive; class certification then denied — individualized data, consent, and injury. |
| Calhoun v. Google | N.D. Cal. (Jun 2025) | Class certification denied on consent grounds — individualized questions about user knowledge predominated.[2] |
| In re Meta Pixel Tax Filing Cases | N.D. Cal. (Mar 2026) | Certification denied — individualized standing and statute-of-limitations issues predominated.[2] |
| Torres v. Prudential | N.D. Cal. (Apr 2025) | Summary judgment for defendant — §631 needs real-time reading of contents, not post-hoc data capture.[9] |
The through-line: even when a website-tracking claim is strong enough to survive dismissal — especially on sensitive data — the individualized nature of consent, data flow, and injury makes class treatment increasingly hard to obtain in the Northern District of California. For plaintiffs, that removes much of the settlement leverage. For businesses, it's a reason to defend rather than fold.[6]
Why this case matters for website operators
For most website owners, the single most useful takeaway is the sensitivity gradient. If your site collects and could transmit genuinely sensitive data — financial eligibility, health information, application outcomes, income — you are in Ingraham territory, where courts take the alleged injury seriously and claims survive dismissal. If your site collects routine marketing analytics, you're in a very different, much lower-risk position, and standing defenses tend to work.[3] The lesson isn't "tracking is fine now" — it's "the stakes scale with the sensitivity of what your trackers can see."
The second takeaway is subtler and more strategic. Ingraham tells businesses that even a claim that survives dismissal may never become a class — which changes the settle-or-fight calculation. But that is a litigation advantage, available only after you've been sued, spent months in discovery, and paid to brief a certification fight. It is not a substitute for not having the exposure in the first place. The cheapest case is the one that never gets filed because your trackers weren't firing on your application pages before consent.
What this means for your site
The durable lesson from Ingraham is about where your trackers run and what they can see. Capital One's exposure came from third-party tools firing on credit-card application pages — the exact pages where the most sensitive data is entered. The single most protective thing any site can do is ensure that non-essential third-party trackers do not fire on sensitive pages (checkout, application, account, health, or financial forms) before a visitor has consented — and ideally not at all on those pages.
That is precisely what ConsentPixel is built to do: block third-party trackers until a visitor opts in, keep them off the pages where sensitive data lives, and log every consent decision so you have a record if a demand letter arrives. The Javier-style consent question that kept Capital One in court — "did the visitor actually, provably consent before anything fired?" — is exactly the question a proper consent record answers in your favour.
And because this entire dispute began with a stack of third-party tags on the defendant's pages — nine separate tools, several of which a site owner might not even realise were transmitting form data — the first, cheapest step is simply seeing what actually runs on your pages, and whether any of it fires before consent on the pages that matter most.
Worried your site has this exposure?
Scan free in about 10 seconds to see every third-party tracker firing on your site — including the ones loading on sensitive pages before consent, exactly the pattern at the heart of this case. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What was Ingraham v. Capital One about?
Did Capital One win or lose?
Why was one plaintiff (Gary Ingraham) dismissed?
Does denying class certification mean the tracking was legal?
What's the practical takeaway for website owners?
Sources
- Security Boulevard — "Give a Mouse a Cookie: California Court Partially Dismisses Cookie Tracking Case Against Capital One". Lists the nine tracking tools and the sensitive-data categories; summarises the standing analysis.
- Fisher Phillips LLP — "California Federal Court's Denial of Class Certification May Reshape Website Tracking Litigation" (June 16, 2026 decision; predominance analysis; Calhoun and Meta Pixel Tax comparisons).
- Fisher Phillips LLP — "What 7 Recent Court Decisions Tell You About Today's Website Privacy Liability" ("Ingraham v. Capital One: Financial Data Changes Everything"; the post-filing reapplication standing point).
- FindLaw — Shah v. Capital One Financial Corporation, Order on Motion to Dismiss (N.D. Cal.). Primary order text; plaintiff allegations and the Javier consent analysis.
- Benesch Law — "Tracking Technology Trouble: Shah v. Capital One Deepens Legal Risk Under CCPA and CIPA". Which claims survived and which were dismissed (CRA/SCA/CFAA).
- CyberAdviser (Blank Rome) — "Another Internet Tracking Class Action Failed at Certification — Here's Why It Matters". Settlement-pressure economics and the defend-vs-settle calculus.
- IAPP — "Beyond data breaches: Court ruling signals broader CCPA liability for tracking technologies". Background on CIPA §631 and ECPA as applied to website trackers.
- Bloomberg Law — "Capital One Fails to Escape Suit Over Meta, Google Data Sharing" (Williams retained standing; Ingraham dismissed; Judge Thompson, May 2026).
- Fenwick — "California Federal Court Denies Class Certification in CIPA Pixel-Tracking Case". The N.D. Cal. class-certification-denial trend.
- CourtListener — Shah v. Capital One Financial Corporation, No. 3:24-cv-05985 (N.D. Cal.). Public docket; filing date and case history.
Sources accessed and summarised July 2026. Case status is current as of the publication date and may change as litigation proceeds.
Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the case is docketed as Shah v. Capital One Financial Corp., No. 3:24-cv-05985 (N.D. Cal.), before Judge Trina L. Thompson. Status is stated as of July 6, 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.