ConsentPixel – Privacy · Verified

⏳ Newly filed · Pending

Kimmons v. NFL Enterprises LLC

A CIPA class action says NFL.com deployed 182 third-party trackers before a visitor could make any choice — and kept 186 running after opt-out, including canvas fingerprinting and a session recorder that allegedly captured keystrokes. It's the most detailed "your opt-out did nothing" complaint of 2026. Here's what forensic testing claims to have found, the legal theory behind it, and what it signals for every site with a consent banner.

ConsentPixel Research Published August 2026 10 min read CIPA §631 · ECPA · session replay · fingerprinting
⚖️ Case snapshot
Court
Alameda County Superior Court (California state court)
Case No.
26CV197596
Filed
July 6, 2026
Status (as of Aug 2026)
Filed — pending, no ruling
Tracking tech
182 trackers · 4 canvas fingerprinting scripts · 1 session recorder (LogRocket) · 24 cookies
Plaintiff / counsel
Thelma Kimmons · Potter Handy · nationwide class + CA subclass

What the case is about

Lead plaintiff Thelma Kimmons is a San Francisco 49ers fan from San Leandro who, according to the complaint, visited NFL.com in and around January 2026 to do something entirely ordinary: check live scores and game schedules.[1] What she alleges happened next is the case. The moment she landed on the site — before she could configure any privacy preference — NFL.com allegedly loaded a roster of trackers operated by Google, The Trade Desk, Rubicon Project, OpenX, LogRocket, and Shape Security, fingerprinted her device, recorded her session, and transmitted her browsing data to advertising networks in real time.[2]

Filed July 6, 2026 in Alameda County Superior Court as Kimmons v. NFL Enterprises LLC, No. 26CV197596, the suit seeks to represent a nationwide class and a California subclass.[1] What sets it apart from the dozens of other website-tracking complaints filed this year isn't the theory — it's the specificity. The complaint is built on forensic testing of NFL.com, and the numbers it pleads are what make it land.

What forensic testing allegedly found

According to the complaint, forensic testing of NFL.com counted 182 third-party trackers running before any consent interaction — that is, before the visitor could accept, decline, or configure anything. Broken down, the alleged inventory was:

  • 182 third-party trackers firing on page load, before any privacy choice;
  • 24 cookies;
  • 4 separate canvas fingerprinting scripts;
  • 1 session recorder (LogRocket, per the complaint);
  • data flowing to four major advertising networks, including Google and The Trade Desk.[3]

Then comes the number that gives the case its edge. The complaint alleges that even after a user opts out, the site continued to run 186 third-party trackers — including 25 cookies, 4 canvas fingerprints, and the session recorder.[4] In other words, opting out didn't reduce the tracking; by the complaint's count, it went slightly up. That single allegation — more trackers after "opt-out" than a naïve reader would expect, and certainly not fewer — is the heart of the case.

Why the two numbers matter. The complaint pleads two distinct failures, not one. First, 182 trackers fired before any choice — the pre-consent gap. Second, 186 kept running after opt-out — the opt-out gap. A site could fix the first and still fail the second, because the tools that ignore opt-out (session recorders, fingerprinting) were never wired to the cookie banner in the first place.

The session recorder and the keystroke problem

The most legally dangerous allegation isn't the raw tracker count — it's what the session recorder allegedly captured. According to the complaint, the LogRocket session-replay tool recorded the full Document Object Model (DOM) state of each page along with enough interaction data to reconstruct the visit visually: mouse movements, clicks and their coordinates, hover events, scrolling, and navigation paths.[3] That alone is intrusive. But the complaint goes further:

The keystroke logging allegedly included the order and timing of individual keys typed into search bars and other input fields — whether or not the visitor ever submitted what they typed.

— Summary of the Kimmons complaint's session-replay allegations[3]

That distinction — capturing what someone typed even if they never hit enter — is what pulls the case out of "routing metadata" territory and into the contents of a communication. And the contents of a communication are exactly what CIPA's wiretapping provision, §631, is written to protect. This is why session replay on input fields is widely regarded as the single highest-risk tracking configuration in CIPA litigation: it's not capturing that you visited, it's capturing what you wrote.

The legal theory — a five-count stack

Where many CIPA complaints lead with a single provision, Kimmons bundles a broad set of state and federal theories, widening the standard §631/§638.51 pleading into something much harder to dispose of in one motion:[5]

The claims pleaded in Kimmons v. NFL

CIPA §631(a) — the wiretapping provision, targeting real-time interception of communication contents (the session-replay/keystroke theory). Federal Wiretap Act (ECPA) — carrying statutory damages of the greater of $10,000 or $100 per day per violation. California Computer Data Access and Fraud Act (CDAFA). California Constitution — the state constitutional right to privacy. Unfair Competition Law (UCL). CIPA damages are commonly cited at $5,000 per violation under Penal Code §637.2.

The strategic logic of the stack is straightforward: different theories survive different defenses. The §638.51 trap-and-trace theory has lost in several 2026 rulings that held cookies aren't a trap-and-trace device — but the §631 wiretapping theory, anchored to a session recorder capturing keystrokes, is a different and much harder-to-dismiss claim, because it targets contents rather than routing data.[5] Adding ECPA brings federal statutory damages into the mix; the constitutional and UCL claims add further avenues. A defendant has to knock out all of them, not one.

The consent banner cuts against the NFL here, not for it. NFL.com has a cookie consent banner, and the complaint engages with it directly — which is the point. A banner that visibly offers a choice, while forensic testing allegedly shows tracking continuing regardless, doesn't demonstrate consent; it frames the gap between what the interface promised and what the site did. That gap is what the plaintiff measured and attached statutory damages to.

Where it stands (as of August 2026)

The case is newly filed and pending. It was docketed July 6, 2026 as No. 26CV197596 in Alameda County Superior Court, brought by Potter Handy on behalf of a proposed nationwide class and California subclass.[1] The NFL has not yet answered, there has been no ruling, and every figure and characterization above comes from the complaint's allegations and the forensic testing it cites — none of it tested in court.

A note on sourcing. Details here come from the complaint as reported by Courthouse News (which quotes it directly), the National Law Review, Privado, and UniConsent — all listed in Sources. The complaint's own tracker counts (182 before consent, 186 after opt-out) are allegations based on forensic testing described in the filing; the NFL has not confirmed them and has not been found liable of anything.

The "opt-out that doesn't opt you out" wave

Kimmons is the most detailed example of a fast-growing 2026 theory: that a site's opt-out is cosmetic. It shares that DNA with a string of recent filings and settlements, and reading them together shows where the litigation is heading:

Case / partyWhat's alleged or resolvedStatus
Kimmons v. NFL (this case)182 trackers before consent; 186 after opt-out; session replay + keystroke capture; five-count stack.Filed Jul 2026
Conner v. ToyotaFingerprinting continued after visitors clicked "Decline"; cross-device ad tracking.Filed Jul 2026
Forbes MediaSettled a "trap and trace" class action.~$10M (May 2026)
Los Angeles TimesSettled a similar website-tracking claim.$3.85M

The through-line is a shift in what plaintiffs measure. Early CIPA tracking suits alleged, in effect, "you tracked me." This sub-wave alleges something more damning and more concrete: "your banner offered me a choice, I made it, and forensic testing shows it changed nothing." That's a story a jury understands instantly — and, because it's demonstrable from outside the company, it's cheap for a plaintiff firm to document.[2]

Read it honestly, though. This is an unproven complaint, not a ruling. The NFL will likely contest the forensic methodology, the counting of "violations," whether the plaintiff suffered a cognizable injury, and the reach of a 1967 statute over modern web tools. CIPA outcomes remain split and fact-specific. The value of Kimmons isn't that the NFL is liable — it's that the alleged configuration (pre-consent firing plus session replay that survives opt-out) is common, measurable, and now expensive.

Why this case matters for website operators

Neither problem the complaint describes is exotic — that's precisely why it should get every operator's attention. Firing on page load is the default in most tag-manager setups, and very few cookie banners were ever connected to session-replay or fingerprinting scripts.[4] The Kimmons complaint didn't uncover an exotic vulnerability; it measured an ordinary gap on a famous website and attached statutory damages to it. The same gap very likely exists on sites that believe their banner has them covered.

Two specific exposures fall out of the case:

  • The pre-consent gap. Trackers that fire the instant a page loads — before any choice — are the 182-tracker problem. A banner that appears after the tags have already fired is decorative.
  • The opt-out gap. Session recorders and fingerprinting scripts that were never wired to the banner keep running when a visitor opts out — the 186-tracker problem. And when a session recorder captures keystrokes in input fields, that's the §631 "contents" exposure, the hardest kind to defend.

What this means for your site

The durable lesson from Kimmons is that a consent banner is only as good as its enforcement, and that session replay deserves special caution. If your banner governs cookies but leaves session recorders and fingerprinting scripts firing — before consent and after opt-out — you have the exact two-part configuration this complaint is built around.

The protective posture is the same regardless of how CIPA case law evolves:

  • Block non-essential third-party trackers until consent. Nothing non-essential — cookie-based or cookieless — should load or transmit before a visitor chooses. That closes the 182-tracker gap.
  • Enforce opt-out on everything, including cookieless tools. Session replay and fingerprinting must stop when a visitor declines, not just cookies. That closes the 186-tracker gap.
  • Keep session replay off sensitive input fields — or disable keystroke capture entirely — to avoid the §631 "contents" exposure.
  • Log every consent decision so you can show the opt-out was honored, not just offered.

That's what ConsentPixel is built to do — block third-party trackers at the browser level until a visitor genuinely consents, honor the opt-out across cookie-based and cookieless tools alike, and log each decision as evidence. This is general information, not legal advice; consult qualified counsel about your specific exposure.

And because the gap is measurable from outside — which is exactly how the plaintiff documented it — the cheapest first step is to run the same measurement on your own site: see what fires before consent, and what keeps firing after opt-out.

How many trackers fire on your site before consent?

Scan free in about 10 seconds to see every third-party tracker on your site — the ones firing before any choice, and the ones that keep running after opt-out. It's the same measurement the Kimmons complaint is built on.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What is Kimmons v. NFL about?
It's a proposed class action filed July 6, 2026 in Alameda County Superior Court (No. 26CV197596) by lead plaintiff Thelma Kimmons, alleging that NFL.com deployed 182 third-party trackers before visitors could make any privacy choice — including four canvas fingerprinting scripts and a session recorder — and continued running 186 trackers even after users opted out. It brings claims under the California Invasion of Privacy Act (CIPA), the federal Wiretap Act (ECPA), the California Computer Data Access and Fraud Act, the California Constitution, and the Unfair Competition Law. The case is newly filed; the allegations are unproven and the NFL has not been found liable. This is general information, not legal advice.
Why does the "186 trackers after opt-out" number matter?
Because it targets the gap between what a consent banner promises and what a website actually does. The complaint alleges that opting out didn't stop the tracking — by its count, 186 third-party trackers kept running afterward, including a session recorder and fingerprinting scripts. Those tools typically don't rely on cookies, so a banner that only manages cookies won't stop them. The allegation reframes the case from "you tracked me without asking" to "you offered me a choice, I opted out, and it changed nothing" — a more concrete and damaging theory.
What did the session recorder allegedly capture?
According to the complaint, the LogRocket session-replay tool recorded the full page state plus enough interaction data to reconstruct the visit visually — mouse movements, clicks and coordinates, hover events, scrolling, and navigation paths. Critically, it allegedly logged keystrokes typed into search bars and other input fields, including the order and timing of individual keys, whether or not the visitor ever submitted what they typed. Capturing what someone types is capturing the contents of a communication, which is what CIPA's §631 wiretapping provision protects — making session replay on input fields the highest-risk tracking configuration in CIPA litigation.
What laws does the case rely on?
Five theories. CIPA §631(a), the wiretapping provision, targeting real-time interception of communication contents. The federal Wiretap Act (ECPA), which carries statutory damages of the greater of $10,000 or $100 per day per violation. The California Computer Data Access and Fraud Act (CDAFA). The California constitutional right to privacy. And California's Unfair Competition Law (UCL). CIPA damages are commonly cited at $5,000 per violation under Penal Code §637.2. Bundling multiple theories makes the complaint harder to dispose of in a single motion, since different claims survive different defenses.
How do I know if my own site has this problem?
Measure it the way the complaint did: check how many third-party trackers fire on page load before any consent choice, then opt out and check what keeps running. A free scan does this in about ten seconds and shows every tracker that loads and when. Pay special attention to session-replay and fingerprinting tools, which often ignore a cookie banner entirely. If anything non-essential fires before consent or survives opt-out — especially a session recorder on pages with input fields — that's the exact exposure this case targets, and the fix is to block those trackers until consent and enforce the opt-out across all of them.

Sources

  1. Courthouse News Service — "NFL accused of collecting, sharing website users' private data" (Jul. 7, 2026). Quotes the complaint, including the tracker counts, the "continues to run 186 third party trackers" after opt-out allegation, and the plaintiff and venue.
  2. Privado — "NFL hit with CIPA class action over website pixels that ignored consent". Summarises the two-part gap (pre-consent firing and opt-out), the five-count legal stack, and the named trackers.
  3. UniConsent — "NFL.com CIPA Lawsuit: When Opting Out Doesn't Stop Tracking". Details the LogRocket session recorder's alleged DOM and keystroke capture and the case number (No. 26CV197596).
  4. Axeptio — "Could the NFL Class Action Make the Case for European CMPs?". Covers the forensic-testing figures and the ECPA/§637.2 damages exposure.
  5. National Law Review — "No Privacy in the Huddle? NFL.com Hit with CIPA Class Action Over 182 Website Trackers". Case caption, docket, plaintiff background, and the named tracker operators.

Sources accessed and summarised August 2026. This case is newly filed; all figures and statements from the complaint are allegations based on forensic testing described in the filing, and status is current as of the publication date and may change as litigation proceeds.

Disclaimer: This page is for general informational purposes only and is not legal advice. Kimmons v. NFL Enterprises LLC is a newly filed complaint; all allegations described — including the forensic tracker counts — are unproven, and nothing here should be read as a finding that the NFL violated any law. Case details are drawn from the complaint as reported in the legal and news coverage listed above. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2; ECPA damages figures are as provided by that statute. Status is stated as of August 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.

Scroll to Top