Kimmons v. NFL Enterprises LLC
A CIPA class action says NFL.com deployed 182 third-party trackers before a visitor could make any choice — and kept 186 running after opt-out, including canvas fingerprinting and a session recorder that allegedly captured keystrokes. It's the most detailed "your opt-out did nothing" complaint of 2026. Here's what forensic testing claims to have found, the legal theory behind it, and what it signals for every site with a consent banner.
What the case is about
Lead plaintiff Thelma Kimmons is a San Francisco 49ers fan from San Leandro who, according to the complaint, visited NFL.com in and around January 2026 to do something entirely ordinary: check live scores and game schedules.[1] What she alleges happened next is the case. The moment she landed on the site — before she could configure any privacy preference — NFL.com allegedly loaded a roster of trackers operated by Google, The Trade Desk, Rubicon Project, OpenX, LogRocket, and Shape Security, fingerprinted her device, recorded her session, and transmitted her browsing data to advertising networks in real time.[2]
Filed July 6, 2026 in Alameda County Superior Court as Kimmons v. NFL Enterprises LLC, No. 26CV197596, the suit seeks to represent a nationwide class and a California subclass.[1] What sets it apart from the dozens of other website-tracking complaints filed this year isn't the theory — it's the specificity. The complaint is built on forensic testing of NFL.com, and the numbers it pleads are what make it land.
What forensic testing allegedly found
According to the complaint, forensic testing of NFL.com counted 182 third-party trackers running before any consent interaction — that is, before the visitor could accept, decline, or configure anything. Broken down, the alleged inventory was:
- 182 third-party trackers firing on page load, before any privacy choice;
- 24 cookies;
- 4 separate canvas fingerprinting scripts;
- 1 session recorder (LogRocket, per the complaint);
- data flowing to four major advertising networks, including Google and The Trade Desk.[3]
Then comes the number that gives the case its edge. The complaint alleges that even after a user opts out, the site continued to run 186 third-party trackers — including 25 cookies, 4 canvas fingerprints, and the session recorder.[4] In other words, opting out didn't reduce the tracking; by the complaint's count, it went slightly up. That single allegation — more trackers after "opt-out" than a naïve reader would expect, and certainly not fewer — is the heart of the case.
The session recorder and the keystroke problem
The most legally dangerous allegation isn't the raw tracker count — it's what the session recorder allegedly captured. According to the complaint, the LogRocket session-replay tool recorded the full Document Object Model (DOM) state of each page along with enough interaction data to reconstruct the visit visually: mouse movements, clicks and their coordinates, hover events, scrolling, and navigation paths.[3] That alone is intrusive. But the complaint goes further:
The keystroke logging allegedly included the order and timing of individual keys typed into search bars and other input fields — whether or not the visitor ever submitted what they typed.
— Summary of the Kimmons complaint's session-replay allegations[3]That distinction — capturing what someone typed even if they never hit enter — is what pulls the case out of "routing metadata" territory and into the contents of a communication. And the contents of a communication are exactly what CIPA's wiretapping provision, §631, is written to protect. This is why session replay on input fields is widely regarded as the single highest-risk tracking configuration in CIPA litigation: it's not capturing that you visited, it's capturing what you wrote.
The legal theory — a five-count stack
Where many CIPA complaints lead with a single provision, Kimmons bundles a broad set of state and federal theories, widening the standard §631/§638.51 pleading into something much harder to dispose of in one motion:[5]
CIPA §631(a) — the wiretapping provision, targeting real-time interception of communication contents (the session-replay/keystroke theory). Federal Wiretap Act (ECPA) — carrying statutory damages of the greater of $10,000 or $100 per day per violation. California Computer Data Access and Fraud Act (CDAFA). California Constitution — the state constitutional right to privacy. Unfair Competition Law (UCL). CIPA damages are commonly cited at $5,000 per violation under Penal Code §637.2.
The strategic logic of the stack is straightforward: different theories survive different defenses. The §638.51 trap-and-trace theory has lost in several 2026 rulings that held cookies aren't a trap-and-trace device — but the §631 wiretapping theory, anchored to a session recorder capturing keystrokes, is a different and much harder-to-dismiss claim, because it targets contents rather than routing data.[5] Adding ECPA brings federal statutory damages into the mix; the constitutional and UCL claims add further avenues. A defendant has to knock out all of them, not one.
Where it stands (as of August 2026)
The case is newly filed and pending. It was docketed July 6, 2026 as No. 26CV197596 in Alameda County Superior Court, brought by Potter Handy on behalf of a proposed nationwide class and California subclass.[1] The NFL has not yet answered, there has been no ruling, and every figure and characterization above comes from the complaint's allegations and the forensic testing it cites — none of it tested in court.
The "opt-out that doesn't opt you out" wave
Kimmons is the most detailed example of a fast-growing 2026 theory: that a site's opt-out is cosmetic. It shares that DNA with a string of recent filings and settlements, and reading them together shows where the litigation is heading:
| Case / party | What's alleged or resolved | Status |
|---|---|---|
| Kimmons v. NFL (this case) | 182 trackers before consent; 186 after opt-out; session replay + keystroke capture; five-count stack. | Filed Jul 2026 |
| Conner v. Toyota | Fingerprinting continued after visitors clicked "Decline"; cross-device ad tracking. | Filed Jul 2026 |
| Forbes Media | Settled a "trap and trace" class action. | ~$10M (May 2026) |
| Los Angeles Times | Settled a similar website-tracking claim. | $3.85M |
The through-line is a shift in what plaintiffs measure. Early CIPA tracking suits alleged, in effect, "you tracked me." This sub-wave alleges something more damning and more concrete: "your banner offered me a choice, I made it, and forensic testing shows it changed nothing." That's a story a jury understands instantly — and, because it's demonstrable from outside the company, it's cheap for a plaintiff firm to document.[2]
Why this case matters for website operators
Neither problem the complaint describes is exotic — that's precisely why it should get every operator's attention. Firing on page load is the default in most tag-manager setups, and very few cookie banners were ever connected to session-replay or fingerprinting scripts.[4] The Kimmons complaint didn't uncover an exotic vulnerability; it measured an ordinary gap on a famous website and attached statutory damages to it. The same gap very likely exists on sites that believe their banner has them covered.
Two specific exposures fall out of the case:
- The pre-consent gap. Trackers that fire the instant a page loads — before any choice — are the 182-tracker problem. A banner that appears after the tags have already fired is decorative.
- The opt-out gap. Session recorders and fingerprinting scripts that were never wired to the banner keep running when a visitor opts out — the 186-tracker problem. And when a session recorder captures keystrokes in input fields, that's the §631 "contents" exposure, the hardest kind to defend.
What this means for your site
The durable lesson from Kimmons is that a consent banner is only as good as its enforcement, and that session replay deserves special caution. If your banner governs cookies but leaves session recorders and fingerprinting scripts firing — before consent and after opt-out — you have the exact two-part configuration this complaint is built around.
The protective posture is the same regardless of how CIPA case law evolves:
- Block non-essential third-party trackers until consent. Nothing non-essential — cookie-based or cookieless — should load or transmit before a visitor chooses. That closes the 182-tracker gap.
- Enforce opt-out on everything, including cookieless tools. Session replay and fingerprinting must stop when a visitor declines, not just cookies. That closes the 186-tracker gap.
- Keep session replay off sensitive input fields — or disable keystroke capture entirely — to avoid the §631 "contents" exposure.
- Log every consent decision so you can show the opt-out was honored, not just offered.
That's what ConsentPixel is built to do — block third-party trackers at the browser level until a visitor genuinely consents, honor the opt-out across cookie-based and cookieless tools alike, and log each decision as evidence. This is general information, not legal advice; consult qualified counsel about your specific exposure.
And because the gap is measurable from outside — which is exactly how the plaintiff documented it — the cheapest first step is to run the same measurement on your own site: see what fires before consent, and what keeps firing after opt-out.
How many trackers fire on your site before consent?
Scan free in about 10 seconds to see every third-party tracker on your site — the ones firing before any choice, and the ones that keep running after opt-out. It's the same measurement the Kimmons complaint is built on.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What is Kimmons v. NFL about?
Why does the "186 trackers after opt-out" number matter?
What did the session recorder allegedly capture?
What laws does the case rely on?
How do I know if my own site has this problem?
Sources
- Courthouse News Service — "NFL accused of collecting, sharing website users' private data" (Jul. 7, 2026). Quotes the complaint, including the tracker counts, the "continues to run 186 third party trackers" after opt-out allegation, and the plaintiff and venue.
- Privado — "NFL hit with CIPA class action over website pixels that ignored consent". Summarises the two-part gap (pre-consent firing and opt-out), the five-count legal stack, and the named trackers.
- UniConsent — "NFL.com CIPA Lawsuit: When Opting Out Doesn't Stop Tracking". Details the LogRocket session recorder's alleged DOM and keystroke capture and the case number (No. 26CV197596).
- Axeptio — "Could the NFL Class Action Make the Case for European CMPs?". Covers the forensic-testing figures and the ECPA/§637.2 damages exposure.
- National Law Review — "No Privacy in the Huddle? NFL.com Hit with CIPA Class Action Over 182 Website Trackers". Case caption, docket, plaintiff background, and the named tracker operators.
Sources accessed and summarised August 2026. This case is newly filed; all figures and statements from the complaint are allegations based on forensic testing described in the filing, and status is current as of the publication date and may change as litigation proceeds.
Disclaimer: This page is for general informational purposes only and is not legal advice. Kimmons v. NFL Enterprises LLC is a newly filed complaint; all allegations described — including the forensic tracker counts — are unproven, and nothing here should be read as a finding that the NFL violated any law. Case details are drawn from the complaint as reported in the legal and news coverage listed above. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2; ECPA damages figures are as provided by that statute. Status is stated as of August 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.