Microsoft Bing UET Tag and Microsoft Clarity: The CIPA Exposure Agencies Are Overlooking
Microsoft Bing UET is named as a pen register in Camplisson v. Adidas (November 2025). Microsoft Clarity and the Bing UET tag together generated a $10 million CIPA settlement for Forbes in May 2026. Most agencies treat Microsoft as the safe, enterprise-grade tracking option. The case law says otherwise. Here's what each tool captures, why the CIPA exposure is real, and the specific configuration changes agencies need to make across every client running Bing Ads or Clarity.
In this article
- Microsoft's two tracking tools: what each does
- Camplisson v. Adidas: Bing UET named as pen register
- The Forbes $10M settlement: Clarity and Bing UET together
- Why agencies treat Microsoft as safe — and why that's wrong
- Microsoft Clarity's specific CIPA risks
- Bing UET's specific CIPA risks
- Clarity vs Bing UET: risk profile comparison
- Microsoft's May 2025 consent mode requirement
- Per-client Microsoft tracking compliance checklist
- Frequently asked questions
Meta Pixel gets the headlines. Google Analytics gets the conference talks. TikTok Pixel gets the congressional hearings. Microsoft's tracking tools — the Bing UET tag and Microsoft Clarity — operate in relative obscurity, which is exactly why they're underaudit ed on most agency-managed sites. That obscurity didn't protect Forbes from a $10 million CIPA settlement. It didn't protect Adidas from a CIPA lawsuit naming the Bing UET tag specifically. And it won't protect the client sites agencies are running both tools on without consent gating today. This article covers both tools, the cases naming them, and the configuration changes that close the gap. Nothing here is legal advice; consult qualified counsel for specific situations.
Microsoft's two tracking tools: what each does
Microsoft Bing UET Tag
Universal Event Tracking — Microsoft's advertising pixel
CIPA exposure: High- Advertising measurement pixel for Bing / Microsoft Ads campaigns
- Fires on page load, sending IP address, browser fingerprint, page URL, and event data to Microsoft servers
- Enables conversion tracking, remarketing audiences, and automated bidding in Microsoft Advertising
- Supports "Auto-Advanced Matching" — can associate browsing with hashed identifiers
- Named as a CIPA pen register in Camplisson v. Adidas (November 2025)
- Microsoft required all advertisers to implement consent mode for UET tag from May 5, 2025
- Transmits data to Microsoft's advertising servers — unambiguously a third party to any website communication
Microsoft Clarity
Session replay and behavior analytics — free from Microsoft
CIPA exposure: High- Free session replay tool: heatmaps, click maps, scroll maps, session recordings
- Captures mouse movements, clicks, scroll depth, keystrokes (with masking options), page navigation
- Transmits behavioral data to Microsoft's Azure infrastructure in real time
- Named in the Forbes $10M CIPA settlement (May 2026) as a pen register capturing unique identifiers and behavioral signals
- Microsoft uses Clarity data for its own benchmarking and AI product development — independent third-party use
- Does not respect Do Not Track browser signals — a documented gap that Hotjar, by contrast, does honor
- More permissive default masking than Hotjar — requires custom configuration for sensitive fields
Camplisson v. Adidas: Bing UET named as pen register
Camplisson et al. v. Adidas America, Inc.
What happened: Website visitors filed a putative class action alleging that two tracking pixels on Adidas.com — the TikTok Pixel and the Microsoft Bing tracker — violated CIPA § 638.51 by collecting personal information without proper consent. Plaintiffs alleged the trackers were placed on visitors' browsers without consent and collected IP addresses, browser information, unique identifiers, and other PII. They also alleged the trackers used device fingerprinting to associate collected data with additional personally identifiable information — including AutoAdvanced Matching features that could tie browsing to names, birthdays, and addresses.
Adidas's defense: (1) The trackers don't qualify as pen registers because they captured only specific outgoing information rather than all communications. (2) Users consented through the privacy policy incorporated into terms and conditions.
Court's ruling: Both defenses rejected at the pleading stage. The court read CIPA's "intentionally broad language" as not requiring capture of all outgoing information to qualify as a pen register. On consent: the privacy policy link was buried in the website footer and not presented to plaintiffs in a conspicuous manner — footer-link-only disclosure is not adequate consent under CIPA. The case proceeds.
Why it matters for agencies: Microsoft Bing UET is now explicitly named in a CIPA pen register complaint that survived dismissal in a federal court. The Bing UET tag is on every site running Microsoft Ads campaigns. If your agency manages Bing Ads for clients, every one of those sites has the UET tag — and most of them are not consent-gated.
The Forbes $10M settlement: Clarity and Bing UET together
Forbes Media CIPA Settlement — $10,000,000
What happened: Forbes agreed to a $10 million preliminary settlement resolving a California wiretapping lawsuit over tracker use on its website. Plaintiffs identified two Microsoft tools as the named devices: Microsoft Clarity (session replay capturing unique identifiers and behavioral signals from page reading) and the Bing UET tag (advertising pixel transmitting routing data to Microsoft servers). Both transmitted unique identifiers and behavioral signals to Microsoft servers automatically, without Forbes visitors' prior consent.
The legal theory: Under CIPA's pen register provision, plaintiffs did not need to prove Forbes or Microsoft read the content of any article. The pen register theory requires only showing that a device captured "addressing and routing" information automatically — and IP addresses plus unique identifiers were sufficient. Behavioral signals from reading patterns strengthened the case.
Additional context: This was Forbes's second major privacy settlement in a year — in 2025 it had paid $7.5 million under the Video Privacy Protection Act for Meta Pixel data sharing on video pages. Combined, Forbes spent $17.5 million on tracker-related litigation in 12 months. Two tools, $17.5 million, one year.
Why it matters: The Forbes settlement is the first major CIPA resolution specifically naming both Microsoft Clarity and Bing UET. It establishes financial precedent for Microsoft tracking exposure and validates the pen register theory against session replay tools running alongside advertising pixels. For agencies running both on client sites, Forbes is the number they need to show clients when explaining why this matters.
The most common agency rationalization for not auditing Microsoft tracking is that Microsoft is an enterprise company with robust privacy programs, unlike smaller ad-tech vendors. CIPA doesn't distinguish between vendors by reputation or size. The statute asks whether a process captured routing and addressing information without prior consent — and both the Bing UET tag and Microsoft Clarity do exactly that by default. Forbes paid $10 million learning this distinction. Adidas is still in litigation over it.
Why agencies treat Microsoft as safe — and why that's wrong
Several legitimate-feeling reasons explain why agencies don't prioritize Microsoft tracking in compliance reviews:
Microsoft Clarity is free. Free tools feel like utilities, not commercial tracking products. But Microsoft uses Clarity data for its own benchmarking products and AI model training — independent data use that removes it from any "mere agent" defense and places it squarely as an independent third-party data recipient. The "free" price reflects the data value to Microsoft, not a privacy-protective product philosophy.
Bing Ads has smaller market share. Agencies running smaller Bing Ads budgets don't scrutinize the UET tag as carefully as they do the Meta Pixel. But CIPA's damages don't scale with ad spend — they scale with California visitor sessions. A client site with 10,000 California monthly sessions running unconsented Bing UET has identical CIPA exposure whether it's spending $500 or $50,000 on Bing Ads.
Microsoft has enterprise credibility. Enterprise software companies feel more privacy-compliant by association. But as both the Forbes settlement and Camplisson v. Adidas demonstrate, the CIPA question is about what the tools transmit and when — not who built them. Microsoft Clarity transmitting behavioral signals to Microsoft's Azure infrastructure without prior consent is legally identical to Meta Pixel transmitting data to Meta's servers without prior consent.
Microsoft Clarity's specific CIPA risks
Microsoft Clarity carries several CIPA risk factors that are specific to it — different from both Bing UET and the session replay tools covered in other articles in this cluster:
The Do Not Track gap
Hotjar respects browser-level Do Not Track signals. Microsoft Clarity does not. When a visitor has enabled DNT in their browser — a deliberate privacy preference — Clarity records their session anyway. This is a documented, publicly known gap in Clarity's privacy posture. For CIPA purposes, it means that for visitors who have expressed a browser-level privacy preference, Clarity overrides that preference and transmits their behavioral data to Microsoft regardless. This gap is one reason Clarity's risk profile is considered higher than Hotjar's in most technical compliance assessments.
Microsoft's independent data use
Unlike a pure SaaS analytics tool that only processes data on your behalf, Microsoft uses Clarity data for its own products: industry benchmarking, AI model training, and product improvement across its Azure and Bing ecosystem. This independent use is the critical factor that prevents Microsoft from claiming "agent" status under CIPA's party exception. When Microsoft uses data for its own commercial purposes, it is an independent third-party recipient — not merely a processor for your client's website.
More permissive default masking
Clarity's default masking is less conservative than Hotjar's. Hotjar masks all form inputs by default (requiring explicit data-hj-allow to unmask). Clarity masks common PII patterns automatically but requires custom configuration for domain-specific sensitive fields. For eCommerce clients with product search bars, account pages, or checkout flows, out-of-the-box Clarity may be capturing and transmitting more sensitive content than the agency realizes.
Bing UET's specific CIPA risks
The Bing UET tag's risk profile is functionally similar to Meta Pixel — it's an advertising measurement pixel that fires on page load, transmitting data to Microsoft's advertising servers before any visitor consent. The specific factors that matter for CIPA:
AutoAdvanced Matching: Like Meta's Advanced Matching, UET's AutoAdvanced Matching feature hashes and transmits customer identifiers from form fields — email, phone, name — to Microsoft for audience matching. On form-heavy pages (checkout, lead generation, account creation), this transmits what courts consider "contents" of communications in real time. AutoAdvanced Matching must be disabled or strictly consent-gated, not left at its default state.
Universal Event Tracking fires on all pages by default: The UET base tag fires on every page where it's installed, regardless of page content. This includes login pages, checkout pages, healthcare or financial services pages — contexts where the combination of sensitive data and real-time transmission to Microsoft's advertising infrastructure represents the highest CIPA exposure.
Microsoft's May 2025 consent mode requirement: Microsoft required all advertisers using the Bing UET tag to configure consent mode signals from May 5, 2025. This requirement means Microsoft has effectively acknowledged that UET must respond to consent state — but implementation requires active configuration by the agency, and most UET deployments predate the consent mode requirement without having been updated.
Clarity vs Bing UET: risk profile comparison
| Factor | Microsoft Bing UET | Microsoft Clarity |
|---|---|---|
| Tool type | Advertising pixel (conversion tracking, remarketing) | Session replay / behavior analytics |
| Fires before consent by default | Yes | Yes |
| Named in CIPA cases | Yes — Camplisson v. Adidas (Nov 2025) | Yes — Forbes settlement (May 2026) |
| Respects Do Not Track | Via consent mode (requires config) | No — documented gap |
| Data use by Microsoft | Advertising audience building | Benchmarking + AI model training |
| Default masking | N/A (pixel, not replay) | Common PII patterns only — less conservative than Hotjar |
| AutoAdvanced Matching / identifier transmission | Yes (if enabled) — hashed identifiers to MS Ads | Unique identifiers captured by default |
| Consent mode available | Yes — Microsoft required config from May 5, 2025 | Via CMP only — no native GPC |
| GPC / opt-out signal honoring | Via CMP — not native | Not honored natively |
| HIPAA BAA available | No | No |
Microsoft's May 2025 consent mode requirement
In May 2025 Microsoft required all advertisers using the Bing UET tag to implement consent mode signals — UET must receive and respond to consent state before firing. This is Microsoft's own acknowledgment that UET needs to be consent-gated.
The requirement mirrors what Google did with GCM v2: UET should be deployed alongside a consent initialization that sets tracking to denied by default, and a consent update that releases UET only when the visitor grants advertising consent. In practice, this means:
- Before Bing Ads campaigns send any data, the UET tag must check whether the visitor has consented to advertising tracking
- In GTM, the UET tag should require
ad_storage: grantedbefore firing — analogous to the Meta Pixel consent configuration - The consent initialization must fire before the UET tag loads, setting all consent types to denied by default
- If your client's UET implementation predates May 2025 and hasn't been updated, it is almost certainly not compliant with Microsoft's own consent requirement — and is certainly not CIPA-compliant
Microsoft's May 2025 consent mode requirement is designed primarily for GDPR compliance in European markets. CIPA's prior-consent standard is stricter: the UET tag must not fire at all before consent, not just operate in a "limited data" mode. Implementing Microsoft's consent mode correctly is necessary but not sufficient for CIPA compliance — you still need technically enforced blocking until affirmative consent, not just signals after the tag has already loaded.
Per-client Microsoft tracking compliance checklist
Microsoft Bing UET + Clarity CIPA Checklist
Per-client · apply to every site running Bing Ads or Microsoft Clarity · not legal advice
Discovery
bat.bing.com or clarity.ms. Both should produce zero requests before consent interaction.Bing UET Configuration
ad_storage: granted. Verify in GTM Preview that the UET tag shows "Not Fired" when consent is denied.Microsoft Clarity Configuration
Verification
bat.bing.com, clarity.ms, or c.clarity.ms before consent interaction.The bottom line
Microsoft Bing UET and Microsoft Clarity are not exempt from CIPA because they're Microsoft products. The Forbes $10M settlement naming both tools, and the Camplisson v. Adidas ruling naming Bing UET specifically, make this explicit. The risk factors are tool-specific: Clarity's Do Not Track gap, Clarity's independent data use for Microsoft's own AI and benchmarking products, UET's AutoAdvanced Matching feature, and the post-May 2025 Microsoft consent mode requirement that most pre-existing UET deployments don't yet satisfy. The fix is the same as for Meta Pixel and TikTok Pixel — block before consent, technically enforce, verify with a clean browser network tab test — but agencies need to apply it to both tools independently, since neither self-enforces. For agencies running Bing Ads campaigns or recommending Clarity to clients, audit both tools across the portfolio this week. This is informational, not legal advice; consult qualified counsel for specific situations.
See if Bing UET or Clarity fires before consent on client sites
ConsentPixel — Privacy · Verified scans any site and shows exactly when Microsoft trackers fire relative to consent. Free, no card required.
Scan a client site freeFrequently asked questions
Is Microsoft Bing UET named in any CIPA lawsuits?
Yes. In Camplisson v. Adidas Am., Inc. (S.D. Cal., November 18, 2025), the Microsoft Bing tracker was named alongside the TikTok Pixel as the two tracking tools at issue. The court declined to dismiss CIPA § 638.51 pen register claims, finding that collecting IP addresses, device identifiers, and using device fingerprinting could plausibly qualify as pen register activity under CIPA's broad language. The ruling explicitly rejected earlier cases that had dismissed similar TikTok Pixel claims. This is the first major federal court ruling naming Bing UET specifically in a CIPA pen register context.
Was Microsoft Clarity involved in the Forbes CIPA settlement?
Yes. Forbes agreed to a $10 million preliminary CIPA settlement in May 2026 that specifically named Microsoft Clarity and the Bing UET tag. Plaintiffs identified both tools as pen registers transmitting unique identifiers and behavioral signals to Microsoft servers without Forbes visitors' prior consent. The pen register theory required only showing that addressing and routing information was captured automatically — IP addresses and unique identifiers were sufficient without needing to prove content interception. The settlement is the largest CIPA resolution specifically naming Microsoft tracking tools.
Does Microsoft Clarity respect Do Not Track signals?
No. Microsoft Clarity does not respect browser-level Do Not Track signals. Hotjar, by contrast, does. This means that when a visitor has enabled DNT in their browser as a deliberate privacy preference, Clarity records their session and transmits their behavioral data to Microsoft regardless. For CIPA compliance, your CMP must explicitly block the Clarity script for DNT-on visitors — Clarity will not self-enforce this. The DNT gap is one reason Clarity's default risk profile is considered higher than Hotjar's in technical compliance assessments.
What is Microsoft's consent mode requirement for Bing UET?
From May 5, 2025, Microsoft required all advertisers using the Bing UET tag to configure consent mode signals, so the tag responds appropriately to visitor consent choices. This means implementing a consent initialization that sets advertising tracking to denied by default and configuring UET to receive consent updates before firing. In GTM, this requires the UET tag to require ad_storage: granted before loading. Microsoft's requirement is designed primarily for GDPR compliance in European markets — for CIPA compliance, technically-enforced prior blocking (not just consent signals) is required. Not legal advice.
Is Microsoft Clarity higher risk than Hotjar?
For most default deployments, yes. Clarity carries several risk factors that Hotjar's default configuration addresses more conservatively: Clarity does not respect Do Not Track signals (Hotjar does), Clarity has more permissive default masking (Hotjar masks all form inputs by default), and Microsoft uses Clarity data for its own benchmarking and AI products (strengthening the independent third-party interceptor argument). Additionally, Clarity has now been named in the Forbes $10M CIPA settlement. Both require the same consent-gating standard — block before consent, verify with network tab test — but Clarity's default configuration creates more surface area for exposure if the consent gate isn't implemented correctly. Not legal advice.