ConsentPixel – Privacy · Verified

CIPA Case Deep-Dive · § 631 Wiretapping · Session Replay

Mikulsky v. Bloomingdale's, LLC

The Ninth Circuit revived a CIPA wiretapping class action over the session-replay code on bloomingdales.com — rejecting the "record data" defense that had killed the case below — and five months later, Bloomingdale's settled. It is the clearest arc in the whole tracker: survive dismissal, and you pay.

By The ConsentPixel Team Updated July 2026 13 min read
⚖️ Case snapshot
Court
U.S. Court of Appeals, 9th Circuit (from S.D. Cal., Judge M. James Lorenz)
Case No.
9th Cir. 24-3564 / 24-3837 · D.C. 3:23-cv-00425
Filed
Mar 2023 (D.C.) · decided Jun 20, 2025 (9th Cir.)
Status (as of Jul 2026)
§ 631 claim revived Jun 2025 — settled Nov 14, 2025
Tracking tech
Session-replay code (FullStory) · mouse, clicks, keystrokes, URLs
Defendant
Bloomingdale's, LLC & Bloomingdales.com, LLC — retail

What the case is about

Plaintiff Erica Mikulsky, a California resident, sued Bloomingdale's over the tracking technology on bloomingdales.com. Her allegation targeted a specific and very common tool: session-replay code. Unlike an analytics pixel that logs which page you loaded, session replay records the session itself — your mouse movements, clicks, keystrokes, the URLs you visit, and how you move through the site — and reconstructs it as a watchable playback.[1]

The complaint alleged that Bloomingdale's fed that captured activity, in real time, to a third-party session-replay vendor — FullStory, Inc. — which analyzed it and handed the retailer marketing and behavioral insights in return. Crucially, Mikulsky alleged FullStory was not a passive tape recorder working only for Bloomingdale's, but an independent party that received and used the contents of her interactions for its own purposes. That framing is what turns an ordinary vendor relationship into an alleged wiretap.[2]

Why session replay is legally different from a pixel. A pen-register case (like Camplisson v. Adidas) argues that a tracker captured routing and addressing data — the digital equivalent of a phone number. Session replay is a step further: it captures what you actually did and typed, which plaintiffs argue is the contents of a communication. That distinction — record data versus contents — is the entire ballgame in this case.

The legal theory — § 631(a) and the third-party wiretap

Mikulsky brought her claim under California Penal Code § 631(a), CIPA's core wiretapping provision — a different theory from the pen-register cases dominating the 2026 tracker. Section 631(a) targets anyone who reads or attempts to read the contents of a communication in transit without consent, and — critically — anyone who aids, agrees with, employs, or conspires with another party to do so.[3]

That "aids and abets" clause is the engine of the theory. Bloomingdale's is a party to its own communications with its visitors, so it can't "wiretap" itself — the well-known party exception. But Mikulsky's argument routes around that: by enabling FullStory, an independent third party, to intercept and learn the contents of her communications, Bloomingdale's allegedly aided a wiretap by someone who was not a party to the conversation. The retailer's own participation doesn't immunize the third party it brought in.[4]

The district court sided with Bloomingdale's — on "record data"

In the Southern District of California, Judge M. James Lorenz dismissed the § 631 claim for failure to state a claim. His reasoning was the defense industry's favorite argument: session replay captures "record data" — the characteristics of a communication, like metadata — not its contents. If no contents were intercepted, there is no § 631 violation. He also dismissed Mikulsky's separate intrusion-upon-seclusion claim, finding the conduct wasn't "highly offensive," while upholding personal jurisdiction over the New York-based retailer.[5]

"The complaint alleged real-time capture of the contents of Mikulsky's communications on Defendants' website without her consent, not merely the real-time capture of information regarding the characteristics of the communications."

— Mikulsky v. Bloomingdale's, LLC, No. 24-3564 (9th Cir. June 20, 2025) (unpublished memorandum)

The Ninth Circuit reversal: contents, not characteristics

Mikulsky appealed, and on June 20, 2025, a Ninth Circuit panel — Judges Bybee, Ikuta, and Forrest — reversed the dismissal of the § 631 claim in an unpublished memorandum. The court held that Lorenz got the contents question wrong at the pleading stage: the complaint alleged real-time capture of the contents of Mikulsky's communications, not merely the characteristics. That single reframing is the whole decision.[6]

The panel found Mikulsky sufficiently alleged that Bloomingdale's aided, agreed with, employed, or conspired with the session-replay providers to enable them to read or learn the contents or meaning of her communications "while the same [was] in transit," without the consent of all parties. In other words: the aiding-and-abetting theory works, and session-replay contents are within § 631's reach.[4]

The line the whole case turns on "RECORD DATA" — characteristics District court's view → dismissed IP address · page loaded timestamps · device type "who/when" of the visit Not enough for § 631 "CONTENTS" — what you did & typed 9th Circuit's view → revived keystrokes · mouse movement clicks · form input · full URLs the "what" of the interaction States a § 631 claim

Same technology, two readings. The district court called session-replay output "record data"; the Ninth Circuit held the complaint plausibly alleged it captured the contents of communications — and revived the case.

The masking argument that didn't save the day

Bloomingdale's had a technical answer: it argued it configured FullStory to mask text fields, so the vendor never actually saw sensitive typed data. The Ninth Circuit was unmoved at this stage. Whether masking fully prevented contents capture is a factual question that can't be resolved on a motion to dismiss — the complaint plausibly alleged contents were captured, and that is all a plaintiff needs to survive the pleadings.[7]

Why "we masked it" isn't an early exit. Masking is a real mitigation, and it may well matter later — but it's a defense you prove with evidence, not one that defeats a well-pleaded complaint at the outset. That timing is the trap: even a defensible configuration can force you through discovery, where cost and exposure mount. The cheapest place to win a session-replay case is before it's filed, by having consent on record.

What the panel did NOT revive

The reversal was partial, and the boundary is instructive. The Ninth Circuit affirmed the dismissal of the intrusion-upon-seclusion claim, agreeing that Mikulsky's complaint failed to plead conduct that was "highly offensive" under California common law. So a plaintiff can clear the statutory § 631 bar — which asks whether contents were intercepted — while failing the common-law tort bar, which asks whether the conduct shocks the conscience. Different tests, different outcomes, same facts.[2]

The jurisdiction holding every online business should note

Bloomingdale's cross-appealed on personal jurisdiction, arguing a New York-based retailer shouldn't be haled into a California court. The Ninth Circuit affirmed jurisdiction, relying on its recent en banc decision in Briskin v. Shopify (135 F.4th 739 (9th Cir. 2025)): a company that operates a website appealing to and profiting from California users is subject to suit there, even with no physical presence in the state.[6]

Translation: "we're not in California" is not a defense. If your site targets and profits from California visitors — which describes nearly every commercial website in the United States — you can be sued under CIPA in California regardless of where your business sits. The old instinct that geography offers protection is gone. What protects you is what happens on the site, not where your headquarters is.

Where it stands (as of July 2026)

The sequence is the lesson:

  • Jun 20, 2025 — revived. The Ninth Circuit reversed the dismissal of the § 631 claim, sending it back to the district court for Bloomingdale's to answer. This is an appellate ruling, carrying weight well beyond the district-court decisions elsewhere in the tracker — even as an unpublished memorandum, it signaled how the Ninth Circuit reads session-replay contents claims.
  • Jul–Aug 2025 — back to the trial court. The mandate issued; Bloomingdale's was ordered to answer the surviving claim. The case was now live, with discovery ahead.
  • Nov 14, 2025 — settled. Roughly five months after the reversal, Bloomingdale's filed a notice of settlement in the Southern District of California. Terms were not made public.[8]
Read the posture honestly. The June 2025 decision was an unpublished memorandum, which limits its formal precedential value, and it resolved only the pleading stage — it did not find Bloomingdale's liable. A late-2024 Ninth Circuit panel had sided with Bloomingdale's in a similar suit, so this area is genuinely contested. But the practical trajectory is hard to miss: the claim survived on appeal, and the defendant chose to settle rather than litigate it to judgment. That is the pattern plaintiffs are counting on.

How Mikulsky fits the 2026 landscape

Most of the CIPA tracker is pen-register litigation under § 638.51. Mikulsky is a different animal — a § 631 wiretapping case about session replay, decided at the appellate level, that ended in a settlement. Placing it next to the others shows how many distinct theories are in play at once.

CaseTheory / courtWhat happened
Mikulsky v. Bloomingdale's (this case)§ 631 wiretap · session replay · 9th Cir.Dismissal reversed — session-replay contents state a claim; jurisdiction affirmed; settled five months later.
Camplisson v. Adidas§ 638.51 pen register · S.D. Cal.MTD denied — pixels plausibly a pen register even on IP alone; buried-footer consent failed.
D'Antonio v. CNN§ 638.51 pen register · S.D.N.Y.MTD denied — adtech trackers can be a pen register; standing via intrusion upon seclusion.
Rounds v. DDI§ 638.51 pen register · C.D. Cal.Cookies aren't a § 638.51 device; no violation, no jurisdiction. Dismissed, no leave.
The pattern across all four. Whether the theory is wiretapping or pen register, the cases that survive share one fact: a third-party tool received user data without consent recorded first. Rounds is the outlier because the court rejected the theory itself — but that's a bet on your forum and your judge. Mikulsky, Camplisson, and D'Antonio are the base rate, and they all point the same way: get consent before the tool runs, or be prepared to litigate.

Why this case matters for website operators

Mikulsky is the case to cite when someone says "session replay is just analytics." Here's why it carries weight the others don't:

  • It's appellate. Most CIPA tracking rulings are single district judges. This is the Ninth Circuit — the federal appellate court covering California — telling district courts how to read session-replay contents claims. Its influence outruns its unpublished status.
  • It lowered the pleading bar. A plaintiff no longer needs to prove contents were captured to get past dismissal; plausibly alleging it is enough. That makes these cases cheaper to file and harder to knock out early.
  • It killed the "record data" shortcut. The defense that session replay only captures characteristics — not contents — no longer reliably wins at the pleading stage in the Ninth Circuit.
  • It ended in a settlement. This is the part that should focus the mind. The case didn't just survive; the defendant paid. Session-replay exposure is not theoretical.
  • Masking wasn't a silver bullet. Even a technical mitigation didn't defeat the claim on the pleadings. Configuration helps, but it's a merits defense, not an exit.

What this means for your site

Session replay is one of the most common tools on modern websites — Hotjar, FullStory, Microsoft Clarity, LogRocket, and dozens more. If you run any of them, Mikulsky is directly about you. The fix is the same one every CIPA case points to:

  • Block session-replay and analytics tools until consent. The tool must not initialize or transmit anything until the visitor has affirmatively agreed. If the recording starts on page load, you have the Mikulsky fact pattern.
  • Get all-party consent for recording. Section 631 requires the consent of all parties to the communication. A clear, conspicuous banner that the visitor accepts before any recording begins is how you obtain it.
  • Don't rely on masking alone. Mask sensitive fields by all means — but treat it as defense-in-depth, not the whole defense. Consent is the load-bearing control.
  • Log the consent. Keep a timestamped record of what each visitor was shown and what they agreed to, so you can prove recording only began after consent.
  • Audit your vendors. Know exactly which third parties receive session data and what they do with it. A vendor that uses the data for its own purposes — as FullStory allegedly did — is what converts a tool into an alleged wiretap.
The reassuring part. Bloomingdale's problem wasn't that it used FullStory — plenty of compliant sites do. The problem was that the recording allegedly started without all-party consent on record. A site that blocks session replay until a visitor accepts a clear banner, and logs that choice, doesn't present the fact pattern that survived appeal here. The tool is fine; the timing and the consent are what matter.

Worried your site has this exposure?

Scan free in about 10 seconds to see every tracker firing on your site — including session-replay tools like FullStory, Hotjar and Clarity loading before consent, the exact Mikulsky fact pattern. It's the same scan a plaintiff firm would run.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What is Mikulsky v. Bloomingdale's about?
Erica Mikulsky, a California resident, sued Bloomingdale's under the California Invasion of Privacy Act, alleging that session-replay code on bloomingdales.com recorded her interactions — mouse movements, clicks, keystrokes, and URLs — and transmitted them in real time to a third-party vendor, FullStory, without her consent. A district court dismissed the claim, but on June 20, 2025, the Ninth Circuit reversed, holding she had adequately alleged that Bloomingdale's aided a third party in capturing the contents of her communications under CIPA Section 631(a). Bloomingdale's settled about five months later.
What is the "record data versus contents" distinction, and why did it matter?
Section 631 of CIPA prohibits intercepting the contents of a communication — what you actually say or type — but not merely its characteristics, sometimes called record data, like an IP address or which page loaded. The district court dismissed Mikulsky's case by holding that session replay captured only record data. The Ninth Circuit disagreed, ruling that the complaint plausibly alleged real-time capture of the contents of her communications — keystrokes, form input, and interactions — not just their characteristics. That reframing is what revived the case, and it is the reason the "it's only record data" defense no longer reliably wins at the pleading stage in the Ninth Circuit.
How can Bloomingdale's be liable if it was a party to its own communications?
CIPA Section 631 has a well-known "party exception" — you cannot wiretap a conversation you are part of, so Bloomingdale's could not illegally intercept its own communications with visitors. But Section 631 also makes it unlawful to aid, agree with, employ, or conspire with someone else to intercept contents. Mikulsky's theory was that Bloomingdale's enabled FullStory — an independent third party that used the data for its own purposes — to capture the contents of her communications. The retailer's status as a party to the conversation does not immunize the outside party it brought in. The Ninth Circuit found that aiding-and-abetting theory adequately pleaded.
Didn't Bloomingdale's mask sensitive fields to protect user data?
Bloomingdale's argued that it configured FullStory to mask text fields so the vendor never saw sensitive typed data. The Ninth Circuit did not accept that as a basis for dismissal. Whether masking actually prevented the capture of contents is a factual question that cannot be resolved on a motion to dismiss — at the pleading stage, the complaint plausibly alleged that contents were captured, and that is enough to proceed. Masking may still matter later as a merits defense, but it did not end the case early.
Can a company outside California be sued under CIPA?
Yes. Bloomingdale's, a New York-based retailer, cross-appealed on the ground that it lacked sufficient connection to California, and the Ninth Circuit affirmed jurisdiction. Relying on its 2025 en banc decision in Briskin v. Shopify, the court held that a company operating a website that appeals to and profits from California users is subject to suit in California, even without a physical presence there. In practice, that covers nearly every commercial website in the United States — geography is not a CIPA defense.
How is this different from the pen-register cases like Camplisson or D'Antonio?
Those cases are brought under CIPA's pen register and trap-and-trace provision, Section 638.51, which targets the capture of routing and addressing information — the digital equivalent of the phone numbers you dial. Mikulsky is brought under Section 631, the wiretapping provision, which targets the interception of the contents of a communication. Session replay is central to Mikulsky because it captures what a user actually does and types, which plaintiffs argue is contents. Mikulsky is also distinctive for being an appellate decision that ended in a settlement, whereas the pen-register cases are district-court rulings still in earlier stages.
Does this case create risk for my website?
If your site runs session-replay software — FullStory, Hotjar, Microsoft Clarity, LogRocket, or similar — and it records visitors before they consent, Mikulsky describes your exact exposure. The Ninth Circuit lowered the bar for these claims to survive dismissal, rejected the "record data" defense, held that masking doesn't defeat a claim at the pleadings, and confirmed California jurisdiction over out-of-state sites — and the defendant settled. The reliable protection is to block session-replay tools until the visitor affirmatively consents, and to log that consent. A free tracker scan will show what currently records on your site before consent.

Sources

  1. Duane Morris LLP — "Ninth Circuit Reversal Expands Potential Liability for Companies Using Session-Replay and Tracking Technologies" (June 25, 2025). Summarises the session-replay allegations, the "record data" dismissal, and the jurisdiction holding.
  2. Top Class Actions — "Bloomingdale's class action revived over alleged website tracking" (July 2025). Names FullStory, the aiding-and-abetting finding, counsel (Lynch Carpenter), and the affirmed dismissal of intrusion upon seclusion.
  3. Blank Rome LLP — "Ninth Circuit Scrutinizes California Wiretap Law" (July 2, 2025). Context on the § 631(a) theory and the trio of appeals argued June 10, 2025.
  4. Proskauer Rose LLP — "Ninth Circuit Reviews Website Tracking Class Actions" (July 3, 2025). Details the aiding/agreeing/employing/conspiring standard and the contents-vs-characteristics holding.
  5. MediaPost — "Bloomingdale's Must Face Online Shopper's Wiretap Suit" (June 23, 2025). Quotes Judge Lorenz's "record data" ruling and the panel judges (Bybee, Ikuta, Forrest).
  6. Justia / Ninth Circuit — Mikulsky v. Bloomingdale's, LLC, No. 24-3564 (9th Cir. June 20, 2025). The unpublished memorandum reversing the § 631 dismissal, affirming jurisdiction (citing Briskin v. Shopify), and affirming dismissal of the intrusion claim.
  7. Klein Moynihan Turco LLP — "Unfavorable Ninth Circuit Pixel Tracking Decision" (June 25, 2025). Defense-side analysis of the masking argument and the lowered pleading threshold.
  8. Bloomberg Law — "Bloomingdale's Settles Suit Over 'Session Replay' Website Tool" (Nov. 17, 2025). Reports the Nov. 14, 2025 notice of settlement, roughly five months after the reversal.

Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the appellate decision is an unpublished memorandum, Mikulsky v. Bloomingdale's, LLC, No. 24-3564 (9th Cir. June 20, 2025), and carries limited precedential value. Status is stated as of July 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.

Scroll to Top