ConsentPixel – Privacy · Verified

⚠ Split result · Wiretap dismissed, pen register survives

Ortiz v. Foris Dax, Inc. (Crypto.com)

The plaintiffs clicked "Disable All" — and, they allege, the tracking kept running anyway. A federal court dismissed their wiretapping claim but let the pen-register claim proceed, in one of the most thorough federal endorsements yet of the theory that cookies can be illegal "pen registers." Here's the full breakdown, and why the "Disable All" detail should worry every site with a consent banner.

ConsentPixel Research Published July 6, 2026 10 min read CIPA §638.51 · pen register
⚖️ Case snapshot
Court
U.S. District Court, N.D. California (Judge Edward M. Chen)
Case No.
3:25-cv-08950-EMC
Filed
October 17, 2025
Status (as of Jul 2026)
Split ruling May 21, 2026 — §631 dismissed (leave to amend), §638.51 survives
Tracking tech
Third-party cookies & advertising/analytics pixels capturing IP, device & browsing data
Defendant
Foris Dax, Inc., d/b/a Crypto.com — cryptocurrency exchange

What the case is about

In October 2025, plaintiffs led by a consumer named Ortiz filed a putative class action against Foris Dax, Inc., the company that operates the cryptocurrency exchange Crypto.com, over the tracking technology on its website. The core allegation is one that's now familiar in 2026: that Crypto.com embedded third-party cookies and advertising/analytics pixels that captured visitors' data — IP addresses, device information, and browsing activity — and shared it with outside parties without valid consent.[3]

But this case has a detail that sets it apart from the typical cookie complaint, and it's the reason the case matters. The plaintiffs allege they didn't just passively browse — they clicked "Disable All" on the site's cookie controls, affirmatively opting out of tracking. And the tracking, they say, continued anyway.[2] That single fact reframes the whole dispute. This isn't "you tracked me without asking." It's "I told you to stop, and you didn't." A consent tool that doesn't actually stop tracking is, for litigation purposes, worse than no tool at all — because it proves the visitor's expectation of privacy while failing to honour it.

Why the "Disable All" fact is the crux. The court found the plaintiffs plausibly alleged a reasonable expectation of privacy precisely because they clicked "Disable All." A visitor who takes an affirmative step to opt out has, by definition, expressed an expectation that tracking will stop. When it allegedly doesn't, the legal picture changes materially.

The two legal theories — and why they split

The plaintiffs pursued two distinct CIPA theories, and understanding the difference is the key to the whole ruling. They are not interchangeable, and this case turned on treating them separately.

The two CIPA theories in one glance

§631 (wiretapping) targets the interception of the contents of a communication in transit — what you actually typed, searched, or submitted. §638.51 (pen register) targets the capture of routing/addressing information — the metadata identifying a communication, like IP addresses and device identifiers — and, subject to exceptions, bars installing or using such a device "without first obtaining a court order."

Why the wiretapping claim (§631) was dismissed

The court dismissed the §631 claim — with leave to amend — for a reason that has become a consistent theme in 2026 rulings: the plaintiffs alleged only the categories of information the cookies were capable of collecting, not what communications of theirs were actually intercepted.[1] To state a wiretapping claim, a plaintiff has to plead that the contents of a real communication were captured — the search terms they entered, the forms they submitted, the specific clicks they made. Alleging that you "browsed" a site whose cookies could collect data gives a court nothing to work with on the contents element.[1]

The court made the same point about the "highly offensive" element of the privacy claim: the plaintiffs didn't specify what they actually did on the Crypto.com site beyond browsing, so the complaint couldn't establish that the intrusion crossed the "highly offensive" threshold.[2] This is a recurring, learnable lesson — vague "the site tracked me" pleading loses on §631; specific "here is the content that was intercepted" pleading is what survives.

Why the pen-register claim (§638.51) survived

The pen-register claim is where Ortiz becomes genuinely significant. The court refused to dismiss it — and in doing so delivered one of the most thorough federal analyses yet of whether CIPA's pen-register provision applies to internet tracking at all. Its answer was yes.[1]

The reasoning is worth understanding because it's the engine driving a large share of 2026 litigation. The court grounded its conclusion in both statutory text and legislative history: California borrowed its pen-register definition from a federal statute that Congress had already broadened in 2001 to cover internet-based tracking, and nothing in the California statute limits the provision to telephone lines or telephonic devices.[4] On that reading, a cookie or pixel that captures IP addresses and device identifiers — the internet's equivalent of routing information — can plausibly be a "pen register" installed "without first obtaining a court order."

"...a person may not install or use a pen register or a trap and trace device without first obtaining a court order."

— Cal. Penal Code §638.51(a), the provision the court allowed to proceed against Crypto.com
The "Disable All" multiplier. Combine the surviving pen-register theory with the opt-out fact and you get the case's real danger for businesses: the plaintiffs alleged an affirmative expectation of privacy (they clicked "Disable All") and a viable statutory hook (§638.51). That pairing is far harder to dismiss than an ordinary passive-browsing cookie complaint.

The bigger picture: a deepening federal–state split

What makes Ortiz impossible to read in isolation is that it lands on one side of a genuine, unresolved split — and the split, not any single ruling, is what determines outcomes right now.

On the federal side, courts have increasingly accepted that CIPA's pen-register provision reaches website tracking. Ortiz joins the AEG (Garcia v. Anschutz Entertainment Group) ruling, which delivered a similarly thorough federal endorsement grounded in the 2001 congressional expansion of the pen-register definition.[1] On the state side, several California courts have gone exactly the opposite way: in Rodriguez v. Ink America, a Los Angeles court held in December 2025 that §638.51 "did not, and does not, criminalize the process by which websites communicate with users who choose to access them," reasoning that reading CIPA that broadly would render the CCPA meaningless.[5]

Does CIPA §638.51 (pen register) reach website tracking? FEDERAL COURTS — increasingly YES • Ortiz v. Crypto.com (N.D. Cal., this case) • Garcia v. AEG — thorough federal analysis Rationale: CA borrowed the federal pen-register definition Congress broadened for the internet. STATE COURTS — often NO • Rodriguez v. Ink America (LA Superior) • Wiley v. Universal Music Group Rationale: statute speaks only of telephone lines; broad reading would gut the CCPA. Now before the California Court of Appeal (Variety Media appeal) — unresolved.
The split that decides these cases. Whether a pen-register claim survives often depends less on your website and more on which court hears it. Until an appellate court resolves the question, forum can matter as much as facts.

Notably, the court declined to treat pending reform legislation (Senate Bill 690, which would exempt "commercial purpose" tracking from CIPA) as a guide to what the law means today. Until either the California legislature acts or an appellate court resolves the split, cases like Ortiz keep the pen-register theory firmly alive in federal court.[1]

Where it stands (as of July 2026)

As of July 2026, the case is alive and proceeding on the pen-register theory. The May 21, 2026 order was a ruling on Crypto.com's motion to dismiss: the §631 wiretapping claim was dismissed with leave to amend (meaning the plaintiffs may try to re-plead it with the specificity the court found lacking), while the §638.51 pen-register claim survived and moves forward.[2] The case is captioned Ortiz et al v. Foris Dax, Inc., No. 3:25-cv-08950-EMC, in the U.S. District Court for the Northern District of California, before Judge Edward M. Chen.[6]

A note on sourcing. Facts here are drawn from the court's order as reported by Fisher Phillips and Security Boulevard, and from the public docket (CourtListener/PacerMonitor/Justia), all listed in Sources below. As a pre-trial ruling on a motion to dismiss, nothing here is a final determination of liability; it reflects the record as of July 6, 2026 and the litigation is ongoing.

How Ortiz fits the 2026 landscape

Ortiz is best understood as the federal counterpart to the pen-register story — the "yes, this theory reaches websites" pole of the split, paired with a vivid opt-out fact. Read alongside its siblings, the pattern is clear:

CaseCourtWhat it held
Ortiz v. Crypto.com (this case)N.D. Cal. (federal)§631 dismissed for lack of specific intercepted contents; §638.51 pen register survived — thorough federal endorsement. Users clicked "Disable All."
Garcia v. AEGC.D. Cal. (federal)Pen-register claim survived where cookies fired before the consent banner loaded — the pre-consent gap.[1]
Rodriguez v. Ink AmericaLA Superior (state)Opposite result: §638.51 doesn't reach websites; broad reading would gut the CCPA.[5]
Khamooshi v. PoliticoN.D. Cal. (federal)Pen-register claim dismissed for lack of standing — generic device/browser metadata isn't a concrete injury.[3]

The through-line across the surviving cases — Ortiz, AEG — is that the pen-register theory is strongest when paired with a fact that undercuts consent: cookies firing before a banner loads (AEG), or tracking continuing after a user clicks "Disable All" (Ortiz). Where a plaintiff alleges only generic metadata capture with no consent wrinkle, standing defenses like Khamooshi and the Popa v. Microsoft framework still knock claims out. The lesson isn't "pen-register claims always win" — it's "they win when your consent mechanism visibly failed."

Read it honestly. This is a trial-court order on a motion to dismiss, not a final judgment, and it sits on the federal side of an unresolved split that the California Court of Appeal may yet resolve the other way. A defendant could still prevail later. But "we might win on appeal in two years" is not a compliance strategy — and it doesn't stop the discovery costs in the meantime.

Why this case matters for website operators

For website owners, Ortiz delivers two lessons that pull in the same direction. The first is about the pen-register theory's durability: in federal court, the argument that ordinary cookies and pixels are "pen registers" is not a fringe theory a judge will wave away — it now has some of the most thorough judicial reasoning behind it. If your site runs third-party trackers that capture IP addresses and device data, that theory can reach you.[1]

The second lesson is sharper and more actionable: a consent banner that doesn't actually stop tracking is a liability, not a shield. The plaintiffs' "Disable All" allegation is what gave their case its teeth. If your cookie banner presents a "reject" or "disable" option but your trackers keep firing anyway — because the banner is cosmetic, or the tags aren't actually gated behind the consent choice — you've manufactured the exact fact pattern that helped Crypto.com's plaintiffs survive. You've created written proof that the visitor expected privacy, and then allegedly denied it.

The trap to avoid: installing a consent banner and assuming you're covered. If clicking "Reject" or "Disable All" doesn't genuinely prevent third-party tags from loading, the banner becomes evidence against you — it documents the user's opt-out while your site ignored it. That is arguably worse than having no banner at all.

What this means for your site

The durable lesson from Ortiz is that consent has to be real, not cosmetic. It isn't enough to show a banner; the "reject" or "disable" choice has to actually block the third-party trackers it promises to block, before they fire. The gap between a banner that looks like consent management and a system that actually enforces it is precisely the gap the Crypto.com plaintiffs are litigating.

That enforcement is exactly what ConsentPixel is built to do: it blocks third-party trackers until a visitor opts in, and when a visitor declines, those trackers genuinely don't fire — so a "Disable All" click means tracking actually stops. Just as importantly, ConsentPixel keeps an immutable log of each consent decision, so if a plaintiff ever claims their opt-out was ignored, you have a timestamped record showing what was blocked and when.

And because this case — like most in the 2026 wave — began with third-party tags a site owner may not have realised were still firing after opt-out, the first, cheapest step is simply to see what actually runs on your pages before and after a visitor rejects consent. If anything fires when it shouldn't, that's your Ortiz exposure, in plain sight.

Worried your site has this exposure?

Scan free in about 10 seconds to see every third-party tracker firing on your site — including the ones that keep loading even when a visitor rejects consent, the exact pattern at the heart of this case. It's the same scan a plaintiff firm would run.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What is Ortiz v. Foris Dax (Crypto.com) about?
It's a putative class action alleging that Crypto.com's website (operated by Foris Dax, Inc.) used third-party cookies and tracking pixels that captured visitors' IP addresses, device information, and browsing data without valid consent, in alleged violation of CIPA. The standout fact: the plaintiffs allege they clicked "Disable All" to opt out, and the tracking continued anyway. It's docketed as Ortiz et al v. Foris Dax, Inc., No. 3:25-cv-08950-EMC (N.D. Cal.).
What did the court decide?
On May 21, 2026, the court issued a split ruling on Crypto.com's motion to dismiss. It dismissed the CIPA §631 wiretapping claim (with leave to amend) because the plaintiffs didn't specify what communication contents were actually intercepted, only what the cookies were capable of collecting. But it refused to dismiss the CIPA §638.51 pen-register claim, delivering one of the most thorough federal analyses concluding that the pen-register provision can reach website tracking.
Why does the "Disable All" detail matter so much?
Because it establishes a reasonable expectation of privacy. A visitor who clicks "Disable All" has affirmatively expressed that they don't want to be tracked. When tracking allegedly continues anyway, the case stops being "you tracked me without asking" and becomes "I told you to stop and you didn't" — a much stronger position. It also turns the consent banner into evidence for the plaintiff rather than a defense for the business.
Does this mean cookies are illegal pen registers everywhere?
No. Ortiz is a federal trial-court ruling, and it sits on one side of an unresolved federal–state split. Federal courts (Ortiz, AEG) have increasingly accepted that CIPA's pen-register provision reaches website tracking, while several California state courts (such as Rodriguez v. Ink America) have held the opposite. The question is currently before the California Court of Appeal. This is general information, not legal advice.
What's the practical takeaway for website owners?
Make your consent real. A banner that shows a "reject" or "disable" option but doesn't actually stop third-party trackers from firing is worse than no banner — it documents the user's opt-out while your site ignores it. Ensure that rejecting consent genuinely blocks non-essential trackers before they load, and keep a record of consent decisions. That's the posture that avoids the fact pattern in this case.

Sources

  1. Fisher Phillips LLP — "What 7 Recent Court Decisions Tell You About Today's Website Privacy Liability". Covers the May 21 Ortiz split ruling, the §631 dismissal reasoning, and the surviving pen-register theory; also the AEG pre-consent analysis.
  2. Security Boulevard (Mark Rasch) — "When Cookies Become Wiretaps: The New CIPA War Over Online Tracking". Details the "Disable All" allegation, the reasonable-expectation-of-privacy finding, the "highly offensive" pleading gap, and §638.51(a) text.
  3. ConsentPixel — CIPA Lawsuit Tracker 2026. Case summary and the "most comprehensive federal analysis" characterisation; Khamooshi v. Politico standing dismissal.
  4. "CIPA and Website Tracking" — analysis citing the Ortiz May 21, 2026 pen-register holding. The 2001 federal-definition expansion and internet-tracking rationale.
  5. Security Boulevard — on Rodriguez v. Ink America and the CCPA-preemption reasoning (the state-court counter-line to Ortiz).
  6. PacerMonitor — Ortiz et al v. Foris Dax, Inc., No. 3:25-cv-08950 (N.D. Cal.). Filing date (Oct 17, 2025) and docket. See also the Justia and N.D. Cal. (cand.uscourts.gov) docket listings.

Sources accessed and summarised July 2026. Case status is current as of the publication date and may change as litigation proceeds.

Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the case is Ortiz et al v. Foris Dax, Inc., No. 3:25-cv-08950-EMC (N.D. Cal.), before Judge Edward M. Chen, and the ruling described is a May 21, 2026 order on a motion to dismiss, not a final judgment. Status is stated as of July 6, 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.

Scroll to Top