Ortiz v. Foris Dax, Inc. (Crypto.com)
The plaintiffs clicked "Disable All" — and, they allege, the tracking kept running anyway. A federal court dismissed their wiretapping claim but let the pen-register claim proceed, in one of the most thorough federal endorsements yet of the theory that cookies can be illegal "pen registers." Here's the full breakdown, and why the "Disable All" detail should worry every site with a consent banner.
What the case is about
In October 2025, plaintiffs led by a consumer named Ortiz filed a putative class action against Foris Dax, Inc., the company that operates the cryptocurrency exchange Crypto.com, over the tracking technology on its website. The core allegation is one that's now familiar in 2026: that Crypto.com embedded third-party cookies and advertising/analytics pixels that captured visitors' data — IP addresses, device information, and browsing activity — and shared it with outside parties without valid consent.[3]
But this case has a detail that sets it apart from the typical cookie complaint, and it's the reason the case matters. The plaintiffs allege they didn't just passively browse — they clicked "Disable All" on the site's cookie controls, affirmatively opting out of tracking. And the tracking, they say, continued anyway.[2] That single fact reframes the whole dispute. This isn't "you tracked me without asking." It's "I told you to stop, and you didn't." A consent tool that doesn't actually stop tracking is, for litigation purposes, worse than no tool at all — because it proves the visitor's expectation of privacy while failing to honour it.
The two legal theories — and why they split
The plaintiffs pursued two distinct CIPA theories, and understanding the difference is the key to the whole ruling. They are not interchangeable, and this case turned on treating them separately.
§631 (wiretapping) targets the interception of the contents of a communication in transit — what you actually typed, searched, or submitted. §638.51 (pen register) targets the capture of routing/addressing information — the metadata identifying a communication, like IP addresses and device identifiers — and, subject to exceptions, bars installing or using such a device "without first obtaining a court order."
Why the wiretapping claim (§631) was dismissed
The court dismissed the §631 claim — with leave to amend — for a reason that has become a consistent theme in 2026 rulings: the plaintiffs alleged only the categories of information the cookies were capable of collecting, not what communications of theirs were actually intercepted.[1] To state a wiretapping claim, a plaintiff has to plead that the contents of a real communication were captured — the search terms they entered, the forms they submitted, the specific clicks they made. Alleging that you "browsed" a site whose cookies could collect data gives a court nothing to work with on the contents element.[1]
The court made the same point about the "highly offensive" element of the privacy claim: the plaintiffs didn't specify what they actually did on the Crypto.com site beyond browsing, so the complaint couldn't establish that the intrusion crossed the "highly offensive" threshold.[2] This is a recurring, learnable lesson — vague "the site tracked me" pleading loses on §631; specific "here is the content that was intercepted" pleading is what survives.
Why the pen-register claim (§638.51) survived
The pen-register claim is where Ortiz becomes genuinely significant. The court refused to dismiss it — and in doing so delivered one of the most thorough federal analyses yet of whether CIPA's pen-register provision applies to internet tracking at all. Its answer was yes.[1]
The reasoning is worth understanding because it's the engine driving a large share of 2026 litigation. The court grounded its conclusion in both statutory text and legislative history: California borrowed its pen-register definition from a federal statute that Congress had already broadened in 2001 to cover internet-based tracking, and nothing in the California statute limits the provision to telephone lines or telephonic devices.[4] On that reading, a cookie or pixel that captures IP addresses and device identifiers — the internet's equivalent of routing information — can plausibly be a "pen register" installed "without first obtaining a court order."
"...a person may not install or use a pen register or a trap and trace device without first obtaining a court order."
— Cal. Penal Code §638.51(a), the provision the court allowed to proceed against Crypto.comThe bigger picture: a deepening federal–state split
What makes Ortiz impossible to read in isolation is that it lands on one side of a genuine, unresolved split — and the split, not any single ruling, is what determines outcomes right now.
On the federal side, courts have increasingly accepted that CIPA's pen-register provision reaches website tracking. Ortiz joins the AEG (Garcia v. Anschutz Entertainment Group) ruling, which delivered a similarly thorough federal endorsement grounded in the 2001 congressional expansion of the pen-register definition.[1] On the state side, several California courts have gone exactly the opposite way: in Rodriguez v. Ink America, a Los Angeles court held in December 2025 that §638.51 "did not, and does not, criminalize the process by which websites communicate with users who choose to access them," reasoning that reading CIPA that broadly would render the CCPA meaningless.[5]
Notably, the court declined to treat pending reform legislation (Senate Bill 690, which would exempt "commercial purpose" tracking from CIPA) as a guide to what the law means today. Until either the California legislature acts or an appellate court resolves the split, cases like Ortiz keep the pen-register theory firmly alive in federal court.[1]
Where it stands (as of July 2026)
As of July 2026, the case is alive and proceeding on the pen-register theory. The May 21, 2026 order was a ruling on Crypto.com's motion to dismiss: the §631 wiretapping claim was dismissed with leave to amend (meaning the plaintiffs may try to re-plead it with the specificity the court found lacking), while the §638.51 pen-register claim survived and moves forward.[2] The case is captioned Ortiz et al v. Foris Dax, Inc., No. 3:25-cv-08950-EMC, in the U.S. District Court for the Northern District of California, before Judge Edward M. Chen.[6]
How Ortiz fits the 2026 landscape
Ortiz is best understood as the federal counterpart to the pen-register story — the "yes, this theory reaches websites" pole of the split, paired with a vivid opt-out fact. Read alongside its siblings, the pattern is clear:
| Case | Court | What it held |
|---|---|---|
| Ortiz v. Crypto.com (this case) | N.D. Cal. (federal) | §631 dismissed for lack of specific intercepted contents; §638.51 pen register survived — thorough federal endorsement. Users clicked "Disable All." |
| Garcia v. AEG | C.D. Cal. (federal) | Pen-register claim survived where cookies fired before the consent banner loaded — the pre-consent gap.[1] |
| Rodriguez v. Ink America | LA Superior (state) | Opposite result: §638.51 doesn't reach websites; broad reading would gut the CCPA.[5] |
| Khamooshi v. Politico | N.D. Cal. (federal) | Pen-register claim dismissed for lack of standing — generic device/browser metadata isn't a concrete injury.[3] |
The through-line across the surviving cases — Ortiz, AEG — is that the pen-register theory is strongest when paired with a fact that undercuts consent: cookies firing before a banner loads (AEG), or tracking continuing after a user clicks "Disable All" (Ortiz). Where a plaintiff alleges only generic metadata capture with no consent wrinkle, standing defenses like Khamooshi and the Popa v. Microsoft framework still knock claims out. The lesson isn't "pen-register claims always win" — it's "they win when your consent mechanism visibly failed."
Why this case matters for website operators
For website owners, Ortiz delivers two lessons that pull in the same direction. The first is about the pen-register theory's durability: in federal court, the argument that ordinary cookies and pixels are "pen registers" is not a fringe theory a judge will wave away — it now has some of the most thorough judicial reasoning behind it. If your site runs third-party trackers that capture IP addresses and device data, that theory can reach you.[1]
The second lesson is sharper and more actionable: a consent banner that doesn't actually stop tracking is a liability, not a shield. The plaintiffs' "Disable All" allegation is what gave their case its teeth. If your cookie banner presents a "reject" or "disable" option but your trackers keep firing anyway — because the banner is cosmetic, or the tags aren't actually gated behind the consent choice — you've manufactured the exact fact pattern that helped Crypto.com's plaintiffs survive. You've created written proof that the visitor expected privacy, and then allegedly denied it.
What this means for your site
The durable lesson from Ortiz is that consent has to be real, not cosmetic. It isn't enough to show a banner; the "reject" or "disable" choice has to actually block the third-party trackers it promises to block, before they fire. The gap between a banner that looks like consent management and a system that actually enforces it is precisely the gap the Crypto.com plaintiffs are litigating.
That enforcement is exactly what ConsentPixel is built to do: it blocks third-party trackers until a visitor opts in, and when a visitor declines, those trackers genuinely don't fire — so a "Disable All" click means tracking actually stops. Just as importantly, ConsentPixel keeps an immutable log of each consent decision, so if a plaintiff ever claims their opt-out was ignored, you have a timestamped record showing what was blocked and when.
And because this case — like most in the 2026 wave — began with third-party tags a site owner may not have realised were still firing after opt-out, the first, cheapest step is simply to see what actually runs on your pages before and after a visitor rejects consent. If anything fires when it shouldn't, that's your Ortiz exposure, in plain sight.
Worried your site has this exposure?
Scan free in about 10 seconds to see every third-party tracker firing on your site — including the ones that keep loading even when a visitor rejects consent, the exact pattern at the heart of this case. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What is Ortiz v. Foris Dax (Crypto.com) about?
What did the court decide?
Why does the "Disable All" detail matter so much?
Does this mean cookies are illegal pen registers everywhere?
What's the practical takeaway for website owners?
Sources
- Fisher Phillips LLP — "What 7 Recent Court Decisions Tell You About Today's Website Privacy Liability". Covers the May 21 Ortiz split ruling, the §631 dismissal reasoning, and the surviving pen-register theory; also the AEG pre-consent analysis.
- Security Boulevard (Mark Rasch) — "When Cookies Become Wiretaps: The New CIPA War Over Online Tracking". Details the "Disable All" allegation, the reasonable-expectation-of-privacy finding, the "highly offensive" pleading gap, and §638.51(a) text.
- ConsentPixel — CIPA Lawsuit Tracker 2026. Case summary and the "most comprehensive federal analysis" characterisation; Khamooshi v. Politico standing dismissal.
- "CIPA and Website Tracking" — analysis citing the Ortiz May 21, 2026 pen-register holding. The 2001 federal-definition expansion and internet-tracking rationale.
- Security Boulevard — on Rodriguez v. Ink America and the CCPA-preemption reasoning (the state-court counter-line to Ortiz).
- PacerMonitor — Ortiz et al v. Foris Dax, Inc., No. 3:25-cv-08950 (N.D. Cal.). Filing date (Oct 17, 2025) and docket. See also the Justia and N.D. Cal. (cand.uscourts.gov) docket listings.
Sources accessed and summarised July 2026. Case status is current as of the publication date and may change as litigation proceeds.
Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the case is Ortiz et al v. Foris Dax, Inc., No. 3:25-cv-08950-EMC (N.D. Cal.), before Judge Edward M. Chen, and the ruling described is a May 21, 2026 order on a motion to dismiss, not a final judgment. Status is stated as of July 6, 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.