Rounds v. Development Dimensions International, Inc.
A federal judge threw out a CIPA "trap-and-trace" class action over website cookies and a 6Sense tracking SDK — ruling that cookies simply aren't a §638.51 device. Here's the full breakdown: the technology, the theory, the two-part holding, and what it means for your site.
What the case is about
Plaintiff Travis Rounds sued Development Dimensions International — a Delaware-based leadership-consulting firm — over the tracking technology on its website. According to the complaint, DDI had installed a data-broker software development kit (SDK) from 6Sense that worked to "deanonymize" visitors. The mechanics matter here, so it's worth being precise: when Rounds visited the DDI site, his approximate geolocation, device information, and browser data were allegedly transmitted to 6Sense, which then matched them against an existing profile and shared additional data about Rounds back to DDI.[1]
That "deanonymization" step is the crux of what made the complaint feel intrusive. 6Sense is a B2B "revenue intelligence" platform whose core function is identifying which companies (and sometimes which individuals) are browsing a site, even when the visitor never fills out a form. For a leadership-consulting firm selling to enterprise HR departments, that's a valuable sales-intelligence tool. To the plaintiff, it looked like covert surveillance — an outside data broker quietly building a dossier on an anonymous visitor.
Rounds argued this conduct amounted to an unauthorized "trap-and-trace device" under California Penal Code §638.51 — a provision of the California Invasion of Privacy Act (CIPA) that, alongside pen registers, is normally reserved for law-enforcement surveillance and generally requires a court order. In plain terms, the theory was that ordinary B2B website tracking is the digital equivalent of tapping a phone line's routing data. That is the same §638.51 theory driving a large share of the 2026 CIPA litigation wave.[3]
The legal theory — and the statute it leans on
To understand why the claim failed, you have to look at the statutory text the plaintiff was stretching. Section 638.51 prohibits installing or using a "pen register or trap and trace device" without a court order, and it borrows its definitions from §638.50. The trap-and-trace definition is the one at issue:
"...a device or process that captures the incoming electronic or other impulses that identify the originating number or other dialing, routing, addressing, or signaling information reasonably likely to identify the source of a wire or electronic communication, but not the contents of a communication."
You can see the plaintiff's angle immediately. The words "routing, addressing, or signaling information" sound like they could describe what a tracking cookie or analytics SDK does — capturing IP addresses, device identifiers, and similar metadata. Plaintiffs across California have been building entire class actions on exactly that textual hook: if a pixel captures "addressing" data, the argument goes, it's a trap-and-trace device, and every consented visit becomes a $5,000 statutory violation.
Why Judge Carter rejected it
The court didn't accept the textual sleight of hand. Judge David O. Carter found persuasive DDI's argument that "allegations of the use of cookies does not suffice as a statutory violation of §638.51 and the alleged use of a trap and trace device."[1] In other words, capturing geolocation, device information, and browser data through cookies and an analytics SDK is not the kind of routing-signal capture the trap-and-trace statute was written to regulate. The provision was built for a world of telephone lines and originating call numbers — not the metadata every website necessarily exchanges to load a page for a visitor who chose to access it.
"...allegations of the use of cookies does not suffice as a statutory violation of § 638.51 and the alleged use of a trap and trace device."
— Order, Rounds v. Development Dimensions Int'l, Inc., 2026 WL 746291 (C.D. Cal. Mar. 11, 2026)The clever procedural twist: no violation, no jurisdiction
What makes Rounds especially useful to defendants isn't just that the claim was dismissed — it's how. DDI, an out-of-state (Delaware) company, moved to dismiss on personal jurisdiction grounds. Its argument: a California court can't hale an out-of-state defendant into its courts unless the company has sufficient "minimum contacts" with California and the claims plausibly "arise from" those contacts. DDI said it didn't target Californians, didn't install software on Californians' devices independent of their own choices, and didn't build its business model around data collected from Californians.[1]
Rounds's counter was that DDI's use of cookies to track California users was itself the California-directed conduct that established jurisdiction. And here's where the court tied the two questions into a single elegant knot: if the cookie tracking wasn't a §638.51 violation in the first place, then it couldn't be the wrongful, California-directed act that the plaintiff's claims "arise from." No statutory violation meant no jurisdiction-conferring wrong — so dismissal followed automatically.[4]
This linkage is what defense lawyers will find most portable. It means an out-of-state company facing a §638.51 cookie claim in California has two ways to win at once from the same argument: attack the merits (cookies aren't a trap-and-trace device) and, through that same finding, knock out personal jurisdiction. For the many businesses sued in California despite having no real presence there, that's a powerful early-exit path.
Where it stands (as of July 2026)
The case is dismissed. On March 11, 2026, Judge Carter dismissed Rounds's claims without leave to amend — meaning the plaintiff was not given a chance to re-plead the complaint to cure its defects. That is the strongest form of dismissal a defendant can obtain at the pleading stage, and it's why legal commentators described the decision as a "swift rebuke" to the trap-and-trace theory.[4] The ruling is reported at Travis Rounds v. Development Dimensions Int'l, Inc., 2026 WL 746291 (C.D. Cal. Mar. 11, 2026). The underlying action was filed August 28, 2025 and docketed as No. 8:25-cv-01975 in the Central District of California.[5]
How Rounds fits the 2026 landscape
Rounds is not an isolated ruling — it's one data point in a genuine 2026 shift. Across California, a growing line of decisions has refused to stretch CIPA's phone-era surveillance provisions to cover routine website cookies and analytics SDKs. Reading them together shows the pattern, and the limits:
| Case | Court | What it held |
|---|---|---|
| Rounds v. DDI (this case) | C.D. Cal. (federal) | Cookies aren't a §638.51 trap-and-trace device; no violation, so no jurisdiction over out-of-state defendant. Dismissed, no leave. |
| Rodriguez v. Ink America | L.A. Superior (state) | Pen-register theory dismissed with prejudice; CIPA can't criminalise what the CCPA already regulates.[7] |
| Heiting v. Wildflower Brands | L.A. Superior (state) | Trap-and-trace provisions designed for telephone surveillance, not commercial websites. Dismissed with prejudice.[7] |
The through-line is a judicial skepticism that these decades-old provisions were ever meant to reach the ordinary metadata a website exchanges with a visitor who chose to load the page. Rounds adds a specifically federal voice to a trend that had been mostly playing out in state court — and it pairs the merits holding with a jurisdiction hook that other out-of-state defendants can reuse.
Why this case matters for website operators
For website owners, Rounds supplies defense counsel with fresh, citable authority on two fronts: that cookies alone are not a trap-and-trace device, and that an out-of-state defendant can defeat a CIPA cookie suit on jurisdiction when the underlying tracking isn't a statutory violation. If your business is sued on a §638.51 theory — especially outside California — this is now a case your lawyer can point to.
But it's essential to read the ruling for exactly what it decides — and, just as importantly, what it doesn't. Rounds turned on the §638.51 trap-and-trace theory and on jurisdiction over an out-of-state defendant. It says nothing about:
- The §631 wiretapping theory, which targets the real-time interception of communication contents (not just routing data) — a live and much harder-to-dismiss theory, especially for session-replay tools.
- Session-replay on checkout, login, or form pages, where tools capture exactly what a visitor types into sensitive fields — the highest-risk configuration in CIPA litigation, untouched by this ruling.
- The pre-consent firing gap — trackers that fire before a visitor is given any choice — which sinks sites regardless of how the trap-and-trace question is resolved.
What this means for your site
The durable lesson from Rounds isn't "relax." It's that your actual risk depends on what your trackers do and when they fire — not on the label a plaintiff attaches or how one district rules. A favourable decision in the Central District of California won't help you if your site fires Meta Pixel, GA4, or a session-replay tool before a visitor consents; that's a different theory, a different fact pattern, and a materially worse position to be in.
The reliable protection is the same no matter which way the case law swings: don't let non-essential third-party trackers run before consent, keep session-replay off sensitive pages, and keep a record proving consent was obtained. That is precisely what ConsentPixel is built to do — block third-party trackers until a visitor opts in, and log every consent decision — so your compliance posture doesn't hinge on a court's mood or a plaintiff's choice of forum.
And notice how this whole dispute began: with a third-party tracking SDK on the defendant's site. In many CIPA cases, the site owner didn't fully realise what a given pixel or SDK was doing, or when it fired. That's why the first, cheapest step is simply seeing what actually runs on your pages — and whether any of it fires before consent.
Worried your site has this exposure?
Scan free in about 10 seconds to see every tracker firing on your site — including the ones loading before consent, the gap this ruling doesn't protect. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What was Rounds v. Development Dimensions International about?
Why did the court dismiss the case?
Does this mean cookies are legal and CIPA doesn't apply to my site?
What is a "trap and trace device" under CIPA?
What's the practical takeaway for website owners?
Sources
- Inside Class Actions — "Federal Court Rejects Claim that Cookies Are Illegal Trap and Trace Devices" (Mar. 26, 2026). Quotes the court order and summarises the 6Sense/deanonymization allegations.
- Loeb & Loeb LLP — "The Millisecond Problem: How Pre-Consent Tracking Is Driving CIPA Lawsuits in 2026". Places Rounds in the context of the federal split and the 2026 pre-consent focus.
- Loeb & Loeb LLP — "Privacy Litigation Update: California Court Rejects 'Trap and Trace' Cookie Claims". Analysis of the trap-and-trace holding.
- Briones PC — "Federal Judge Tosses California Privacy Suit Against Leadership Firm DDI". Covers the personal-jurisdiction reasoning and "without leave to amend" outcome.
- Justia Dockets — Travis Rounds v. Development Dimensions International, Inc. et al (filing date, Central District of California). See also the PacerMonitor and Law360 docket listings (No. 8:25-cv-01975).
- "CIPA Lawsuits 2026: How Pre-Consent Tracking Is Exposing Website Operators". Background on the §631 vs §638.51 theories.
- Briones PC — "Los Angeles Court Rejects Expanding CIPA to Cover Routine Website Analytics" (Rodriguez v. Ink America; related trap-and-trace/pen-register rulings).
- Primary decision: Travis Rounds v. Development Dimensions Int'l, Inc., 2026 WL 746291 (C.D. Cal. Mar. 11, 2026).
Sources accessed and summarised July 2026. Case status is current as of the publication date and may change as litigation proceeds.
Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above; the primary decision is reported at 2026 WL 746291 (C.D. Cal. Mar. 11, 2026). Status is stated as of July 6, 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.