TikTok Pixel Lawsuit: The CIPA Case Law Whipsaw Every Agency Running TikTok Ads Must Understand
In April through August 2025, three courts dismissed CIPA claims against the TikTok Pixel. In November 2025, a federal court in Camplisson v. Adidas found the TikTok Pixel could plausibly qualify as a pen register under CIPA — explicitly rejecting the earlier cases. The result is a genuine circuit split that leaves agencies running TikTok Ads on client sites in a legally uncertain but practically urgent position. Here's the full picture.
In this article
- What the TikTok Pixel does and what it collects
- The two CIPA theories against it
- The case law timeline: dismissals, then a circuit split
- Camplisson v. Adidas: why it changed everything
- What the circuit split means for agencies today
- TikTok Pixel vs Meta Pixel: risk profile comparison
- The SB 690 wild card
- What agencies running TikTok Ads should do now
- Frequently asked questions
The TikTok Pixel is relatively new to the CIPA litigation landscape compared to Meta Pixel, but it has produced some of the most significant and contradictory court rulings of 2025. Three dismissals in a row through mid-2025 gave agencies reason to think TikTok Pixel claims were heading for extinction. Then Camplisson v. Adidas in November 2025 revived the theory — explicitly rejecting the cases that had dismissed it — and handed plaintiff firms fresh ammunition heading into 2026. Understanding the arc of these cases is essential for any agency managing TikTok Ads campaigns for clients with California traffic. Nothing in this article is legal advice; consult qualified counsel for specific situations.
What the TikTok Pixel does and what it collects
The TikTok Pixel — formally the TikTok Events API, though most agencies deploy the browser-side pixel — is TikTok's equivalent of Meta Pixel. It's a JavaScript snippet installed on client websites that fires on page load or specific events to help measure ad performance, build audiences, and optimize TikTok ad campaigns. Its default data collection includes:
- IP address — the visitor's IP, used for location approximation and identity matching
- Device identifiers — browser fingerprint, user agent, screen dimensions, device type
- Page URL and referral — the full URL being visited and the referring source
- Custom events — ViewContent, AddToCart, Purchase, Lead, and other events you configure in Events Manager
- Click IDs — TikTok Click IDs (ttclid) that link ad clicks to on-site conversions
- Hashed customer data — if Advanced Matching is enabled: hashed email, phone, name
Like the Meta Pixel, the TikTok Pixel fires by default on every page where it's installed, the moment the page loads — before any visitor consent interaction. That default firing behavior is the CIPA exposure: data flows to TikTok's servers (a separate legal entity) in real time, without prior consent from California visitors.
One reason TikTok Pixel CIPA claims have been harder to defend against than Meta Pixel claims: TikTok is unambiguously a third party with entirely independent commercial interests in the data. The "agent/tool" defense — arguing the vendor is merely an extension of the website operator — is significantly weaker for TikTok than for, say, a first-party analytics tool. TikTok uses pixel data for its own ad targeting ecosystem, not just to serve the website operator.
The two CIPA theories against it
Plaintiffs have pursued TikTok Pixel claims under both of CIPA's main digital-tracking theories, and the courts have reached dramatically different conclusions on each:
§ 631 wiretapping (content interception): The argument that TikTok Pixel reads the "contents" of communications in transit — keystrokes, form values, interaction data. Courts have been more skeptical of this theory for pixels, because pixels generally capture routing/identifier data rather than communication contents. The § 631 theory is stronger for session replay tools that capture actual keystrokes.
§ 638.51 pen register / trap and trace: The argument that TikTok Pixel is a "device or process" that captures routing and addressing information — IP addresses, device identifiers, page paths — functioning as a pen register installed without consent. This is the more active theory for pixel litigation, and it's where the 2025 case law whipsaw played out most dramatically.
The case law timeline: dismissals, then a circuit split
Price v. Headspace, Inc. (California Supreme Court)
The California Supreme Court held that the TikTok Pixel — and similar technologies including the Meta Pixel — is "definitionally not a trap and trace device" under CIPA. The court's reasoning: the plaintiff's own complaint alleged capture of content (name, date of birth, address), which removed it from § 638.51's coverage, because pen registers capture metadata and routing information, not content. Unusually, capturing more data was the defense, not the plaintiff's advantage.
Kishnani v. Royal Caribbean Cruises Ltd. (N.D. Cal.)
Court dismissed TikTok Pixel pen register claim on two independent grounds: (1) the "content-based" analysis from Headspace — if the pixel captures content rather than just routing information, it doesn't qualify as a pen register; and (2) the plaintiff lacked Article III standing because the complaint failed to allege when or how many times the plaintiff visited the site, what specific data was collected and decrypted, or what harm the plaintiff suffered. Standing failures are independently dismissible.
Mitchener v. CuriosityStream, Inc. (N.D. Cal.)
Dismissed with prejudice — combining both rationales from the earlier cases. The complaint's allegations were too generalized to establish Article III standing, and the TikTok Pixel did not meet the statutory definition of a trap and trace device because it collected content, not merely metadata. Three defense wins in a row, across April through August 2025, suggested the TikTok Pixel pen register theory was in decline.
Camplisson v. Adidas Am., Inc. (S.D. Cal.) — the reversal
A Southern District of California federal judge refused to dismiss claims that the TikTok Pixel and Microsoft Bing trackers violated CIPA § 638.51 as pen registers. The court explicitly rejected the three earlier cases. Its reasoning: CIPA's "intentionally broad language" should not be limited to processes that collect all information from a device — collecting partial information (IP addresses, device identifiers, unique trackers) can still qualify. The court also found that the defendant's only notice was a buried footer privacy policy link, which was not "conspicuous" enough to constitute consent and "requiring users to click through terms without affirmative action was insufficient." Traverse Legal called this ruling one that will "fuel a new wave of class action lawsuits."
Camplisson v. Adidas: why it changed everything
Camplisson v. Adidas is the most important TikTok Pixel case of 2025–2026, and it's worth understanding precisely why it reversed the defendant-friendly trend rather than simply noting that it did.
The earlier dismissals in Headspace, Kishnani, and CuriosityStream all relied on a specific analytical framework: if the pixel captures "content" (names, emails, form data) rather than just routing metadata (IP addresses, identifiers), it doesn't qualify as a pen register under § 638.51, because the pen register provision covers routing information — not content. This reasoning created a perverse situation: the more data a pixel collected, the less likely it was to be a pen register.
The Adidas court rejected this logic directly. It read CIPA's language more broadly and found that TikTok Pixel's collection of IP addresses, browser information, unique identifiers, and device fingerprinting data plausibly constitutes pen register activity — precisely because these are the kinds of routing and addressing signals the pen register statute was designed to prohibit. The court also found that TikTok's device fingerprinting — correlating collected data with specific devices across sites — strengthened the pen register analogy.
On consent: Adidas argued that its privacy policy covered the tracking. The court explicitly rejected a buried footer link as adequate consent, finding both that it wasn't conspicuous enough and that passively clicking through terms without affirmative action was insufficient. This consent-inadequacy finding applies to virtually every standard privacy-policy-only deployment in the industry.
What the circuit split means for agencies today
A circuit split is not resolved until a higher court — in this case the Ninth Circuit or ultimately the Supreme Court — settles the question. Until that happens, both plaintiff and defense counsel have viable precedent to cite, and outcomes will vary by which judge, which court, and which specific facts are in front of them.
For agencies, this creates a specific risk posture that's different from the Meta Pixel situation. The Meta Pixel has more settled unfavorable precedent for defendants (Javier, Mikulsky, Garcia v. AEG). The TikTok Pixel has a genuinely contested landscape with recent defense wins. But "the law is unsettled" is not a safe operating position when the downside is $5,000 per California-resident session and a class period stretching back to when the pixel was first installed.
The practical implication: a circuit split means plaintiff firms can shop courts and facts. A filing that emphasizes the Adidas reasoning goes to federal courts in the Southern District. A case with weaker pleading, or where a state court is more favorable, gets routed differently. The split doesn't reduce the number of demand letters — it increases them, because plaintiff firms have fresh ammunition that no one can dismiss as a fringe theory anymore.
Most TikTok Pixel CIPA exposure never reaches a courtroom. A plaintiff firm scans your client's site, finds the TikTok Pixel firing before consent, sends a demand letter calibrated below the cost of defense, and collects a settlement. The circuit split gives them a viable case to cite. Whether a court would ultimately rule for or against them is irrelevant to whether the demand letter arrives — and whether it makes economic sense to settle rather than fight.
TikTok Pixel vs Meta Pixel: risk profile comparison
| Factor | TikTok Pixel | Meta Pixel |
|---|---|---|
| Named in CIPA cases | Yes (Adidas, Price, Kishnani, Mitchener) | Yes (many cases) |
| Court wins for defense | Yes (3 in 2025) | Some (Ramos, Torres, Bosley) |
| Court wins for plaintiff | Yes (Camplisson Nov 2025) | Yes (Javier, Mikulsky, Garcia) |
| Active circuit split | Yes — explicitly created by Adidas | Partial — less settled than TikTok |
| Third-party status | Clear — TikTok uses data independently | Contested — party exception arguments available |
| Consent standard to defeat | Same — prior, affirmative, technically enforced | Same — prior, affirmative, technically enforced |
| Default fires before consent | Yes | Yes |
| GPC / consent mode support | Via CMP only (no native GPC) | Via CMP only |
The practical takeaway from this comparison: the TikTok Pixel and Meta Pixel require identical consent configurations to be defensible — the difference is in how the case law has developed around them, not in what good compliance looks like. Agencies who have consent-gated their Meta Pixel correctly should apply the same configuration to TikTok Pixel. Agencies who haven't done either have exposure on both.
The SB 690 wild card
California Senate Bill 690 would, if enacted, explicitly exclude tracking technologies used for "commercial business purposes" from CIPA's scope — effectively legislatively reversing the litigation wave. The bill passed the California Senate unanimously (33–0) but stalled in the Assembly in 2025 and was designated a "two-year bill," meaning it won't take effect until 2027 at the earliest, if at all.
The SB 690 delay is itself a driver of 2026 demand letter volume. Plaintiff firms explicitly know they have a window before potential reform closes. Every TikTok Pixel lawsuit filed before SB 690 takes effect is filed under the current, ambiguous statute. Traverse Legal described the period between now and any SB 690 enactment as a window where "legal uncertainty is at maximum levels, which means litigation risk is through the roof."
For agencies, SB 690's delayed status means: do not plan compliance strategy around waiting for reform. Implement consent gating now and treat any future reform as a bonus reduction in exposure, not a reason to delay.
What agencies running TikTok Ads should do now
The circuit split doesn't change what good compliance looks like. It makes getting to good compliance more urgent, because both sides of the split have viable cases to argue. The configuration standard is identical to the one that won in Bosley — prior, affirmative consent before the pixel fires — and the checklist below is your agency's minimum standard for every TikTok Pixel client.
TikTok Pixel CIPA Compliance Checklist
Per-client · apply to every site running TikTok Ads · not legal advice
analytics.tiktok.com or business-api.tiktok.com. If requests appear before any consent interaction, the client is exposed.The bottom line
The TikTok Pixel lawsuit landscape in 2026 is more contested than any other tracking technology — three defense wins in mid-2025 followed by a circuit-splitting plaintiff win in November that explicitly rejected them. For agencies, the circuit split doesn't reduce risk; it increases demand letter volume by giving plaintiff firms a recent, federal-court victory to cite. The consent configuration that makes the TikTok Pixel defensible is identical to the one required for Meta Pixel: the pixel is blocked until the visitor affirmatively accepts, with prior consent technically enforced and timestamped records proving the order. The distinction between the TikTok and Meta Pixel situations isn't in what compliance looks like — it's in how much time agencies have before the next filing wave arrives. Given the SB 690 delay and the Adidas ruling's momentum, that window is shorter than it was six months ago. This is informational, not legal advice; consult qualified counsel for specific situations.
See if TikTok Pixel fires before consent on client sites
ConsentPixel — Privacy · Verified scans any site and shows exactly when the TikTok Pixel and every other tracker fires relative to consent. Free, no card required.
Scan a client site freeFrequently asked questions
Is the TikTok Pixel illegal under CIPA?
Not inherently — the TikTok Pixel is not illegal as a tool. Whether using it creates CIPA exposure depends on the deployment: specifically, whether it fires before California visitors have given prior consent. The 2025–2026 case law is split: three courts dismissed TikTok Pixel pen register claims in 2025 (Headspace, Royal Caribbean, CuriosityStream), and Camplisson v. Adidas (November 2025) found the claims viable and created a circuit split. The configuration standard that generates clean dismissals — prior, technically-enforced consent before the pixel fires — is the same regardless of which case law trend prevails. Not legal advice.
What did Camplisson v. Adidas say about the TikTok Pixel?
In Camplisson v. Adidas Am., Inc. (S.D. Cal., November 18, 2025), a federal court declined to dismiss CIPA § 638.51 pen register claims against the TikTok Pixel and Microsoft Bing trackers. The court found that collecting IP addresses, browser information, unique identifiers, and using device fingerprinting could plausibly qualify as pen register activity under CIPA's "intentionally broad language." It also rejected Adidas's consent defense, finding that a privacy policy buried in a footer wasn't conspicuous enough and that requiring users to click through terms without affirmative action was insufficient consent. The court explicitly rejected three earlier cases that had dismissed TikTok Pixel claims.
Why did courts dismiss TikTok Pixel CIPA claims in 2025?
The three 2025 dismissals — Price v. Headspace, Kishnani v. Royal Caribbean, and Mitchener v. CuriosityStream — relied on two main grounds: (1) a "content-based" theory that if the pixel captures actual content (names, emails, specific form data) rather than just routing metadata, it doesn't qualify as a pen register, which covers metadata not content; and (2) Article III standing failures where plaintiffs didn't adequately allege what data was collected, how it was used, or what concrete harm they suffered. The Adidas court rejected the first ground in November 2025, creating a circuit split.
Is the TikTok Pixel different from Meta Pixel for CIPA purposes?
The case law trajectory differs — Meta Pixel has had more plaintiff-favorable precedent since 2022, while TikTok Pixel had a period of defense-favorable dismissals before Camplisson v. Adidas. But the consent standard that makes either pixel defensible is identical: prior, affirmative consent that technically blocks the pixel before any visitor data is transmitted. TikTok's third-party status is arguably clearer than Meta's, because TikTok is unambiguously an independent commercial entity using pixel data for its own ad ecosystem — weakening the "agent/tool" defense that sometimes works for Meta. Not legal advice.
What is SB 690 and does it protect against TikTok Pixel lawsuits?
California Senate Bill 690 would amend CIPA to exclude tracking technologies used for "commercial business purposes" from the pen register provisions — effectively removing the legal hook for most website pixel claims. The bill passed the California Senate 33–0 but stalled in the Assembly and was designated a two-year bill, meaning it won't take effect until 2027 at the earliest, if it passes at all. Don't plan compliance strategy around SB 690. Implement prior consent gating now and treat any future reform as a reduction in future exposure rather than a reason to delay.