Most companies would never intentionally hand a third party a play-by-play of what customers are doing on their website. Yet that may be happening every day, automatically and largely out of sight. Common website tools can quietly transmit information about visitors and their activity to advertising, analytics, and other technology companies (sometimes before anyone clicks "accept"). These tools can be incredibly useful, but they are also fueling a growing wave of lawsuits and regulatory scrutiny.
Pixels have become one of the fastest-growing categories of privacy litigation, and the exposure often builds silently, long before anyone at the company realizes it exists. So before worrying about the legal risk, it helps to understand what these technologies actually are, what they do, and why they are on your website in the first place.
What Is a Pixel – and Why Should You Care?
Despite the name, a tracking pixel is not something a website visitor sees. Think of it instead as a tiny messenger working behind the scenes of a website. When someone visits a webpage or takes an action such as viewing a product, clicking a button, submitting a form, or making a purchase, the pixel can send information about that activity to another company, often an advertising or analytics provider.
That information can help the website operator understand what visitors are doing and whether its advertising is working. For example, imagine you see an advertisement for a pair of shoes on social media. You click the ad, browse the retailer's website, and eventually buy the shoes. A tracking technology may allow the retailer to connect those dots and determine that its advertisement resulted in a sale.
That is incredibly valuable information to a marketing department. But it can also create legal risk.
"Pixel" has become shorthand for a much larger family of technologies: app software development kits (SDKs), session replay scripts, chat tools, AI assistants, and server-side interactions that transmit data from a company's own systems, rather than the visitor's browser. When this alert refers to pixels, it means that whole category.
If your company has a website, there is a good chance it has pixels. Your marketing team probably likes them. Your website developers may consider them routine. And until recently, your legal department may never have heard of them.
That has changed.
Website tracking technologies have become the focus of a rapidly growing wave of privacy lawsuits and regulatory scrutiny. Technologies that companies have used for years to answer seemingly harmless questions (How many people visited our website? Did they click on our ad? What pages did they view? Did they buy something?) are now being characterized in lawsuits as wiretapping, eavesdropping devices, and tools for unlawfully disclosing personal information. They are also, increasingly, the subject of enforcement actions by regulators who do not need a plaintiff at all.
Why Do Companies Use Pixels?
There is nothing inherently nefarious about pixels. They became ubiquitous for a simple reason: they are useful. Companies use pixels and similar tracking technologies to:
- Measure website traffic and performance;
- Determine whether digital advertising is generating sales or leads;
- Understand which pages visitors view and how they navigate a website;
- Build audiences for future advertising;
- Personalize advertising and online experiences; and
- Measure the return on advertising dollars.
In other words, pixels help businesses understand their customers. The problem is that doing so frequently requires information to move from the company's website to a third party. And increasingly, plaintiffs' lawyers and regulators are asking: Exactly what information is being transmitted, to whom, when, and did the consumer agree to it?
That is where things get complicated.
What Information Can a Pixel Collect?
The answer depends on the technology and how it is configured.
Tracking technologies may transmit information such as the webpage visited, buttons clicked, search terms, device and browser information, IP address, identifiers associated with a user or device, purchases, or other actions taken on the site. Standing alone, some of that information may seem relatively innocuous. But context matters.
A URL showing that someone visited a generic retail homepage is very different from a URL potentially revealing that someone researched a particular medical condition. A product identifier may reveal little by itself – until it is connected with an identifiable consumer. Information collected on a bank, health care, insurance, employment, or video-streaming website may raise issues that would never arise from the same technology operating somewhere else.
And pixels rarely operate in isolation. When information from a website is combined with information already held by an advertising platform or other third party, it may be possible to associate website activity with a particular individual or profile. That is one reason these technologies have attracted so much attention. Newer identity resolution and device fingerprinting tools can recognize the same person across sessions and devices without relying on cookies at all, so turning off cookies does not necessarily turn off the tracking.
So, What's the Legal Problem?
The technology itself is not necessarily the problem. The problem is what the pixel collects, where it sends that information, and whether that happens before the visitor has consented.
Plaintiffs have filed lawsuits alleging that ordinary website tracking technologies violate decades-old wiretapping and privacy statutes. Depending on the technology and circumstances, claims may be brought under the California Invasion of Privacy Act (CIPA), federal and state wiretap statutes, the Video Privacy Protection Act (VPPA), state consumer privacy laws, and other privacy and consumer-protection statutes.
CIPA remains the engine of this litigation, but filings have spread well beyond California. Florida is now the highest volume forum outside of it, with Pennsylvania, Illinois, and Washington close behind. Massachusetts is the exception: its high court held that the state's wiretap act does not reach ordinary website analytics, pushing plaintiffs there toward consumer protection and federal theories instead.
The theories vary, and courts have reached conflicting conclusions about many of them. But the litigation risk is very real. Perhaps more importantly, the technology can create risk before anyone at the company realizes it even exists.
Marketing departments add new tools. Vendors update software. Tags are added through tag-management platforms. A website redesign introduces new trackers. A consent banner may look correct but allow certain technologies to fire before the visitor makes a choice. The result can be a significant disconnect between what a company's privacy policy says its website does and what the website actually does.
Where the Courts Are Now
The most important development of the past year has little to do with pixels and everything to do with whether the plaintiff can show a real injury. Building on the Ninth Circuit's 2025 decision in Popa v. Microsoft, courts have held that a bare statutory violation is not enough for Article III standing in federal court; the plaintiff must identify a harm resembling a traditional privacy injury. Routine browsing data (an IP address, a device identifier, the fact that someone viewed a product page) has repeatedly been held insufficient.
That principle has migrated from the motion to dismiss to class certification, which is where the money is. In two decisions issued just five weeks apart, federal courts in California denied class certification after concluding that determining what data individual users transmitted, how they understood the disclosures, and whether they suffered any injury would require individualized inquiries. The practical lesson is that the records you keep today (what each tag transmitted, what each visitor saw and chose, and when) may be what defeats a class three years from now.
None of this means the theory is dead. Recently, one California federal court allowed a CIPA wiretapping and trap and trace claims to proceed against a national retailer, rejecting at the pleading stage the arguments that the trackers captured no content and the visitor consented. Ten days earlier, a different California federal court reached nearly the opposite conclusion, reasoning that the wiretapping provision was never meant to reach the internet at all. Companies should not assume the favorable line of cases is the settled one, particularly as appellate courts consider key questions regarding whether pen register and trap and trace provisions apply to routine website analytics and whether the sharing of IP addresses constitutes a concrete injury sufficient for standing.
Courts have also begun pushing back on filing volume. In July 2026, a federal judge declared a prolific individual CIPA filer a vexatious litigant in Shah v. Crain Comms., Inc. But the limits matter: that order does not stop demand letters or individual arbitration demands, which remain the highest-volume form of exposure.
The Millisecond Problem
One of the most important issues today is timing. A company may have an impressive cookie banner asking visitors whether they consent to advertising cookies. But if the advertising technology begins transmitting information the instant the webpage loads, before the visitor clicks "Accept," that banner may provide far less protection than the company thinks. This has become an increasingly important focus of website-tracking litigation.
It is a widespread problem, not an edge case. A study published in late June 2026 tested the 250 most-visited websites and found roughly half misconfigured a leading consent framework, and that about 40 percent of California-tested sites still reported consent as "granted" after the visitor's browser transmitted an opt-out signal. The banner rendered, the visitor opted out, and the data kept flowing.
The practical lesson is simple: Having a cookie banner is not the same thing as having a compliant consent process. Companies need to know not only whether consent is requested, but also what happens technologically before and after that consent is obtained. A banner that displays but does not actually gate tag firing is arguably worse than no banner at all, because it creates a documented representation a plaintiff or regulator can measure the website against.
If Your Website Has Video, Watch the Supreme Court
The Video Privacy Protection Act (VPPA), a 1988 statute enacted after a newspaper obtained a Supreme Court nominee Robert Bork's video rental records, has become a favorite vehicle for pixel claims against any website hosting video. The recurring question is who counts as a protected "consumer." Some courts hold that anyone receiving any good or service from a company that also offers video qualifies, including someone who merely signed up for an email newsletter, while others require a subscription to audiovisual content specifically. The Supreme Court of the United States is expected to resolve this split, with oral argument scheduled for October 2026. If your website hosts video of any kind, including product demonstrations, patient education, recorded webinars, or training content, and runs advertising pixels on those pages, this issue matters even if you have never thought of your company as a video business.
Regulators Have Opened a Second Front
For several years, tracking risk was almost entirely private litigation risk. That is no longer true. The FTC returned to this space in July 2026 with a complaint against a telehealth company, joined by two states, alleging it shared sensitive health information with a long list of advertising platforms while marketing itself on discretion and privacy. It was the agency's first significant new privacy case in roughly a year and a half, and agency leadership has signaled more are coming.
California's privacy regulator, now branded CalPrivacy, voted unanimously to begin formal rulemaking on opt-out preference signals (OOPS), including codifying the Global Privacy Control (GPC) as a valid signal. Enforcement staff made the expectations plain: businesses must accept the signal, must verify it works end to end rather than assume it does, and must understand that the opt-out belongs to the consumer, not to a single browser or device. California Attorney General (AG) Rob Bonta has made the same point through settlements, including a February 2026 resolution centered on opt-outs that applied only to the device that submitted them (even for logged in account holders) while data kept flowing to embedded third-party advertising companies.
Partial compliance is being treated as noncompliance. Nor is this exclusive to California: a multistate consortium of privacy regulators is coordinating strategy; California, Colorado, and Connecticut have an active joint sweep of businesses that ignore browser opt-out signals; and Connecticut has reported sweeping cookie banners for designs that make opting out harder than opting in.
Health care organizations should note one point in particular. A federal court vacated part of the Department of Health and Human Services' online tracking guidance in 2024, and more than two years later there is still no replacement. That vacatur is not a safe harbor: it addressed unauthenticated public webpages, while the guidance's treatment of authenticated pages (patient portals, scheduling flows, symptom checkers behind a login) was never disturbed. In practice, the enforcement risk for health care pixels now runs through private class actions and state regulators, with publicly disclosed provider settlements this year ranging from a few hundred thousand dollars to $9.5 million.
Do Not Count on Legislative Relief
Many companies have been watching California's SB 690, introduced as a broad "commercial business purpose" exemption to CIPA. As amended on July 2, 2026, that exemption is gone. What remains is far narrower: removing the private right of action for pen register and trap-and-trace claims and leaving those provisions to the California AG. The bill was passed by the California legislature on August 28, 2026, and remains with Governor Gavin Newsom for his signature as of this writing. Even if signed or no action is taken by the governor—resulting in the legislation taking effect on January 1, 2027—it would do nothing about the wiretapping claims that make up the large majority of website tracking suits. It is not the relief many companies think it is.
The broader trend runs in the other direction. New Jersey enacted a registration regime on June 30, 2026, reaching ordinary first party website operators who sell or license data downstream, and flatly barring the sale of sensitive data including precise geolocation and health information (a prohibition no consent banner can cure). It followed on July 23, 2026, with the first state law restricting personalized pricing based on browsing activity.
A New York bill sweeping algorithmically derived health inferences into a strict consent regime passed both chambers in June 2026 and awaits action from Governor Kathy Hochul. New comprehensive privacy laws in Indiana, Kentucky, and Rhode Island took effect in January 2026, as did Oregon's universal opt-out obligation, and beginning in 2027 California will require browsers to offer an opt-out setting, meaning signal volume, and exposure for companies that ignore signals is about to rise sharply.
Abroad, the trend is identical: UK guidance finalized in April 2026 confirms that consent obligations attach to tracking technologies generally rather than merely to cookies, and French regulators fined a major technology company €325 million in September 2025 over advertising and cookie consent practices.
Why Should Executives Care?
This is no longer simply an IT or marketing issue. Pixels sit at the intersection of marketing, technology, privacy, cybersecurity, and litigation. Yet responsibility for them is frequently fragmented among departments. Marketing selects the technology. IT implements it. A vendor may configure it. Legal drafts the privacy policy. And nobody necessarily checks whether all four pieces match. That is precisely where risk develops. Because the exposure spans various departments at once, closing the gap takes counsel comfortable working across the company, not just reviewing a policy after the fact.
And plaintiffs' firms know it. Website tracking claims have become one of the fastest-growing areas of privacy litigation, including claims under CIPA and other wiretap statutes. Courts continue to wrestle with these theories, meaning the law remains unsettled even as companies continue receiving demand letters and lawsuits.
What Should Companies Be Doing Now?
You do not necessarily need to remove every pixel from your website. You do need to understand what is there. Start with these five questions:
- What tracking technologies are operating on our websites and apps?
- What information does each technology collect or transmit?
- Who receives that information?
- When does the transmission occur, particularly, does it happen before consent?
- Do our privacy disclosures and consent mechanisms accurately reflect what is actually happening?
Further, companies should periodically scan their websites for tracking technologies, review the configuration of higher-risk tools, test consent management platforms to confirm they actually block technologies when appropriate, and establish a process for approving new tracking technologies before they are deployed. And do not assume that last year's review is still accurate. Websites change constantly.
The Bottom Line
Pixels are not new, but the scrutiny surrounding them is. For years, companies treated website tracking primarily as a marketing function. Today, the same technologies can create privacy, regulatory, and class action exposure.
The answer is not necessarily to stop using them. It is to stop using them blindly. Companies should know what technologies are operating on their websites, understand what information those technologies transmit, make deliberate decisions about when consent is required, and ensure their public-facing disclosures match reality.
Because when the next pixel demand letter arrives, "we didn't know it was there" is not much of a defense.
A short conversation now costs far less than responding to a demand letter later. If you need help assessing these risks, updating your website privacy or consent practices, or developing processes and procedures to protect your company from pixel exposure, please contact Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP, Alex Koskey, CIPP/US, CIPP/E, PCIP, David Oberly, or a member of Baker Donelson's Digital Marketing, AdTech, and Consumer Privacy Compliance Team.