Class Action Lawsuits Continue Targeting Companies For Tracking Users’ Website Activity
Time 3 Minute Read

Plaintiff’s firms continue to file variations of state law wiretapping lawsuits over “session replay” software and “live chat” or “chatbot” applications in various jurisdictions. These filings typically allege that companies use such software tools to record users’ interactions with a website without first obtaining users’ consent, thereby violating the wiretapping, eavesdropping, or interception provisions of various state laws. Session replay software allows companies to record and play back users’ interactions on its websites. The “live chat” or “chatbot” feature allows a website user to engage in text conversations with an assistant, to which the company has access. These wiretapping claims threaten substantial penalties. Companies that use these web-tracking tools, however, can take steps to protect themselves from these lawsuits by a careful examination of the software being used and by evaluating what disclosures or consents may be warranted.

Plaintiffs’ claims arise from the wiretapping or interception provisions of various state laws that prohibit the recording of confidential communications without the consent of all parties to the communication. California courts, for example, have experienced a surge of class action filings pursuant to the California Invasion of Privacy Act (“CIPA”). Specifically, section 631 of CIPA prohibits (i) intentional wiretapping of any telegraph or telephone wire, line, or cable, (ii) willfully and without the consent of all parties attempting to learn the contents of a communication in transit, and (iii) attempting to use or communicate information obtained as a result of engaging in either activity. CIPA entitles plaintiffs to $5,000 per violation. A violation arguably occurs each time a user visits a website. Thus, these penalties can grow quickly.

Further, recent case law has encouraged the Plaintiffs’ bar with favorable interpretations of these state statutes. For example, the Third Circuit recently took a narrow view of the direct-party exception defense under Pennsylvania’s Wiretapping and Electronic Surveillance Control Act, resulting in the initiation of several class actions. The direct-party exception works to exempt a party from liability pertaining to communications directly with another party. In Popa v. Harriet Carter Gifts, Inc., however, the Third Circuit held that the legislature “codified only a law-enforcement exception, thus limiting any direct-party exception to that context” and remanded the case for further consideration by the District Court, which had not reached the issue of consent. Thus, companies facing claims under the Pennsylvania statute cannot avoid liability merely by showing that plaintiff and the company were the direct parties to the communication. If successful, the Pennsylvania statute entitles plaintiffs to $100 a day for each day of violation, or $1,000, whichever is higher.

Accordingly, it is important for companies to be aware of how their website software is being utilized, what information they and their vendors are collecting from website users, and what disclosures or consents may be warranted in light of the above. User consent is consistently a defense under state wiretapping statutes. Therefore, companies should evaluate their website terms of service and privacy policies to confirm that they include sufficient and clear disclosures and/or obtain user consent depending on the type of activity taking place on company websites by the company and its service providers.

  • Partner

    John is the managing partner of Hunton’s Miami office. He handles a range of complex litigation matters, including financial fraud, defense of financial institutions, and cutting-edge cybersecurity issues. As a former federal ...

  • Associate

    As a member of the firm’s litigation team, Natalia’s practice focuses on commercial litigation and arbitrations. Natalia has successfully represented clients in various aspects of litigation in both state and federal court ...

You May Also Be Interested In

Time 3 Minute Read

On March 24, 2026, Washington Governor Bob Ferguson signed House Bill 2225, an Act regulating artificial intelligence companion chatbots.

Time 3 Minute Read

On January 8, 2026, the Kentucky Attorney General announced the first enforcement action against a company for alleged violations of the Kentucky Consumer Data Protection Act, just eight days after the law went into effect. The enforcement action is part of a larger legislative and regulatory focus on AI-powered chatbots used by minors.

Time 4 Minute Read

On May 9, 2024, the First Circuit became the first federal appellate court to address whether national retail websites’ use of session replay code creates specific personal jurisdiction for wiretapping claims allowing website users to hale retailers into court in any state where they visited these websites. The First Circuit concluded that it does not. It held that a website user failed to demonstrate that Ohio-based Bloomingdales.com intentionally targeted its website and its accompanying use of session replay software at users in Massachusetts and, therefore, failed to establish specific personal jurisdiction over Bloomingdales.com for alleged violations of the Massachusetts Wiretapping Act and Massachusetts Invasion of Privacy Statute. Rosenthal v. Bloomingdales.com, LLC, No. 23-1683, 2024 WL 2074685 (1st Cir. May 9, 2024). 

Time 4 Minute Read

Earlier this month, a Pennsylvania federal judge held that users of Bass Pro Shops’ and Cabela’s websites lacked Article III standing to sue the retailers for use of “session replay” software, where the users failed to allege that the software captured their personal information, such as financial data or medical diagnosis information.  In Re: BPS Direct, LLC, and Cabela's, LLC, Wiretapping, No. 2:23-md-03074 (E.D. Pa. Dec. 5, 2023).  

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page