I’ve spent a lot of time talking about the lifecycle of privacy claims. For the most part, they all follow the same path:

Pen-register/trap-and-trace claims provide a useful example.
Following Greenley v. Kochava in 2023, plaintiffs began sending demand letters alleging violations of CIPA's pen-register statute. A year later, Judge Klausner's decision in Moody v. C2 Educational Systems gave plaintiffs an early strategic victory. Settlements followed, including several class-wide resolutions worth millions of dollars.
The next wave of cases appeared poised to target large publishers and other high-traffic websites. But before that could happen, the California Court of Appeal accepted the writ in Variety Media, LLC v. Superior Court, signaling a serious challenge to the theory. The Legislature then went a step further. On September 30, 2026, Governor Newsom signed SB 690, eliminating private claims under CIPA Section 638.51.
The Wiretapping Lifecycle
Wiretapping claims under CIPA have followed a similar path, but the response phase looks different.
For pen-register claims, the response was legal. Defendants challenged the theory through appellate review, and the Legislature ultimately amended the statute.
For wiretapping claims, the response has largely been factual.
Defendants have achieved their greatest successes by focusing on two questions:
- What information was actually collected?
- How was it collected?
Take Popa v. Microsoft Corp., for example. Microsoft focused on the nature of the information collected, arguing that the alleged collection did not constitute a concrete privacy injury. The Ninth Circuit agreed, likening the conduct to a "store clerk's observation that a customer lingered in one aisle, skipped another, and ultimately made a purchase," conduct that would not ordinarily be considered highly offensive.
Other technology providers have followed a similar strategy. In one recent case, a provider argued that its conduct was more akin to an employee observing users from a distance as they picked up informational forms or brochures. The court agreed and dismissed the claims for lack of Article III standing.
Defendants have also prevailed by focusing on how information was collected. In Torres v. Prudential Financial, the court found no evidence that the technology provider attempted to understand or decipher the contents of communications while they were in transit, a key factual deficiency in the plaintiffs' theory.
Why Plaintiffs Targeted Website Operators
The common thread in these cases is straightforward: the technology provider was a defendant.
Given the scale at which many technology providers operate, its seems counterintuitive not to sue the tech provider. Why limit yourself to one website when the same technology may be deployed across thousands of websites?
The answer is knowledge. Technology providers understand exactly how their products function. Website operators often do not.
That is not a criticism. Website operators are in the business of publishing content, selling products, or providing services, not building analytics and advertising technology. They rely on third-party vendors precisely because those vendors possess the relevant expertise.
That expertise matters when litigation turns on highly technical questions regarding web architecture and data collection. Website operators may understand what information a tool collects and may even possess documents reflecting those configurations. But they often cannot explain, with technical precision, how the collection occurs. Technology providers can.
When the technology provider is absent from the case, plaintiffs benefit from that knowledge gap. When the technology provider is present, the gap disappears. The litigation becomes a dispute about facts rather than assumptions.
That distinction may help explain why the overwhelming majority of wiretapping claims have been brought against website operators rather than the companies whose technologies are actually at issue. It also helps explain why technology providers have enjoyed some of the most significant defense victories in the space.
Takeaway
Many of the most important wiretapping decisions over the last two years have not turned on legal theories. They have turned on facts.
Importantly, those facts generally do not change based on who is sued. Plaintiffs typically allege that the website operator is liable because it allowed the technology provider to engage in the challenged conduct. The underlying technology remains the same.
The difference is confidence. Technology providers know exactly how their products work and, therefore, whether the facts support a defense. Website operators often do not.
That knowledge gap has fueled years of settlements and theory testing. As website operators become more sophisticated and technology providers increasingly enter the litigation, that gap is beginning to close. If it does, the lifecycle of wiretapping claims may finally reach its response phase.

/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-10-02-03-11-45-039-6abf20f1792ab853edbc1887.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-10-01-17-11-58-835-6abe945ed57b9b5290e571bd.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-09-29-18-56-12-739-6abc09ccf976767f673c6dbc.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-09-10-19-25-14-418-6aa3041aa309dcf7376bc3b9.jpg)