California may no longer be the ideal forum for plaintiffs.
Class action lawsuits alleging improper tracking of online activity have grown more prevalent in recent years as both use and awareness of the software have continued to increase.
But a federal court in California has recently called into question whether a class action is the appropriate way to resolve those claims. In Ingraham v. Capital One Financial Corporation, the court denied the plaintiff’s motion for class certification, saying that three key questions would require individualized proof and would therefore not be appropriate or possible to resolve on a class-wide basis.
What was tracked. According to the court, the first key question was what information was tracked. The information tracked would vary depending on the individuals’ browsing activity and the configurations of their devices and web browsers. Although the question of which types of personal information were generally tracked applied to the class as a whole, the answer would not be common to all of the members of the class. Rather, there would have to be individualized findings for each class member.
Consent. The second key question related to consent. The court identified two questions that would have to be answered individually for each class member: (1) which disclosures they received (because the website provided different disclosures based on the legal requirements of the jurisdictions from which users accessed the site), and (2) the class members’ individual understandings of those disclosures.
Injury. The third key question related to whether all of the members of the proposed class had experienced enough of an injury to have standing to sue. Even with respect to the named plaintiffs, the court had ruled earlier that one plaintiff had demonstrated a sufficient expectation of privacy that could have caused injury, but another named plaintiff had not.
The ruling in Ingraham is significant because the issues addressed in it are not specific to the facts of the case but could apply to essentially any class action alleging claims based on website tracking. Other federal courts in California have reached similar conclusions (see here and here). Plaintiffs have long been attracted to California because of its stringent privacy statutes and the potential statutory damages they carry for violations. However, if the California courts continue to deny class certification, plaintiffs may start to look elsewhere.
The Constangy Cybersecurity & Data Privacy Team regularly defends businesses of all sizes and industries against privacy lawsuits. With experience in jurisdictions across the nation, we are happy to help defend your organization. If you’d like to learn more, please contact us at cyber@constangy.com.
- Partner
He regularly defends clients in a variety of complex and high-stakes privacy and cyber-related litigation, including class action data breach suits, wire fraud litigation, and employee data theft actions. John’s experience ...
- Associate Attorney
Scott works with our cyber litigation team to defend clients in class actions arising out of data privacy or security incidents. He has several years of experience representing clients in state and federal courts in matters ...
The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation.



