Consent Banner Litigation: When the Fix Becomes the Target

Many companies with consumer-facing websites have spent the last several years defending a surge of invasion of privacy and privacy litigation claims. A common response has been to deploy cookie consent banners advising visitors that the site uses cookies, and then offering some way to accept or reject them. Cookie consent banners also provide a mechanism to effectuate data subject opt-out requests pursuant to comprehensive consumer data privacy laws such as the California Consumer Privacy Act. The idea is straightforward: give users a way to signal their choices about tracking and reduce the risk that a plaintiff can later claim data was gathered without consent. That approach remains a sensible and effective way to mitigate risk, and a banner with the appropriate consent language that honors a user’s choice continues to be a viable defense to wiretapping and wrongful-collection lawsuits.

Plaintiffs’ firms take a different view. A slew of recent lawsuits takes aim at cookie banners, focusing on alleged instances when the banner allegedly did not function as intended or when tracking begins before the banner appears. These new theories seek to transform a tool that was meant to provide privacy choices to the consumer and reduce exposure for the company into possible grounds for a privacy lawsuit.

Banners That Do Not Do What They Say

The typical fact pattern in a non-functioning cookie banner case alleges that the site places cookies on a visitor’s browser and continues to share information with third parties even after the visitor clicks a button to reject all non-essential cookies or tracking technologies. Plaintiffs frame this as a broken promise akin to fraud. They use this alleged broken promise to support an array of common law and statutory claims, including invasion of privacy, intrusion upon seclusion, common law fraud and misrepresentation, wiretapping and pen-register or trap and trace theories under the California Invasion of Privacy Act (CIPA) and the Electronic Communications Privacy Act. A recent complaint filed in the Northern District of California illustrates the pattern well: the plaintiff alleged that after clicking “Decline All,” the operator nonetheless caused third-party cookies to be placed and transmitted the visitor’s data to advertising and analytics partners, contrary to what the banner and cookie-settings window represented.

So far, courts have not agreed on how to treat these theories, and no clear rule has emerged. In one case, in federal court in the Northern District of California, the plaintiffs alleged that clicking “Reject All” did not actually stop the site from placing cookies and letting third parties track them. The court let the intrusion upon seclusion, invasion of privacy, and some of the common law fraud claims move forward, reasoning that a promise to honor an opt-out, followed by tracking anyway, could add an element of deception that makes the alleged intrusion offensive enough to survive an early challenge. But the court threw out the CIPA wiretapping and pen-register claims, because the plaintiffs never alleged that they had any actual communication with the site that could have been intercepted, and it dismissed one plaintiff’s fraud claim because she did not say clearly enough when she visited the site. That decision allowed some claims to proceed while dismissing others. But other courts have been less receptive.

In another Northern District of California case involving a portfolio of websites, the court dismissed CIPA wiretapping, pen-register, federal Wiretap Act, invasion of privacy, and unjust enrichment claims, holding that the plaintiffs had not pleaded the fraud-based theories with the specificity that federal rules require. Later rulings in that same litigation allowed certain fraud claims to proceed only after the plaintiffs added the specific details about which sites they visited and when.

As these cases demonstrate, plaintiffs still face real pleading challenges, and several theories in these complaints have fallen even when the underlying story about a broken banner is compelling. But the risk is genuine: where the facts are well pleaded, at least some courts have shown a willingness to let claims proceed past an early motion to dismiss, which is enough to generate litigation exposure.

Technology That Fires Before the User Can Choose

The second flavor of claims focuses on timing. Here, the cookie banner functions as intended, but the cookies or trackers are alleged to fire before, sometimes only milliseconds before, the visitor has any chance to accept, reject, or customize. On this theory, plaintiffs argue that a banner appearing after the scripts have already run offers no meaningful consent, and they point to the sequence of script loads and cookie drops as the heart of the alleged violation.

In one case, a federal court in the Southern District of California let a proposed class action making a CIPA pen-register claim go forward, where the site allegedly buried its disclosure in a footer instead of using a pop-up that asked users to agree before the trackers fired. After the court reasoned that the pixels could plausibly count as a pen register under CIPA’s broad language, the court found that the footer-only approach, without a pre-tracking affirmative consent step, was not enough to show that users had consented. Beyond the filed cases, many more claimants have sent pre-suit demand letters alleging that consent banners are insufficient where pixels fire upon page load, often attaching technical evidence showing the sequence of script execution relative to the user’s first opportunity to interact with the banner.

Companies still retain their usual defenses to these claims on the merits, and some courts continue to be skeptical of these theories, dismissing cases on grounds ranging from the absence of any interception of content “in transit,” to a lack of standing, to a conclusion that routine searches on a website do not implicate a protectable privacy interest. But the trend is clear: plaintiffs are now looking at websites where a user starts to be tracked before any interaction with the banner can occur, and companies should treat this as a new potential area for increased litigation activity.

Practical Implications

None of this means that a consent banner will violate the law and shouldn’t be used. To the contrary, a properly functioning banner with appropriate disclosures can mitigate risk, and many defenses remain available on the merits, including the pleading standards that have already defeated a number of these theories. The practical concern is simply that a consent tool adopted to answer one set of privacy claims can, if it does not function carefully and comprehensively, create a factual hook for the next set of privacy claims. In that sense, a poorly implemented banner risks plugging one hole while opening another, because it can be characterized as evidence that the operator knew that consent mattered and collected data anyway. Because this area is evolving quickly and the theories, defenses, and rulings are still taking shape, any company using a consent banner should speak with privacy counsel before deciding whether and how to adjust its approach.