A new decision from the Central District Court for Central District of California Judge Fred Slaughter in Reisberg v. Renaissance Learning may provide insight into what website and app tracking litigation could look like if California’s SB 690 becomes law and limits certain claims under CIPA, the California Wiretapping Law.

The case involved Renaissance, a K-12 educational platform that schools required students to use. Plaintiffs, including children under 13, alleged that Renaissance collected and shared personal information through numerous third-party analytics, advertising, and identity-resolution technologies. They asserted a wide range of privacy, wiretapping, and unjust enrichment claims.

The court dismissed all claims without leave to amend. In doing so, the court repeatedly stated that plaintiffs were attempting to fit modern data collection and sharing practices into traditional common law causes of action, and the court was unwilling to expand those doctrines beyond their historical boundaries.

The case is interesting to companies that have applications with third party trackers as it provides potential insight into three questions that are top of mind right now: 

  • If SB 690 becomes law, how viable are the alternative causes of action plaintiffs have begun asserting alongside or instead of CIPA claims?
  • Does it matter whether tracking occurs only within a company’s own website or application rather than across multiple websites?
  • Does the analysis change when the data belongs to children?

Below are some of the key takeaways. 

More causes of action, but not a “slam dunk”

If California SB 690 is signed into law, the wave of website tracking lawsuits may ebb, but there are still plenty of causes of action available to plaintiffs under California law, other state laws, and federal law.

This decision highlights, however, that those alternative causes of action come with their own significant hurdles.

For example:

Intrusion upon seclusion claims require more than the collection and disclosure of information on a company’s own platform. Courts may look for evidence that the defendant intruded into a private place, conversation, or matter, such as by tracking users outside the platform or continuing tracking across other sites. Courts also require the intrusion of privacy to be done “in a manner which is highly offensive to a reasonable person”. Routine practices, including the collection of internet browsing data and persistent identifiers, may not suffice. Courts frequently focus on the nature and sensitivity of the information at issue when determining whether the alleged conduct constitutes an egregious breach of social norms.

Public disclosure of private facts Claims for public disclosure of private facts may require more than sharing information with vendors, analytics providers, or advertising partners. Plaintiffs may face challenges showing both that the disclosure was sufficiently “public” and that the information disclosed was sufficiently intimate or sensitive.

Here, the court acknowledged that Renaissance allegedly shared information with numerous third parties, many of which were large and sophisticated companies. Nevertheless, it concluded that such disclosures were not equivalent to disclosure to the “public at large.”

Plaintiffs also faced a second hurdle: showing that the information disclosed was sufficiently sensitive or intimate to be highly offensive to a reasonable person. The court pointed to examples from prior cases involving such disclosures, including dissemination of photographs of a decapitated corpse, disclosure of HIV status, improper use of mental health records, and information associating a person with sexual molestation, while acknowledging that less extreme facts could also potentially qualify.

Here, however, the allegedly disclosed information largely consisted of information about how students interacted with Renaissance’s platforms, including page visits, content interactions, and video content viewed through the platform. The court concluded that plaintiffs had not plausibly alleged disclosure of sufficiently intimate private facts to satisfy the claim..

Federal wiretapping claims laims under the federal Electronic Communications Privacy Act (“ECPA”) face the additional obstacle of the party exception, which generally shields a party to a communication from liability. Plaintiffs therefore may be required to invoke the crime-tort exception by showing that the interception was undertaken for an independent criminal, tortious, or otherwise wrongful purpose.

The court noted that courts are divided on whether the crime-tort exception applies when a defendant’s primary motivation is financial gain, but appeared persuaded by the view that a profit motive does not automatically defeat application of the exception.

The exception has been found potentially applicable in situations involving:

  • violations of HIPAA;
  • disclosures that contradict representations made in a company’s privacy policy; or
  • uses of intercepted information that independently violate state law, including privacy-related causes of action.

Here, however, the court found that plaintiffs failed to plausibly allege any independent criminal, tortious, or otherwise wrongful purpose, particularly after the court dismissed the underlying privacy claims.

Unjust enrichment Unjust enrichment claims may require plaintiffs to establish not only that their information conferred a cognizable benefit, but also that there was an underlying wrongful act making retention of that benefit inequitable. The court was skeptical that the alleged collection of personal information alone was sufficient and further concluded that plaintiffs had failed to establish any underlying actionable wrong that would make retention of the alleged benefit unjust.

In short, while plaintiffs are increasingly asserting alternative claims alongside or instead of traditional CIPA theories, this decision demonstrates that those claims are far from a “slam dunk” and often involve elements that are substantially more difficult to satisfy.

ECPA and the Crime Tort Exception

The court’s discussion of the federal Wiretap Act serves as an important reminder that the “crime-tort” exception can still create risk even where a company is a party to the communication. Courts have found the exception potentially applicable where data is used for an independently wrongful purpose, including conduct that allegedly violates privacy laws, HIPAA, or even representations contained in a privacy policy.

Sensitive Information will always be more sensitive

Courts remain focused on the sensitivity of the information at issue. Health information, mental health data, financial information, and similarly sensitive categories of data continue to receive heightened scrutiny. By contrast, usage analytics, browsing behavior, and device identifiers may face greater challenges supporting common law privacy claims, at least absent additional facts.

Children’s Information may be sensitive

While this court was not persuaded that the involvement of children materially changed the analysis, businesses should not view that holding as a free pass. Regulators, including the FTC, have consistently treated children’s information as particularly sensitive, and children’s privacy remains a significant enforcement priority.

Your own site or cross site tracking?

Courts may be more receptive to claims involving tracking that extends beyond a company’s own website or app than claims involving data collection that occurs solely within the company’s own platform. Here the court rejected the claims despite the company having shared the information with third parties that use it for their own purposes. However, this conduct may still run afoul of privacy and consumer protection laws and similar case have been the subject of significant regulatory enforcement, especially when dealing with information of minors and children.