LinkedIn · November 17, 2025
The US internet is falling prey to the consent-banner plague. A more effective opt-out system will soon deliver greater agency
On the parallel evolution of ePrivacy compliance in the EU and the US, from the late 90s to the “Digital Omnibus” and California’s AB566
(You are reading a GenAI-free article, solely relying on auto-correct for some expressions and typos. A previous version of this article was shared with Masters of Privacy subscribers.)
The analysis below is basically an exercise in comparative law and an effort to build a bridge between two mostly disconnected worlds. All of it personal opinions and my own interpretation (feel free to help me polish it up), but in no case legal advice. I have broken it down into three parts:
- An introduction to US ePrivacy compliance, CIPA and VPPA claims - This will take the bulk of the article.
- Back to Europe. No magic pill.
- An opt-out that beats the opt-in at its own game.
The whole thing is rounded up by some resources available on the Masters of Privacy Substack: an analysis of the CIPA/VPPA case law (reaching 54 recent claims at this point), a free auditing tool, and basic explanatory videos.
Also, if anyone is tired of reading, we have published a "dramatized" recording of Part I on the Masters of Privacy podcast feeds (just to make it more digestible).
Down to it...
Part I. An introduction to US ePrivacy compliance, CIPA and VPPA claims
So, just when we thought the US internet was on a clear, predictable path towards a risk-based approach that pretty much amounted to an opt-out regime discriminating against the most intrusive personal data collection or data processing practices, a bunch of decades-old privacy laws suddenly appear in the rear-view mirror's blind spot to throw it all down the drain by persuading many website owners to deploy consent pop-ups before any third-party pixels, or cookies are fired.
Why does this sound so familiar to the European lawyer? Because, of course, we understand the feeling. This is very similar to what happened in May 2018 when, unable to find consensus in the alignment of the 2002 ePrivacy Directive (amended in 2009) with the more nuanced approach of the GDPR’s six legal bases, the European internet woke up to the worst of both worlds: a blanket “cookie-consent” requirement that could not care less about the very notion of personal data, or even the specific purpose of a given technology, together with a revamped, much harsher test for valid consent.
But the current drama is taking place in the United States. Universal opt-out requirements from targeted advertising, “personal data sales” and certain types of profiling are already being enforced across various states. Some of them (California, Colorado, Connecticut) have even announced a joint enforcement action (“sweep”) against websites unprepared for such opt-out signals. Providing additional certainty, California has just approved a law (AB566) that will finally force all browsers to support the Global Privacy Control (or other similar signal-management standards). As of 2027, this will result in Chrome, Safari and Edge finally joining Brave and Firefox under this new umbrella.
For a minute, as I was saying, it did look like the US was going to dodge the bullet that has ruined European websites, polluting the internet with consent requests that blackmail and frustrate users while creating a false sense of control. That is, until a few people discovered they could make money by scrutinizing today’s websites under the light of “legacy” privacy laws that once protected individuals against wiretapping and the sharing of video rental records. Let’s say that what bureaucracy (and the clash of mighty lobbies) did to the European internet, greed and the private right of action are doing to the American internet.
For a minute, it did look like the US was going to dodge the bullet that has ruined European websites, polluting the internet with consent requests that blackmail and frustrate users while creating a false sense of control.
The California Invasion of Privacy Act (1967) leads the pack in the first group, offering $5,000 of statutory damages per violation and resulting in over 1,500 lawsuits filed against website owners since 2022, with demand letters and early settlement offers estimated to have targeted tens of thousands of companies. Arbitration clauses hoping to protect defendants have had the opposite effect, quickly multiplying potential costs and forcing website owners into an even tighter corner. Similar anti-wiretapping laws in Pennsylvania (WESCA), Arizona (TUCSRA), or Florida (FSCA) are starting to gain presence, despite providing for smaller statutory damages ($1,000 per violation). Wells Fargo’s $19.5m CIPA settlement after it was found to serve pixels on its website is one of the largest known to date.
The federal Video Privacy Protection Act (1988) -originally enacted after a journalist managed to obtain and publish video rental records for Reagan’s Supreme Court nominee Robert Bock (in fact, to make a point against his narrow view of privacy rights)- has become the weapon of choice in the second camp. It provides for $2,500 of statutory damages per violation. Famous settlements include Buzzfeed’s $9m for the inclusion of the Meta Pixel in website-embedded videos.
What are the technologies at play?
We could easily differentiate between data processors and data controllers (thus mapping it to GDPR concepts).
In the first bucket we will find marketing and data analytics solutions that act on your instructions (data processors) for the purposes of improved website performance, visitor support, analytics and the general improvement of the customer experience. By their nature, wiretapping claims tend to search for the following types of data processors: session replay solutions (FullStory, Clarity, HotJar/Contentsquare), AI chatbots (Drift, Salesforce, Qualtrics), Analytics (Adobe, Heap, Google Analytics). Video privacy claims look at video analytics platforms such as Adobe Analytics.
We will find the larger platforms (digital advertising channels on which you are running campaigns) in the second bucket. Ad investments are measured, improved, and made more cost-efficient through attribution or targeting pixels on the advertiser’s digital properties. Third parties are in this case assuming the role of an independent (or in some cases “joint”) data controller, able to use the collected signals for their own overarching purposes, beyond the time and budget constraints of a given campaign. The usual suspects do not change much across both wiretapping and video privacy claims: Meta, TikTok, Snapchat, Google, Amazon.
What legal grounds are plaintiffs usually relying on in their approach to their preys?
To put the focus on CIPA first, it provides two main avenues for plaintiffs: Eavesdropping and the use of a Pen Register or Tap/Trace Device. The first one will make specific contents, or the actual message being recorded a central part of its claim. The second will focus instead on IP addresses or metadata, just as a Pen Register would care about phone numbers instead of the actual communications.
Section 631 a) of the California Penal Code (where CIPA is codified), the so-called “eavesdropping” provision, requires that the contents of a communication are intercepted in transit without consent from all participants. Given that parties to the actual conversation (that is, the website and its visitor) are exempted from such claim, plaintiffs will also have to prove that the website has “aided and abetted” a third party (the embedded technology) in its interception. Defendants, therefore, can rely on four different strategies to counter a claim: a) There is no such “eavesdropper” because the alleged third party acts as per its instructions and is akin to a “mere tape recorder” (see Graham v. Noom) - this case will be strengthened by the fact that the recipient has no means to benefit from such data; b) No such “content” has been intercepted, as only metadata has been passed through to such third party (see In Re Zinga or Yoon v. Lululemon); c) The “in-transit” test fails as it was not contemporaneous (see Mastel v. Miniclip, where the data being accessed had previously been stored in the device onto which the app had been installed); and d) The visitor had consented to the interception.
Section 638.50 and 638.51 a) of the CPC provide the grounds for Pen Register and Tap/trace device claims, the underlying idea being that nobody can tap a specific device without a court order. The unique identifier of such a device, or any metadata surrounding the actual content, becomes the essential element in these cases, as the transmission of a “message” will itself run counter to its core definition and invalidate the claim. Defendants will typically rely on three strategies as a result: a) There has been an interception of actual content, rather than mere metadata (counterproductive as it sounds), and this kills the claim, as the definition of a pen register falls by the wayside (as in Kishnani v. Royal Caribbean); b) The plaintiff lacks standing as no actual harm or injury have taken place and the case bears no resemblance to the traditional torts of privacy (as in Gabrielli v. Insider); and c) The visitor consented to the interception.
As for Video Privacy Protection Act claims, they must argue that a defendant which acts as a Video Tape Service Provider (VTSP) knowingly shared personally identifiable information about a “subscriber” with a third party without the customer’s consent. It follows that defendants have five primary lines of defense: a) The company cannot be considered a VTSP (as in Cantu v. Tapestry/Coach); b) The plaintiff is not really a subscriber (an argument that failed in Mata v. Zillow and Jackson v. Fandom); c) The defendant did not knowingly share anything (as in In Re Hulu); d) The information being shared does not amount to PII (as in Edwards v MUBI); e) The plaintiff had consented to it.
Options on the table
Ok, assuming that you have not yet received a demand letter (in which case I strongly suggest that you reach out to one of our excellent past and coming Masters of Privacy guests and other experts in our network - Jennifer Oliver, Matthew Pearson, Taylor Bloom, John Pavolotsky). there are a few things that you can do, depending on how many enemies you want to make in the marketing, analytics, IT, or AI departments:
You may want to play it very safe with a catch-all consent banner that requires explicit consent for each purpose, à la EU ePrivacy Directive. Do you have enough volume of website visitors to be able to do anything meaningful with a 10-15% sample of your audience in terms of campaign measurement, content analytics, session replay, or even AI chatbots? If the answer is no and you still want absolute certainty - Why keep those trackers at all? Yes, I know some people will argue that their numbers are much better, but I have already covered why I think this is a specific European pattern born out of the long-running mistreatment of local audiences.
Anyway, you may bring your risk tolerance up by one notch. Let’s say that you cannot really fight the entire marketing department. You need the data, and it cannot be 15% of the data.
Tweaking a consent banner to the point that it results in greater acceptance rates has become quite a risky business. Despite the fact that the US remains, insofar as the specific regulatory environment is concerned, an opt-out regime, public enforcement authorities are taking measures against unfair and deceptive practices (both under the FTC mandate and in the state-level version of the same provisions) and a choice which does not provide a perfect balance between both options is being considered a “dark pattern”, potentially exposing the company to a public enforcement action. This is also rather counterintuitive, as it would appear that showing a mere pop-up notice of the pixels that will follow could arguably be equivalent to the common call center disclaimer (“your call will be recorded for training purposes”) that once stemmed from the very same anti-wiretapping laws - abandoning the website would then amount to hanging up the phone as a means of declining consent.
This would take us into what seems to me like the most intelligent strategy, assuming that marketers are willing to play along. How about replacing the riskier vendors with alternative providers which are demonstrably unable to use the data being collected for their own purposes? Such a move should facilitate a successful motion to dismiss under the “mere tape recorder” defense (or under the light that no specific harm could have resulted from it, leading to a lack of standing).
We cannot treat this last option lightly, however, as internal marketing or analytics teams will have developed long-term relationships with their existing vendors. Furthermore, their own technical competencies (or worse, their careers) may very well be strongly tied to the very specific solution and the accreditations a particular supplier may have issued over the years. As with everything that steps on emotional barriers, this is fine surgery, and requires management buy-in. The trade off, painful as it is, could be presented in the following terms for everyone to understand:
Would you rather deploy a consent banner that offers a clean accept/reject choice and stick to vendor x for session recording, website analytics, A/B testing, personalization, etc. - OR switch to a privacy-friendly alternative (there always is one that can work with aggregate data or any other data minimization and privacy by design strategy) and keep 90% of your audience? In other words: Would you rather go deep and narrow, or shallow and wide?
An additional question could be thrown in the mix: Do the 15% of visitors or customers who agree to being tracked confidently represent your entire audience?
Hard times call for hard choices. Dismissing the growing regulatory pressure for Privacy Enhancing Technologies and data minimization (even putting the extortion that CIPA claims boil down to aside) will only result in greater pain further down the line.
Part II. Back to Europe
Ok, so how does this help EU-based lawyers? For starters, any meaningful consumer brand doing business in California will be subject to both CPPA enforcement actions and privacy-related class actions (as France-based L’Occitane has found). The “GDPR-native” peace of mind will not really help beyond wiretapping opt-in defenses: complying with the ePrivacy Directive (eg., for cookie consent) does not translate fully into opt-out compliance (e.g., supporting the Global Privacy Control signal) or local transparency requirements (e.g., Do No Sell/Share notices in California).
In the use of website analytics tools a gap is also opening, as some EU data protection authorities (France, Spain, The Netherlands) are now allowing businesses to skip consent requirements for stand-alone, high level cookie-based analytics.
Most of us have read about the proposed reforms to the ePrivacy Directive and the GDPR to deal with so-called “consent banner fatigue”. Although the initial leak of the Digital Omnibus reform seems too raw (or early-stage) a document to arrive at any meaningful conclusions, even the most timid advance in this direction should result in the codification of the aforementioned trend amongst supervisory authorities - pretty much along the lines of recent changes in the UK's personal data protection framework. None of these scenarios is, however, getting a free pass from CIPA plaintiffs.
In other words, adapting to “EU standards” is no longer a magic pill, but an effective cross-jurisdictional strategy can still be worked out.
Part III. An opt-out that beats the opt-in at its own game
I may sound like a broken record reminiscing of my Brussels life in the late 90s, and how I managed to get my hands on early drafts of the ePrivacy Directive. Not only was an opt-in approach part of the discussion from the outset (eventually discarded - to be revived in 2009), but browser-level configurations, in alignment with open standards, were always the obvious solution to all. To the point that Recital 66 of its updated version would end up including the following provision: “the user’s consent to processing may be expressed by using the appropriate settings of a browser or other application.”
If back then the W3C’s Platform for Privacy Preferences (P3P) standard -eventually supported by both Internet Explorer and Netscape Navigator- was considered insufficient (complex, hard to enforce, and shifting the burden to individuals), the Global Privacy Control -which California’s new law will, as said, oblige all browsers to support by 2027- is today much better positioned to facilitate choice while ensuring convenience.
The paradox of it all is that an opt-out approach that actually works, allowing people to make a sweeping choice in advance without friction or complexity, will result in far fewer trackers and much better privacy than the theoretically stricter opt-in regime.
An opt-out approach that actually works [...] will result in far fewer trackers and much better privacy than the theoretically stricter opt-in regime.
An alignment of the stars might also be in the offing. If the same California legislature manages to pass SB690 by 2027 (putting an end to CIPA claims) we know that could be the year that we collectively reclaim control of the Internet from consent banners. The clutter-free, accessible, mobile-friendly web that once made us so happy, but now even safer and more respectful of our personal data.
Bottom line:
- Wired: A single choice in your browser to discard all third-party trackers for every single website, forever avoiding consent banners that reiterate a question that has been answered in advance.
- Tired: An illusion of control and respect that only serves CMP software vendors.
All additional resources: From wiretapping and video rentals to website pixels, SDKs, and APIs. CIPA/VPPA litigation, risk management, and practical strategies (Nov 2025 update)
A dramatized audio version of Part I (Masters of Privacy, November 16 2025).