On November 18, 2025, the U.S. District Court for the Southern District of California denied Adidas’s motion to dismiss a putative class action alleging that the company violated the California Invasion of Privacy Act (“CIPA”) by installing tracking pixels on consumers’ web browsers without their consent. The ruling holds that tracking pixels can constitute “pen registers” under CIPA and that standard browsewrap disclosures may be insufficient to establish consumer consent.
Background
Plaintiffs alleged that Adidas installed TikTok Pixel and Microsoft Bing tracking pixels on its website which consumers use to browse and purchase branded products. These tracking pixels are small, nearly invisible images embedded in a website that, once installed on a user’s browser, can track user interactions and collect a broad range of data. The data collected by the TikTok Pixel included timestamps, IP addresses, unique device identifiers, device details, and browser information. In addition, TikTok Pixel’s “AutoAdvanced Matching” feature enabled personal information such as names, dates of birth, and addresses to be sent to TikTok to identify targeted individuals. The Microsoft Bing Tracker similarly placed cookies on user browsers to collect information, including a unique Microsoft ID used to track activity across the internet.
Adidas did not actively notify users of the trackers on its website. Instead, the company maintained a link to its Terms and Conditions and Privacy Policy in the footer of its website in small font, which users could access only by scrolling to the bottom of the page. The Privacy Policy stated that cookies and other tracking technologies were implemented on browsers to collect and store data.
Key Holdings
Statutory and Article III Standing. The court held that plaintiffs sufficiently alleged both statutory standing and Article III standing. With respect to statutory standing, the court noted that district courts in the Ninth Circuit have consistently concluded that a plaintiff in a CIPA action need not allege actual harm beyond the invasion of the private right conferred by the statute. The court further held that CIPA codifies a substantive right to privacy, and the violation of that right gives rise to a concrete injury sufficient to confer Article III standing without any requirement that the information collected be sensitive or misused.
Adidas argued that the plaintiffs’ claimed injuries were not consistent with traditional privacy harms, relying on Popa v. Microsoft Corp., 153 F.4th 784 (9th Cir. 2025), in which the Ninth Circuit found that session-replay technology capturing only browsing interactions was insufficient to constitute a traditional privacy harm. The court distinguished Popa, finding that the tracking pixels at issue here collected a much broader set of personal identifying and addressing information, which is squarely within the scope of traditional privacy harms.
Tracking Pixels as Pen Registers. The court agreed with courts in the district and elsewhere that website-based tracking pixels can plausibly constitute “pen registers” under CIPA Section 638.50(b). The court emphasized that CIPA’s definition of a pen register is intentionally broad and not limited to specific technologies. This is the case even when only IP addresses are collected.
Consent Defenses Rejected. The court rejected two consent-based defenses raised by Adidas. First, the court found that Adidas, as the website operator, was not the appropriate “user” whose consent could defeat a CIPA claim; the relevant question is whether the consumers themselves consented to the placement of trackers on their browsers. Second, the court held that Adidas’s browsewrap Terms and Conditions and Privacy Policy did not provide adequate notice to consumers because the terms were buried in the footer of the website and there was no mechanism, such as a pop-up window or checkbox, to obtain affirmative consent.
Camplisson v. Adidas America, Inc., 809 F. Supp. 3d 1095 (S.D. Cal. Nov. 18, 2025).
