On March 25, 2026, in the Central District of California, Judge Frimpong denied a bank’s Motion to Dismiss a putative class action alleging the bank disclosed to LinkedIn, without consent, the personally identifiable information that loan and credit card applicants entered on its website through an embedded LinkedIn Insight Tag, holding that the plaintiff had Article III standing, that the Court had personal jurisdiction over the bank, that the complaint satisfied Rule 8, and that the plaintiff stated claims under the Electronic Communications Privacy Act, the California Invasion of Privacy Act, and the California Constitution.
Background. Garcia alleged that, while applying for an unsecured loan through the bank’s website, he provided citizenship, housing, and employment information. He used the same device and browser through which he maintained a LinkedIn account, and alleged that the bank’s LinkedIn Insight Tag disclosed his personally identifiable and nonpublic financial information to LinkedIn without consent. The putative class claims under the ECPA, CIPA, and California constitutional privacy protections challenged the alleged interception and disclosure of loan-application information. The bank moved to dismiss, contesting Article III standing, personal jurisdiction, notice, and the sufficiency of the statutory and constitutional claims.
The Court’s Analysis. The court applied Article III’s concrete-injury requirement, including TransUnion’s rule that a statutory violation alone is insufficient, but recognized that privacy rights protected by the common law, ECPA, and CIPA can support standing when the alleged disclosure implicates a legally protected interest. Garcia identified the categories of information disclosed—citizenship, housing, employment, and other confidential loan information—and alleged that LinkedIn could associate that information with his identity. Those allegations plausibly described a concrete privacy injury. The court also found a tortious purpose sufficient to overcome the ECPA and CIPA party-exemption arguments, and held that the complaint plausibly alleged an intentional interception of communication content. Finally, the bank’s purposeful online targeting of California consumers and the alleged injury to a California resident supported specific jurisdiction, while the complaint satisfied Rule 8.
Significance. The ruling places financial-application tracking in a materially different category from claims involving routine browsing metadata. Businesses using advertising pixels on lending or other sensitive-service websites should assess whether the technology can transmit identifiable application information and whether consent and disclosure practices address that risk.
Garcia v. Truist Financial Corp., 2026 WL 972328 (C.D. Cal. 2026).
