Insights
E-Commerce Compliance Series (I): Why Are Cross-Border Sellers Being Sued in the U.S. Over Website Cookies?
Author
Jiaxin Wu · 吴嘉欣
美国(纽约州)执业律师
Published
2026-03-09 · 17 min read
TL;DR
Plaintiffs are no longer suing under data privacy statutes. They are using CIPA — a 1967 wiretapping law — to characterize tracking code as an unlawful interception device.
Over the past year, a notable trend has emerged in U.S. litigation: demand letters and class actions over website data tracking — cookies, pixels, session replay — are growing markedly.
Technically, take cookies as an example: they are small data files stored automatically on a visitor's device when they land on your site. They typically run silently in the background, recording login state, user preferences, or browsing paths. Some cookies are necessary to keep a site functioning; the more contentious ones are the marketing cookies used for analytics, personalization, and following your ads across the web. Nearly every modern direct-to-consumer site uses them, and most companies have no idea how many trackers fire the moment someone reaches their homepage.
It is precisely that silently running code that has become the focus of legal attack. Cross-border clients receiving a demand letter from a U.S. firm are often bewildered, and their first question to us is: "There's a privacy policy link in my footer and a consent banner — why am I being sued?"
In the current U.S. environment, a privacy policy or a pro forma cookie banner is no longer an effective legal firewall. Below I break the risk down across three dimensions: the legal theory, the technical traps, and compliance strategy.
I. The Shift in Legal Theory: From "Notice" to "Wiretapping"
Traditional compliance thinking rests on notification — telling users we collect data. Plaintiffs' counsel have adopted a more aggressive approach, relying not on data privacy statutes but on the California Invasion of Privacy Act ("CIPA").
(1) An Old Statute, Newly Applied: Code as a Listening Device
CIPA was enacted in 1967 to prevent telephone wiretapping. Plaintiffs have constructed a new theory: that modern tracking technologies — Meta Pixel, Google Analytics, session replay software recording mouse movement — running without the user's prior express consent are equivalent to installing an unlawful listening device or pen register.
(2) The Core Allegation: Interception of Communications
In these cases the issue is not whether you "sold" data. It is whether, before the user knew and consented, you "intercepted" their browsing behavior, IP address, or input, and transmitted it in real time to a third party such as Google — so that related product ads could be served back to that user.
II. The Fatal Gap Between Technology and Legal Promises
Why do large companies with compliance teams — Adidas among them — get caught? Because of a substantial disconnect between what is promised legally and what is implemented technically. These are the gaps we see most often on review:
(1) The fake banner and the timing gap. Many sites install a cookie banner, but the tracking code in the background may already be running before the user clicks "Accept."
Legal consequence: this is treated as interception without consent. Even where it is an inadvertent configuration error, plaintiffs' counsel will seize on it to argue that the privacy intrusion occurred before authorization.
(2) The "Reject" button that does nothing. When a user clicks "Reject All" or "Necessary Only," does the site actually cut off the data flow at a technical level? Often, because of site updates or auto-loading third-party plugins, the trackers continue running silently.
Legal consequence: this constitutes misrepresentation and deception. Promising privacy protection and failing to deliver it is a more serious breach than simply failing to give notice.
(3) A privacy policy that does not match reality. Your policy may say "we respect your choices" while the code collects everything. That inconsistency is plaintiffs' counsel's favorite evidence and is enough to support a deceptive business practices claim.
III. The Cost of Non-Compliance
This is not merely a remediation question — it is real financial exposure.
(1) Statutory damages. CIPA permits claims of $5,000 per violation, with no requirement that the plaintiff prove actual economic loss.
(2) The multiplier effect of class litigation. Suppose your site receives 1,000 visitors a day. Certified as a class action, potential exposure escalates into the millions almost immediately.
(3) California's long-arm reach. Even if your company is not in California, if your site is directed at California residents — as most e-commerce sites are — you are within scope.
IV. Building a Substantive Compliance Defense
Based on our practice, two steps are recommended:
(1) Conduct a full technical compliance review
Do not assume compliance — scan. Do not take it on faith that your site is safe. Use a professional compliance scanning tool across the entire site to identify every cookie, pixel, and tag running in the background. In our experience, companies routinely discover trackers they had no idea existed, typically left behind by old plugins or outsourced development.
A simple self-test: verify that blocking actually works. Visit your own site in a browser's private mode and, without clicking "Accept" on the cookie banner, check whether data is already being transmitted to Google, Meta, or other third parties.
The standard: if transmission begins before express consent, your site is not technically blocking non-essential cookies (particularly analytics and marketing). That is textbook non-compliance and the most frequently attacked point in current litigation. Remediate immediately.
(2) Revise the core agreements and dispute resolution terms
Privacy Policy. Ensure that what you write is what you do. Disclose, in plain language, the specific categories of tracking tools actually in use. Do not copy a generic template, which produces a policy that does not match the trackers actually running — usually the first gap plaintiffs' counsel attacks.
Terms & Conditions. Optimize the existing terms with targeted legal provisions establishing better risk controls against systemic attack. A class action waiver, for example, will not prevent a user from bringing a claim, but it is currently among the more effective shields: procedurally it dismantles plaintiffs' counsel's attempt to mount a large-scale class action, confining potential disputes to individual matters and sharply reducing defense cost and damages exposure.
Conclusion
In digital compliance, ignorance is not a defense in court. This wave of litigation is not simply legal extortion; it reflects an awakening among regulators and the public regarding data sovereignty. For companies, cleaning up website tracking and ensuring that practice matches representation is not only about avoiding litigation — it is foundational to brand trust.
This article addresses general legal questions only and does not constitute legal advice on any specific matter.
关于作者 / About the Authors
Non-Equity Partner · LawMay P.C.
吴嘉欣律师专长于为希望在美国开展业务的中国企业、高管及技术型人才提供全方位法律服务,包括美国公司设立与治理、投融资交易、基于雇佣的签证及移民事务、知识产权合规与诉讼等。凭借对中美法律体系的深厚理解,她能够提供兼具中国本土视角与美国合规标准的综合性法律解决方案。
吴律师在法律领域拥有十余年的执业经验,曾在多家全国知名律师事务所任职,积累了丰富的跨境投融资实务经验,客户涵盖银行、高科技、电商及高净值个人等多个行业。
其主要跨境投融资项目包括:招商局集团旗下投资平台对一家美国公司的股权投资项目、陕西西咸新区空港新城开发建设集团的离岸美元债发行项目、以及焦作投资集团 1 亿美元离岸债券项目。
此外,吴律师曾多次主导或参与大型金融机构的跨境债券与贷款项目,代表客户包括中国工商银行(亚洲)、中国进出口银行、中国工商银行纽约分行、中国银行伦敦分行及花旗银行新加坡分行等。
中美跨境投融资 · 美国公司设立与治理 · 雇佣类签证移民事务 · 知识产权合规与诉讼
About LawMay P.C.
美国路迈律师事务所(LawMay P.C.)
深耕中美跨境争议解决的美国精品律所。专注于美国联邦知识产权诉讼、337 调查、产品责任纠纷及重大商事争议。
Law May, We May.