What a pixel actually does
Begin with the technology, because the legal theories depend on details most lawyers skip.
A tracking pixel — also called a tag, a beacon, or an SDK on mobile — is a snippet of code a website operator places on its pages. When a visitor loads the page, the browser executes that code, which makes a request to a third party's server. That request carries information: the page URL, the referring page, the browser and device characteristics, an identifier stored in a cookie or generated from device attributes, and whatever additional parameters the site operator configured.
A conversion pixel fires on a specific event — a purchase, a form submission, a video play — and reports it, often with parameters describing what happened: the product, the amount, the content viewed.
Session replay goes further. It records the visitor's interaction with the page — mouse movements, scrolling, clicks, keystrokes in form fields — and transmits it to a vendor who reconstructs the session for playback.
A chat widget routes the visitor's typed messages through a third-party service.
The commercially important point: the third party receives the data directly from the visitor's browser, not from the site operator's server. The site operator instructed the browser to send it, but the transmission runs from the visitor to the vendor.
That architecture is what plaintiffs' counsel seized on. If the visitor's interaction with a website is a "communication," and a third party receives its contents contemporaneously, the vocabulary of wiretapping becomes available.
The federal wiretap framework
18 U.S.C. § 2511 prohibits intentionally intercepting the contents of a wire, oral, or electronic communication. "Intercept" is defined in 18 U.S.C. § 2510 as acquisition of contents through a device, and the acquisition must be contemporaneous with transmission. 18 U.S.C. § 2520 provides a civil remedy with statutory damages.
The party exception is why federal claims usually fail. Section 2511(2)(d) provides that it is not unlawful for a person who is a party to the communication to intercept it, or for a person to intercept where one of the parties has given prior consent — unless the interception is for the purpose of committing a criminal or tortious act.
A website operator is a party to the visitor's communication with the website. Under the federal one-party consent rule, the operator's own consent suffices, and its authorization of a vendor generally comes along with it.
Plaintiffs respond with two arguments. First, that the vendor is not merely a passive recipient but is intercepting for its own independent purposes, taking it outside the party's authorization. Second, the crime-tort exception — that the interception was for the purpose of a tortious act, which courts have generally read narrowly to require a tortious purpose independent of the interception itself.
Federal claims accordingly fail more often than they succeed. The state claims are the problem.
Two-party consent states
Several states require all parties to consent to recording a communication. Their statutes predate the internet by decades and were written for telephone calls, but their text is not limited to telephones.
The most heavily litigated is California's, which prohibits using any "machine, instrument, or contrivance" to read or learn the contents of a communication without the consent of all parties, and separately addresses use of a "pen register" or "trap and trace device" — a provision originally aimed at devices capturing dialing information that plaintiffs now apply to browser fingerprinting and identifier collection.
Why these claims are dangerous:
- Statutory damages per violation, which in aggregate across a website's visitors produces enormous theoretical exposure without proof of harm.
- No requirement to show actual injury beyond the statutory violation, though federal court plaintiffs still face Article III standing after TransUnion LLC v. Ramirez, 594 U.S. 413 (2021).
- Attorney fee provisions in several statutes.
- The party exception is narrower. Where all parties must consent, the operator's consent alone does not authorize a third party's acquisition, and the central question becomes whether the vendor is a party or an eavesdropper.
The party-versus-eavesdropper distinction is the whole case. Courts ask whether the vendor is functioning as an extension of the website operator — a tool, like a tape recorder the operator holds — or as an independent third party listening in. Factors that matter: whether the vendor uses the data for its own purposes, whether the contract restricts it to providing services to the operator, whether the data is aggregated across sites, and whether the vendor could identify the individual independently.
The practical consequence for drafting: vendor agreements that permit the vendor to use data for its own product improvement, cross-site profiling, or advertising optimization make the eavesdropper characterization far easier. Agreements that restrict the vendor to processing on the operator's behalf make it harder.
The Video Privacy Protection Act
18 U.S.C. § 2710 was enacted in 1988 after a newspaper published a Supreme Court nominee's video rental history. It prohibits a "video tape service provider" from knowingly disclosing "personally identifiable information" about a consumer to a third party, with limited exceptions, and provides liquidated damages of $2,500 per violation plus fees.
For twenty-five years it was a curiosity. It is now one of the most active privacy claims in the country, because modern websites deliver video and modern instrumentation reports what visitors watch.
The elements, and where they are fought:
"Video tape service provider." Any person engaged in the business of rental, sale, or delivery of prerecorded video cassette tapes or similar audio visual materials. Courts have applied it to streaming services, news sites with embedded video, retailers with product videos, and educational platforms. Defendants argue that a business whose primary activity is not video delivery falls outside; results vary.
"Consumer." A renter, purchaser, or subscriber of goods or services from the provider. The scope of "subscriber" is contested — does a newsletter signup make someone a subscriber? Does creating a free account? Courts have split, and this is frequently the dispositive element.
"Personally identifiable information." Information that identifies a person as having requested or obtained specific video materials. Circuits apply different standards: some ask whether an ordinary person could identify the individual from the disclosed information; others ask whether the recipient could. Under the second, transmitting a persistent identifier to a company that holds a profile keyed to that identifier is a disclosure of personally identifiable information; under the first, it may not be.
"Knowingly disclosed." The provider must know it disclosed the information. Configuring a pixel to transmit video-viewing events supplies this.
The consent exception requires consent that is informed, written, in a form distinct and separate from any other legal or financial notice, and that provides an opportunity to withdraw. A privacy policy does not satisfy it. A checkbox that appears with terms of service acceptance generally does not either. The statute's specificity here is unusual, and it is why so few defendants can establish consent.
Health, financial, and other sensitive contexts
Where the underlying pages concern sensitive subjects, additional regimes attach and enforcement risk rises sharply.
Health. Pixels on patient portals, appointment scheduling pages, symptom checkers, and provider directories can transmit information about an individual's health conditions. Where a covered entity is involved, the health privacy framework's disclosure rules apply and a business associate arrangement is required — one that adtech vendors typically will not sign. Regulators have issued guidance treating this as a compliance failure, and the litigation is substantial.
Financial. 15 U.S.C. § 6801 and 15 U.S.C. § 6802 restrict disclosure of nonpublic personal information by financial institutions. Pixels on account pages, loan applications, and product comparison tools implicate these directly.
Children. 15 U.S.C. § 6501 and 16 C.F.R. Part 312 require verifiable parental consent before collecting personal information from children under thirteen, and persistent identifiers count as personal information. A third-party advertising pixel on a child-directed page is a straightforward violation.
Consumer protection generally. 15 U.S.C. § 45 reaches unfair and deceptive practices, and a privacy policy that describes data practices inaccurately is deceptive regardless of any wiretap theory. This is the most reliable enforcement vector and the one most within the operator's control.
The damages arithmetic
These cases are valuable because of statutory damages, not because of harm.
| Claim | Per-violation exposure |
|---|---|
| VPPA — 18 U.S.C. § 2710 | $2,500 liquidated damages, plus fees |
| Federal wiretap — 18 U.S.C. § 2520 | Statutory damages, plus fees |
| State two-party consent statutes | Statutory amounts, often per violation, plus fees |
| State pen register provisions | Statutory amounts per violation |
Multiply by the number of visitors to a page over the limitations period, and a website with ordinary traffic generates a theoretical exposure figure with no relationship to any injury. Defendants therefore litigate about class certification, standing, and arbitration — not about damages.
Standing is the first battleground. After TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), a statutory violation alone does not establish Article III injury; the plaintiff must show a concrete harm with a close relationship to one traditionally recognized. Disclosure of private information has a strong historical analogue in privacy torts, so plaintiffs frequently clear the bar — but the analysis is claim-specific and defendants win some of these motions. Note the strategic asymmetry: a defendant who wins on standing in federal court often faces the same case refiled in state court, where Article III does not apply.
Arbitration is the most effective defense. Where the operator has an enforceable arbitration clause with a class waiver, aggregate exposure collapses. This is why formation records matter enormously and why plaintiffs' counsel target sites without account registration, where no agreement was formed.
Frequently asked questions
How far back does the exposure go? To the limitations period for each claim, which varies by statute and jurisdiction and commonly runs one to four years. The practical significance is that removing a tag today does not eliminate the historical claim — which is why stopping ongoing collection matters for the class period rather than for the past.
Does it help that our competitors do the same thing? Not legally, and the plaintiffs' firms running automated scans are working through industries systematically. Being typical is a reason to expect a demand letter, not a defense to one.
What if a tag was added by an agency without our knowledge? The operator placed the code on its own site, through an agent it authorized. Agency involvement does not eliminate the operator's exposure, though it may create an indemnity claim. Review the agency agreement, and add tag approval to its scope of work going forward.
Is a privacy policy disclosure enough? For deception claims, accurate disclosure helps substantially. For VPPA, no — the statute requires separate, distinct written consent. For two-party consent statutes, a policy nobody reads is a weak consent argument, though disclosure plus an interactive banner is much better than a policy alone.
Does a cookie banner solve this? It helps if it actually gates the tags. A banner that appears while tags fire anyway is worse than none, because it documents that consent was sought and not obtained.
Are we liable for what the vendor does? The operator placed the code. Claims run against the operator first, and against the vendor as an alleged interceptor. Indemnity provisions matter, and many adtech agreements disclaim exactly this.
Does removing the pixel fix it? Prospectively. The limitations period continues to cover past collection.
Is this only a California problem? No. Several states have all-party consent statutes with damages provisions, and VPPA is federal.
What about server-side tagging? It changes the technical path — data goes to the operator's server first — but not necessarily the analysis. The question remains what is disclosed to whom and with what consent.
Do these cases go to trial? Almost never. They resolve on standing, arbitration, class certification, or settlement.
A worked assessment
Fernbrook Health Partners operates a network of urgent care clinics. Its website has: a symptom checker, an appointment scheduler, a patient portal login, a blog with educational videos, and a "find a location" tool.
Its marketing team, working with an agency, has deployed eleven tags over four years. Nobody in legal was consulted for any of them.
General counsel Rosalind Ekwueme-Barr receives a demand letter alleging wiretap and health privacy violations. She starts by finding out what is actually on the site.
The tag inventory
She has an engineer run the site through a tag scanner and compare the results against the tag manager configuration. The two do not match — a common finding, because tags get added directly to page templates and never make it into the manager.
| Tag | Where it fires | What it transmits | Assessment |
|---|---|---|---|
| Analytics platform | All pages | URL, referrer, device ID | URL of a symptom page is health information |
| Social advertising pixel | All pages, plus custom events | URL, device ID, custom "SchedulerStart" event | Highest risk — third-party ad network, health context |
| Second ad network pixel | All pages | URL, device ID | Same |
| Session replay | Scheduler and portal login | Keystrokes in form fields | Captures typed symptoms and possibly credentials |
| Chat widget | All pages | Full message contents to vendor | Patients describe symptoms in chat |
| Video player analytics | Blog | Video titles watched, viewer ID | VPPA exposure |
| Heatmap tool | All pages | Click and scroll data | Lower risk |
| Two ad conversion pixels | Scheduler confirmation | Conversion event | Health context |
| Call tracking | All pages | Phone numbers, session ID | Moderate |
| Consent management platform | All pages | — | Not actually gating anything |
The last row is the finding that matters most. Fernbrook has a cookie banner. It presents choices. And the tags fire on page load regardless of what the visitor selects. This is worse than having no banner: it establishes that Fernbrook told visitors it was honoring their choices and did not.
The exposure, by theory
Health privacy. The symptom checker URLs, the scheduler events, and the chat contents are individually identifiable health information transmitted to third parties. None of the ad vendors would sign a business associate arrangement, and they are not permitted recipients under any exception. This is the enforcement exposure.
Two-party consent statutes. The chat widget and session replay are the strongest claims. Both capture the contents of communications — typed messages and keystrokes — and both send them to vendors who use the data for their own purposes. The party-versus-eavesdropper analysis favors plaintiffs where the vendor's contract permits independent use, and Fernbrook's session replay agreement does.
VPPA under 18 U.S.C. § 2710. The blog videos plus the video analytics tag plus a persistent identifier is the pattern. Fernbrook will argue it is not a "video tape service provider" and that blog readers are not "subscribers." Both arguments are real; neither is certain.
Deception under 15 U.S.C. § 45 and state analogues. The privacy policy says Fernbrook does not share health information with advertisers. It does. This is the claim Rosalind cannot defend and the one she fixes first.
What she does
Day one: stop the bleeding. Remove all advertising pixels from the symptom checker, the scheduler, the portal, and the chat pages. This takes an afternoon and eliminates the ongoing collection.
Day two: fix the consent platform. The banner now actually gates non-essential tags. This required a configuration change the agency had never completed.
Week one: the privacy policy. Rewritten to describe what Fernbrook actually does. Rosalind resists the instinct to write it broadly enough to cover everything — an accurate narrow description is defensible; an inaccurate broad one is not.
Week two: session replay and chat. Session replay is removed from all form pages. The chat vendor agreement is renegotiated to prohibit any use of message contents other than providing the service to Fernbrook, with deletion obligations and no cross-customer use. This is the single change that most improves the party-exception argument.
Week three: video. The video analytics tag is removed pending a decision. Rosalind's assessment is that removing it costs marketing very little and eliminates a $2,500-per-violation theory.
Week four: governance. A rule that no tag is added without legal review, enforced technically by restricting publish rights in the tag manager. A quarterly scan comparing deployed tags against the approved inventory.
Month two: vendor agreements. All eleven reviewed. Six permit vendor use for the vendor's own purposes; those are renegotiated or replaced.
Month three: arbitration. Fernbrook adds an arbitration clause with a class waiver to its portal terms, with a proper clickwrap record. This does not help for anonymous website visitors, which is the population most of these claims target — a limitation Rosalind explains to the board rather than overselling the fix.
What the assessment cost, and what it bought
About $140,000 in legal and engineering time over three months. It did not resolve the demand letter, which settled separately. It did eliminate the ongoing violation, which is what converts a bounded historical claim into an unbounded one, and it produced the documentation Fernbrook needed when a regulator asked the same questions eight months later.
Rosalind's summary: "The banner that did not gate anything was the worst fact in the file, and it was a configuration setting nobody had checked."
What actually reduces exposure
Ranked by effect, not by ease.
1. Remove tags from sensitive pages. Health, financial, children's, and account-authentication pages should have no third-party advertising or analytics tags. This single step eliminates the highest-value claims and costs almost nothing in marketing performance, because those pages are not where conversion optimization happens.
2. Make the consent mechanism actually work. A banner that does not gate tags is affirmative evidence against you. Test it: load the site, decline, and watch the network traffic. Do this quarterly, because tag changes break gating silently.
3. Fix the vendor contracts. The party-versus-eavesdropper analysis turns substantially on whether the vendor may use the data for its own purposes. Contracts restricting the vendor to processing on the operator's behalf, prohibiting cross-customer use and independent profiling, and requiring deletion make the strongest available argument that the vendor is a tool rather than a third party.
4. Make the privacy policy accurate. Deception claims are the easiest for plaintiffs to prove and the easiest for defendants to prevent. Describe what actually happens, in specific terms.
5. Remove session replay from form pages. Keystroke capture in fields is the strongest contents-interception fact available to a plaintiff.
6. Reconsider chat widgets. Routing user messages through a third party is interception in the most literal sense the statutes contemplate. Either bring it in-house, or contract so tightly that the vendor is unambiguously an agent.
7. Address video separately. The VPPA analysis is distinct and the damages are per-violation liquidated. Either obtain consent in the specific form the statute requires — separate, distinct, written, revocable — or do not transmit video-viewing events with identifiers.
8. Build tag governance. Approval before deployment, technical enforcement, an inventory, and quarterly scans. Every one of the failures above originates in a tag someone added without review.
9. Get an enforceable arbitration clause where you can. It collapses aggregate exposure for authenticated users. It does nothing for anonymous visitors, and being honest about that limitation is better than implying otherwise.
10. Document the analysis. A dated assessment showing what was reviewed and why decisions were made is worth a great deal with regulators and something with courts.
The regulatory layer
Litigation is not the only pressure, and the regulatory obligations are increasingly specific.
Comprehensive state privacy laws now impose: opt-out rights for sale and for targeted advertising, with recognition of universal opt-out signals; heightened treatment of sensitive data including health, precise location, and information about minors; data protection assessments for targeted advertising and sensitive processing; and contractual requirements for processors and third parties.
The "sale" question. Several statutes define sale broadly enough to include disclosure of identifiers to advertising vendors for value, whether or not money changes hands. Operators who concluded they do not "sell" data should revisit that conclusion against the actual statutory definitions.
Universal opt-out signals. Where a state requires honoring a browser-transmitted preference signal, the obligation is technical, not policy-based. Test whether the site actually honors it.
Sensitive data. Health, biometric, precise geolocation, and information revealing certain characteristics generally require opt-in consent rather than opt-out. A pixel on a page revealing a health condition processes sensitive data.
Data broker registration requirements in several states reach entities that sell personal information about individuals with whom they have no direct relationship, and the definitions can capture participants in the advertising ecosystem who do not think of themselves as data brokers.
Consumer health data statutes in a few states create private rights of action and reach health information far beyond what the federal framework covers, including inferences drawn from browsing behavior.
Federal enforcement. 15 U.S.C. § 45 reaches both deception and unfairness. Enforcement actions have addressed pixels on health-related pages, undisclosed data sharing, and dark patterns in consent interfaces. Consent orders in this area typically require deletion of improperly collected data, algorithmic disgorgement in some cases, and multi-year compliance programs with independent assessment.
The practical implication: a compliance program built to answer only the litigation risk will fail the regulatory review, and vice versa. The overlap is large — accurate disclosure, working consent, restricted vendor use, and sensitive-context restrictions serve both — and building for both is not much more work than building for either.
Defending a pixel case
These cases follow a recognizable sequence, and the defense decisions that matter are made early.
The demand letter stage. Most begin with a letter from a firm that has run an automated scan of the site. The letter identifies tags, recites statutes, and proposes a pre-suit resolution. Two responses are wrong: ignoring it, and paying without an assessment. The right response is to run the tag inventory immediately, because the answer determines everything — including whether the alleged tag is even present.
Stop the ongoing conduct. Whatever else happens, remove the tags from sensitive pages. A defendant still collecting during the litigation has a materially worse posture, faces a growing class period, and invites injunctive relief.
Preserve. Tag manager configuration history, vendor contracts, consent platform logs, privacy policy versions, and the site's page templates. Configuration histories are frequently overwritten.
Assess arbitration first. If an enforceable clause reaches the plaintiff, everything else is secondary. The analysis: was an agreement formed, when, with what notice, and does the claim fall within the clause's scope? Formation records are usually the weak point, and they cannot be created after the fact.
Then standing. In federal court, TransUnion LLC v. Ramirez, 594 U.S. 413 (2021) requires concrete injury with a close historical analogue. Disclosure claims often clear it; claims premised purely on a technical violation with no disclosure to anyone sometimes do not. Consider the consequence of winning: dismissal for lack of standing sends the case to state court, where Article III does not apply and the statutory damages are the same.
The party exception. For two-party consent claims, this is the merits. Build the record on what the vendor is contractually permitted to do, what it actually does, and whether it functions as an extension of the operator. Vendor declarations and contract terms carry the argument.
Contents versus record information. Many statutes distinguish the contents of a communication from information about it. A URL may be contents in some framings and not others; a device identifier generally is not contents. Session replay keystrokes and chat messages plainly are. Sorting the tags by this distinction narrows the case considerably.
Consent. Assemble everything: the banner, its configuration, the policy, the account terms, and any interstitial. For VPPA, remember the statute requires consent that is separate, distinct, written, and revocable — a standard almost no operator meets, so do not build the defense on it unless the record genuinely supports it.
Class certification. Individualized issues about consent, about what each visitor saw, about which tags fired for which browser configuration, and about whether any given visitor is identifiable can defeat predominance. This is often the strongest defense and it requires technical evidence about variability across sessions.
Vendor relationships. Consider whether to bring the vendor in, and check the indemnity. Many adtech agreements disclaim exactly this exposure; a few do not.
Settlement structure. Where resolution is the answer, negotiate for prospective relief the company was going to implement anyway, a narrow release scoped to the identified practices, and a class definition tied to the specific pages and period rather than to all site visitors.
Why the old statutes fit badly, and why that matters
It is worth being clear-eyed about the doctrinal position, because clients ask whether these claims are legitimate and the honest answer is complicated.
The statutes were written for a different technology. 18 U.S.C. § 2511 descends from telephone wiretapping law. The two-party consent statutes were enacted to stop people from secretly recording conversations. 18 U.S.C. § 2710 was a response to a journalist obtaining a nominee's video rental records from a store clerk. None of them was drafted with browsers, cookies, or third-party analytics in mind.
The text nonetheless reaches the conduct, on a natural reading. A visitor typing into a chat window is communicating. A vendor receiving those keystrokes contemporaneously is acquiring the contents of an electronic communication through a device. Nothing in the statutory language limits it to telephones. Courts applying text rather than legislative purpose reach the result plaintiffs want, and courts weighing purpose sometimes do not — which is why the case law is inconsistent across districts applying the same statute.
The damages provisions were calibrated for a different scale. Two thousand five hundred dollars per violation is a sensible deterrent when the violation is a clerk disclosing one customer's rentals. Applied to every visitor to a website over four years, it produces numbers that bear no relationship to any injury and that no legislature contemplated. This is the structural feature that makes the litigation economically viable regardless of the merits, and it is why so few cases are tried.
Two consequences for advice.
First, do not tell a client the claims are frivolous. Some are weak and some are strong, the law varies by jurisdiction, and a defendant who treats a demand letter as a nuisance frequently finds out otherwise. The assessment should be technical and specific, not dismissive.
Second, do not let the doctrinal awkwardness become a compliance strategy. A company waiting for legislatures or appellate courts to rationalize this area is accruing exposure in the meantime. The remediation steps that reduce risk — restricting tags on sensitive pages, making consent work, fixing vendor contracts, describing practices accurately — are things a well-run privacy program should do anyway, for reasons that have nothing to do with wiretap statutes from the 1960s.
Adjacent claim theories
Plaintiffs' counsel in this space test theories continuously, and several beyond the core wiretap and video claims recur often enough to plan for.
Stored communications. 18 U.S.C. § 2701 prohibits unauthorized access to communications in electronic storage. Applied to browser cookies and local storage, the theory is that a third party accessed material stored on the user's device without authorization. Courts have generally resisted this — a cookie the site set is not a communication in electronic storage at a facility providing electronic communication service — but it appears in complaints regularly.
Computer fraud. 18 U.S.C. § 1030 requires access without authorization or exceeding authorized access, and its scope has been substantially narrowed. Claims that a tracking script exceeded authorized access to a user's browser have not fared well, but the statute's civil remedy makes it worth pleading from a plaintiff's perspective.
Intrusion upon seclusion. The common law privacy tort requires an intentional intrusion into a private matter that would be highly offensive to a reasonable person. It has no statutory damages, which makes it less valuable, but it survives where statutory theories fail and it supports punitive damages in egregious cases.
Unjust enrichment. The theory that the operator and vendor profited from data taken without consent. Courts split on whether personal information has cognizable value to the individual, and the measure of restitution is genuinely difficult.
Breach of contract. Where the privacy policy is incorporated into the terms of service, a policy describing practices the operator does not follow is a breach. This theory is underused and is one of the more durable ones, because it does not depend on any statute fitting awkwardly.
Consumer protection statutes. State unfair and deceptive practices acts, many with statutory damages and fee-shifting. These track the 15 U.S.C. § 45 analysis and are frequently the strongest claim in the complaint.
Sale without opt-out. Under comprehensive state privacy statutes, disclosing identifiers to advertising vendors may constitute a "sale" or "sharing for targeted advertising," triggering opt-out obligations. Most of these statutes lack private rights of action, so the exposure is regulatory rather than litigation — but a few do not, and consumer health data statutes in particular have created private claims.
Practical takeaway: the defense should be built around the conduct rather than around any single statute. An operator that removed tags from sensitive pages, made consent work, restricted vendor use, and described its practices accurately has a defense to every theory on this list. One that defeated the wiretap count on a technicality while leaving the practices in place has not.
Building the tag governance program
Every failure described in this article originates in the same place: someone added a tag without review. The program that prevents it is small.
An inventory that is real. Not the tag manager's list — a list produced by scanning the live site, in multiple browser configurations, from multiple geographies, and reconciled against the manager. The two will not match on the first run. Tags get hard-coded into templates, embedded in third-party widgets, and loaded by other tags.
A record for each tag:
| Field | Why |
|---|---|
| Tag name and vendor | Identification |
| Business owner | Someone must answer for it |
| Purpose | Analytics / advertising / functionality / support |
| Pages it fires on | Determines sensitive-context exposure |
| Data transmitted, field by field | The core of every legal analysis |
| Custom events and parameters configured | Where health and financial data leaks |
| Consent category | Essential / analytics / advertising |
| Gated by consent? Verified how? | The most common failure |
| Vendor contract reference | |
| Vendor permitted to use data for its own purposes? | Drives the party-exception analysis |
| Data retention and deletion terms | |
| Approval date and approver | |
| Last verified |
Approval before deployment. A written rule, enforced technically: publish rights in the tag manager restricted to a small group, and a review requirement before any new tag or any change to an existing tag's configuration.
Restricted zones. A standing prohibition on third-party advertising and analytics tags on defined page categories: health, financial account, children's, authentication, and any page whose URL reveals a sensitive attribute. Enforce it by scanning, not by policy.
Quarterly verification. Load the site, decline consent, and capture the network traffic. Compare against the approved inventory. This takes an engineer an afternoon and catches the failure mode — silent breakage of consent gating after an unrelated change — that produces the worst facts in these cases.
Change triggers. Re-run the review when: a new tag is proposed; an existing tag's configuration changes; a new page category launches; a vendor is acquired or changes its terms; a new jurisdiction becomes relevant; or the consent platform is updated.
Vendor contract standards. A short list of required terms for any tag vendor: processing on the operator's behalf only; no cross-customer use; no independent profiling; deletion on termination; audit or attestation rights; and indemnity for the vendor's own violations. Vendors that will not accept these are telling you something about the party-exception analysis.
Document the decisions. A dated record of what was reviewed, what was approved, what was rejected, and why. It is worth a great deal with a regulator and something with a court, and it costs nothing to maintain if it is created contemporaneously.
Related documents
- Auditing Your Website Tracking Stack: A Practical Guide
- Website Tracking Compliance Checklist: A Practical Checklist
- Adtech Privacy Toolkit: Tag Inventories, Consent Records, and Litigation Defense
- State Consumer Privacy Laws: The CCPA, the CPRA, and the Multi-State Patchwork
- Article III Standing After TransUnion: Concrete Injury, Traceability, and the End of No-Injury Claims
- Personal Privacy: Data Brokers, Surveillance, and Your Rights Over Your Own Information
- Privacy and Data Protection Toolkit: Building and Running a Privacy Program
- Website Terms of Service and Online Contract Formation: Clickwrap, Browsewrap, and Enforceable Arbitration
- Data Minimization and Avoiding the Over-Retention of Personal Information