How lawsuits under a 1967 wiretapping law exposed California’s privacy paradox

The California Senate Privacy Committee voted earlier this month to advance a bill that aims to alter one of the state’s landmark privacy laws — a measure that could quell a long-fought battle against serial “frivolous” lawsuits and potentially reshape privacy rights for Californians.

Read more Why juries rejected murder charges in K Street shootout Davis stabbings

Outside a packed Assembly Privacy Committee hearing on July 2, small business owners crowded around a television to watch lawmakers debate Senate Bill 690, authored by state Sen. Anna Caballero, D-Merced. The measure would narrow the California Invasion of Privacy Act, or CIPA — one of two landmark privacy laws in California. Enacted in 1967, the series of statutes prohibits wiretapping; the recording of private communications without consent.

But in recent years, CIPA has become the focus of thousands of lawsuits against predominantly small businesses, alleging that owners unlawfully collected consumers’ data through third-party tracking technologies — such as third-party cookies — on their websites.

Caballero and a coalition of business owners who have been sued under CIPA argued the penalties were “predatory” and “unfair” at the July hearing. They urged lawmakers to pass SB 690 to protect businesses from future lawsuits.

But inside the room, privacy advocates pressed lawmakers to reject it, warning that the measure would weaken consumer protections and erode one of the state’s landmark privacy safeguards.

After a short, contentious hearing, the committee referred SB 690 to the Assembly Appropriations Committee. Privacy experts said it exposes a broader paradox in Californian privacy law — one that has made compliance “nearly impossible,” according to Lothar Determann, a data privacy law compliance attorney and legal expert.

If the bill passes this year, it stands to set the stage for privacy rights in California, as lawmakers attempt to “strike the right balance between privacy interests and the realities of the modern internet,” a bill analysis prepared for the committee said.

Serial suits and privacy violations

Gytahnna Loffgren thought the lawsuit against her business was a scam when she and her husband first received notice of it in the mail on May 27.

“We received a packet — just a normal USPS envelope in the mail, and my husband was like, I think this is fake,” Loffgren said in an interview outside the hearing.

A phone call to a friend confirmed what she had feared — that she and her husband, owners of Element Electric, a Dixon-based solar panel installation company, were being sued for violating multiple statutes under CIPA. They were served the lawsuit on June 7, she said.

According to Loffgren, the plaintiff, an Orange County resident, had visited her company’s website sometime in March. When they loaded the website, their IP address and the timestamp of their visit were allegedly collected and shared with Meta-controlled domains before they could “opt-in” and consent to the process.

“But we didn’t steal their information,” Loffgren said. “We’re not selling their information on the black market. It’s an IP address that we don’t even store.”

Loffgren’s website requests users to reject, accept or customize cookies and tracking technologies for “personalized advertising and content, advertising and content measurement, audience research and services development” upon loading the site.

Still, the visit — and alleged collection of data — prompted a suit against Loffgren’s company, citing violations of four CIPA provisions: wiretapping; the Computer Data Access and Fraud Act, or CDAFA; unfair competition law; and pen register, or trap-and-trace.

Each CIPA violation can yield up to $5,000 in civil damages.

Loffgren’s case is one of roughly 4,000 filed as of early July — a staggering increase from some 60 lawsuits filed in 2022, Caballero said at the hearing.

“They have the same serial plaintiffs,” said Usama Kahf, co-chair of his law firm’s Privacy and Cyber Practice Group, in an interview. “One person is suing 500 businesses, right? So, it results in a lot of abuse.”

The day that Loffgren was sued by Mou Law PC, the firm representing the plaintiff in her case, at least 17 other lawsuits had been filed against similar businesses in her area, she said. Mou Law PC was unreachable via phone call on several occasions.

Caballero likened the serial lawsuits to those filed under the American Disabilities Act, or ADA, in California, describing the CIPA cases as “vexatious” litigation “that has cost millions of dollars to California businesses” at the hearing.

The argument has also found traction in federal court, where a U.S. District Judge ruled Monday that a plaintiff who filed a CIPA privacy lawsuit against Crain Communications, a privately-owned media company, was a “vexatious litigant.”

According to a statement from Crain Communications’ counsel, KJC Law Group, the 39-year-old West Hollywood man had filed seven nearly-identical CIPA lawsuits this year, and was prohibited from filing additional cases in the Central District of California without first obtaining the court’s permission.

But Klausner’s ruling was narrow. It does not prevent the serial plaintiff from filing CIPA complaints in other federal districts, nor does it affect the several others he already has pending — limitations that underscore the concerns of business owners like Loffgren.

After they were served, Loffgren said she and her husband attempted to contact seven different law firms. They each returned the same advice: It would be cheaper to settle than fight her case. But the business owner pushed back, arguing that nothing would prevent another plaintiff from filing a nearly identical lawsuit against her company.

“She can turn around and file again on us with one of the other names that she has in her back pocket, so it doesn’t ensure that this goes away if I give her $10,000,” Loffgren said of her case.

Loffgren added that the only way she could imagine avoiding another lawsuit would be to take down her company’s website altogether — an option she said simply wasn’t realistic in the digital age.

Read more Padilla introduces a new bill to counter Trump’s ‘attacks’ on federal elections

“If somebody told you, hey, you guys should check out this company, it’s really great, the first thing you’re going to do is look them up online,” she said. “If they don’t exist online, are you going to even believe that they’re there?”

A 1960s act in the digital era

Caballero said she authored SB 690 after concluding that CIPA was a “1960s act that never really contemplated the complexity of the internet.”

CIPA was passed in 1967 to prohibit the unlawful recording or interception of communications without consent. In the decades after, lawmakers amended the statutes to keep pace with technological advancements. In 1992, the statutes were changed to prohibit intercepting cellular phone and cordless telephone calls.

However, aside from a 2017 amendment banning the sharing of confidential communications involving healthcare providers without consent, the law has yet to be updated to address internet or digital privacy specifically.

“I mean, the top of the technology (at the time) was a phone attached to the wall, and that’s what CIPA was developed to protect,” Caballero said. “It is the collecting of phone numbers, wiretapping and eavesdropping. It was the inability of one person to see what the other person on the other end of the line was doing.”

Today, plaintiffs have increasingly argued that common website technologies — including third-party cookies and analytics software — constitute the unlawful interception of communications under CIPA.

A legislative balancing act

When Caballero first drafted SB 690, she sought to exempt businesses from commercial or civil penalties under the statute, where they collected data from their consumers for a “commercial business purpose.”

“I mean, we’re not talking about the creators of technology that can really invade the privacy of people,” she said in an interview. “We’re talking about basic websites.”

But privacy advocates and activists warned that the measure was too broad, and would enable companies to collect and share sensitive information without meaningful accountability.

Speaking at the July hearing, civil rights activist and labor leader Dolores Huerta said the proposal would enable companies to collect searches, location data, conversations and other personal information without sufficient safeguards — placing immigrants, women and LGBTQ+ Californians at greatest risk.

The opposition prompted Caballero to narrow the bill to instead only tackle CIPA’s pen register provision, the section under which nearly two-third of lawsuits have been filed. Businesses owners, like Loffgren, have been sued under the provision for collecting the IP address of visiting users before obtaining “opt-in” consent.

Caballero said the amendment addressed concerns that companies could stretch the definition of “basic website analytics” to justify broader data collection practices.

Still, Usama Kahf, a cyber practice and privacy legal expert who advocated for the bill alongside Caballero at the hearing, said the change would leave significant gaps. Lawsuits could still be filed under the wiretapping and eavesdropping of statutes under CIPA — the other one-third of the cases, he added.

California’s consumer privacy ‘conundrum’

As debate over SB 690 continues, privacy experts say the legislation highlights a broader paradox embedded in California’s privacy framework.

Under the California Consumer Privacy Act, or CCPA, enacted in 2018, companies are required to provide users with an opt-out option when selling or sharing a user’s personal information.

Under CIPA, by contrast, businesses are required to seek opt-in consent, a “parallel universe” that Determann said makes compliance “so difficult” and “nearly impossible” for businesses.

“Either you do opt-out or opt-in. In Europe, at least it’s just opt-in — everybody does the same thing,” Determann said in a July interview. “But in California, you’re supposed to do both, under opt-in and then under the other one, opt-out.”

Determann explained that the passage of the CCPA should have prompted lawmakers to revisit CIPA, updating or repealing provisions where the two landmark laws overlapped or seemed to be in conflict.

The lack of legislative change birthed the “conundrum” the Legislature aims to tackle today, he said.

He added that key provisions under SB 690 — including a retroactivity provision, that would apply the bill to any claim under CIPA that occurred within two years of its enactment, and the shift of enforcement of violations from the private individual to the attorney general — would limit the scope of “abusive” serial litigation.

However, he cautioned that California still lacks litigation reform that would prevent the next string of serial lawsuits, like those filed under the ADA or CIPA.

A bill analysis prepared for the committee reached a similar conclusion. It said that the Legislature “may wish to consider a more comprehensive set of solutions that provide courts, consumers and businesses clearer guidance and strike the right balance between privacy interests and the realities of the modern internet,” as the fight for SB 690 proceeds.

Read more Cooper Lutkenhaus, 17, captures 800 meters at USATF Outdoor Championships

By admin

Leave a Reply

Your email address will not be published. Required fields are marked *