About
Consumer Privacy Class Action

Consumer Privacy Class Action

Tracking class action litigation alleging consumer privacy violations, data breaches, and unauthorized data collection.

10 entries in Legal Intelligence Tracker

LawSnap Briefing Updated June 22, 2026

State of play.

  • State AGs are deploying consumer-protection statutes as the primary enforcement vehicle against AI platforms. The Florida AG has filed what it describes as the nation's first state-led suit against OpenAI and CEO Sam Altman under Florida's Deceptive and Unfair Trade Practices Act, alleging concealed safety risks and harms to minors—coordinated with a parallel criminal investigation . Kentucky's AG has separately sued Character.AI under consumer and data-protection statutes, and the FTC issued Section 6(b) orders to chatbot companies in 2025 .
  • The FTC has obtained a court order freezing a $700M subscription-fraud network, targeting Genesis Tech and 14 related entities for ROSCA and FTC Act violations—burying subscription terms, adding unauthorized charges, and obstructing cancellation through an offshore shell structure .
  • Subscription misrepresentation has reached the AI sector directly, with a federal class action against Anthropic alleging that its Claude Max 5x and Max 20x plans delivered materially less usage than marketed—a theory that, if certified, would extend consumer-protection class action exposure to AI platform pricing across the industry .
  • Arbitration clauses are being used to foreclose children's privacy class actions, with a Central District of California ruling compelling minor plaintiffs to arbitrate Roku data-collection claims based solely on parental acceptance of terms of service—a ruling that, if it spreads, systematically channels children's privacy disputes out of class litigation .
  • For counsel advising consumer-facing digital platforms, AI companies, or subscription businesses, the practical baseline is simultaneous exposure across state AG enforcement, FTC ROSCA actions, AI-specific class actions, and a rapidly shifting arbitration landscape for minors—all moving without new federal legislation.

Where things stand.

  • VPPA pixel litigation has a firm circuit split. The Second Circuit applies an "ordinary person" test that has dismissed multiple pixel-based VPPA claims including the NBCUniversal action; other circuits remain more plaintiff-permissive, making venue selection material for both sides .
  • CCPA's private right of action is expanding beyond breach. District court rulings in Shah v. Capital One and a Therapymatch case have allowed CCPA claims to proceed based on unauthorized disclosure through tracking tools to third parties—no traditional breach required—a departure that has not yet been tested at the Ninth Circuit .
  • Article III standing doctrine is actively sorting tracking claims by data sensitivity. Courts allow pixel-tracking claims to survive when sensitive health data is exposed; claims based on routine behavioral data without sensitive information attached are routinely dismissed; the DPPA standing dismissal in Cicale reinforces that tangible injury beyond data misuse is required across privacy statutes .
  • ROSCA enforcement against subscription dark patterns is active and expanding. The FTC's Uber case survived dismissal on the theory that pre-stored payment credentials cannot substitute for fresh affirmative consent before subscription enrollment; 21 state AGs are co-plaintiffs; the Genesis Tech action extends the same theory to offshore shell structures .
  • State auto-renewal law is tightening at the state level. Virginia's amendments to its automatic-renewal statute, effective July 1, 2026, require cancellation to be at least as easy as enrollment through the same channels, eliminate prior good-faith safe harbors, and treat violations as prohibited practices under the Virginia Consumer Protection Act—federal rules do not preempt .
  • Cookie banner compliance is an independent litigation vector. CIPA claims targeting non-functional "Reject All" buttons and dark-pattern consent interfaces are proliferating; Honda and HelloFresh have already resolved enforcement actions, and a thickening pattern of CIPA suits was filed in 2025 .
  • California CPPA is enforcing opt-out fragmentation. The agency's 2026 enforcement actions target businesses that honor opt-outs in some contexts but not others—fragmented compliance is itself the violation .
  • Biometric and wearable health data exposure is accelerating across consumer product sectors. Virtual try-on tools, wearable health monitors, and cookie-based tracking practices are drawing simultaneous CIPA class action filings and state AG scrutiny under a reshaped 2026 multi-state privacy regime; consumer health data from wearables falls outside HIPAA but within state health data statutes in Connecticut and Washington .
  • State privacy law proliferation continues without federal resolution. Alabama enacted the 21st comprehensive state privacy statute; the SECURE Data Act has been introduced with full state-law preemption but lacks bipartisan support; Indiana, Kentucky, and Rhode Island privacy laws took effect January 1, 2026 .
  • Junk fee class actions and mass arbitrations are accelerating. The FTC's Rule on Unfair or Deceptive Fees is in force for live-event tickets and short-term lodging; California's SB 478 adds per-violation penalties; plaintiffs' firms are bypassing class-action waivers through coordinated mass arbitrations .

Latest developments.

Active questions and open splits.

  • AI platform liability under existing consumer-protection statutes: how far does the duty-to-disclose run? The Florida AG's OpenAI complaint and the Kentucky AG's Character.AI suit both proceed under existing state UDAP and product-liability frameworks—no AI-specific statute required. Whether courts treat concealed safety warnings as actionable misrepresentation, and how they define duty of care for AI systems accessible to minors, will determine whether these cases establish a replicable enforcement template .
  • AI subscription misrepresentation: what disclosure standard applies to usage limits? The Anthropic class action tests whether marketing AI plans by usage multiples—without disclosing the actual cap methodology—constitutes actionable deception. If certified, the theory extends to every AI platform with tiered pricing and variable usage constraints .
  • Arbitration clauses binding non-consenting minors: will appellate courts hold the line? The Roku ruling channels children's privacy claims into individual arbitration based solely on parental assent. The enforceability of that approach against non-signatories who lack contractual capacity is unresolved at the circuit level—and the Florida AG's parallel state enforcement action against Roku suggests the ruling does not foreclose all avenues .
  • CCPA private right of action scope: breach-only or tracking-disclosure? The Shah and Therapymatch rulings extend CCPA liability to third-party tracking disclosures without a breach—a significant departure from prior precedent that has not yet been tested at the Ninth Circuit. Whether the court endorses this expansion will determine class action exposure for the entire California-facing digital economy .
  • ROSCA asset recovery against offshore shell structures: can the FTC reach international assets? The Genesis Tech action targets a network deliberately structured through offshore entities and continuously spawning new companies to evade enforcement. Whether the court's asset freeze and preliminary injunction survive challenge—and whether asset recovery reaches beyond U.S.-held funds—will define the practical limits of ROSCA enforcement against sophisticated evasion architectures .
  • DPPA standing: does the data-commercialization model determine survival? Cicale dismissed a parking enforcement DPPA claim for lack of injury while the Carfax crash-report case in Maryland survived—suggesting courts are distinguishing incidental DMV data use from systematic commercial exploitation. The line between those models is not yet defined by any circuit court .
  • Federal preemption: will the SECURE Data Act displace state privacy regimes? The bill's preemption language would eliminate CCPA, the Virginia CDPA, and 19 other state frameworks if enacted—but it lacks bipartisan support and faces a long history of failed federal privacy efforts. The preemption question is the central advisory issue for multistate compliance programs .

What to watch.

  • Early motions practice in the Florida AG v. OpenAI action—whether the complaint survives dismissal on duty-of-care and FDUTPA grounds, and whether the sealed factual record becomes public; also whether other state AGs file parallel suits using the Florida complaint as a template .
  • Whether the Anthropic class action survives a motion to dismiss and proceeds to class certification—the court's treatment of usage-multiple marketing as a measurable, class-wide representation will be the signal for the broader AI subscription market .
  • Appellate review of the Roku minor-arbitration ruling—whether the Ninth Circuit or other circuits address whether parental assent to platform terms can bind non-consenting minors, and whether the Florida AG's state enforcement action produces a conflicting outcome .
  • Virginia's July 1, 2026 auto-renewal effective date—whether enforcement actions follow promptly and whether other states adopt the symmetry-of-cancellation model .
  • Whether the FTC's Genesis Tech asset freeze survives preliminary injunction challenge and whether the agency pursues individual liability against the named founder-CEOs—the outcome will calibrate how aggressively the FTC can reach offshore ROSCA violators .
  • State AG enforcement actions in the fashion, beauty, and wearable tech sectors under the 2026 multi-state privacy regime—the first enforcement wave will set the compliance baseline for biometric and consumer health data handling outside HIPAA .

10 Contributing Entries

Brands Warn as Creators Flood TikTok Shop with AI Avatar Affiliate Videos

TikTok Shop is being flooded with AI-generated product demonstrations, fake creator personas, and duplicate avatars that are undercutting human creators and eroding consumer trust. Merchants and affiliate creators are using TikTok's built-in AI tools to mass-produce makeup tutorials, clothing reviews, and product showcases without holding inventory—a low-cost strategy that prioritizes algorithmic reach over authenticity. Some operators have deployed synthetic personas, including a fabricated Black creator named "Aliyah," to sell dropshipped goods from retailers like Shein, exploiting algorithmic biases that reward emotional connection to creators.

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based law firm, faces two proposed class-action lawsuits over a data breach that exposed sensitive information on 57,554 current, former, and prospective clients. The breach occurred in May 2026 when a cybercriminal impersonated the firm's IT department and convinced an attorney to upload client files to an external Google Drive account. The exposed data includes names, Social Security numbers, addresses, dates of birth, driver's license numbers, passport numbers, medical records, and health insurance information. Blank Rome announced the breach to affected clients on June 26, 2026—nearly a month after the incident occurred. The firm stated it will "aggressively defend" against the suits and claims they lack merit.

Judge Approves $46.75M Bankruptcy Settlement for 23andMe 2023 Data Breach Victims

A U.S. bankruptcy judge has approved a $46.75 million settlement to compensate victims of 23andMe's 2023 data breach, resolving claims after the genetic testing firm exposed the genetic data of nearly 6.9 million people worldwide. U.S. Bankruptcy Judge Brian Walsh in St. Louis ordered Chrome Holding—the entity that acquired 23andMe following its bankruptcy filing—to disburse the funds through Kroll Restructuring within five days.

42 States Secure Multistate Settlement for 23andMe 2023 Genetic Data Breach

A coalition of 42 state attorneys general, led by Washington AG Nick Brown, announced a settlement with 23andMe's bankruptcy trustee on July 14 resolving claims over a 2023 data breach that exposed genetic data of more than 220,000 Washington customers. Washington will receive approximately $500,000 as part of the multistate agreement, which addresses the company's failure to safeguard sensitive user information.

ChatGPT and Claude Account Sharing Leads to Privacy Breaches, Data Mix-ups, and Cybersecurity Risks

Users are sharing login credentials for premium AI services—ChatGPT Plus and Claude Pro—exposing themselves to serious privacy breaches. Connor Effrain, a 22-year-old digital fundraising associate, shared his ChatGPT account and inadvertently gave others access to sensitive health information about his Crohn's disease and personal details he had discussed with the chatbot. Both OpenAI and Anthropic explicitly prohibit account sharing in their terms of service, classifying these subscriptions as single-user only. The platforms detect concurrent sessions and suspend accounts that violate this rule.

Lawyers Moonlight to Train AI While Scammers Impersonate Immigration Attorneys

The legal profession faces a convergence of ethics crises driven by artificial intelligence and fraud. Attorneys are increasingly taking side work training AI models, while scammers deploy AI-generated deepfakes and cloned identities to impersonate immigration lawyers and steal from vulnerable clients. The problem intensified with the exposure of Washington State attorney Alexandra Lozano, who fabricated thousands of domestic abuse and trafficking narratives to secure humanitarian visas without client consent. Her scheme, which enlisted hundreds of employees across Colombia, Mexico, and Argentina to process fraudulent applications, affected tens of thousands of immigrants and drained client bank accounts while exposing victims to deportation risk.

Blank Rome Hit With Two Class Actions After May Data Breach Exposes 57,000 Clients

Blank Rome LLP, a Philadelphia-based firm, faces two proposed class-action lawsuits following a May 2026 data breach that compromised the personal information of 57,554 current, former, and prospective clients. A cybercriminal impersonating an IT staff member tricked an attorney into uploading sensitive files to an unauthorized external Google Drive. The exposed data includes Social Security numbers, medical records, driver's license numbers, passport information, and health insurance details.

Meta Alleged to Have Used AI to Target Users With Scam Ads, Drawing Consumer Watchdog Suit

Meta faces a lawsuit filed by the Consumer Federation of America in Washington, DC, alleging that the company violated consumer protection laws by allowing fraudulent advertisements to proliferate on Facebook and Instagram. The CFA claims Meta's AI-powered advertising tools have enabled scams including fake government checks and counterfeit product offers despite the company's stated commitment to combating fraud. The suit also highlights Meta's AI ad-generation tool, which has produced errors that distort product images, compromise text legibility, and misrepresent people in advertisements. Separately, the Tech Transparency Project documented instances where Meta approved harmful ads targeting minors—promoting drug use, alcohol, and eating disorders—using Meta's own AI-generated imagery and targeting children as young as 13.

Meta Faces Class Action Lawsuit Over AI Glasses Footage Sent to Overseas Human Reviewers

Meta faces a federal class action lawsuit alleging that its Ray-Ban smart glasses secretly transmit user-captured video to thousands of human contractors in Kenya for AI training—contradicting the company's privacy commitments. Filed March 4, 2026, by plaintiffs Gina Bartone and Mateo Canu, the suit claims Meta and Luxottica violated federal and state law by routing footage to overseas servers for manual labeling without user disclosure, rather than processing it solely through AI models.

$45M Multistate Settlement Reached with Block Over Cash App Fraud

California Attorney General Rob Bonta and 46 state attorneys general have secured a $45 million settlement with Block, Inc., the parent company of Cash App, over allegations that the company misled consumers about fraud protections and failed to safeguard users from theft. The agreement requires Block to implement 24-hour live customer support, halt false marketing claims about safety features, and comply with a separate Consumer Financial Protection Bureau settlement obligating the company to distribute $75 million to $120 million in consumer redress.

mail Subscribe to Consumer Privacy Class Action email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap