About
Consumer Privacy Class Action

Consumer Privacy Class Action

Tracking class action litigation alleging consumer privacy violations, data breaches, and unauthorized data collection.

11 entries in Litigator Tracker

LawSnap Briefing Updated June 22, 2026

State of play.

  • State AGs are deploying consumer-protection statutes as the primary enforcement vehicle against AI platforms. The Florida AG has filed what it describes as the nation's first state-led suit against OpenAI and CEO Sam Altman under Florida's Deceptive and Unfair Trade Practices Act, alleging concealed safety risks and harms to minors—coordinated with a parallel criminal investigation . Kentucky's AG has separately sued Character.AI under consumer and data-protection statutes, and the FTC issued Section 6(b) orders to chatbot companies in 2025 .
  • The FTC has obtained a court order freezing a $700M subscription-fraud network, targeting Genesis Tech and 14 related entities for ROSCA and FTC Act violations—burying subscription terms, adding unauthorized charges, and obstructing cancellation through an offshore shell structure .
  • Subscription misrepresentation has reached the AI sector directly, with a federal class action against Anthropic alleging that its Claude Max 5x and Max 20x plans delivered materially less usage than marketed—a theory that, if certified, would extend consumer-protection class action exposure to AI platform pricing across the industry .
  • Arbitration clauses are being used to foreclose children's privacy class actions, with a Central District of California ruling compelling minor plaintiffs to arbitrate Roku data-collection claims based solely on parental acceptance of terms of service—a ruling that, if it spreads, systematically channels children's privacy disputes out of class litigation .
  • For counsel advising consumer-facing digital platforms, AI companies, or subscription businesses, the practical baseline is simultaneous exposure across state AG enforcement, FTC ROSCA actions, AI-specific class actions, and a rapidly shifting arbitration landscape for minors—all moving without new federal legislation.

Where things stand.

  • VPPA pixel litigation has a firm circuit split. The Second Circuit applies an "ordinary person" test that has dismissed multiple pixel-based VPPA claims including the NBCUniversal action; other circuits remain more plaintiff-permissive, making venue selection material for both sides .
  • CCPA's private right of action is expanding beyond breach. District court rulings in Shah v. Capital One and a Therapymatch case have allowed CCPA claims to proceed based on unauthorized disclosure through tracking tools to third parties—no traditional breach required—a departure that has not yet been tested at the Ninth Circuit .
  • Article III standing doctrine is actively sorting tracking claims by data sensitivity. Courts allow pixel-tracking claims to survive when sensitive health data is exposed; claims based on routine behavioral data without sensitive information attached are routinely dismissed; the DPPA standing dismissal in Cicale reinforces that tangible injury beyond data misuse is required across privacy statutes .
  • ROSCA enforcement against subscription dark patterns is active and expanding. The FTC's Uber case survived dismissal on the theory that pre-stored payment credentials cannot substitute for fresh affirmative consent before subscription enrollment; 21 state AGs are co-plaintiffs; the Genesis Tech action extends the same theory to offshore shell structures .
  • State auto-renewal law is tightening at the state level. Virginia's amendments to its automatic-renewal statute, effective July 1, 2026, require cancellation to be at least as easy as enrollment through the same channels, eliminate prior good-faith safe harbors, and treat violations as prohibited practices under the Virginia Consumer Protection Act—federal rules do not preempt .
  • Cookie banner compliance is an independent litigation vector. CIPA claims targeting non-functional "Reject All" buttons and dark-pattern consent interfaces are proliferating; Honda and HelloFresh have already resolved enforcement actions, and a thickening pattern of CIPA suits was filed in 2025 .
  • California CPPA is enforcing opt-out fragmentation. The agency's 2026 enforcement actions target businesses that honor opt-outs in some contexts but not others—fragmented compliance is itself the violation .
  • Biometric and wearable health data exposure is accelerating across consumer product sectors. Virtual try-on tools, wearable health monitors, and cookie-based tracking practices are drawing simultaneous CIPA class action filings and state AG scrutiny under a reshaped 2026 multi-state privacy regime; consumer health data from wearables falls outside HIPAA but within state health data statutes in Connecticut and Washington .
  • State privacy law proliferation continues without federal resolution. Alabama enacted the 21st comprehensive state privacy statute; the SECURE Data Act has been introduced with full state-law preemption but lacks bipartisan support; Indiana, Kentucky, and Rhode Island privacy laws took effect January 1, 2026 .
  • Junk fee class actions and mass arbitrations are accelerating. The FTC's Rule on Unfair or Deceptive Fees is in force for live-event tickets and short-term lodging; California's SB 478 adds per-violation penalties; plaintiffs' firms are bypassing class-action waivers through coordinated mass arbitrations .

Latest developments.

Active questions and open splits.

  • AI platform liability under existing consumer-protection statutes: how far does the duty-to-disclose run? The Florida AG's OpenAI complaint and the Kentucky AG's Character.AI suit both proceed under existing state UDAP and product-liability frameworks—no AI-specific statute required. Whether courts treat concealed safety warnings as actionable misrepresentation, and how they define duty of care for AI systems accessible to minors, will determine whether these cases establish a replicable enforcement template .
  • AI subscription misrepresentation: what disclosure standard applies to usage limits? The Anthropic class action tests whether marketing AI plans by usage multiples—without disclosing the actual cap methodology—constitutes actionable deception. If certified, the theory extends to every AI platform with tiered pricing and variable usage constraints .
  • Arbitration clauses binding non-consenting minors: will appellate courts hold the line? The Roku ruling channels children's privacy claims into individual arbitration based solely on parental assent. The enforceability of that approach against non-signatories who lack contractual capacity is unresolved at the circuit level—and the Florida AG's parallel state enforcement action against Roku suggests the ruling does not foreclose all avenues .
  • CCPA private right of action scope: breach-only or tracking-disclosure? The Shah and Therapymatch rulings extend CCPA liability to third-party tracking disclosures without a breach—a significant departure from prior precedent that has not yet been tested at the Ninth Circuit. Whether the court endorses this expansion will determine class action exposure for the entire California-facing digital economy .
  • ROSCA asset recovery against offshore shell structures: can the FTC reach international assets? The Genesis Tech action targets a network deliberately structured through offshore entities and continuously spawning new companies to evade enforcement. Whether the court's asset freeze and preliminary injunction survive challenge—and whether asset recovery reaches beyond U.S.-held funds—will define the practical limits of ROSCA enforcement against sophisticated evasion architectures .
  • DPPA standing: does the data-commercialization model determine survival? Cicale dismissed a parking enforcement DPPA claim for lack of injury while the Carfax crash-report case in Maryland survived—suggesting courts are distinguishing incidental DMV data use from systematic commercial exploitation. The line between those models is not yet defined by any circuit court .
  • Federal preemption: will the SECURE Data Act displace state privacy regimes? The bill's preemption language would eliminate CCPA, the Virginia CDPA, and 19 other state frameworks if enacted—but it lacks bipartisan support and faces a long history of failed federal privacy efforts. The preemption question is the central advisory issue for multistate compliance programs .

What to watch.

  • Early motions practice in the Florida AG v. OpenAI action—whether the complaint survives dismissal on duty-of-care and FDUTPA grounds, and whether the sealed factual record becomes public; also whether other state AGs file parallel suits using the Florida complaint as a template .
  • Whether the Anthropic class action survives a motion to dismiss and proceeds to class certification—the court's treatment of usage-multiple marketing as a measurable, class-wide representation will be the signal for the broader AI subscription market .
  • Appellate review of the Roku minor-arbitration ruling—whether the Ninth Circuit or other circuits address whether parental assent to platform terms can bind non-consenting minors, and whether the Florida AG's state enforcement action produces a conflicting outcome .
  • Virginia's July 1, 2026 auto-renewal effective date—whether enforcement actions follow promptly and whether other states adopt the symmetry-of-cancellation model .
  • Whether the FTC's Genesis Tech asset freeze survives preliminary injunction challenge and whether the agency pursues individual liability against the named founder-CEOs—the outcome will calibrate how aggressively the FTC can reach offshore ROSCA violators .
  • State AG enforcement actions in the fashion, beauty, and wearable tech sectors under the 2026 multi-state privacy regime—the first enforcement wave will set the compliance baseline for biometric and consumer health data handling outside HIPAA .

11 Contributing Entries

FTC, Utah, and California Sue Hims & Hers Over Health Data and Billing Practices

The FTC, joined by Utah and California, sued telehealth company Hims & Hers Health, Inc. on July 29, 2026, in U.S. District Court for the Northern District of California. The complaint alleges that Hims shared consumers' sensitive health information with third-party ad platforms including Meta and Snap despite privacy commitments, and that it charged customers for prescriptions immediately after intake forms were completed—before any provider consultation occurred. The agencies also claim Hims misled customers about billing, subscriptions, and cancellation procedures. The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act (ROSCA), while Utah and California assert violations of state consumer protection and false-advertising statutes.

FTC, California, and Utah Sue Hims & Hers Over Health Data and Billing Practices

The Federal Trade Commission, joined by California and Utah, has sued telehealth company Hims & Hers Health, Inc. in U.S. District Court for the Northern District of California, alleging that the company shared sensitive health data with advertising platforms including Meta and Snap while marketing itself as private and discreet. The complaint also charges Hims with deceptive subscription practices, including charging customers immediately after intake forms were submitted—before any medical consultation occurred—and making cancellation unreasonably difficult. The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act, while California invokes its False Advertising and Unfair Competition Laws and Utah cites its Consumer Sales Practices Act.

FTC, Utah, and California Sue Hims & Hers Over Health Data Sharing

The FTC, joined by Utah and California, filed a federal complaint in the U.S. District Court for the Northern District of California against Hims & Hers Health, Inc., alleging the telehealth company shared consumers' sensitive health information with third-party advertising platforms including Meta and Snap while publicly promising privacy protection. The complaint also charges that Hims & Hers misled users about billing and cancellation practices. According to the filing, the company disclosed health-related data and customer lists through tracking technologies embedded on its website, charged consumers for prescriptions immediately after intake forms were submitted—before any provider consultation occurred—and deliberately made subscriptions difficult to cancel. The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act (ROSCA), while Utah invokes the Utah Consumer Sales Practices Act and California cites its False Advertising and Unfair Competition laws.

Meta Faces Wave of Social-Media Addiction and Safety Lawsuits

Meta faces a sprawling litigation campaign alleging that Facebook and Instagram were engineered to addict minors and that the company concealed safety and privacy risks from users. State attorneys general from New Mexico, Vermont, Massachusetts, and a coalition led by California, Colorado, Kentucky, and New Jersey have filed suit alongside individual plaintiffs and school districts in federal and state courts. Related defendants including Google/YouTube, Snap, and TikTok face similar claims in some actions.

Blank Rome Sued Over May 2026 Data Breach Exposing 57K Clients' Data

Blank Rome LLP, a Philadelphia-based law firm, faces two proposed class-action lawsuits over a data breach that exposed sensitive information on 57,554 current, former, and prospective clients. The breach occurred in May 2026 when a cybercriminal impersonated the firm's IT department and convinced an attorney to upload client files to an external Google Drive account. The exposed data includes names, Social Security numbers, addresses, dates of birth, driver's license numbers, passport numbers, medical records, and health insurance information. Blank Rome announced the breach to affected clients on June 26, 2026—nearly a month after the incident occurred. The firm stated it will "aggressively defend" against the suits and claims they lack merit.

Brands Warn as Creators Flood TikTok Shop with AI Avatar Affiliate Videos

TikTok Shop is being flooded with AI-generated product demonstrations, fake creator personas, and duplicate avatars that are undercutting human creators and eroding consumer trust. Merchants and affiliate creators are using TikTok's built-in AI tools to mass-produce makeup tutorials, clothing reviews, and product showcases without holding inventory—a low-cost strategy that prioritizes algorithmic reach over authenticity. Some operators have deployed synthetic personas, including a fabricated Black creator named "Aliyah," to sell dropshipped goods from retailers like Shein, exploiting algorithmic biases that reward emotional connection to creators.

WilmerHale Faces Class Action After Employee Disclosed Client Data

WilmerHale faced a proposed class action lawsuit filed this week in U.S. District Court for the District of Columbia over a May 8, 2026 data incident in which a firm employee disclosed sensitive client information to an unauthorized third party who had misrepresented their identity. The breach exposed names and Social Security numbers of thousands of clients. Nevada resident Jason Perry filed the suit, styled Perry v. Wilmer Cutler Pickering Hale & Dorr LLP, No. 1:26-cv-02470, seeking negligence and contract damages on behalf of affected clients.

Rising Star: Mayer Brown's Sophie Mancall-Bitel

Sophie Mancall-Bitel, a litigation partner at Mayer Brown, has been named a 2026 Rising Star by Law360 Pulse for her defense of major technology companies in privacy and wiretapping class actions. Her clients include TikTok, Google, and YouTube. Mancall-Bitel's practice centers on internet and technology companies defending claims under the federal Wiretap Act, the California Invasion of Privacy Act, the Video Privacy Protection Act, and biometric privacy statutes. She has handled wiretapping litigation and internet data privacy matters for tech and financial-services clients.

Nike and Lululemon sued in California over alleged fake discount pricing

Nike and Lululemon face separate class action lawsuits alleging "phantom discount" pricing schemes on their online platforms. Both companies are accused of displaying artificially inflated struck-through prices to exaggerate the depth of sales discounts and mislead consumers about actual savings. Nike was sued on July 21, 2026 by Corinne Pearson in U.S. District Court for the Southern District of California over pricing on its website and mobile app. The complaint cites specific examples, including Air Max 2017 sneakers allegedly kept on discount beyond the 90-day window permitted under California's False Advertising Law without proper disclosure of when the original price was actually in effect. The proposed class covers California purchasers who bought Nike products at a discount since July 21, 2022. Lululemon faces a parallel suit filed by Annette Cody in Los Angeles Superior Court, which alleges the company listed products with fictitious regular prices. One example cited involves Wunder Train high-rise tights marked down from $98 to $59, allegedly without having sold at the higher price for months.

Granola AI Notetaker Faces California Wiretapping Lawsuit Over Hidden Recording

A California federal lawsuit alleges that Granola, an AI meeting-notetaking tool, secretly recorded virtual meeting participants without notice or consent and used the captured content for commercial purposes, including AI model training enabled by default. The case, Chamberlain v. Granola, Inc., filed in the Northern District of California, centers on wiretapping and consent violations under state and federal privacy law. According to the complaint, Granola distinguished itself from competitors by joining meetings invisibly, announcing no presence, and providing participants no mechanism to remove the notetaker from the call.

mail Subscribe to Consumer Privacy Class Action email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap