Every day, personal data is bought, sold, and traded online by companies most people have never heard of, often for purposes they never explicitly agreed to. Consumers typically don’t know it’s happening. And the businesses operating websites are also often in the dark as to how some data-collection technologies work in practice. Up until now, there have been few legal avenues for better understanding and addressing these potential harms.
That’s changing. Today, artificial intelligence is helping legal teams pull back the curtain on how companies that buy and sell consumer information online—often called data brokers—access and use that data. That same technology is also helping organizations that operate online understand whether their data privacy policies and practices are actually effective. And it’s helping consumers’ attorneys spot and address entities on all sides of consumer data exchanges that fail to protect data privacy.
Staying up to date on all the ways consumer data can be misused (whether intentionally or not, and whether by the organization itself or an external partner) is time-consuming and challenging. Yet businesses operating online likely can’t avoid interacting with external partners, such as data brokers, that seek to access their consumer data. Therefore, they must be aware of the potential privacy risks those organizations introduce so they can better manage them. Here’s what you need to know.
The shifting landscape of consumer data privacy litigation
Data privacy litigation has historically focused on website owners that collect personal digital data, such as health information, financial details, browsing activity, location, and communications, without consent. This can happen when operators add third-party tracking technologies, such as cookies and pixels, to their websites.
- Pixels collect and transmit user data so websites can better understand who a user is and what actions they might take.
- Cookies store data on a user’s computer, allowing websites to identify the user and provide a targeted experience based on past online behavior.
These trackers shape how individuals experience the internet. The information can be intercepted by third-party technology providers who use it to customize advertising and other online experiences to each individual based on the interests they have demonstrated.
Courts increasingly view the practice of intercepting and disclosing this type of consumer behavior data without proper consent as a potential wiretap violation.
Wiretap claims against medical websites, in particular, have historically dominated this area of plaintiff litigation. But as the category evolves, a new kind of case is emerging for firms seeking to protect consumer data through the courts. Instead of focusing on consumer-facing companies, plaintiffs are bringing claims against organizations whose trackers collect consumer information in the background of those websites and profit from it (often without explicit consent and in violation of data privacy statutes) using the Electronic Communications Privacy Act (“ECPA”).
These more recent cases go beyond the tech giants that have historically faced class action lawsuits (e.g., Google and Facebook) and look at other players in the adtech pipeline. These entities are typically registered data brokers that operate within the real-time bidding (“RTB”) infrastructure, which precisely targets ads to individual users based on the information collected about them. These cases turn largely on the collection of users’ browsing history, persistent digital identifiers, and communications to build identity profiles for advertising.
At the same time, states have begun implementing laws to put parameters around how these companies can collect and use consumer information, but these laws are generally not enforceable through private litigation.
Key developments driving potential claims against data brokers include the following:
- The emergence of positive case law on the privacy harm of profiling users in this way (discussed below)
- Governments being allowed to purchase citizen data without warrants
- The recent implementation of California’s DROP centralized deletion mechanism on August 1, 2026
The potential impact on consumer data privacy is significant. A congressional committee found that, over the last decade, just four data breaches involving major data brokers cost U.S. consumers more than $20 billion in losses related to identity theft. That’s a mere snapshot of the likely harm caused by poor data privacy protections. The growing use of AI across business sectors is raising even more concerns about the security of personal data online. In a recent IBM survey, 97 percent of organizations reported an AI-related security incident and lacked proper data access controls.
Darrow data shows an emergence in this category of data privacy cases. Darrow analyzed a subset of consumer data privacy class actions filed directly in federal courts in the first quarter of 2026 involving allegations of website-based tracking. Of the 128 cases identified, over 10 percent targeted advertising technology and data vendors directly rather than the website operators hosting the tracking technology. Prior to 2026, cases advancing wiretap and pen register claims directly against these kinds of advertising-technology vendors were far less common. In 2025, Darrow observed only a handful of similar cases being filed in federal court compared to a surge of website-operator wiretap cases.
Technology vendors make up a growing share of ECPA class actions.

Federal data-privacy class actions involving allegations of website-based tracking. Source: Darrow
Cases shaping consumer data broker privacy litigation today
Several recent cases and settlements are beginning to establish precedent, indicating paths forward for future privacy cases focused on actions by data brokers and ad tech vendors.
Case Name | Impact |
Riganian v. LiveRamp Holdings Inc. (N.D. Cal. 2025) and | In both cases, the Northern District of California allowed plaintiffs’ claims to move forward based on allegations that the companies’ practices of monitoring and collecting data on users’ web browsing activity, combining that data with information from other sources, and using it to build unique profiles that track individuals’ activity across the internet could violate California and federal wiretap laws. In doing so, the courts rejected the argument that collecting data for profit, rather than for surveillance, was sufficient to avoid federal wiretap claims. |
Semien v. PubMatic Inc. (N.D. Cal. 2026) and | In two recent cases, the Northern District of California found a privacy injury arising from the collection of IP addresses, device and browser information, digital “fingerprint” information, and the URLs of online pages, which were used to profile users. The court rejected defendants’ arguments that the “pseudonymization” of data precluded liability. These cases reinforce that programmatic advertising vendors may be held liable under both wiretap and California Invasion of Privacy Act pen-register laws for the type of tracking and identity-resolution conduct. |
Other notable cases indicate potential outcomes as more claims work through the courts.
Oracle agreed to pay $115 million in 2024 to settle a lawsuit alleging that the company sold consumer profiles containing a wide range of personal information to marketers directly and through an Oracle product that helps companies personalize their online marketing. Oracle also had to agree to limits on how it collects user information online going forward.
The Federal Trade Commission will closely watch data broker Kochava after they reached a settlement earlier this year requiring Kochava to revise how it collects, uses, discloses, and disposes of user location data, following the resolution of a class action lawsuit over its disclosure of location data from sensitive venues, including health care facilities, jails, and schools. Kochava agreed to a class settlement in 2025 providing injunctive relief and approximately $1.5 million in attorneys’ fees and expenses, saying it lacked sufficient funds and insurance coverage to pay significant class-wide damages.
And earlier this year, Google agreed to sweeping injunctive relief in a class action settlement to amend its RTB privacy practices.
These types of orders and settlements are just the beginning as these cases continue to mature. However, several issues remain in bringing these claims that businesses and consumers should consider.
Challenges to advancing data broker privacy claims
While data broker and adtech vendor privacy claims are growing in number, there are several hurdles to bringing forward these claims, from clearly defining the class to proving harm on technology platforms that are constantly changing.
Understanding which companies introduce the risk. Identifying the specific intermediaries that buy and sell consumer data collected on a given website can be challenging. Consider that in California alone, more than five hundred companies have registered with the state as data brokers—a figure that likely does not capture all the companies processing consumer data across the United States.
Identifying class members. Because these companies operate in the background, data privacy advocates have historically lacked visibility into the volume and type of consumer data they have accessed. Even when that information is known, classes can be difficult to define if class members used numerous websites with these hidden tracking technologies at different points in time. However, technical analysis used in discovery can help ascertain class members and provide the basis for defining common classes with similar privacy harms. Businesses implicated by these claims will have to consider what individual data they have retained and how any data elements were derived.
Proving harm or consent. Different legal theories exist about what counts as a privacy harm and what level of consent is required when being tracked online. Another recent decision from the Northern District of California, In re Meta Android Privacy Litigation, highlights two competing theories of consent.
- Broad consent: This theory posits that if an app or website’s privacy policy discloses the collection and sharing of users’ data, even in general terms, then acceptance of that policy counts as consent to having their information tracked and shared. Under this theory, reasonable users would understand that their online data is generally being collected, and thus consent, even where the precise contours of that collection are not stated.
- Narrow consent: This theory holds that users must be informed of the specific ways in which their information is tracked and shared, meaning they can agree to some usage but not others—particularly if those others rely, as they did in the In re Meta Android Privacy Litigation case, on knowledge of the platform’s technical architecture that a user would not reasonably be expected to understand. Whether a reasonable user would understand and consent to the collection would be determined based on the specific context.
In this decision, which examined how Meta accessed Android users’ data, the court found that users might agree to basic tracking but not to a more nuanced, hidden process that runs counter to their expectations of online data privacy. The court emphasized that consent goes beyond the four corners of the privacy policy and is dependent on the circumstances.
Four signals shaping consumer data broker privacy risk
With the arrival of AI, legal teams now have the ability to identify and address potential harm more quickly. This allows them to map their digital exposures and make changes to swiftly mitigate their organization’s risk or take steps to secure remedies for consumers—all before privacy violations escalate.
Here are four factors poised to shape the risk landscape around consumer data privacy, and how AI can help organizations better understand what’s at risk and address it accordingly.
1. Millions of potential class members
Growing awareness of data brokers’ reach stemming from government use of consumer data—for example, ICE using Medicaid data, allegedly via a Palantir-created tool, for immigration enforcement—is prompting consumers to reassess their comfort level with how their data is used and may make them more open to participating in class actions.
How AI can help: Legal teams can use AI to review public disclosures, such as government contracting data, to identify arrangements with data brokers that suggest improper data collection and use. Companies should pay attention to these signals and look for similar agreements that might be putting them at risk.
2. More receptive courts
Courts are warming to the idea that consumers shouldn’t be profiled and tracked without their consent in commercial settings. That means more cases across a wide range of sectors are entering discovery. There, legal teams can watch and learn which practices are most likely to trigger liability. Consider the landmark litigation against Facebook over how it tracked user activity on non-Facebook websites, in which the U.S. Court of Appeals for the Ninth Circuit held in 2020 that users had standing for their privacy harms and that the company violated wiretap laws. Although this case was settled, the ruling helped to shape dozens of subsequent cases.
How AI can help: As litigation in this sector continues to grow, AI can be used to scan cases and identify potential patterns that could help legal teams more efficiently identify, and therefore mitigate, other areas of potential harm.
3. An impactful target
Data brokers built their business model around the ability to access and sell consumer data. What’s more, unlike the massive platforms on which that data is accessed, these entities are usually undisclosed to consumers while profiting from data aggregation at scale—leaving them with fewer defenses and giving advocates a privacy harm narrative that courts understand.
How AI can help: Public marketing materials from data brokers and other adtech vendors are rife with claims about the types of data they collect and how comprehensive their data collection is. Legal teams can use AI to analyze tracking behavior across websites and flag inconsistencies between actual practices and privacy policies, as well as discrepancies between the data broker’s privacy policy and the website’s privacy policy where it collects data.
4. State privacy laws and litigation trends
Organizations that collect consumer data must navigate a growing patchwork of compliance rules, as many states have passed comprehensive data privacy laws in recent years. As regulations increase, consumer data privacy benefits from greater transparency, disclosure, and the setting of thresholds for violations, even though most of these laws do not provide a private right of action. States such as California with stricter privacy laws are also frequent venues for federal class action litigation.
How AI can help: AI enables legal teams to track data brokers’ behavior at scale and better understand what data is being collected, where, and when.
Top states for federal online-tracking class actions filed in Q1 2026

Federal data-privacy class actions involving allegations of website-based tracking. Source: Darrow
The future of consumer data broker privacy risk
With the emergence of AI, identification of data privacy violations is shifting from reactive methods (in response to a data breach or government enforcement action) to proactive ones (by identifying where trackers are used and determining whether they comply with consent laws).
Litigation will likely continue to rise, but companies and consumers can take steps to better understand how data brokers access data and how that access is (or isn’t) reflected in the privacy policies they ask customers to accept. At the same time, privacy advocates will likely continue to unearth privacy violations caused by data brokers at scale.
With this new depth of insight, legal teams have the clarity and foresight needed to flag and address signals of data privacy risk to not only protect consumer data today but also shape how consumer data is tracked and shared online for decades to come.
