CIPA Marketplace Fashion Brand Compliance Report
Reports

CIPA Marketplace Fashion Brand Compliance Report

Retail is now the most-sued industry under California’s CIPA, at $5,000 per violation. We scanned 699 independent fashion storefronts that sell on retail marketplaces like Nordstrom, Target+ and Macy's: 93% load the exact trackers named in these lawsuits, and barely one in four has any consent tooling.

The California Invasion of Privacy Act was written in 1967 to stop people tapping phone lines. In 2026 it is the most active legal threat to a fashion brand's website. Plaintiff firms have filed more than 1,800 website-wiretapping suits against retailers since May 2022 — more than against any other industry — arguing that a Meta Pixel, a TikTok Pixel, or a session-replay script is a third party "listening in" on shoppers. The statute carries $5,000 in damages per violation, and the demand letters typically settle for $10,000 to $25,000 before a case is ever filed.

To see how exposed the typical independent brand selling on retail marketplaces is, we scanned 790 fashion, footwear, jewelry, accessories, and beauty storefronts in August 2026. 699 loaded as working storefronts, 659 of them on Shopify. The short version: 93% load the exact tracking technologies named in these lawsuits, and barely one in four has any consent tooling.

1,817Retail wiretapping suitsFiled since May 2022 — the most-sued industry, ~33% of all cases
$5,000Per violationStatutory damages under Penal Code §637.2, plus attorneys’ fees
93%Load the named trackersOf 699 scanned fashion storefronts running ad pixels or session replay
28%Have consent toolingBarely one in four storefronts showed any consent-management platform

Why a 1967 wiretap law is hitting fashion brands

Two sections of the statute are doing the damage. §631 makes it illegal to read the contents of a communication in transit without everyone's consent — or to help anyone who does. Plaintiffs argue that a pixel, a session-replay script (Hotjar, Microsoft Clarity, FullStory), or a chat widget relayed to a vendor is a third party reading the shopper's interactions. §638.51 bans installing a "pen register" without a court order; since Greenley v. Kochava (2023), courts have accepted that software capturing a visitor's IP address and device identifiers can qualify.

Each violation carries $5,000 in statutory damages or three times actual damages, whichever is greater, plus attorneys' fees. Multiply a class of California visitors by $5,000 and you get the exposure numbers that make defendants settle: in the Flo Health case, roughly 1.6 million class members put Meta's theoretical exposure at about $8 billion after a jury found it liable under CIPA in August 2025.

The pivotal shift was Javier v. Assurance IQ (9th Cir., May 2022), which held that consent must be obtained before tracking starts — retroactive consent doesn't count. Filings have compounded ever since: the Fisher Phillips tracker counted 522 retail suits in January 2025 and 1,817 by July 2026, a 3.5× jump in eighteen months, while pen-register claims grew from roughly 600 to over 4,000.

Website-wiretapping suits by industry, since May 2022
Retail1,817
Technology542
Professional services447

Fisher Phillips digital-wiretapping litigation tracker, as of late July 2026. Retail's ~33% share has held steady across three snapshots while the absolute number tripled.

View as table
 Value
Retail1,817
Technology542
Professional services447

The fashion brands already in court

No fashion brand has announced a public CIPA settlement yet — cases are pending, dismissed, or settled confidentially. But the roster of defendants reads like a mall directory.

BrandTracking tech allegedTheoryWhere it stands
Ulta BeautyHartigan v. Ulta (S.D. Cal. 2026)Meta Pixel§631PendingNewly filed class action
AdidasCamplisson v. Adidas America (S.D. Cal.)TikTok + Bing pixels§638.51Surviving dismissalMotion to dismiss denied Nov 2025; footer privacy policy ≠ consent
NikeSaleh v. Nike (C.D. Cal.)FullStory session replay§631Surviving dismissalSurvived dismissal, proceeded to discovery
NikeAbdullah v. Nike (N.D. Cal. 2025)Google, Meta, The Trade Desk§638.51PendingPending
Estée LauderElmarouk v. Estée Lauder (N.D. Cal. 2025)Google + Facebook trackers§638.51PendingPending
LuxotticaMoore v. Luxottica (2025)Cookies set after rejection§631 + §638.51PendingPending
Bloomingdale’sMikulsky v. Bloomingdale’s (9th Cir. 2025)Session replay§631Surviving dismissalDismissal reversed — replay data can be “contents”
ConverseGutierrez v. Converse (9th Cir. 2025)Salesforce chat§631DismissedDefense win at summary judgment
Old NavyLicea v. Old Navy (C.D. Cal. 2023)Salesforce chat§631 / §632.7Surviving dismissal§631 dismissed; §632.7 survived
Kohl’sEsparza v. Kohl’s (S.D. Cal. 2024)Email tracking pixels§631SettledSurvived dismissal, then settled (undisclosed)
LululemonYoon v. Lululemon (C.D. Cal. 2021)Quantum Metric session replay§631Surviving dismissalRepeated motions to dismiss
VuoriMatisen v. Vuori (Cal. Super. Ct. 2025)IP + device IDs to ad-tech§638.51PendingIndividual suit
Hot Topic, American Eagle, SephoraByars / Licea / Martin (2023)Chat widgets§631DismissedDismissed under the party exception

Two patterns matter if you're deciding what to do next. The 2023 chat-widget cases mostly failed — a vendor that merely records a conversation for the retailer is treated as the retailer's agent, not an eavesdropper. The 2025–2026 pixel and session-replay cases are surviving: Mikulsky held that session-replay data can be "contents," Camplisson held that a TikTok pixel can be a pen register and that a privacy-policy link in the footer is not consent, and Hartigan v. Ulta — Meta Pixel, filed this month — is the newest test.

The hard dollars so far have actually come from regulators under the CCPA, not CIPA: Sephora paid $1.2 million in 2022 (third-party trackers as a "sale" of data, and ignoring the Global Privacy Control signal), and menswear brand Todd Snyder paid $345,178 in 2025 (a cookie banner that appeared and disappeared before shoppers could opt out). The same misconfigured pixel that triggers a CCPA fine is the evidence in a CIPA complaint — treat them as one problem.

How the case law got here

  1. May 2022Javier v. Assurance IQ (9th Cir.)Consent must come before tracking starts; retroactive consent doesn’t count. The filing wave dates from this ruling.
  2. 2023Greenley v. KochavaSoftware that captures IP addresses, device identifiers, and routing data can be a “pen register” under §638.51.
  3. Apr 2025Briskin v. Shopify (9th Cir., en banc)Shopify can be sued in California for cookies it sets on shoppers’ devices — the plaintiff had bought athletic apparel from a Shopify merchant.
  4. Jun 2025Mikulsky v. Bloomingdale’s (9th Cir.)Session-replay capture of keystrokes and mouse movements can be the “contents” of a communication. Dismissal reversed.
  5. Jul 2025Gutierrez v. Converse (9th Cir.)The party exception holds for chat vendors that only record for the retailer — the main defense that still works.
  6. Aug 2026SB 690 nears a floor voteWould strip the private right of action from pen-register claims — but leaves §631 pixel and session-replay suits untouched.

What we found scanning 700 fashion storefronts

We loaded each of the 790 domains once in a fresh Chrome session — no cookies, no prior consent, North American IP — and recorded every third-party network request in the first ~5 seconds, plus any consent banner or consent-management platform (CMP) evidence. 699 loaded as working storefronts; 659 were on Shopify. The point is the base rate, not any one store, so we don't name brands.

Tracker prevalence — % of scanned storefronts
Meta Pixel85%
Google Ads tags73%
Klaviyo email/SMS73%
Any session replay40%
Microsoft Clarity28%
Live-chat widget24%
Attentive / Postscript16%
Microsoft Ads (Bing UET)15%
Hotjar11%
Pinterest Tag7%
TikTok Pixel6%
Snap Pixel5%

Share of 699 storefronts loading each technology on first pageview. 91% load at least one advertising pixel; 40% run session replay; the median store runs two of the tracker categories named in CIPA complaints, and 47% run three or more.

View as table
 Value
Meta Pixel85%
Google Ads tags73%
Klaviyo email/SMS73%
Any session replay40%
Microsoft Clarity28%
Live-chat widget24%
Attentive / Postscript16%
Microsoft Ads (Bing UET)15%
Hotjar11%
Pinterest Tag7%
TikTok Pixel6%
Snap Pixel5%

Consent tooling is the other half of the picture, and it's nearly absent. Our test visitor wasn't in California, so geo-targeted banners undercount — but the CMP scripts load regardless of region, and we found them on barely more than a quarter of sites.

Consent tooling — % of scanned storefronts
Any consent-management platform28%
Banner visible on first load13%
“Your Privacy Choices” link9%

Consentmo, Pandectes, Shopify's native banner, and OneTrust were the most common platforms among the sites that had one.

View as table
 Value
Any consent-management platform28%
Banner visible on first load13%
“Your Privacy Choices” link9%

Put trackers and consent together and you get the exposure picture. We put each storefront in one of three tiers, defined by the two technologies at the center of Hartigan v. Ulta (Meta Pixel) and Mikulsky v. Bloomingdale's (session replay):

Where 699 fashion storefronts land
  • High — 64%Loads ad pixels or session replay with no consent tooling detected
  • Medium — 28%Loads the same trackers, but a consent-management platform is present
  • Low — 7%No ad pixel and no session replay

One cell ≈ 7 storefronts (percentages rounded). Within the high tier, 65% of all sites load the Meta Pixel with no consent tool present, and 26% run session replay with no consent tool present.

We also watched for the pixel actually transmitting before any interaction: on 28% of sites the Meta Pixel fired its PageView beacon within seconds of load, before a visitor could possibly have consented to anything — and since beacons sent via sendBeacon don't always appear in the resource log, the true rate is higher. Javier makes pre-consent firing the whole ballgame.

These numbers run slightly above earlier cross-industry scans — Lokker found the Meta Pixel on 58% of retail sites in 2024, and StoreInspect found it on 69% of ~1,830 Shopify stores. Independent fashion brands appear to run more tracking and less consent tooling than the average retailer.

The Shopify-specific problem

Shopify brands have a false sense of security for two reasons. First, Briskin v. Shopify: in April 2025 the Ninth Circuit held, en banc, that Shopify can be sued in California for cookies it sets on shoppers' devices — and on remand the court noted that Shopify's own terms put the consent obligation on the merchant.

Second, Shopify's native cookie banner and Customer Privacy API govern Shopify's first-party cookies and Shopify-managed pixels — not the scripts you add through the theme, Google Tag Manager, or apps that inject their own tags. Custom pixels have to be written to check the Customer Privacy API. That matches what we saw: 93% of Shopify stores had the API loaded, but 91% of those reported marketing trackers as allowed by default for our visitor, and the Meta Pixel, Klaviyo, and Clarity were loading regardless.

SB 690: relief for only half the problem

California's SB 690 would remove the private right of action for §638.51 pen-register claims from websites and apps, leaving enforcement to the Attorney General — and apply retroactively. It has cleared every vote so far unanimously and needs an Assembly floor vote before the session ends August 31.

  1. SenatePassed 35–0, June 2025
  2. Assembly Privacy CommitteeNarrowed, passed 14–0, July 1, 2026
  3. Assembly AppropriationsCleared 15–0, August 13, 2026
  4. Assembly floorNeeds a vote before the session ends August 31
  5. GovernorSignature required; would apply retroactively

If it passes, the Adidas, Abdullah v. Nike, Estée Lauder, and Vuori theory loses its private enforcement mechanism. But §631 is untouched — Meta Pixel and session-replay suits like Ulta and Bloomingdale's continue at $5,000 per violation, and the same tracking is actionable under wiretap statutes in Florida (811 suits), Illinois, Pennsylvania, and New York.

What fashion brands should do now

  1. Inventory every script that loads before consent. Open your homepage, product page, and checkout in a fresh incognito window with the network panel open. Anything calling facebook.com/tr, analytics.tiktok.com, clarity.ms, hotjar.com, or a chat vendor before a click is your exposure list.
  2. Gate marketing tags behind a real consent signal for California visitors. A banner that displays but doesn't block is the Todd Snyder fact pattern. On Shopify, that means a CMP integrated with the Customer Privacy API — and custom pixels and GTM tags wired to wait for it.
  3. Honor Global Privacy Control. Sephora's $1.2M penalty was substantially about ignoring GPC. It's a one-line check in most CMPs.
  4. Decide whether session replay is worth it. 40% of the brands we scanned run it; Mikulsky makes keystroke and mouse capture "contents." If you keep it, mask inputs and gate it behind consent.
  5. Audit the chat widget's data flow. The party-exception defense that saved Hot Topic and Converse depends on the vendor only recording for you, not using transcripts for its own purposes.
  6. Keep timestamped consent logs. Demand letters arrive with a screenshot; the defense is a record showing what that visitor consented to and when.
  7. Add a visible "Your Privacy Choices" link. Only 9% of the storefronts we scanned had one, and it's a CCPA requirement independent of CIPA.

Where marketplaces fit

One structural observation from working with Shopify fashion brands that also sell on Nordstrom, Macy's, Bloomingdale's, and Target+: on a marketplace, the retailer runs the storefront, sets the cookies, operates the consent banner, and carries the visitor-data relationship. The brand supplies product data and fulfills orders. That doesn't reduce your obligations on your own DTC site — but it does mean marketplace revenue isn't tied to the pixel stack that's drawing demand letters, which matters if tightening consent dents paid-social attribution. For brands weighing channel mix, it's one more reason the marketplace listings Osello automates look like a hedge rather than a distraction.

Methodology and limits

  • Sample: 790 independent fashion, footwear, jewelry, accessories, and beauty brand domains; 699 resolved as consumer storefronts, 659 identified as Shopify stores. Each homepage was loaded once in Chrome with a fresh profile, no interaction, from a North American (non-California) IP in August 2026.
  • "Consent tooling detected" required network or markup evidence of a named CMP; generic "cookie consent" strings weren't counted. Homepage-only scanning understates exposure — checkout and product pages typically load more tags, not fewer.
  • Litigation figures come from the Fisher Phillips litigation tracker, the California Assembly committee analysis of SB 690, and the cited court opinions. Case statuses are as reported as of August 21, 2026.
  • Nothing here is legal advice. If you've received a demand letter, talk to counsel.
Osello Team

The Osello team helps fashion brands get accepted, listed, and selling on premium marketplaces like Nordstrom, Macy’s, and Bloomingdale’s.

Written by Osello Team · Published August 23, 2026 · Filed under Reports