Blog
Pennsylvania Court Lets Pixel-Tracking Wiretap Claims Proceed as EDPB Orders Belgian DPA to Rule on noyb Cookie-Banner Complaint
July 22, 2026
Want to receive these privacy recaps in your inbox each week? Subscribe here.
A Pennsylvania federal court allowed most of a class action against Warren General Hospital to proceed, holding that the Meta Pixel qualifies as an intercepting device under the state’s wiretapping law. Meanwhile, the EDPB rejected the Belgian DPA’s abuse-of-rights finding and ordered it to assess a noyb cookie-banner complaint on the merits.
Keep reading to discover my analysis and takeaways.
United States
Pennsylvania Hospital Must Face Most of Pixel-Tracking Suit
A Western District of Pennsylvania judge largely denied Warren General Hospital’s motion to dismiss a putative class action alleging the hospital’s use of the Meta Pixel and Google Analytics disclosed patients’ protected health information and patient status to Facebook and Google without authorization (Brunecz v. Warren General Hospital, No. 1:24-cv-00203-SPB, W.D. Pa. July 15, 2026).
The court dismissed the request for injunctive relief without prejudice (the tracking had already been removed, making future injury too speculative) and the negligence per se claim without prejudice, while allowing negligence, invasion of privacy, breach of implied contract, unjust enrichment, breach of fiduciary duty, a state consumer-protection claim, and — notably — a claim under Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (“WESCA”) to proceed. The court held that the Meta Pixel qualifies as an intercepting “device” under WESCA and that the statute’s primary provision doesn’t require pleading interception of communication “contents” at all.
Takeaway
Pennsylvania is roughly where California was two years ago regarding the application of wiretapping laws to pixel tracking. WESCA courts are still resolving first-impression questions (is a pixel a “device,” must plaintiffs plead “contents”) and are doing so almost uniformly in plaintiffs’ favor, while California’s CIPA docket has moved on to appellate review, a legislative carve-out bill, and open judicial backlash against sheer volume.
For companies facing exposure in both states, a few mitigation tactics are worth evaluating together rather than in isolation:
Consent mechanisms built for opt-in, not opt-out.
Wiretapping statutes are unforgiving on timing: Javier v. Assurance IQ (9th Cir.) held that CIPA requires consent prior to interception, meaning a banner that lets tracking fire by default and only offers a later opt-out doesn’t satisfy the exception; the tracking has already happened by the time the user acts. WESCA courts have accepted affirmative agreement to Terms of Use/Privacy Notices as sufficient consent (Adair v. Cigna), but critically, that agreement predated the tracked sessions. A CCPA-style “opt-out of sale/sharing” toggle is a different compliance obligation entirely and doesn’t defeat either statute’s consent exception.
Server-side tracking.
Less understood, but the logic is straightforward: every version of wiretapping law (e.g., CIPA, the federal Wiretap Act, WESCA) requires an alleged interception, meaning acquisition of a communication while still in transit between the sender and intended recipient. Server-side architecture (routing data through the company’s own server first, which then forwards a curated subset to a vendor like Meta or Zeta) removes the browser-to-third-party transmission that pixel-based interception theories depend on.
In Smith v. Rack Room Shoes (N.D. Cal. Jan. 23, 2026), the court dismissed a CIPA claim targeting exactly this architecture, without leave to amend, because plaintiffs, after three amended complaints, still couldn’t allege the forwarding was contemporaneous with the original communication:
“Although the TAC alleges that the server-side tracker ‘directly forward[s]’ communications and does so on an ‘automatic’ basis, there is no information about how soon this forwarding occurs or whether it is contemporaneous with the receipt. As pled, the TAC thus fails to allege that Zeta ‘reads, or attempts to read, or to learn the contents or meaning’ of Plaintiffs’ communications ‘in transit.'”
The court was explicit that it wasn’t deciding whether server-side tracking is immune from CIPA as a matter of law, only that plaintiffs couldn’t plead the timing. That may highlight another value of the tactic though: even if it’s not a guaranteed legal shield, it’s a structural advantage because the timing and architecture that would defeat it are largely invisible to plaintiffs’ counsel, who typically build these cases from captured browser network traffic and pixel payloads, evidence that doesn’t exist when the transmission never touches the user’s browser at all.
Why Pennsylvania may be an even better jurisdiction for this argument.
WESCA is interpreted as a direct supplement to the federal Wiretap Act, unlike CIPA, a 1967 statute with no such lineage. The “contemporaneous interception” doctrine is a federal doctrine, so a properly implemented server-side architecture may have an even cleaner, more direct defense in Pennsylvania than the still-unsettled version currently playing out in California. No Pennsylvania court has tested this yet, but it’s an open question worth watching.
Europe
EDPB Rejects Abuse-of-Rights Finding and Orders Belgian DPA to Address Cookie-Banner Complaint on the Merits
The European Data Protection Board (EDPB) has published a binding decision resolving a dispute between Belgium’s Data Protection Authority, acting as lead supervisory authority, and Austria’s Data Protection Authority over a cookie-banner complaint lodged by noyb. It alleged violations of the GDPR and the ePrivacy Directive, and was one of the multiple noyb complaints that led the EDPB to establish its Cookie Banner Taskforce.
The Belgian DPA’s draft decision proposed dismissing the complaint without addressing whether the cookie banner at issue complied with the GDPR or ePrivacy rules. Instead, Belgium argued that the complaint amounted to an abuse of rights. Its reasoning relied heavily on a 19 March 2025 Belgian Market Court judgment that had annulled an earlier Belgian DPA decision in a similar noyb-supported case against Mediahuis. The EDPB rejected Belgium’s conclusion and ordered that the case be decided on its merits. The Belgian DPA argued that both parts of the CJEU’s abuse-of-rights test were satisfied.
On the objective component, it pointed to noyb’s standardized, partly automated process for generating complaints; the complainant’s apparent lack of connection to the ordinary audience for a Dutch-language Belgian website; a pre-existing working relationship between the complainant and noyb; and the fact that noyb had outlined the project and identified target controllers before the individual granted the mandate. Belgium considered this sequence inconsistent with the direction contemplated by the GDPR, under which a data subject mandates an organization to act on their behalf.
On the subjective component, Belgium alleged that noyb’s real objective was to manufacture access to proceedings it could not otherwise bring, citing the use of trainees or staff as data subjects in model cases and noyb’s public campaign to end “cookie banner terror.” The EDPB did not dispute that noyb had played a leading role, selected controllers according to predefined criteria, or used automated tools. But because the individual had successfully granted a mandate under Article 80(1) of the GDPR, and the validity of that mandate was not itself disputed, the Board concluded that the objective component of abuse was absent. The Board concluded that the purpose of allowing a data subject to obtain professional representation appeared to have been fulfilled.
The subjective component was also unproven, according to the decision. The EDPB found no concrete evidence that noyb had pursued interests other than those of the individual or that the individual had simply been instructed to act without participating in the initiative. Nor did the EDPB find evidence that the complainant obtained an undue benefit, such as compensation or other financial benefit. It considered technical assistance with collecting evidence, such as producing screenshots and log files during a website visit, consistent with the purpose of Articles 77 and 80(1). The Board therefore ordered Belgium not to dismiss the complaint for abuse of rights and to prepare a new draft decision assessing the underlying allegations on their merits.
Takeaway
The decision confirms the evidentiary bar for dismissing an NGO-supported complaint merely because it arose from an organized, template-based or partly automated campaign. It does not, however, abolish the EU abuse-of-rights doctrine or rule out that defense in future proceedings.
The EDPB expressly stated that its decision was without prejudice to assessments in other cases, including cases involving the same parties, based on the evidence and objections presented there. The holding is therefore case-specific: coordination, automation, prior planning and an existing relationship with the complainant were insufficient, without more, to establish abuse in this proceeding.
For companies facing similar complaints, the decision means that an authority will need concrete evidence of both the objective and subjective components of abuse; the organized nature of a campaign will not be enough by itself. Where a complaint proceeds to the merits, the relevant issues may include whether consent-dependent cookies are placed before a positive action, whether users have a meaningful way to refuse, whether options are pre-ticked, whether the purpose of the requested consent is clearly explained, whether the interface improperly steers users toward acceptance, and whether consent can be withdrawn easily. On button color and contrast specifically, the Cookie Banner Taskforce’s 2023 report declined to impose a general standard, calling instead for case-by-case review of whether a particular design is misleading.
By contrast, a “vast majority” of participating authorities considered that the absence of a refuse, reject or not-consent option on any layer containing a consent button is inconsistent with the requirements for valid consent and constitutes an infringement, although a few authorities disagreed. That reflects a firmer consensus, but not a binding EU-wide bright-line rule: the report states that its positions do not prejudge the assessment of individual banners and must be read together with applicable national ePrivacy law. None of those substantive questions was resolved by the EDPB in this particular decision.
A LITTLE MORE PRIVACY, IF YOU PLEASE
- EU-U.S. Data Privacy Framework (DPF): What would a Schrems III decision mean for your business?
- Google Consent Mode 2026 changes: What you need to know
A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.
Latest Blog Posts
FTC and States Sue Hims & Hers Over Health-Data Sharing; Vermont Releases Draft Age-Appropriate Design Code Rules
August 4, 2026FTC and states sue Hims & Hers over health-data...
New Jersey Signs Surveillance Pricing Law as South Korea Fines Apple and TikTok for Lacking a Legal Basis to Process Data
July 28, 2026New Jersey signs surveillance pricing law banning personal-data-based grocery...
Pennsylvania Court Lets Pixel-Tracking Wiretap Claims Proceed as EDPB Orders Belgian DPA to Rule on noyb Cookie-Banner Complaint
July 22, 2026PA court holds Meta Pixel is a wiretap device...
Latest White Papers
Connecting Legal & Marketing Teams on Consent and Preferences
February 4, 2025Break down data silos and unlock better collaboration. Marketing...
Navigating Sensitive Data in the U.S.
February 4, 2025Download our comprehensive guide to learn how different states...
Enterprise Guide To Cookie management & Tracker List Curation
July 1, 2024How to review the tracking tech on your websites...