What happened
EPIC outlines how recent court decisions using the Electronic Communications Privacy Act (ECPA) and California Invasion of Privacy Act (CIPA) address non‑consensual pixel tracking and its privacy harms. The analysis cites multiple district‑court rulings that recognize standing when companies collect IP addresses, health data, or other sensitive information without user consent, and highlights circuit splits on what constitutes an intrusion upon seclusion.
Why it matters for trust and compliance
- Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
- The piece provides practitioners with case‑law guidance on how pixel‑tracking claims are being evaluated under federal and state privacy statutes ahead of the Salazar v. Paramount Supreme Court review.
- It relates to HIPAA. The regulations library explains what that law requires.
Who is affected
technology healthcare retail media advertising controller processor data broker platform developer Meta Google TikTok MyFitnessPal Oracle OpenX Technologies CNN TJX Companies Cabela’s Bass Pro Shops GameStop Teladoc Health Edward-Elmhurst Health Nourish Orlando Health
Recommended actions
- Review consent, cookie and tracking practices against the requirement.
- Check that privacy notices describe the practices this addresses.
- Inventory where this data is shared or sold and whether opt-outs are honoured.
- Map the security requirements to existing controls and close gaps.
- Inventory AI or automated decision systems in scope and their assessments.
- Confirm handling of sensitive data categories meets the stricter rules.