705 F.Supp.3d 333
E.D. Pa.2023Background
- Bass Pro Shops (BPS Direct, LLC) and Cabela’s (Cabela’s, LLC) embedded third‑party "session replay" code (vendors like Microsoft, Quantum Metric, Mouseflow) and Facebook Pixel on their websites, which can record mouse movements, clicks, keystrokes, form entries, URLs, and create persistent "fingerprints."
- Eight named plaintiffs in an MDL (session‑replay plaintiffs) and one Pennsylvania plaintiff (David Irvin, the Facebook plaintiff) sued, alleging violations of the Federal Wiretap Act, CFAA, multiple state wiretapping/privacy statutes, state consumer‑protection laws, and common‑law privacy torts.
- Plaintiffs generally do not allege disclosure or access to financial account numbers, bank data, Social Security numbers, or medical records; some plaintiffs allege they made purchases but did not specify the exact sensitive fields captured.
- The court applied Article III standing principles post‑Spokeo and TransUnion, focusing on whether the alleged interceptions implicated historically protected privacy interests (i.e., capture/disclosure of private, sensitive information).
- Result: the court dismissed six session‑replay plaintiffs with prejudice for lack of standing (they never alleged purchase or capture of sensitive data); three plaintiffs (two purchasers and Irvin) were dismissed without prejudice and given leave to amend only if they can truthfully plead capture/disclosure of non‑anonymized, unencrypted highly sensitive data (e.g., credit‑card/bank data or medical information). Claims for injunctive relief were also dismissed for lack of likelihood of future injury.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Article III standing for purely browsing users (no purchases or alleged sensitive data) | Any interception of website communications (mouse/keystrokes) is a concrete injury analogous to intrusion/public‑disclosure privacy torts | Browsing captures non‑sensitive, observable shopping activity; mere statutory violation is insufficient—plaintiff must allege capture/disclosure of sensitive or private data | Dismissed for lack of standing (six plaintiffs); browsing alone not a concrete injury absent capture of historically protected private data |
| Standing for purchasers who allege they entered information but do not identify sensitive fields | Purchase and keystroke capture plausibly shows interception of private information | Plaintiffs fail to identify whether sensitive fields (credit card, bank, medical) were actually captured or whether data were anonymized/encrypted | Dismissed without prejudice; leave to amend to allege non‑anonymized capture/disclosure of highly sensitive data |
| Claim under Pennsylvania Uniform Firearms Act (Irvin: disclosure to Facebook of firearm purchase) | Disclosure of firearm purchase and identifiers to Facebook is a concrete, privacy‑type injury analogous to intrusion upon seclusion | Disclosure to a single corporate recipient (Facebook) is not "publicity" required for public‑disclosure tort; disclosed facts (name, address, Facebook ID, gun purchase) are not sufficiently private | Dismissed without prejudice; plaintiff may amend only if he can allege capture/disclosure of non‑anonymized, highly sensitive data |
| Standing for injunctive relief | Ongoing use of session replay creates risk of future interceptions warranting an injunction | Plaintiffs now know about the practices and will act (or refrain) accordingly; any future injury is speculative | Injunctive claims dismissed for lack of likelihood of future injury; awareness defeats alleged risk of repeated harm |
Key Cases Cited
- Spokeo, Inc. v. Robins, 578 U.S. 330 (2016) (Article III requires a concrete injury even for statutory violations)
- TransUnion LLC v. Ramirez, 141 S. Ct. 2190 (2021) (courts must assess whether statutory violations caused concrete harms closely related to historical private‑law harms)
- In re Google Inc. Cookie Placement Consumer Privacy Litigation, 934 F.3d 316 (3d Cir. 2019) (tracking cookies and browser profiling may produce concrete injury when personal data are collected without authorization)
- In re Nickelodeon Consumer Privacy Litigation, 827 F.3d 262 (3d Cir. 2016) (collection/disclosure of personal information about children can constitute concrete injury)
- In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589 (9th Cir. 2020) (longitudinal tracking of users’ likes/habits without control can support standing)
- Lujan v. Defenders of Wildlife, 504 U.S. 555 (1992) (standing doctrinal basics: injury‑in‑fact, causation, redressability)
- Town of Chester, N.Y. v. Laroe Estates, Inc., 581 U.S. 433 (2017) (standing is assessed individually for each claim and form of relief)
- McNair v. Synapse Group, Inc., 672 F.3d 213 (3d Cir. 2012) (named plaintiffs aware of past conduct lack standing for injunctive relief when future deception is unlikely)
- In re Johnson & Johnson Talcum Powder Litigation, 903 F.3d 278 (3d Cir. 2018) (awareness of alleged risk undermines standing for injunctive relief)
