Don't get caught with your hand in the cookie jar

California Invasion of Privacy Act (CIPA) filings targeting pixel tracking have surged - what brokers need to know before their clients become the next defendant

Don't get caught with your hand in the cookie jar

Insurance News

By Emily Douglas

Cookies, pixels and other tracking technologies have become a standard part of the modern digital experience. From measuring advertising performance to understanding customer behaviour, they help organizations optimize websites, personalize content, and improve marketing outcomes.

The same technologies that power digital business are increasingly driving privacy litigation, exposing organizations to risks that many never anticipated. Anything from an insufficient cookie notice to a website search bar linked to analytics can give rise to a claim carrying $5,000 in statutory damages per violation, and despite ongoing legislative efforts, no safe harbor currently exists.

The history of tracking technology litigation has been marked by constant change. What began with mass arbitration demands targeting website chat tools quickly shifted to lawsuits involving the Meta Pixel and other tracking technologies. Today, the focus has largely moved again, with plaintiffs increasingly alleging that tracking technologies are activated before users have the opportunity to consent.

In a recent interview with Insurance Business, Quinn Barbeito, underwriter of cyber and technology E&O at Munich Re Specialty – North America, explained how this digital shift has changed the way privacy risk is assessed, with underwriters no longer looking solely at whether a company has a privacy policy. Instead, underwriting teams are assessing how tracking technologies are deployed, adherence to regulatory laws, and ultimately how any third-party vendors handle that information.

No clear picture: The visibility gap with third-party vendors

“There is a visibility gap at the center of how we think about this [kind of] risk,” added Barbeito. “Tracking technologies have become ubiquitous, and the class action wave targeting them shows no signs of slowing down. The challenge isn't just about what data organizations are collecting, it's that many do not have a clear picture of what their third-party vendors are collecting on their behalf, or where that data ends up.”

What has made this more pressing from an underwriting standpoint is the modern litigation environment. As Barbeito told IB, organizations tend to feel reasonably protected when they have a privacy policy and opt-out mechanisms in place, and in many cases they are from a regulatory compliance perspective. However, the current wave of litigation is operating under a different legal theory, largely centered on wiretap statutes like CIPA, which focus on whether user communications are being intercepted in real time.

“These wiretap statutes apply regardless of whether a privacy policy exists,” added Barbeito. “[As such], when we're underwriting these risks today, we’re leveraging technology to identify whether organizations are utilizing tracking technologies and asking pertinent questions with respect to obtaining proper consent, as well as meeting disclosure requirements under applicable regulations.

“For insureds who want to get ahead of this, Munich Re Specialty is launching a complimentary service through our Reflex™ Cyber Risk Management program, specifically designed to help organizations understand what tracking technologies they're running, where their gaps are and recommended best practices. Because the best outcome for everyone is addressing this before a claim.”

‘Having a privacy policy and opt-out rights in place is a baseline’

When it comes to assessing risk, there’s a danger that many organizations are seriously underestimating the threat levels. While regulatory compliance is essential, some firms mistakenly believe that that’s the finish line. An assumption that could be costly.

“Having a privacy policy and opt-out rights in place is a baseline, and it does matter, but it does not insulate an organization from the class action exposure that's been driving most of the pixel tracking litigation,” added Barbeito. “Those cases are being brought under different legal frameworks, and a compliant privacy policy does not necessarily address them.”

Exposure more widespread than organizations realize

In today's digitized age, pixel tracking litigation is heating up across a range of industries. As this trend has continued to impact organizations, it has simultaneously revealed some common exposure points and subsequently changed the way underwriters approach these nuanced risks.

“The litigation trend has clarified that this exposure is about how user interactions are being captured and shared in real time through these tracking tools, and whether that constitutes unauthorized interception under applicable statutes,” said Barbeito.

According to a March 2024 report, nearly half of all websites deploy Meta Pixel, including 55% of S&P 500 companies and 58% of retailers. That essentially means that the exposure here is much more widespread than most organizations realize.

“The organizations drawing the most scrutiny tend to share a few characteristics,” added Barbeito. “[Including] strong Business-to-Consumer (B2C) models, a heavy reliance on digital advertising and targeted marketing, and tracking deployed on sensitive pages, whether that might take the form of checkout flows in account login areas or any page where a user is sharing meaningful personal information. Some organizations may be heavily dependent on digital marketing to the point where implementing a consent management platform and absorbing the resulting impact on online revenue is not a trade-off they're willing to make.”

From an underwriting standpoint, Barbeito told IB that this has pushed underwriters to look more closely at where tracking is deployed on a site, whether consent is obtained before tracking begins, and how heavily the business model relies on behavioral advertising.

The tracking and privacy elements form something of a patchwork. There are so many different agencies out there, all with individual standards, making accounting for all these variables increasingly difficult – especially when they cross into different jurisdictions. As Barbeito told IB, at Munich Re Specialty they approach this by separating regulatory compliance from litigation risk.

Even as theories of liability evolve, certain trends have remained persistent. Pen register claims, alleging the collection of identifying information without consent, continue to drive substantial CIPA litigation, while similar allegations are now emerging in Florida under the Florida Security of Communications Act.

However, efforts are underway to address these trends. The California Senate Bill 690 (SB 690), which would amend the California Invasion of Privacy Act (CIPA) to exempt certain commercial website tracking activities from liability, remains stalled and has not been enacted. Even if ultimately passed, the legislation is not expected to take effect before January 2027 and, in its current form, addresses only a narrow subset of claims involving pen registers.

In the meantime, businesses should not view SB 690 as a reason to delay action. Historically, proposed legislative changes that limit litigation exposure often trigger a surge in lawsuits and demands before the effective date, as plaintiffs seek to preserve claims under the existing legal framework.

If there is one consistent theme in tracking technology litigation, it is that plaintiffs continue to pivot to new legal theories and emerging technologies.

“On the regulatory side, most US state privacy laws operate on a notice and opt-out model,” added Barbeito. “If an organization has a clear privacy policy, a functional opt-out mechanism, and is actually honoring user rights, then they will generally be in a reasonable position from a compliance standpoint. For organizations with meaningful EU exposure, GDPR introduces stricter consent requirements that we factor in.”

Barbeito revealed that he’s also been seeing multiple state-level bills advancing around data transparency and AI usage, an early signal of broader regulatory scrutiny over how companies interact with user data.

“We address this through a strong claims team that stays current on legislative developments that could impact our insured organizations. That being said, the more material underwriting concern in the US right now is the litigation side, specifically statutes like CIPA and similar wiretap frameworks at the state level, which are not traditional privacy regulations but are being used aggressively in pixel tracking cases.”

What data is collected, how is it used, and which third-parties are involved?

For organizations that rely heavily on these third-party tracking tools, there are certain steps leaders can take to drastically reduce any privacy risk exposure. It is important to remember to have privacy disclosures that reflect what is happening, because vague or outdated privacy policies that do not accurately describe tracking practices are a red flag, according to Barbeito.

“Organizations should look at robust and functional consent and opt-out frameworks,” he told IB. “This starts with a formal opt-in / opt-out mechanism that clearly establishes affirmative user consent before any tracking data is collected or used. Just as important here is ensuring users have an ongoing ability to opt-out at any time through a readily accessible, user-friendly mechanism, not just at the initial interaction.”

Equally critical, Barbeito revealed, is what happens after that choice is made. Organizations need to ensure that opting out actually results in full cessation of data collection, including any downstream tracking or sharing with third-party vendors.

“Underwriters are increasingly focused not just on whether these controls exist, but whether they operate effectively and consistently in practice. For governance over third-party tools, organizations should be able to answer basic questions about what pixels or trackers are deployed on their properties, what data those tools collect, and how that data is used or shared by vendors.”

Beyond those fundamentals, Barbeito explained that at Munich Re Specialty, they have seen more organizations implement consent management platforms, particularly where they have significant web traffic or operate across multiple jurisdictions.

“While not strictly required under most state privacy laws, these tools can help operationalize consent, support auditability, and demonstrate a level of maturity that is becoming a meaningful differentiator from a risk profile standpoint,” he added.

‘The direction is becoming clear, even if the exact pace is not’

As litigation continues to evolve and new privacy laws emerge, businesses that understand their digital ecosystem and actively govern the technologies operating within it will be best positioned to navigate an increasingly complex privacy landscape. Looking ahead, Barbeito believes that these litigation and regulatory changes will fundamentally impact the overall underwriting conversations in the months and years to come.

“The direction is becoming clear, even if the exact pace is not,” he told IB. “We're moving from a compliance checkbox conversation to something more substantive, a genuine evaluation of how an organization's tracking practices interact with its litigation exposure, business model and operational controls. There are also a few things that we expect to become more routine [including] more robust tracking-related questions as a standard part of cyber submissions, greater differentiation in pricing and terms based on consent practices and vendor governance, and more explicit policy language around pixel and behavioural tracking whether that's through specific exclusions, supplements, or affirmative coverage grants.”

Barbeito sees the insured-insurer relationship evolving alongside the new legislation and tracking technologies.

“[At Munich Re Specialty], we have taken a position to support our insured organizations with a complimentary service within our Reflex™ Cyber Risk Management program, to help them understand what tracking technologies are being used, offering legal guidance on the regulatory risk associated with those technologies and recommendations for best practices.

“Organizations that are proactively managing their tracking governance are better risks. Because the goals should be helping insureds get ahead of a claim not just pricing for it after the fact.”

Learn more about how Munich Re Specialty – North America’s Reflex™ Cyber Risk Management helps mitigate liability from web tracking technologies and other data collection practices to prevent privacy litigation, contain financial impact, and maintain reputation:

This article was created in partnership with Munich Re Specialty.

Keep up with the latest news and events

Join our mailing list, it’s free!