Pixel litigation

Know your pixel exposure before plaintiffs do

Wiretapping claims under the California Invasion of Privacy Act (CIPA) and the federal ECPA target tracking pixels and session replay that capture user activity without valid consent.

What plaintiffs look for

Most complaints say a third-party pixel intercepted communications: page URLs, search terms, form fields, or purchase details. The pixel sent them to an ad platform before consent, or despite a refusal.

How the Privacy Pentest tests it

  • Runs real journeys on your site, such as reading an article, viewing a product, or starting checkout.
  • Repeats each journey after rejecting cookies, after accepting, and with Global Privacy Control.
  • Records every request and identifies pixels, the parameters they carry, and whether consent changed their behaviour.

What you get

For each test you get findings with severity, the applicable laws, and supporting evidence (screenshots, network traffic, cookies, action logs). The report also gives remediation steps you can hand to engineering.

Run a Privacy Pentest on your site