NFL.com CIPA Lawsuit: When Opting Out Doesn't Stop Tracking — How to Make Opt-Outs Actually Work

UniConsent Team

6 min read
Add UniConsent as a preferred source on Google
Table of contents

NFL Enterprises LLC, the operator of NFL.com, is the latest household name to face a wiretapping class action in California. The complaint, Kimmons v. NFL Enterprises LLC, No. 26CV197596, was filed in Alameda County Superior Court on July 6, 2026, on behalf of a proposed nationwide class and a California subclass.

The plaintiff is a San Francisco 49ers fan from San Leandro who says she visited NFL.com in January 2026 to check scores and game schedules. She alleges that trackers operated by Google, The Trade Desk, Rubicon Project, OpenX, LogRocket, and Shape Security loaded in her browser as soon as the page did, and that the site fingerprinted her device, recorded her session, and passed her browsing data to advertising networks before she had made any privacy choice at all.

NFL.com CIPA Lawsuit: When Opting Out Doesn't Stop TrackingNFL.com CIPA Lawsuit: When Opting Out Doesn't Stop Tracking

An Opt-Out That Changed Nothing

NFL.com has a cookie consent banner, and the complaint engages with it directly. That is the part worth paying attention to.

Forensic testing cited in the complaint counted 182 third-party trackers running before any consent interaction: 24 cookies, four canvas fingerprinting scripts, and one session recorder. After a visitor declines cookies through the banner, the same testing counted 186 trackers, now with 25 cookies, alongside the same fingerprinting scripts and the same session recorder. On these numbers, declining tracking left a visitor slightly worse off than doing nothing.

The complaint says the banner gives visitors a "false and misleading sense of security," and its two reasons are both about how the site is wired rather than what the banner says. Tags fired on page load, so tracking was already underway before anyone could answer the banner. And the banner governed only cookies, so tools that never needed cookies in the first place kept running regardless of the visitor's choice.

Neither problem is exotic. Firing on page load is the default in most tag manager setups, and very few cookie banners were ever connected to session replay or fingerprinting scripts. The Kimmons complaint simply measured that gap on a famous website and attached statutory damages to it.

What the Trackers Allegedly Collected

The session recorder, supplied by LogRocket according to the complaint, captured the full Document Object Model state of each page along with enough interaction data to reconstruct the visit visually: mouse movements, clicks and their coordinates, hover events, scrolling, navigation paths, and keystrokes typed into search bars and other input fields. The keystroke logging allegedly included the order and timing of individual keys, whether or not the visitor ever submitted what they typed.

The fingerprinting allegations go into more technical depth than most CIPA filings have. Four separate canvas fingerprinting scripts allegedly ran on the site, three loaded through Google Tag Manager and one through Shape Security. Each collected font rendering, geometry rendering, and data URL signals, which combine into a device-specific signature derived from the GPU, graphics drivers, installed font library, and browser rendering engine. Three of the scripts were tied to Google Ads and Campaign Manager accounts, which the complaint reads as evidence that the fingerprints fed cross-site advertising attribution. A fingerprint survives a cleared cookie jar; that is the point of using one.

The Claims and the Exposure

The complaint pleads five causes of action. Under CIPA Section 631(a), California's wiretapping provision, it alleges the trackers intercepted the contents of the plaintiff's communications with the site in transit, relying on Mikulsky v. Bloomingdale's, LLC (9th Cir. 2025) for the position that session recording captures "contents," and on Smith v. Rack Room Shoes and Ambriz v. Google to argue the vendors acted as third-party interceptors rather than extensions of the website. Under Section 638.51(a), following Greenley v. Kochava, it alleges each tracker functions as a pen register by recording routing, addressing, and signaling information, including IP addresses, without consent or a court order. The remaining counts arise under the federal Wiretap Act (ECPA), the California Computer Data Access and Fraud Act, the privacy clause of the California Constitution, and the state's Unfair Competition Law.

The damages arithmetic explains why plaintiffs keep filing these cases. CIPA Section 637.2 sets statutory damages at $5,000 per violation with no requirement to prove actual harm, and the ECPA count adds the greater of $100 per day per violation or $10,000. Applied across the traffic of one of the most visited sports websites in the country, the theoretical figure becomes very large very quickly. European Wax Center settled for $5 million over a far smaller tag stack and far less traffic.

The usual caveat applies. These are allegations, the NFL has not yet responded, and whether the banner covered the challenged technologies or valid consent existed through some other route will be argued. But the theories themselves are the same ones that have been surviving motions to dismiss throughout the current wave of CIPA pre-consent tracking litigation.

Everything the plaintiff needed came from scanning the site. Whether trackers fire before consent, and whether an opt-out actually suppresses the session recorder, are not legal questions. They are testable facts about tag configuration, and any operator can run the same test the plaintiff did.

That is also why the fix is architectural rather than cosmetic. A consent management platform has to stand in front of every third-party technology on the page, not only the ones that set cookies. UniConsent's tag gating holds back pixels, session recorders, and fingerprinting scripts loaded through tag managers until the visitor's consent state is resolved, so nothing executes pre-consent. When a visitor opts out, the suppression covers cookieless tools as well, and the choice propagates to downstream vendors through Google Consent Mode and the IAB frameworks, with Global Privacy Control support for California opt-outs.

The remaining piece is proof. UniConsent's website scanning shows what actually fires before and after each consent choice, and the consent audit trail keeps the records demonstrating that the banner does what it promises. Running that test on your own site is inexpensive. Learning the answer from a complaint filed in Alameda County is not.

Activate Google Consent Mode UniConsent to enhance the accuracy of your Google Analytics and Google Ads conversion data.

Set up Google Consent Mode →

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up