The Los Angeles data privacy lawyers with Tauler Smith LLP recently secured another pre-trial win in an important case: Swinerton Construction accused of tracking website visitors by secretly installing LinkedIn software. The national commercial construction company allegedly used tracking technology to surveil website visitors, collect their online data, and then share the data with LinkedIn. A lawsuit was filed in state court because these actions constitute very serious violations of California’s consumer-friendly data privacy laws, including the California Invasion of Privacy Act (CIPA) and the California Trap and Trace Law.
To learn more about the CIPA lawsuit against Swinerton, keep reading.
Data Privacy Lawsuit: Construction Company Swinerton Sued in Orange County Superior Court
The defendant in the data privacy case is Swinerton, Inc., a national commercial construction company. Swinerton operates a website, www.swinerton.com, that provides information about the company’s construction projects and the services they offer. Swinerton was accused of violating California’s online privacy laws by spying on website visitors and collecting their personal information without permission.
The case, Blalock v. Swinerton Incorporated, was filed in the Superior Court of California, County of Orange. Now the case could be headed to trial after the court issued a minute order, which briefly summarized the judge’s decision in advance of a formal order and rejected the defendant’s attempt to dismiss.
California’s Trap and Trace Law Prohibits Companies from Using Internet Tracking Tools Without Consent
The data privacy case concerns California’s Trap and Trace Law, which is part of the California Invasion of Privacy Act (CIPA) and is codified at Cal. Penal Code § 638. The consumer privacy law prohibits website operators from utilizing tracking pixels to monitor site visitors and collect their data, declaring that “a person may not install or use a pen register or a trap and trace device without first obtaining a court order pursuant to the law.”
CIPA offers legal definitions of both pen registers and trap & trace devices:
- Pen Registers: Section 638.50(b) of the statute defines a pen register as “a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted.”
- Trap & Trace Devices: Section 638.50(c) defines a trap & trace device as “a device or process that captures the incoming electronic or other impulses that identify the originating number or other dialing, routing, addressing, or signaling information reasonably likely to identify the source of a wire or electronic communication.”
Lawsuit: Swinerton Violated the California Invasion of Privacy Act (CIPA)
The lawsuit against Swinerton specifically alleges that the defendant violated California’s Invasion of Privacy Act (CIPA) by installing and operating LinkedIn Software on its website to capture and transmit data from site visitors. Additionally, the tracking software allegedly allows the defendant to identify anyone who visits the website.
Swinerton is accused of invading the legally protected privacy rights of website visitors by collecting their personal identifying information without permission. Furthermore, the plaintiff alleges that the defendant uses this stolen data to create detailed behavioral profiles of website visitors.
In the data privacy lawsuit against Swinerton, the plaintiff argues that he suffered significant injury due to the theft of his extremely valuable personal data. Additionally, the plaintiff alleges that the defendant’s secret monitoring of his internet activity had a chilling effect on his free expression online.
California Court Rejects Demurrer Motion to Dismiss Data Protection Lawsuit Against Swinerton
The defendant attempted to get the data protection lawsuit dismissed by filing a demurrer. Swinerton argued that the case should not proceed further because the plaintiff failed to state a valid cause of action that could be remedied by the law. However, the court rejected the demurrer and ruled that the plaintiff did, in fact, allege sufficient facts to state a claim pursuant to Cal. Penal Code Section 638.51, also known as California’s Trap & Trace Law.
Court: Plaintiff Has Standing to Sue Swinerton for Online Surveillance of Customers
The defendant’s demurrer argued that the plaintiff lacked standing to sue because he failed to allege an injury required for a lawsuit under the California Invasion of Privacy Act (CIPA). The defendant contended that there can be no reasonable expectation of privacy for anyone who visits a commercial website. As legal precedent, the defendant tried to rely on a criminal case where a California appellate court held that a subscriber has no expectation of privacy in the subscriber information they supply to an internet provider. However, the Orange County Superior Court rejected that case law because it was limited to criminal matters involving a warrant, which is not at all similar to the Swinerton case that concerns the tracking of commercial website visitors and the unauthorized transmission of their data to third parties.
Instead, the California state court highlighted a federal court decision in another data privacy lawsuit. That case, Hassid v. Alex and Ani, LLC, involved a national jewelry retailer installing TikTok tracking software on its website to collect customers’ identifying information without consent. The online privacy lawyers with Tauler Smith LLP also represented the plaintiff in that case and successfully argued that the use of these kinds of online tracking technologies could constitute a violation of CIPA. The court in Alex and Ani agreed and held that the “right to privacy encompasses the individual’s control of information concerning his or her person.”
In the recent lawsuit against Swinerton, the court found that the plaintiff also sufficiently established standing to sue because visitors of commercial websites have a reasonable expectation of privacy. This is particularly true when the website operator has not obtained consent to track users, collect their browsing data, and transmit their identifying information to social media platforms, data brokers, and other third parties.
California Invasion of Privacy Act (CIPA) Applies to Website Communications
The defendant in Blalock v. Swinerton also attempted to get the case dismissed by arguing that California’s Trap & Trace Law only applies to telephone communications, not website communications. The court strongly disagreed.
The court noted that the defendant relied on outdated case law from as far back as 1948, which simply isn’t applicable to a modern world with a surveillance economy that relies on computers, Artificial Intelligence (AI), and the internet.
The court also pointed to several other lawsuits where courts held that the California Invasion of Privacy Act (CIPA) broadly applies to more than just telephones. In Hassid v. Alex and Ani, for instance, the U.S. District Court for the Central District of California said that the statute applies to website operators. That court also ruled that the Trap & Trace Law can be the basis for liability even when there are no actual online communications; it’s enough for the plaintiff to show that the defendant embedded website tracking tools to collect consumer data without permission.
Contact the Los Angeles Data Privacy Attorneys at Tauler Smith LLP
California has some of the strongest consumer protection laws in the country, including data privacy laws that shield residents against unauthorized tracking online. If you live in California and you visited a retail or commercial website, it’s possible that your personal information was collected without your knowledge and then shared with third parties. As a result, you may be eligible to file a lawsuit for financial compensation.
The experienced Los Angeles consumer protection lawyers at Tauler Smith LLP can help you. Call or email us to schedule a free consultation.