tracking pixels CIPA online privacy email tracking surveillance encryption news

Are Tracking Pixels Illegal? Courts Spent All of 2026 Fighting About It. Here Is What They Actually Do to You.

Adrian Maverick · · 6 min read

If you followed privacy news this year, you saw the same headline over and over. Tracking pixels are illegal. Courts are cracking down. Meta and Google are in trouble.

The reality is messier, and honestly more interesting. California courts spent all of 2026 disagreeing with each other about whether a tracking pixel counts as an illegal wiretap. Some judges said yes. Others said no. Nobody won cleanly. But while the lawyers argue over a 1980s surveillance law, one thing never came up for debate: what the pixel actually does. Let me walk through both.

What actually happened

The fight is over a part of the California Invasion of Privacy Act, or CIPA, that bans "pen registers." A pen register is old surveillance language. It originally meant a device that records the numbers dialed from a phone. Plaintiffs argue that a tracking pixel does the modern equivalent: it records who you are and where you go online, then reports it to a third party.

Through 2026, courts split hard on whether that argument holds.

On one side, the claims kept surviving. In Ortiz v. Foris Dax, decided May 21, a federal court ran one of the most thorough analyses yet and concluded CIPA's pen register rule does reach internet tracking. In Garcia v. Anschutz Entertainment Group on May 5, the pen register claim was allowed to move forward. In Krzyzek v. OpenX, a Northern District of California court refused to throw out claims under CIPA wiretapping, the pen register provision, and the federal wiretap statute all at once.

On the other side, defendants kept winning too. On April 27, a court dismissed all CIPA claims against Bosley with prejudice. On May 13, news broke that a Northern District of California court had tossed a pen register claim against Meta, ruling the plaintiffs had not shown how the tracking fit the statute's language about "dialing, routing, addressing or signaling." On May 27, another judge ruled the pen register rules only ever applied to telephones, not to software on a website.

So the honest answer to "are tracking pixels illegal" is: it depends on the courtroom, and the law is still being fought out. What is not in doubt is that the trackers are real and everywhere. The Los Angeles Times settled a pixel case for 3.85 million dollars, with final approval on June 26, over three trackers running on its site and apps. CIPA allows statutory damages of 5,000 dollars per violation with no proof of harm required, which is why these cases keep coming.

What the headlines got wrong

Here is the part almost nobody said out loud. The entire legal fight is about a technicality. Does a surveillance law written for phone lines stretch to cover web trackers? That is the whole argument.

Notice what is not being argued. Nobody in these cases is claiming the pixels do not record you. No defendant stood up and said their tracker collects nothing. The data collection is a given. The only open question is whether an old statute happens to reach it. That should tell you something. The surveillance is so normal that its own defenders take it as background.

How do tracking pixels actually work

A tracking pixel is a tiny piece of code, often a transparent one by one image you will never see. When a page or an email loads it, your device quietly reaches out to a third party server to fetch it. That request alone hands over a surprising amount: your IP address, which points at your rough location and internet provider, your device and browser details, and the fact that you loaded this exact page or opened this exact email at this exact moment.

Multiply that by every site and every marketing email you touch. The same handful of companies have pixels on huge swaths of the web, so they can stitch those pings together into a trail. Page by page, email by email, they build a map of what you read, what you buy, and when you are awake.

Email is the sharpest example. When a sender embeds a tracking pixel in a message, opening that email fires the request automatically. The sender learns you opened it, roughly where you were, and what device you used. You never clicked a thing. Loading the message was enough.

What you can actually do about it

You do not need to wait for a court to settle this. You can turn most of it off yourself.

For email, the single highest impact move is to stop images from loading automatically. A tracking pixel is just a remote image, so if remote images do not load without your say-so, the pixel never fires and the sender learns nothing. Most serious privacy focused mail services block or proxy remote content by default for exactly this reason. At Secria we treat that as table stakes rather than a setting you have to go dig for. Whatever you use, find that option and turn it on.

For browsing, a good content blocker like uBlock Origin stops a large share of known trackers before they load. Privacy focused browsers that block third party tracking by default do similar work without setup. And clearing or partitioning cookies limits how well those separate pings get linked back to you.

None of this is exotic. It is a few settings and one extension. The gap between a tracked life and a mostly untracked one is smaller than the industry wants you to believe.

The bigger picture

Step back and the lawsuits look less like a crackdown and more like society slowly noticing something that has been standard for a decade. The tracking pixel is the surveillance business model made visible. It is small and invisible precisely so you never think about it.

The courts will keep going back and forth, because they are trying to fit a phone era law onto a web era machine. That could take years. Your inbox and your browser do not have to wait for them. The tools to opt out already exist, and they work today.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.