This alert serves as a follow-up to prior alerts regarding class actions filed under state wiretap laws.
Massachusetts is one of several states, including Pennsylvania and California, where plaintiffs have filed numerous class actions via decades-old wiretap laws. These lawsuits allege that businesses who use, and companies that provide, website tracking code, such as analytics and pixels, which share personal, sensitive, or protected health information are ‘intercepting communications’ in violation of such laws.
These cases, as discussed in prior articles, are extremely dangerous for defendants because most state wiretap laws provide a private civil remedy to those aggrieved under the statute, as well as statutory damages ranging up to thousands of dollars per violation multiplied by the theoretical number of class members – which can quickly add up to millions of dollars in potential penalties and damages.
Last month, the highest court in Massachusetts ruled in Vita v. New England Baptist Hospital et al that website tracking code enabling the sharing of personal data from web visitors to advertising and analytics companies, without the web visitor’s knowledge, categorically does not violate the Commonwealth’s Wiretap act.
This decision is significant for wiretap cases because it involves the sharing of patient health data via analytics and pixels—a fact pattern that presents arguably the most serious subject matter among these class actions compared to ordinary retailers sharing information about customers’ views and purchases of items of general merchandise. In other words, the sharing of patient health data through website tracking code appears to be the most acute and impactful form of website tracking class action litigation.
The court’s majority held that the Massachusetts criminal wiretap statute, written over 50 years ago to address surreptitious eavesdropping or recording of conversations, was not intended to apply to communications between a website visitor and the website itself or third-party websites. Instead, the law was specifically enacted to prohibit the recording of person-to-person communications.
This case raises the ongoing issue of whether criminal statutes written decades before the development of modern internet technology should apply to activity that legislatures could not have foreseen.
Courts in other jurisdictions are divided on whether a person-to-website communication is a “communication” for purposes of their own Wiretap act.
The opinion in Vita was not without dissent. One judge summarized the majority’s opinion as a mistake that only the legislature can now correct. Although the majority dismissed the claims and held that the company’s use of analytics on the website did not fit squarely within the four corners of the wiretap statute, the court was sympathetic to the Plaintiffs’ claims and suggested that while the surreptitious sharing of personal data may not violate the wiretap, it may be in violation of other laws that protect the privacy of individuals’ information.
Companies should remain vigilant and aware of the constant moving target and novel permutations of class action lawsuits related to the use of analytics and tracking technologies. At the very least, business’ compliance, information technology, marketing, and legal departments should all be on the same page and have a clear understanding of how the business’ website utilizes pixel, cookie and analytics technology and how it affects their customers’, clients’ and visitors’ personal data. Although the future of these cases is uncertain, clear steps can be taken to mitigate your business’ exposure to these lawsuits.
For assistance with complying with CIPA or other privacy/wiretap related law, please contact James K. Paulick at jpaulick@leechtishman.com or 424.738.4400 for an initial consultation. Jim is Counsel with Leech Tishman and a member of the Corporate Group, where he leads the Data Privacy & Cybersecurity Group.