Attorneys with Los Angeles consumer protection law firm Tauler Smith LLP recently secured a potentially precedent-setting judgment in a digital privacy case: Tauler Smith wins data privacy lawsuit against Peer39. U.S.-based digital advertising company Peer39 was sued in a California court for allegedly collecting customers’ personal information without permission and then selling it to data brokers. This constituted a clear violation of the California Comprehensive Data Access and Fraud Act (CDAFA), which explicitly protects individuals against the unauthorized use of their personal information online. A judge has now issued a ruling in the case, granting both monetary damages and injunctive relief to the plaintiff.
To learn more about Tauler Smith’s latest legal victory in a major data privacy lawsuit, keep reading.
Peer39 Sued in L.A. County Superior Court for Collecting and Sharing Customer Data Without Consent
Cammorata v. P39 Tech LLC is a data privacy lawsuit that was filed in the Ventura County Superior Court before being moved to the Los Angeles County Superior Court.
The defendant in the case is P39 Tech LLC, more commonly known as Peer39: a contextual data platform that provides advertisers with valuable consumer information. This information is used by advertisers, including registered data brokers, to create targeted ad campaigns. The plaintiff in the case is a California resident who visited the Peer39 website at https://www.peer39.com. She was represented in the civil suit by the highly respected California data privacy lawyers with Tauler Smith LLP.
According to the complaint filed by the Tauler Smith litigation team, Peer39 engaged in unlawful surveillance of website visitors and committed multiple violations of the California Comprehensive Data Access and Fraud Act (CDAFA). The lawsuit sought compensatory damages.
Lawsuit: Peer39 Website Continued to Collect Customer Data After Opt-Out
The data privacy lawsuit alleged that Peer39’s website presented site visitors with a consent banner but then ignored visitors’ choices to decline tracking. In fact, an expert witness in the case concluded that a website visitor’s decision to decline consent to be tracked on the site “had no observable effect on third-party data flows.”
Beyond that, site visitors’ device-, browser-, and network-identifying information was allegedly sent by Peer39 to dozens of third-party advertising, tracking, and identity-resolution services. For example, the expert witness found that Peer39 engaged in page-by-page surveillance of website visitors and then transmitted every page view to third parties that included Facebook, Google, LinkedIn, and TikTok. Also prominent among these third parties were LiveRamp and The Trade Desk, both registered data brokers that buy and sell consumers’ personal information for the purpose of targeted advertising.
Additionally, third-party data brokers were allegedly allowed to add “cookies” to the computers of Peer39 website visitors. These small data files then tracked the visitors’ online behavior
Expert Witness: Peer39 Website’s Cookie Consent Banner Was Ineffective
The Peer39 website displayed a cookie-consent banner on screen when a visitor landed on the site. The consent banner offered the visitor a choice: accept or decline tracking. According to an expert witness in the case, it was not possible for users to opt out of tracking because the consent banner was ineffective: tracking began within one to three seconds of the page loading, before the consent banner had even been interacted with. Additionally, the expert found that Peer39 utilized tracking technology – including tracking pixels and website cookies – to collect a site visitor’s personally identifiable information even after the visitor explicitly rejected data collection via the consent banner.
Lawsuit: Peer39 Stored Third-Party “Cookies” on Website Visitors’ Devices to Track Users and Accumulate Data
What are third-party cookies? Third-party cookies are small text files stored directly on a user’s device or browser. These cookies allow different companies to recognize and track website visitors when they later visit different websites.
The Peer39 website allegedly caused tracking code with unique-identifier cookies from several third parties to execute in the visitor’s browser as soon as the visitor landed on the site. These third parties included Facebook (Meta), Google, HubSpot, LinkedIn, Reddit, and TikTok. Peer39 was also accused of sharing data with The Trade Desk, a data broker company headquartered in California. When a person visited the Peer39 website, The Trade Desk allegedly employed a cookie-synchronization chain to transmit the user’s data to the data broker.
The third parties that continued to track Peer39 website visitors did so with browser cookies that were not scheduled to expire for up to two years.
What Is the California Comprehensive Computer Data and Access Fraud Act (CDAFA)?
The California Comprehensive Computer Data and Access Fraud Act (CDAFA) is codified in Cal. Penal Code § 502. The law stipulates that anyone who “knowingly accesses and without permission takes, copies, or makes use of any data from a computer” may be sued for damages in a civil action.
In a CDAFA claim, the plaintiff must show that they suffered an economic injury because of a statutory violation. In the Peer39 data privacy lawsuit, the plaintiff alleged that Peer39 unjustly profited by using website tracking tools to monitor her online activity without consent and then sold her personal information to data brokers. This alleged violation of the CDAFA was even more egregious because the company explicitly told website visitors that they would not collect their data after the visitors opted out.
Damages and Remedies in a CDAFA Claim
The California Comprehensive Computer Data and Access Fraud Act (CDAFA) allows plaintiffs to sue for the economic harm they suffered when their personal information was collected and/or sold to third parties. In other words, an individual can seek compensatory damages equaling the value of the data collected without their consent.
The CDAFA also allows for damages through disgorgement: a defendant found liable for violating the statute could be required to give up any profits derived from the unlawful collection and sharing of consumer data. In Smith v. Rack Room Shoes, Inc., the California Northern District Court went further by declaring that the plaintiff in a CDAFA claim may be entitled to damages even when there was no direct financial harm.
Judgment Issued Against Peer39 for Multiple Violations of California Data Privacy Law
The Los Angeles Superior Court judge presiding over the Peer39 online privacy case recently ruled in favor of the plaintiff when the defendant failed to respond to the lawsuit. The default judgment awards statutory damages and injunctive relief to the plaintiff. This includes an order enjoining Peer39 from using the Data Broker Software on its website in the future, as well as disgorging the plaintiff’s data that was provided to the Peer39 website and to data brokers through the tracking software.
This was an excellent outcome for the plaintiff and yet another major courtroom victory for the Tauler Smith LLP law firm. Our California data privacy lawyers continue to win case after case for clients whose online activity was tracked without consent.
What Is the Market Value of Customer Data Collected by Peer39?
One of the key questions in the Peer39 data privacy lawsuit was: How much is website visitor data worth?
The high-value data sold by Peer39 comes from the company’s content database, which encompasses 4300 categories and fulfills 400 billion daily bid requests by data brokers and third-party companies. It is marketed as the largest set of data available on the marketplace, which makes it extremely valuable to advertisers looking to scale their digital ad performance campaigns.
Additionally, the comprehensive user data sold by Peer39 is granular and specific, which allows advertisers to consider users’ online activity, broader interests, and their location when creating targeted ad campaigns. This can be used to build an assembled user profile: a dossier that identifies a specific person and follows them from website to website.
The expert witness in the Peer39 data privacy lawsuit closely examined the marketplace for the types of customer data shared by Peer39, including published market pricing. He determined that the data allegedly collected and shared by Peer39 with data broker companies has a value of $100-$250 per user. When considering the massive number of people whose online activity has been tracked by Peer39, the potential damages in a class action lawsuit could be staggering.
Contact the Los Angeles Data Privacy Lawyers at Tauler Smith LLP
Do you live in California? Did you visit the Peer39 website, or any other website with a cookie consent banner? If so, it’s possible that your online activity was tracked without consent and unlawfully shared with data brokers. The Los Angeles consumer protection attorneys at Tauler Smith LLP have extensive experience representing plaintiffs in data privacy lawsuits. We can help you protect your personal information and get financial compensation.