Wiretap claims arising from cross-border transfers of website user data
July 23, 2026
Wiretap claims arising from cross-border transfers of website user dataJuly 23, 2026 On June 16, 2026, the US District Court for the Northern District of Illinois denied a motion to dismiss a putative class action complaint alleging violations of the federal Wiretap Act, where the plaintiff’s claim was premised on an alleged violation of the US Department of Justice’s (DOJ) Bulk Data Rule (Rule). We have previously written on the proliferation of wiretapping claims and how companies can better defend themselves, but this development is particularly noteworthy.1 In a first-of-its-kind decision, the court in Baker v. Index Exchange, Inc., Case No. 1:25‑cv‑10517, 2026 WL 1734901 (N.D. Ill. June 16, 2026), accepted the plaintiff’s theory that a violation of the Rule can satisfy the federal Wiretap Act’s crime/tort exception to the one-party consent rule. Accordingly, the defendant’s purported use of tracking software on a website to intercept user data and share it with a foreign advertiser could give rise to a private cause of action and, with it, statutory damages on behalf of a class. This decision is likely to embolden the privacy class action plaintiffs’ bar, which is already active in pursuing state-level claims arising from website data-sharing practices. Bulk Data RuleExecutive Order 14117 (February 2024), issued under the International Emergency Economic Powers Act, directed the DOJ to issue regulations preventing “countries of concern” from accessing Americans’ sensitive personal data. On April 8, 2025, the DOJ issued the final Bulk Data Rule.2 Under the Rule, US persons are prohibited from knowingly engaging in covered data transactions that give “countries of concern”3 or “covered persons” tied to those countries access to bulk US sensitive personal data or US government-related data. Data brokerage transactions with covered persons/countries of concern are flatly prohibited. Vendor, employment, and investment agreements are permitted only if certain cybersecurity and compliance requirements are met. Notably, the Rule carries criminal and civil penalties for violations but does not provide for a private cause of action. Federal Wiretap ActThe federal Wiretap Act makes it unlawful to intentionally intercept “any wire, oral, or electronic communication.”4 Importantly, the Wiretap Act contains a one-party consent exemption: An interception is not unlawful if one party consents to the disclosure. This exemption has been an effective defense for websites sharing user data derived from communications between a user and the website itself under the theory that the website provides the one-party consent. Under the crime/tort exception to this exemption, however, the one-party consent rule does not apply. If a communication is intercepted “for the purpose of committing any criminal or tortious act,” the one-party consent is not a defense. If the crime/tort exception applies, then both parties to the communication must consent to the interception. Some courts have found that the crime/tort exception can apply when an entity allegedly violates the Health Insurance Portability and Accountability Act or commits a common law tort. Other courts have found that the crime/tort exception does not extend to violations of other statutes, such as certain provisions of the Gramm-Leach-Bliley Act, where the alleged violation does not carry criminal penalties and does not have a private right of action. The Wiretap Act provides for statutory damages of up to $100 for each day of a violation or $10,000, whichever is greater.5 Such statutory damages could quickly multiply and expose companies to liabilities amounting to hundreds of millions of dollars or more in the context of a nationwide class action. Baker v. Index Exchange, Inc.In Baker, the plaintiff alleges that a website used the defendant’s tracking software to intercept user data and transmit it to advertising partners, including a US subsidiary of a Chinese e-commerce company. The tracking software allegedly collects information such as users’ IP address, cookie and advertising identifiers, device data, and inferred demographic and behavioral data. The plaintiff, on behalf of a proposed class, alleges that advertisers then use the data through a real-time bidding platform to bid on the right to place ads for the website user. Advertisers also used the data through a process called “cookie syncing,” allowing the advertisers to track users across multiple websites and tailor ads targeting the user. The plaintiff alleges that the tracking software constituted an illegal wiretap in violation of the federal Wiretap Act. The defendant moved to dismiss, arguing that the website, as a party to the allegedly intercepted communications, consented thereto, so the one-party consent exemption precluded the claim. In denying the motion to dismiss, the Northern District of Illinois held that the plaintiff plausibly alleged that the crime/tort exception applied. The court reasoned that the alleged transfer to a Chinese company constituted a violation of the Rule, which in turn constitutes a tortious act within the meaning of the exception. TakeawayThe Baker decision supports a litigation theory that plaintiffs across the country are likely to replicate. It gives plaintiffs a potentially actionable theory to sue website operators and ad-tech providers for the use of common tracking software where user data is purportedly shared with companies in China or other countries of concern. Without sufficient controls, website operators and ad-tech companies may risk significant exposure under this theory. In light of this decision, businesses may consider assessing whether their website user data collection procedures are compliant with the Rule. This could include assessing whether direct or indirect recipients of their user data are organized in, or majority-owned by, a country of concern and auditing data brokers and other data vendor relationships to ensure downstream compliance. More broadly, the Rule’s obligations are not limited to ad-tech or wiretap-adjacent conduct; any US company with cross-border data sharing arrangements (e.g., vendor agreements, cloud storage, offshoring, joint ventures) may be subject to the Rule’s prohibitions and restrictions. Many businesses are finding out the hard way that pixels and other tracking technologies are getting through their consent management platforms, leading to wiretapping claims under similar state-level statutes, such as those in California, Florida, Michigan, and Pennsylvania. Proactive steps to mitigate this risk could include:
__________ If you have any questions about this Legal Briefing, please feel free to contact any of the attorneys listed or the Eversheds Sutherland attorney with whom you regularly work. 1 See, e.g., Wiretapping litigation shows no signs of slowing in California and Florida (Feb. 2, 2026); Eight-figure CIPA settlement underscores importance of telemarketing compliance (June 2, 2025). Key contacts
Michael Bahar Partner Washington, DC, United States Francis X. Nolan IV Partner New York, United States Alexander Bussey Senior Associate New York, United States Jonathan Freimann Senior Associate Washington, DC, United States Rebekah Whittington O'Brien Associate Atlanta, United States Claire E. Scavone Associate Atlanta, United States Latest Insights
Latest News
Latest Events
legal updates July 23, 2026 AI Governance Bill: Malaysia’s Next Step Towards the First AI Rulebook legal updates July 22, 2026 Commercially Connected shorts - 22 July 2026 legal updates July 20, 2026 Industrials Unpacked #1: Supply Chain Contracts legal updates July 17, 2026 EU MISP reforms: ESMA to supervise more firms firm news July 10, 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... client news July 10, 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... client news July 09, 2026 Eversheds Sutherland advises Costello Medical on transition to employee own... client news July 02, 2026 We acted as legal counsel in Digitalist Group's convertible bond restructur... virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States |