Summary
The United States District Court for the Northern District of California partially granted and partially denied Rack Room Shoes, Inc.'s motion to dismiss claims arising from alleged third-party interception and use of consumers' electronic communications and personally identifiable information. The court allowed the plaintiffs' Electronic Communications Privacy Act, California Invasion of Privacy Act wiretap-use, and California Comprehensive Computer Data Access and Fraud Act claims to proceed, but dismissed the CIPA wiretap claim based on server-side technology for failure to adequately allege contemporaneous interception. The dismissal was without leave to amend, and a related motion to certify an earlier order for interlocutory appeal was denied as moot.
Holdings
- The Wiretap Act claim was adequately pleaded because the Third Amended Complaint provided sufficient notice of plaintiffs' legal theory and alleged Rack Room's active role in using computer code to intercept and use electronic communications.
- Plaintiffs adequately alleged the interception of content and plausibly alleged that the content was incorporated into consumer profiles received and used by Rack Room.
- Plaintiffs adequately alleged that the crime-or-tort exception applied to the party-to-the-communication exemption, and therefore stated a Wiretap Act claim.
- Plaintiffs adequately pleaded their CDAFA claim, including a theory of secondary liability through California Penal Code section 31.
- Plaintiffs adequately pleaded their CIPA section 631 use claim by alleging intercepted content and its subsequent use.
- The server-side CIPA section 631 claim was inadequately pleaded because the Third Amended Complaint did not allege facts showing that the communications were read, attempted to be read, or learned in transit contemporaneously with their receipt.
- The court declined to decide whether server-side routing occurring after a communication reaches its destination can violate CIPA section 631 when the technology permits real-time eavesdropping.
Questions Presented
- Whether the Wiretap Act claims were adequately pleaded despite plaintiffs' failure to identify the specific statutory subsection allegedly violated.
- Whether the alleged intercepted information constituted content under the Wiretap Act.
- Whether the Wiretap Act's party-to-the-communication exception was defeated by the statutory crime-or-tort exception.
- Whether Rack Room could be liable under CDAFA through California Penal Code section 31.
- Whether plaintiffs adequately pleaded a CIPA section 631 use claim.
- Whether plaintiffs adequately pleaded a CIPA section 631 claim based on server-side tracking technology and interception of communications in transit.
- Whether the case should be dismissed without leave to amend.
Disposition
other
Cases Cited (8)
- Askins v. U.S. Department of Homeland Security, 899 F.3d 1035, 1043 (9th Cir. 2018)(followed)
- Smith v. Rack Room Shoes, Inc., No. 24-cv-06709-RFL, 2025 WL 1085169, at *4-6 (N.D. Cal. Apr. 4, 2025)(followed)
- Smith v. Rack Room Shoes, Inc., No. 24-cv-06709-RFL, 2025 WL 2210002, at *4-5 (N.D. Cal. Aug. 4, 2025)(followed)
- Vera v. O'Keefe, 791 F. Supp. 2d 959, 963 (S.D. Cal. 2011)(followed)
- Doe v. Eating Recovery Center LLC, No. 23-cv-05561-VC, 2025 WL 2971090, at *5-6 & n.10 (N.D. Cal. Oct. 17, 2025)(discussed)
- Konop v. Hawaiian Airlines, Inc., 302 F.3d 868, 874, 877-78 & n.6 (9th Cir. 2002)(discussed)
- In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589, 598, 607 (9th Cir. 2020)(discussed)
- Ribas v. Clark, 696 P.2d 637, 639-41 (Cal. 1985)(followed)
Cited In (0)
No citing cases on record yet.