LmCast :: Stay tuned in

Ad Tech Has A Multibillion-Dollar Privacy Problem. It Started Decades Ago

Recorded: Sept. 21, 2026, 5 a.m.

Original Summarized

Ad Tech Has A Multibillion-Dollar Privacy Problem. It Started Decades Ago | AdExchanger

image/svg+xml:

Topics
Latest
Marketers
Agencies
Publishers
Technology
Platforms
Identity
Measurement
Data Privacy
Artificial Intelligence
CTV
Commerce
AdExplainer
Exclusive Report
Daily News Roundup

Opinion
All Columns
Data-Driven Thinking
On TV & Video
The Sell Sider
Content Studio
Comic
Contributor Guidelines

About Us
Advertise
Newsletter
AdExchanger Advisory Board
About Us
Contact Us

Events
Programmatic I/O 2026
CTV World 2027
Top Women in Media & Ad Tech
Webinars
All Events
Network Events

Podcasts
AdExchanger Talks
The Big Story
Inside the Stack

Programmatic I/O

CTV World 2027

Become an AdHero

Subscribe

Sign In

Sign In

Topics
Latest
Marketers
Agencies
Publishers
Technology
Platforms
Identity
Measurement
Data Privacy
Artificial Intelligence
CTV
Commerce
AdExplainer
Exclusive Report
Daily News Roundup

Opinion
All Columns
Data-Driven Thinking
On TV & Video
The Sell Sider
Content Studio
Comic
Contributor Guidelines

Events & Awards
Programmatic I/O 2026
CTV World 2027
Top Women in Media & Ad Tech
Webinars
All Events
Network Events

Podcasts
AdExchanger Talks
The Big Story
Inside the Stack

Subscribe Free
Sign Up

About Us
Advertise
Newsletter
AdExchanger Advisory Board
About Us
Contact Us

CONNECT

Home Data Privacy Roundup Ad Tech Has A Multibillion-Dollar Privacy Problem. It Started Decades Ago

Data Privacy Roundup
Ad Tech Has A Multibillion-Dollar Privacy Problem. It Started Decades Ago By
Allison Schiff

Monday, September 21st, 2026 – 1:00 am
SHARE:


An interview with
Müge Fazlioglu
Principal Researcher


The biggest privacy risk facing ad tech isn’t whatever state privacy law passed last month; it’s the ones that passed decades ago.
The Video Privacy Protection Act was written to protect VHS renters in 1988. Another, the California Invasion of Privacy Act, was enacted in 1967 to stop illegal wiretapping, about which there was a lot of paranoia at the time. (Whenever I write about CIPA, I think about that scene from “The Conversation” with Gene Hackman, where his character rips apart his apartment looking for hidden bugs that aren’t there.)
Today’s equivalent is a lot less dramatic: It’s a pixel silently firing in the background on a website.
Over the past few years, plaintiff attorneys have figured out that these vintage statutes are surprisingly malleable, and they’ve been stretching them to target modern tracking technology.

Since 2022, there have been more than 10,000 data privacy cases filed in US courts – 3,414 in 2025 alone – spanning wiretapping, data breaches, web tracking and unauthorized data sharing, according to Müge Fazlioglu, a principal researcher at the IAPP with a focus on privacy law and policy.
And she’d know. She counted.
Fazlioglu co-authored a new IAPP report on the legal trends driving pixel and tracker litigation and what the surge in cases means for companies on the receiving end.
The tab so far? Roughly $7 billion in settlements.
“Privacy litigation is no longer a minor risk,” Fazlioglu said. “It’s now become a major source of legal and financial exposure for organizations.”
Fazlioglu spoke with AdExchanger.
AdExchanger: What’s driving the acceleration in data privacy cases? Is it that plaintiff attorneys are getting more creative?
MÜGE FAZLIOGLU: Plaintiffs are increasingly relying on older statues in creative ways, particularly around web tracking, video viewing and data sharing with third parties. And the risk is real even for companies that think their practices are commonplace.
Things are moving very quickly, and compliance lessons are emerging from private litigation. Court decisions are becoming an important source of privacy law in their own right, so organizations need to understand not just what legislators or regulators are saying, but also what the courts are interpreting.
What’s the theory of harm in a pixel case?
Harm is one of the trickiest parts of privacy law, because it’s so hard to conceptualize. Sometimes it’s financial, sometimes it’s emotional and sometimes you may not see the harms right away, but they come out later.
That’s part of what makes privacy harms so difficult to prove. But the discomfort of knowing your data was shared without your knowledge is real, even if it’s hard to put a dollar amount on it.
What does “good” consent actually look like for a company running third-party tags on its site? Because just having a cookie banner clearly isn’t enough.
Vague, generalized disclosures definitely aren’t enough. For example, has consent been obtained in a way that’s distinct from other consumer obligations? Is it renewed every two years? Is the ability to opt out clear?
Companies also can’t rely on consent that a third party obtained on their behalf, because it might not be sufficient or meet the VPPA bar, for example.
How exposed are companies because of what their downstream vendors and partners are doing?
The courts are increasingly looking not just at what a company is doing, but at what its analytics providers, advertising partners and session replay providers are doing with consumer data. In some cases, vendors have been treated as extensions of the business. In others, their independent use or potential use of data has created liability exposures.
Organizations need strong contractual controls and a clear understanding of how their vendors collect, process and use data. You are responsible for what the third parties you work with are doing.
What should digital publishers and content platforms understand about their exposure under the Video Privacy Protection Act?
The courts are still grappling with who qualifies as a consumer [under VPPA], what constitutes personally identifiable information and when disclosures to third parties trigger liability. And the potential damages remain significant. [It’s $2,500 per violation.]
The consent requirements are also stricter than most companies realize. Consent needs to be written, informed and separate from other consumer obligations and it expires every two years.
There’s still no federal privacy law, but, as we’ve been talking about, there have been thousands of private cases and billions in settlements. At what point does private litigation become almost like de facto regulation, essentially doing what Congress hasn’t?
I wish I knew the answer to that question. It’s hard to say one approach is better than the others, and even if a federal law passed tomorrow, a lot would depend on what it actually said. There are real disagreements over things like preemption and private rights of action.
What I do know is that court decisions are becoming an important source of privacy law, and companies that understand the legal landscape will be much better positioned to stay ahead of regulatory risk rather than just responding after a complaint is filed.
This interview has been lightly edited and condensed.
🙏 Thanks for reading! As always, feel free to drop me a line at allison@adexchanger.com with any comments or feedback. And guess what I found? Live action lawyer cat!
📣 In non-cat-related news (yes, there is such a thing), you still have time to snag your ticket to Programmatic IO coming up in New York City on September 28 and 29.
We’ve got a great agenda lined up for you, including a panel on AI governance with Yum! Brands, The Brandtech Group and BBDO, and a session hosted by privacy attorney Daniel Rosenzweig of DBR Tech Law on why it’s critical to get AI right from Day One. See you there!

Tagged in:

California Invasion of Privacy Act

//
CIPA

//
IAPP

//
lawsuits

//
Müge Fazlioglu

//
privacy laws

//
Video Privacy Protection Act

//
VPPA

Next In Data Privacy Roundup

Your Doctor’s Office Is An Ad Channel Now

Related Stories

Data Privacy Roundup
To Put It Plainly, Don’t Become A Target For Plaintiffs’ Attorneys

Data Privacy Roundup
Why A 1967 Privacy Law Is Powering A New Wave Of Ad Tech Lawsuits

Data Privacy Roundup
Putting UID2 Under the Legal Microscope

Must Read

ad tech acquisition
Infillion Acquires Foursquare, Adding More Location Data To Its Ever-Growing Ad Tech Stack

Infillion checked in with its latest acquisition on Friday: Foursquare. Apparently, if there’s a strategically interesting or distressed ad tech asset on the market, Infillion will find it.

Platforms
HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud

A week ago, HBO MAX had its verified Reddit account overrun by a hacker group, which eluded notice for two days while it ran 108 different ad permutations targeting an unknown number of Redditors.

Gaming
Gaming Wants To Prove It’s Just Like Other Media Channels – While Also Owning How It’s Different

Adapting other channels’ strategies might be what gaming platforms need to do to get advertisers comfortable spending more. Leaning into gaming’s differentiators will come later, after bigger budgets arrive.

ad tech acquisition
Taboola Eyes The Finance Vertical With An Offer To Acquire Ad Network Dianomi

Taboola has made an offer to buy Dianomi, a UK-based ad tech company that connects financial advertisers with premium business and finance publishers.

CTV
How The Try Guys Turned Their Love For Liquid I.V. Into A Brand Deal

When a creator already loves the product they’re marketing, it’s easy to work it into their content in ways that feel natural. That’s exactly what the Try Guys did.

Google remedies
The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR

The court has unsealed Judge Leonie Brinkema’s full remedies opinion in US v. Google (ad tech edition). So, what’s in there?

Popular

Platforms

Why Wall Street Turned Against The Trade Desk

Platforms

The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR

Publishers

Chrome Has A New Way To Measure Ad Overload On The Web

Commerce

Sam’s Club Debuts Ad Targeting Products That Confidently Assert Future Buyers

CTV

Horizon Is Bringing Roku’s TV Data ‘In House.’ Here’s What That Means For Advertisers

Join the AdExchanger Community
Join Now

Your trusted source for in-depth programmatic news, views, education and events.
AdExchanger is where marketers, agencies, publishers and tech companies go for the latest information on the trends that are transforming digital media and marketing, from data, privacy, identity and AI to commerce, CTV, measurement and mobile.

NEXT EVENT
Programmatic I/O New York
September 28-29, 2026Marriott Marquis, New York
Learn More

ABOUT ADEXCHANGER
About Us
Advertise
Contact Us
Events
Subscribe
RSS
Cookie Settings
Privacy & Terms
Accessibility
Diversity, Equity, Inclusion & Belonging

CONNECT

© 2026 Access Intelligence, LLC - All Rights Reserved

The major privacy risk facing the ad technology sector stems not from recent legislation but from outdated statutes enacted decades ago, which are now being adapted to govern modern tracking technologies. For instance, laws such as the Video Privacy Protection Act, which originated in 1988, and the California Invasion of Privacy Act from 1967, are being stretched by plaintiff attorneys to target contemporary issues like pixel tracking and data sharing.

This trend has fueled a significant surge in legal action; since 2022, over ten thousand data privacy cases have been filed in U.S. courts, with 3,414 cases noted in 2025 alone spanning areas like wiretapping, data breaches, and web tracking. These legal challenges, which rely on interpretations of older laws, have resulted in approximately seven billion dollars in settlements, establishing privacy litigation as a significant source of legal and financial exposure for organizations.

Müge Fazlioglu, a principal researcher at the IAPP focusing on privacy law and policy, observed that plaintiffs are increasingly utilizing these older statutes in creative ways to pursue rights related to web tracking and third-party data sharing. This reality necessitates that organizations understand not only regulatory guidance but also judicial interpretations, as court decisions are emerging as an important source of privacy law.

A central challenge in these cases involves defining the harm caused by data sharing, which is inherently difficult because privacy harms can be financial or emotional and may not be immediately quantifiable. Companies employing third-party tags face complex issues regarding consent, as a simple cookie banner is insufficient. Obtaining valid consent requires standards that go beyond general consumer obligations, demanding clarity on whether consent is renewed, whether opt-out mechanisms are explicit, and ensuring that consent is obtained separately from other consumer requirements. Furthermore, relying on consent obtained by a third party is often insufficient, particularly concerning standards like the VPPA.

Companies are also exposed through the actions of their downstream vendors and partners. Courts are increasingly examining not only the company's direct actions but also the data practices of analytics providers and advertising partners. This suggests that vendors can be treated as extensions of the business, creating liability exposures for the advertising entities. Consequently, organizations must establish robust contractual controls and possess a clear understanding of how all partners collect, process, and utilize data, as they remain responsible for the actions of these external entities.

Specifically regarding the Video Privacy Protection Act, digital publishers and content platforms grapple with ambiguities concerning who constitutes a consumer, what defines personally identifiable information, and the thresholds for liability when sharing disclosures with third parties. The potential damages associated with these violations, estimated at two thousand five hundred dollars per violation, underscore the severity of this exposure. Although a federal privacy law remains absent, the accumulation of private litigation suggests a trend toward de facto regulation. Ultimately, understanding the evolving legal landscape, driven by private litigation, is crucial for organizations to proactively manage regulatory risk rather than react only after legal complaints are filed.