Blog
September 22, 2026
5 mins
Privacy Laws
US

Meta Pixel, Google Analytics and Website Consent: What Two New US Privacy Cases Show

Two U.S. federal rulings from September 15, 2026 put Meta Pixel, Google Analytics, and website consent under fresh scrutiny. Here is what Shopify merchants should take from Wehrle and Felsen without overreading the outcomes.
Consentmo graphic illustrating a U.S. court case involving online privacy and tracking.

What two new US tracking lawsuits mean for your store

Key Takeaways

  • On September 15, 2026, two federal courts issued motion-to-dismiss rulings in website-tracking cases involving Meta Pixel, Google Analytics, Google Tag Manager, and LinkedIn Insight Tag.
  • In Wehrle v. McLaren Health Care Corp., a Michigan federal court let federal Wiretap Act (ECPA) and unjust-enrichment claims proceed to discovery on allegations that health-related site activity was shared with third parties.
  • In Felsen v. The Vanguard Group, a Pennsylvania federal court dismissed the federal Wiretap Act claim without prejudice but kept Pennsylvania WESCA and California CIPA claims alive, and refused to treat a footer privacy-notice link as proven consent at the pleading stage.
  • These are early-stage decisions, not final verdicts.
  • They still underscore a practical point for website operators: know which trackers run on your site, what they send, and whether visitors actually saw and could act on your consent choices, especially on pages that handle sensitive activity.

What happened on September 15, 2026

Two U.S. district courts issued orders the same day in putative class actions about third-party tracking code on consumer-facing websites and apps.

Wehrle v. McLaren Health Care Corporation (E.D. Mich.)

Patients alleged that McLaren and the Karmanos Cancer Institute embedded tracking tools on their websites, including Meta Pixel, Google Analytics, Google Tag Manager, and LinkedIn Insight Tag.

They claimed those tools collected and sent information tied to health conditions, treatment interest, facility and physician searches, search queries, and appointment booking activity to Meta, Google, and LinkedIn without consent.

Judge Matthew F. Leitman granted the motion to dismiss in part and denied it in part. The court:

  • Allowed the federal Electronic Communications Privacy Act / Wiretap Act claim (Count II) to proceed
  • Allowed the unjust enrichment claim (Count V) to proceed
  • Dismissed breach of fiduciary duty, intrusion upon seclusion, breach of implied contract, and negligence claims

The court stressed that the ECPA ruling reflects its view of the pleadings and current case law, that courts nationwide still disagree on the crime-tort exception in pixel cases, and that it will revisit the issue with an open mind.

Felsen v. The Vanguard Group, Inc. (E.D. Pa.)

Brokerage customers alleged that LinkedIn Insight Tag, Google Analytics, and Meta Pixel on Vanguard’s website and app captured account-related activity and investment behavior, including search queries, ticker symbols, and buy/sell activity, and that third parties used that information for marketing.

Claims included the federal Wiretap Act, Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA), California’s Invasion of Privacy Act (CIPA), and California constitutional/common-law privacy claims.

Judge John F. Murphy held that the plaintiffs had Article III standing. On the pleadings, the court:

  • Dismissed without prejudice the federal Wiretap Act claims (and certain California common-law and constitutional claims)
  • Allowed the Pennsylvania WESCA claim to continue
  • Allowed the California CIPA claims to continue past the motion stage (after addressing choice-of-law and merits arguments in the memorandum)

Two points in Felsen matter for operators of any high-intent website, not only brokerages.

1. “Contents” of a communication can include search terms and trading activity.
WESCA defines “contents” to include information concerning the substance, purpose, or meaning of a communication. The court treated that definition as aligned with federal Wiretap Act case law holding that a search for information on a particular topic can reveal the substance and meaning of a communication. On the facts pleaded, search terms for financial products and trading activity could qualify as “contents.”

2. A privacy-notice link in the footer is not automatic proof of consent at the motion-to-dismiss stage.
Vanguard argued that a plaintiff consented because a privacy notice was linked at the bottom of every page. The court declined to find consent on that basis at this stage. Even if the notice itself were considered, Vanguard would still need to establish additional facts, including that the hyperlink was functional and conspicuous enough that the user could reasonably have seen it.

That second holding is the one many Shopify merchants should read carefully. A policy page that exists is not the same as consent the user actually received and could act on.

Why the two courts reached different results on the federal Wiretap Act

Both cases sit in the same broader wave of pixel and tag litigation. The federal outcomes still diverged for doctrinal reasons tied to how each circuit and district treats the Wiretap Act’s “party” rules and the crime-tort exception.

Under the federal Wiretap Act, a private party who is a party to the communication is generally not liable for interception, unless the interception is for the purpose of committing a criminal or tortious act. In the Third Circuit, that criminal or tortious purpose must be independent of the interception itself, not simply the alleged wiretapping restated as another privacy tort. In Felsen, the court found the plaintiffs had not adequately pleaded that independent crime or tort under binding Third Circuit authority, so it dismissed the federal claim without prejudice.

In Wehrle, the Michigan court allowed the ECPA claim to proceed on the pleadings. Plaintiffs alleged intentional transmission of HIPAA-protected information to third parties without consent. The court found those allegations enough, at this stage, to engage the crime-tort exception theories other courts have accepted in healthcare pixel cases, while expressly noting the unsettled national split and reserving the right to revisit after discovery.

Practical takeaway: Federal Wiretap Act claims can turn heavily on venue, the pleaded facts, and how a court interprets the crime-tort exception. State laws such as WESCA and CIPA may still proceed even when a federal claim does not. Merchants should not treat a single headline — whether “wiretap case dismissed” or “wiretap case survives” — as a nationwide rule.

For earlier Consentmo coverage of California-focused tracking risk and CIPA context, see California Tracking Lawsuits Are Rising.

What this tells website operators about trackers

Strip away the procedural labels and both complaints describe a familiar stack:

  • marketing and analytics tags embedded sitewide or in apps
  • capture of page views, identifiers, search input, and high-intent actions
  • transmission to platforms that also sell advertising services
  • disputes about whether users knew and agreed

Courts are willing, at least at the pleading stage, to treat some of that activity as more than dry “routing” metadata. Search terms, appointment flows, and product/ticker selections can look like the substance of what the user was communicating to the site.

That does not mean every website must block Meta Pixel or Google Analytics until consent in every jurisdiction. Requirements turn on:

  • where your visitors are
  • what data the scripts actually send
  • whether the data is sensitive under a specific statute (health, financial, or other regulated categories)
  • how you present notices and choices
  • whether a given law is a consent statute, a wiretap-style interception statute, a consumer privacy statute, or sector rules such as HIPAA

Overclaiming “these cases require X everywhere” helps no one. Under-reading them is also a mistake. They show that plaintiffs and courts will dig into what the pixel fired on, not only whether a privacy policy existed somewhere on the domain.

Special note for health-related sites

If your website handles protected health information, a cookie banner alone is not enough for HIPAA.

  • Telling users about tracking in your privacy policy does not automatically make sharing health data with tracking vendors permitted.
  • Clicking Accept on a cookie banner is not the same as giving a valid HIPAA authorization.
  • Some tracking tools may need additional legal review, contracts, or to be removed from certain pages entirely.

Bottom line: a CMP helps manage cookie consent, but it does not replace HIPAA compliance checks where health information is involved.

What Shopify merchants should check on their own sites

Use these two rulings as a prompt for an operational review, not as a panic trigger.

1. Inventory what actually runs

List every marketing, analytics, advertising, social, and session tool on the storefront, checkout-adjacent pages, account area, search, and any embedded apps. Include Meta Pixel, Google tags, LinkedIn Insight, TikTok, Pinterest, review widgets, chat, and personalization scripts. Categorize each as essential or non-essential for your compliance model.

Consentmo’s scanner and Tracker Manager are built for this continuous inventory: scripts change when you install apps, edit theme code, or launch campaigns.

Consentmo Tracker Manager showing scanned cookies, scripts, storage, pixels, and tracker categories.

2. Map what each tool can observe

For important pages and actions, check what third-party trackers can learn from things like the URL, search terms, products viewed, form steps, or event names. In Felsen, the court said search and transaction-related activity could count as the “contents” of a communication.

In Wehrle, health-related searches and appointment activity received even closer scrutiny.

3. Test consent as a user would see it

Ask:

  • Is the choice presented before non-essential tags fire in regions where you require prior consent?
  • Are accept and reject (or equivalent granular controls) actually usable?
  • Is the privacy or cookie policy link easy to find, working, and readable on mobile?
  • Do you keep records of what version of the banner and policy applied when consent was given?

Felsen refused to assume consent from a bottom-of-page privacy link without proof that the link was functional and conspicuous. That is a UX and evidence problem as much as a legal theory problem.

4. Align analytics and ads with consent signals

Where you use Google tags, configure Consent Mode and verify behavior after opt-in and opt-out. See Consentmo’s Google Consent Mode V2 guidance.

For Meta and other pixels, confirm load rules match your regional consent settings rather than firing on every first paint worldwide.

Consentmo integrations dashboard showing Google Consent Mode v2, Meta Pixel, and TikTok Pixel consent integrations.

5. Rescan on a schedule

Theme edits, app installs, and Black Friday pixels are common ways silent tags return. A one-time audit ages quickly. Build rescans into your release checklist.

6. Get counsel for regulated categories

Health, finance, children’s products, and cross-border sales raise statute-specific issues. These two opinions are district-court pleadings decisions. They are useful signals, not a compliance certificate.

Practical tracking and consent checklist

Check Why it matters after Wehrle / Felsen
Full tag inventory (theme + apps + GTM) Both cases turn on what third-party code was embedded and what it collected.
Event and URL review on search, account, booking, and checkout-adjacent pages Search terms and high-intent actions may be treated as communication contents under some laws.
Prior blocking of non-essential tags where your model requires consent Helps reduce “invisible transmission before choice” fact patterns.
Clear, working policy and preference links Footer-only notice was not enough to establish consent at the pleading stage in Felsen.
Equal-prominence reject / manage choices where you promise choice Supports the argument that consent was meaningful rather than theoretical.
Consent logging (who, when, what text, what version) Creates a record if your disclosure and consent practices are later challenged.
Recurring scans after app or campaign changes Tracking stacks change over time as apps, themes, and campaigns are updated.
Separate HIPAA / sector review if applicable Cookie banners are not HIPAA authorizations under HHS OCR guidance.
Counsel review for multi-state U.S. exposure Federal and state wiretap-style claims can diverge, as these cases illustrate.

What Consentmo helps you with

Consentmo is a Shopify-focused consent and tracking control layer. It does not replace your lawyer, and it does not convert a healthcare or financial product site into an automatically compliant one. It does help merchants run the controls these cases keep putting in issue:

  • Scan the store for cookies and trackers and classify them
  • Block non-essential scripts until the visitor’s consent choice allows them
  • Present clear banner and preference-center choices, including region-aware setups
  • Document consent where your process requires a record
  • Rescan so new pixels from apps and campaigns do not silently reappear
  • Support Google Consent Mode and related ad-stack consent signals so analytics and ads respect the choice you collected

If you already run a CMP, use this week’s rulings as a reason to verify real browser behavior on search, product, and account pages, not only the banner screenshot in your brand guidelines.

Conclusion

Wehrle and Felsen, both decided September 15, 2026, are early-chapter opinions in the long-running U.S. fight over website pixels and tags. One healthcare case lets federal Wiretap Act and unjust-enrichment theories proceed into discovery. One financial-services case drops the federal Wiretap Act claim for now but keeps state WESCA and CIPA theories alive, and refuses to treat a footer privacy link as proven consent on the pleadings. Together they push operators toward a simple operational standard: know your trackers, know what sensitive interactions they can observe, and make consent something users can actually see and exercise.

This article is general information for merchants, not legal advice. Outcomes depend on facts, jurisdiction, and counsel’s guidance for your store.

Mariya Petrova
Growth & Product Marketing
With over 7 years of experience in advertising across agencies and e-commerce brands, Mariya has made marketing her core element. Today, she supports Consentmo users by guiding them through the realms of compliance, Shopify, and all things marketing.