Skip to main content
BlogLegal-Tech

CVS Pays $20.5 Million Over Tracking Pixels. Here's Why You Could Be Next.

Ben Alton
4 min read

CVS recently agreed to pay $20.5 million to settle a privacy lawsuit, according to reports. There was no data breach. No hackers. No stolen database. The problem was tracking code sitting on its own website and app - the kind of marketing pixel that exists on a huge share of the internet - which allegedly shared visitor data with advertising companies without the consent the law requires.

That settlement is not an outlier. It is the visible tip of one of the fastest-growing areas of privacy litigation in the United States, and the thing being sued over is something almost every company has on its site right now and rarely thinks about.

What CVS was accused of

The allegation, as reported, was straightforward: CVS's website and app used third-party tracking software that sent information about visitors to advertising and analytics firms, including the ad-tech company Criteo, without proper consent. The data wasn't taken by an attacker. It was handed over automatically, by code the company itself installed, every time someone visited.

If that sounds like a description of a normal website, that is exactly the point. Marketing pixels from the major ad platforms do precisely this by design. They load when a page loads, and they report back. CVS is simply a large, recognizable name attached to a pattern that runs across thousands of ordinary sites.

Why an old wiretapping law is suddenly everywhere

The legal theory driving many of these cases is older than the modern web. Plaintiffs are using state wiretapping and eavesdropping laws - most prominently California's Invasion of Privacy Act - which were written to stop people from secretly recording phone calls. The argument is that when a third-party pixel silently captures what a visitor does on your site and streams it to an outside company, that is a form of interception the visitor never agreed to.

Courts are still working out the boundaries, but the volume tells the story. Privacy-related filings are on track to exceed 3,500 this year, and website tracking technology is the single most-targeted category in all of them. These suits are attractive to file because the alleged violation is easy to demonstrate and exists on thousands of sites in identical form. One theory, copied across hundreds of defendants.

The reason this catches good companies off guard

Here is what makes tracking-pixel exposure so dangerous: it is completely invisible from the outside, and it usually isn't a decision anyone consciously made.

A pixel gets added through a tag manager, often by a marketing team, often months or years after the last privacy review. It might be a remarketing tag, a conversion pixel, an analytics script, or a social media tracker. It fires the instant a visitor lands on the page - frequently before the person has clicked anything on the cookie banner - and ships data to a third party. The website looks completely normal. The page renders perfectly. Nothing breaks. No one gets an alert.

So the company has no idea it is happening. The marketing team assumes the tags are fine. The legal team assumes the cookie banner covers it. And the two assumptions never get checked against what the site actually does.

What "sharing data" really means here

When people hear "we don't sell data," they picture a spreadsheet changing hands. That is not what these lawsuits are about. The issue is the automatic, real-time transmission that happens when a pixel loads:

  • The pages someone views, which can reveal health conditions, financial situations, or other sensitive interests. In the CVS case, the health-adjacent nature of the browsing is part of what made it sensitive.

  • Identifiers that let an ad network tie that browsing back to a real profile across the web.

  • Actions taken on the site, often including form inputs, sent to the third party as they happen.

And critically, much of this fires before the visitor consents - which is where the legal exposure concentrates. A cookie banner that asks for consent while the trackers have already loaded and reported back is, functionally, asking permission for something it already did.

How plaintiffs find it, and how you should too

The uncomfortable part is how easy this is to prove. A plaintiff's lawyer does not need your source code or an insider. They load your website with the browser's network tab open and watch, in plain sight, exactly which third parties your site contacts and what it sends them, before any consent is given. That recording is the evidence.

Which means the defense is the same move, run first. You find out what your own site does before someone else documents it for a filing.

What a defensible setup looks like

You do not have to remove every tracker. You have to control when they fire and get real consent first. In practice that means:

  • Nothing non-essential fires before consent. Advertising and analytics tags should be blocked until the visitor actively agrees. A consent banner that loads the trackers anyway is the core problem, not the solution.

  • Honor the Global Privacy Control signal. When a browser signals opt-out, your site should suppress the sharing automatically, with no further action from the visitor.

  • Know every tag on your site. Tag managers make it trivial to add a pixel and easy to forget it exists. The inventory drifts. Someone has to own keeping it accurate.

  • Re-check after every change. A redesign, a new campaign, or a new vendor can reintroduce a pre-consent tracker overnight. Compliance here is a state you fall out of, not a box you tick once.

How to check your own site

You can start today, the same way a plaintiff would:

  • Open your site in a fresh browser with the network tab recording, before clicking anything on the cookie banner. Note every third-party domain your site contacts.

  • Ask, for each one, whether a visitor consented before it fired. If the answer is no, that is your exposure.

  • Turn on Global Privacy Control and confirm the trackers actually stop.

  • Repeat after any change to your tag manager, ad stack, or site design.

This is exactly the kind of behavior Complyy tests automatically. We load your live site the way a visitor would, record which third-party trackers fire and when, check whether they respect consent and the Global Privacy Control signal, and capture timestamped evidence of what actually happened - so you find the gap before a plaintiff's lawyer does, and you keep catching it every time your site changes.

Run a free scan of your website and see what your pages are really sending, and to whom.

This article is for general information and is not legal advice. Details of the CVS settlement are described as publicly reported and may differ from the final court record; specific obligations depend on your business and jurisdiction.

CVS Pays $20.5 Million Over Tracking Pixels. Here's Why You Could Be Next.