This is the regulatory companion to Why Web Tracking Survives and Web Tracking Techniques: A 2026 Field Guide.
The past 18 months produced more durable enforcement precedent than the previous five years combined. Three jurisdictions acted in ways that will shape compliance posture for the next decade: the UK ICO drew a hard line on fingerprinting, California AG Rob Bonta extracted the largest CCPA settlement in state history from Disney and Governor Newsom signed a browser-level opt-out mandate into law, and the EU's AI Act prohibitions took effect. California's CPPA finalized CPRA risk assessment regulations. The Ninth Circuit kept the CIPA session replay litigation wave alive despite a defense win in the district courts.
None of these actions occurred in isolation. Each builds on the others. The ICO's fingerprinting position and the Disney settlement share the same enforcement logic: if a business uses a technique to track users, it must honor opt-out signals at the same technical scope. CPRA risk assessments formalize that logic into a proactive obligation. The CIPA wave reflects a litigation theory that behavioral data capture is wiretapping - a theory courts have not fully resolved.
Privacy engineers and compliance officers face a changed surface in 2026. Automated compliance scans audit cookie declarations and consent banner presence. They do not audit server-side tracking payloads, consent signal propagation to server containers, or CNAME-cloaked endpoints. A site can pass every automated check while transmitting behavioral data to advertising platforms without consent. That gap is where enforcement is focused.
The five actions practitioners need to understand: the ICO's formal fingerprinting position, the CPRA risk assessment requirements, the Disney DTC settlement and its identity symmetry theory, the CIPA session replay litigation landscape, and the Opt Me Out Act. Together they define the compliance floor for web tracking operations in California-adjacent and EU-adjacent businesses.
What changed. The ICO established that fingerprinting is subject to the same PECR consent rules as cookies - there is no legal distinction based on whether a user can easily delete the identifier. The CPPA published mandatory risk assessment regulations covering a broad set of automated processing activities, effective January 1, 2026. The California AG established that opt-out obligations must match the scope of a company's identity resolution - a business that unifies identity for targeting must unify it for opt-out. California extended the Global Privacy Control mandate to browsers with the Opt Me Out Act. The EU AI Act's Article 5 prohibited practices took effect February 2, 2025.
What to do. Audit fingerprinting use for PECR and GDPR lawful basis. If your stack runs server-side tracking or CNAME-cloaked endpoints, ensure consent signals propagate to those layers. Inventory any automated processing that infers personal traits - CPRA risk assessments are mandatory if that processing presents significant risk. If your business uses cross-device identity resolution for targeting, your opt-out suppression must operate at the same scope. Activate session replay SDKs only after explicit consent. Implement GPC signal handling as a first-class opt-out across all properties and devices associated with an authenticated account.
ICO on Fingerprinting: The Formal Position
Google reversed its 2019 policy prohibiting advertisers from using fingerprinting techniques, permitting fingerprinting from February 16, 2025. The ICO's response was direct: "We think this change is irresponsible." [^1]
The ICO's enforcement theory has two prongs. First, fingerprinting violates GDPR and PECR because users cannot easily consent to it in the way they can with cookies - there is no "delete fingerprint" button. The ICO invoked Google's own 2019 position that fingerprinting "subverts user choice and is wrong," framing the reversal as a departure from stated principles. Second, the ICO published draft PECR guidance in December 2024 clarifying that fingerprinting is subject to PECR storage-and-access rules - the same consent rules that govern cookie placement. [^1]
The practical consequence: fingerprinting is not a consent-free alternative to cookies. A business that replaces a cookie-based identifier with a canvas fingerprint has not reduced its regulatory obligations. It has reproduced them in a form users cannot inspect or delete - which the ICO considers more problematic, not less.
The ICO's position also applies to passive fingerprinting signals that are not actively set by a script. If a server derives a persistent identifier from browser characteristics sent in HTTP headers - User-Agent, Accept-Language, TLS fingerprint - PECR's storage-and-access analysis still applies to the act of using that data to identify the user across sessions.
For practitioners. Document the lawful basis for any fingerprinting operation. Consent is the appropriate basis for most tracking-oriented fingerprinting. Legitimate interests requires a balancing test that the ICO's position makes difficult to sustain for advertising use cases. Review the December 2024 ICO draft guidance before finalizing legal basis documentation. [^1]
CPRA Risk Assessments: What Is Required as of January 1, 2026
The California Privacy Protection Agency finalized CPRA risk assessment regulations in September 2025. The regulations took effect January 1, 2026. [^2]
Risk assessments are mandatory for any processing activity that presents "significant risk" to consumer privacy. The CPPA identified five categories:
- Selling or sharing personal information
- Processing sensitive personal information
- Using automated decision-making technology (ADMT) for significant decisions affecting individuals
- Using automated processing to infer personal traits - including intelligence, health, economic status, preferences, reliability, or movements
- Processing to train ADMT or biometric technologies
The risk assessment must weigh privacy risks against benefits and must determine whether to restrict or prohibit processing if risk outweighs benefits. The assessment is not a checkbox - it requires documented analysis of the specific processing activity, the data involved, the affected population, and the available mitigations.
What triggers the requirement for web tracking operations. Probabilistic cross-device tracking triggers the risk assessment requirement on at least two grounds: sharing personal information and inferring personal traits. Session replay triggers it where the data informs behavioral profiles or is shared with vendors. Behavioral profiling for ad targeting triggers it where the inferred profile constitutes a personal trait inference - the CPPA's language on "preferences" and "movements" covers most interest-based advertising models.
The fifth category - processing to train ADMT or biometric technologies - captures any use of behavioral session data to train machine learning models, including models used for fraud detection, content recommendation, or audience segmentation.
For practitioners. Map all processing activities against the five categories before conducting an inventory. Any activity that touches more than one category requires a separate risk assessment per activity, not a single aggregate document. The CPPA has not published a prescribed format, but the assessment must be sufficient to demonstrate that the business weighed the specific risks. Retain risk assessment documentation - it will be the first document requested in any CPPA inquiry.
Disney DTC CCPA Settlement: Account-Level Identity Symmetry
California Attorney General Rob Bonta announced a $2.75 million settlement with Disney DTC, LLC and ABC Enterprises on February 11, 2026, marking the largest CCPA settlement in state history. [^3] The settlement stemmed from a January 2024 investigative sweep of streaming services.
The AG's complaint alleged that Disney diligently linked consumer devices and data for targeting but failed to link those same devices and data when honoring opt-out requests. Consumers who opted out through Disney's web form stopped data sharing only with Disney's internal ad platform - not with third-party advertising technology companies embedded in its apps. Disney's streaming TV apps had no in-app opt-out mechanism. Consumers on connected TV devices were redirected to a web form that did not stop tracking code embedded in the TV apps. A consumer with the full Disney bundle would have needed to submit up to ten separate opt-out requests across devices and services.
AG Bonta's quote at announcement: "Consumers shouldn't have to go to infinity and beyond to assert their privacy rights." [^3]
The enforcement theory. The AG's central position: if a business associates a consumer's devices with that consumer for advertising purposes, it must associate those same devices for purposes of honoring the consumer's opt-out. Identity resolution scope for targeting must equal identity resolution scope for opt-out compliance.
This theory addressed account-based identity resolution - authenticated users across Disney+, Hulu, and ESPN+ with linked accounts. It did not directly address probabilistic cross-device graphs. But the enforcement logic points in one direction: a business that infers cross-device relationships for advertising purposes carries the obligation to suppress opt-out signals at the same inferential scope.
Settlement terms. Disney must pay $2.75 million in civil penalties. The injunctive relief requires account-wide opt-out propagation for logged-in users, clear in-app opt-out links across all streaming services, GPC signal treatment as a valid opt-out for known accounts, third-party notification of opt-out requests, and a three-year compliance monitoring program with 60-day progress reports. [^3] [^4]
For practitioners. Audit whether your opt-out propagation matches your targeting scope. If your stack unifies cross-device identity for ad delivery, it must unify it for opt-out suppression. GPC signals from authenticated users must trigger account-wide opt-out, not device-level or service-level opt-out. Pseudonymous profiles associated with a device must also be suppressed for consumers who are not logged in. Technical limitations are not a defense - the Disney complaint specifically noted that Disney cited technical limitations on connected TV opt-outs while those same platforms ran behavioral targeting without apparent technical limitation.
CIPA Session Replay Litigation: An Active and Unresolved Landscape
California's Invasion of Privacy Act (CIPA), Section 631(a), prohibits wiretapping and interception of communications without all-party consent. A litigation wave tested whether session replay tools - which capture keystrokes, mouse movements, clicks, and form inputs - constitute wiretapping under this definition. Over 1,800 CIPA suits were filed through 2025. [^5]
Three cases define the current landscape:
Javier v. Assurance IQ (Ninth Circuit, 2022): The Ninth Circuit reversed the district court's dismissal, holding that retroactive consent - consent obtained after data collection has already begun - does not satisfy Section 631(a). Consent must precede collection. The court explicitly declined to reach the question of whether session replay constitutes interception of communications, and declined to address implied consent or statute of limitations arguments. On remand, the district court dismissed on statute of limitations grounds. The practical effect was procedural: the reversal made claims viable at the pleading stage, enabling the subsequent wave of filings. [^5]
Torres v. Prudential Financial, Inc. (N.D. Cal., April 2025): The court granted summary judgment for the defendant. Session replay data "does not become readable content until after they are stored and reassembled into a session replay" - the data is not intercepted "in transit" as CIPA requires. A defense win at summary judgment on this theory. [^5]
Mikulsky v. Bloomingdale's (Ninth Circuit, June 20, 2025): The Ninth Circuit revived a session replay class action, holding that the complaint plausibly alleged real-time capture of contents without consent. The Torres "not in transit" theory did not dispose of the claim at the pleading stage. [^5]
Where this leaves practitioners. Torres and Mikulsky are not inconsistent - they addressed different procedural postures and different factual records. Torres was summary judgment with a developed record; Mikulsky was a motion to dismiss with a well-pleaded complaint. The doctrinal question of whether session replay constitutes wiretapping under CIPA 631(a) remains unresolved at the Ninth Circuit level. The litigation threat remains active.
A defensible session replay configuration requires: explicit user consent before SDK activation (not retroactive, not implied), input field masking by default for all form fields, retention limits of 30-90 days with automatic deletion, documented data flows to third-party vendors, and consent gating applied to vendor transmission - not just recording activation.
Opt Me Out Act: Browser-Level Opt-Out Mandate
California Governor Newsom signed the Opt Me Out Act in October 2025. The law requires browsers used by California consumers to provide a single opt-out preference signal to all businesses, extending the Global Privacy Control mandate that CPRA regulations established for websites. [^6]
The practical effect: browser vendors must build GPC-equivalent opt-out signaling into their products for California users. Businesses receiving a GPC signal from a California browser user must treat it as a valid opt-out of the sale and sharing of personal information - an obligation that already existed under CPRA regulations but now has additional statutory backing at the browser level.
Combined with the Disney settlement's GPC enforcement theory, this creates a clear compliance standard: GPC signals must trigger account-wide opt-out suppression for authenticated users and device-level opt-out suppression for unauthenticated users.
EU AI Act Intersection: Article 5 and the Behavioral Inference Gap
The EU AI Act's Article 5 prohibited practices took effect February 2, 2025. The prohibitions relevant to web tracking cover: AI systems that perform social scoring based on behavior over time, AI systems that infer emotions in workplace or educational settings, and AI systems that perform biometric categorization for sensitive attributes. [^7]
Behavioral profiling for advertising targeting decisions classifies as a "high-risk AI system" under Article 6 if it involves real-time behavioral inference driving automated decisions with significant effects on individuals - triggering conformity assessment obligations.
The regulatory gap. The highest-risk categories under the AI Act target biometric and social scoring applications. Probabilistic behavioral inference from consented first-party data to drive ad targeting may fall into a grey zone. The data is consented (the user accepted the cookie banner). The processing is probabilistic (not identity-asserting). The output is an advertising decision (not a significant life decision in the narrow sense). A behavioral inference system built on first-party consented data may be functionally equivalent to surveillance-scale profiling without triggering any current EU AI Act prohibition.
CPRA regulations close part of this gap on the California side: risk assessment obligations explicitly cover "automated processing to infer or extrapolate personal traits, such as intelligence, health, economic status, preferences, reliability, or movements." This language covers behavioral profiling that infers preferences from session data, regardless of whether consent was obtained.
For practitioners. Do not rely on consent as a complete shield for behavioral inference systems. The CPRA risk assessment obligation applies even to consented processing. The EU AI Act's Article 6 high-risk classification may apply to behavioral targeting systems operating at scale. Document the decision logic, the data inputs, and the significant effects analysis for any ADMT system.
Per-Technique Legal Exposure Reference
The following table consolidates legal exposure by tracking technique for GDPR/ePrivacy, CCPA/CPRA, and CIPA contexts. This is a reference summary, not legal advice. Specific deployments require jurisdiction-specific analysis.
| Technique | GDPR / ePrivacy | CCPA / CPRA | CIPA / Other US |
|---|---|---|---|
| First-party cookies | Consent required for analytics/personalization; not required for session/auth. ePrivacy storage-and-access rules apply. | Persistent identifiers constitute personal information. Triggers disclosure and opt-out rights. | No direct CIPA exposure. State breach notification laws may apply to cookie theft vectors. |
| URL parameters / click IDs | Pseudonymous identifiers linkable to a natural person require lawful basis under GDPR. | Click IDs enabling cross-context behavioral advertising trigger opt-out rights. | No direct CIPA exposure. |
| Pixel tracking | GDPR/PECR transparency requirements apply. Email tracking pixels without disclosure violate ePrivacy storage-and-access rules. Several DPAs classify email pixels as requiring consent. | Pixel-based data collection triggering cross-context behavioral advertising triggers opt-out obligations. | No direct CIPA exposure for standard pixels. |
| ETags | Any persistent identifier on a device requires consent unless strictly necessary under ePrivacy. The KISSmetrics precedent established wiretap exposure under US law for ETag-based tracking without notification. [^8] | ETag-based persistent identifiers constitute personal information. | KISSmetrics settled a class action in 2012 on wiretap and deception theories. [^8] |
| HSTS tracking | PECR and ePrivacy storage-and-access rules apply to "access to information already stored" on a device, regardless of which API stores it. | HSTS-based identifiers constitute persistent device identifiers and trigger CCPA obligations. | No established US case law directly addressing HSTS tracking as wiretapping. |
| Browser fingerprinting | ICO position: subject to PECR consent rules. No "delete fingerprint" option makes consent harder to operationalize, not easier to avoid. GDPR/ePrivacy apply regardless of whether the fingerprint is actively set by script or derived from HTTP headers. [^1] | Fingerprint-derived persistent identifiers constitute personal information. | No CIPA case law directly on fingerprinting, but the interception theory from session replay cases could extend to fingerprinting scripts. |
| CNAME cloaking | Consent requirements for the underlying tracking purpose apply regardless of the DNS obfuscation layer. The ICO has stated that storage-and-access consent obligations apply regardless of technical mechanism. | CNAME cloaking does not change the CCPA analysis of what data is collected and for what purpose. | Authentication cookie exfiltration via CNAME endpoints may create breach notification exposure. [^9] |
| Server-side tracking | GDPR applies regardless of where processing occurs. The critical compliance gap: consent signals captured client-side must propagate to server-side containers. Many deployments do not implement this propagation. | CCPA obligations attach to the data collected and the purpose, not the collection mechanism. Server-side tracking of California consumers requires the same disclosure and opt-out mechanisms as client-side tracking. | No direct CIPA exposure for server-side data handling that does not involve client-side interception. |
| Cross-device tracking | GDPR data minimization (Article 5(1)(c)) constrains identity resolution scope: link devices only to the extent necessary for the stated purpose. | Disney DTC settlement establishes that opt-out suppression scope must match identity resolution scope used for targeting. Applies to account-based identity; enforcement logic extends toward probabilistic matching. [^3] | No direct CIPA exposure for cross-device linking that does not involve real-time interception. |
| Session replay | Processing of behavioral data requires consent for purposes beyond strict functionality. Transmission to third-party vendors constitutes a separate processing activity requiring its own lawful basis. | Sharing session replay data with vendors constitutes "sharing" personal information and triggers opt-out obligations. Risk assessment required if data informs behavioral profiles. | CIPA 631(a) exposure active and unresolved. Javier established retroactive consent is invalid. Mikulsky kept claims viable at pleading stage. Torres defense theory does not dispose of claims with well-pleaded real-time capture allegations. [^5] |
References
[^1]: Our response to Google's policy change on fingerprinting - ICO
[^2]: California Privacy Protection Agency - CPRA Rulemaking
[^4]: CCPA Settlement Targets Gaps in Opt-Out Processes - Jones Day
[^5]: Javier v. Assurance IQ, No. 20-16176 (9th Cir. 2022); Torres v. Prudential Financial, Inc., N.D. Cal. Apr. 2025; Mikulsky v. Bloomingdale's, 9th Cir. June 20, 2025. CIPA 631(a) litigation background: A privacy pro's CIPA playbook - IAPP
[^6]: Opt Me Out Act - California Legislature (SB/AB, October 2025)
[^7]: EU Artificial Intelligence Act - Article 5, Prohibited Practices (effective February 2, 2025)
[^8]: Web-Analytics Firm KISSmetrics Reverses Course on Sneaky Tracking - Wired
[^9]: An Analysis of First-Party Cookie Exfiltration due to CNAME Redirections - NDSS Symposium