Mount v. PulsePoint, Inc., 2016 WL 5080131 (2016)

Facts

  • Apple’s Safari browser had a default privacy setting that blocked third-party tracking cookies.
  • PulsePoint, Inc. (successor to ContextWeb) operated as a third-party online advertising company that served ads to users while they visited first-party websites.
  • Advertisers paid more when PulsePoint could serve targeted ads based on users’ browsing histories, so PulsePoint sought to collect browsing information through tracking cookies.
  • Because Safari’s default settings blocked third-party cookies, PulsePoint allegedly used a technical workaround (including JavaScript) to bypass the default block and place third-party tracking cookies on users’ devices without consent.
  • Plaintiffs Brian Mount and Thomas Naiman used Safari with the default cookie-blocking settings and alleged PulsePoint installed tracking cookies on their devices during the proposed class period (alleged as June 1, 2009 through February 29, 2012).
  • Plaintiffs alleged the tracking cookies (i) affected device performance, (ii) invaded their privacy, and (iii) enabled PulsePoint to profit by collecting and selling data derived from their browsing activity.
  • Plaintiffs did not plead specific, measurable device impacts (such as quantified storage depletion, data-usage charges, or documented slowdowns) and did not allege out-of-pocket losses tied to PulsePoint’s data practices.
  • Plaintiffs filed a putative class action in the Southern District of New York asserting a federal Computer Fraud and Abuse Act (CFAA) claim and New York statutory and common-law claims (including N.Y. Gen. Bus. Law § 349, trespass to chattels, and unjust enrichment).
  • PulsePoint moved to dismiss for lack of Article III standing and for failure to state a claim.

Issues

  1. Whether plaintiffs’ allegations that PulsePoint bypassed Safari’s default privacy settings and placed tracking cookies without consent alleged a concrete and particularized injury sufficient for Article III standing.
  2. Whether plaintiffs plausibly alleged “damage” or “loss” as defined by the CFAA based on cookie placement and generalized assertions of device burden.
  3. Whether plaintiffs stated an “actual injury” under N.Y. Gen. Bus. Law § 349, and whether they stated viable New York common-law claims (including trespass to chattels and unjust enrichment) without alleging measurable device impairment or compensable loss.

Decision

  • The court held plaintiffs had Article III standing because the alleged surreptitious tracking and circumvention of Safari’s default cookie-blocking setting constituted an alleged invasion of privacy sufficiently concrete for standing purposes.
  • The court dismissed the CFAA claim because plaintiffs failed to plead statutory “damage” or “loss,” relying only on conclusory assertions of diminished device performance and lacking facts showing qualifying monetary loss or impairment to data or systems.
  • The court dismissed the N.Y. Gen. Bus. Law § 349 claim for failure to plead “actual injury,” concluding that allegations of data collection and monetization, without a cognizable personal loss or concrete harm, were not enough.
  • The court dismissed trespass to chattels because plaintiffs did not allege substantial interference with their devices (no meaningful impairment, dispossession, or other tangible disruption).
  • The court dismissed unjust enrichment because plaintiffs did not plausibly allege that PulsePoint was enriched at plaintiffs’ expense in a way that supports restitution absent a cognizable deprivation to plaintiffs.
  • The Second Circuit later affirmed in a summary order for substantially the reasons stated by the district court.
  • Article III standing may be satisfied by an alleged intangible privacy injury when the alleged harm is similar in kind to harms traditionally actionable at common law (even if a particular state does not recognize the identical tort label).
  • A civil CFAA claim requires allegations of “damage” (impairment to the integrity or availability of data, a program, a system, or information) or “loss” (including certain response and restoration costs) meeting the statute’s thresholds; generalized cookie-related allegations without supporting facts do not suffice.
  • N.Y. Gen. Bus. Law § 349 requires a deceptive act or practice, causation, and “actual injury”; allegations of undisclosed tracking and data monetization must still connect to a concrete, non-speculative injury to the plaintiff.
  • Trespass to chattels under New York law requires substantial interference with the plaintiff’s possessory interest; minimal, unquantified use of device resources from cookies is insufficient.
  • Unjust enrichment requires a showing that equity and good conscience require restitution because the defendant’s benefit was obtained at the plaintiff’s expense; allegations of defendant profit alone, without a plaintiff loss recognized by law, are inadequate.

Conclusion

In Mount v. PulsePoint, Inc., the Southern District of New York held that alleged circumvention of Safari’s default cookie-blocking settings and undisclosed tracking stated a privacy injury sufficient for Article III standing, but dismissed the CFAA and New York claims because plaintiffs did not plead the statute-required CFAA damage or loss, did not allege “actual injury” under N.Y. Gen. Bus. Law § 349, and did not allege substantial device interference or a restitution-worthy deprivation supporting trespass to chattels or unjust enrichment.