International

Privacy in the US: Could the NFL Class Action Make the Case for European CMPs?

Content

A few weeks ago, the World Cup had the whole country talking about soccer. This summer, it's the other kind of football that has landed in the privacy spotlight. In early July, a class action was filed in California against the National Football League's website. According to the complaint, 182 third-party trackers fired on the site before the user, Thelma Kimmons, had any chance to make a choice, and 186 were still running after she declined cookies and opted out.

The case is only in its early stages. It nonetheless says a great deal about how attitudes toward online consent are shifting in the United States. In this summer edition of Compliance Check-Up, we look at the case itself, at what it reveals about the gap between the European framework and US law, and at the mechanisms already available in Axeptio to handle opt-out signals properly on the American market.


NFL v Kimmons Class Action

Trackers, Fingerprinting, Session Recording: In Kimmons v. NFL Enterprises LLC, Cookies Are Only the Tip of the Iceberg

According to the analysis published by the National Law Review, Thelma Kimmons, a California resident, says she visited NFL.com around January 2026. She alleges that the moment she landed on the site, the NFL caused a whole series of trackers and cookies from vendors including Google, The Trade Desk, Rubicon Project, OpenX, LogRocket, Inc. and Shape Security to be installed on her browser.

Forensic testing then became the backbone of the case. It reportedly found 182 third-party trackers deployed before the user could configure any preferences, among them 24 cookies, 4 fingerprinting scripts and 1 session recorder, according to Courthouse News Service.

Several legal grounds are said to be at stake, and the damages sought could climb to $5,000 per violation under Section 637.2 of CIPA and, under the ECPA, the greater of $10,000 or $100 per day per violation.

Kimmons v. NFL Enterprises LLC is far from an isolated case. A wave of similar class actions is currently making its way through various US states, with plaintiffs relying in particular on electronic eavesdropping and wiretapping statutes such as CIPA. Faced with this surge in filings, US courts will inevitably have to rule on how far these laws reach when applied to cookies and other online tracking technologies.

The most interesting allegation, though, concerns the opt-out itself: declining trackers through a banner designed to refuse cookies allegedly did nothing to stop the data processing.

The complaint argues that the banner gives users a false sense of security, for two reasons:

  • Trackers allegedly fire as soon as the page loads, before any interaction with the banner. Fingerprinting, session recording and the placement of cookies and pixels would therefore already have happened by the time the user expresses a choice.
  • Declining cookies allegedly has no effect on session recording, on fingerprinting scripts, or on any other script that does not rely on cookies to work. According to the testing cited in the complaint, 186 third-party trackers were still running after the user had opted out through the interface.

As the National Law Review points out, several questions have yet to be settled: did the banner cover every technology at issue, was the information provided sufficient, had consent been obtained by some other means, and so on. Even so, the case makes one thing plain: when a consent interface only governs cookies, it covers just a fraction of what the site is actually collecting.

A New Era of the US Privacy Market

The European and US frameworks part ways on one key principle: opt-in versus opt-out by default. More precisely, the ePrivacy Directive, transposed into French law through the Loi Informatique et Libertés, requires prior consent (opt-in) before any non-essential tracker is placed. US laws, starting with California's CCPA, allow trackers to run as soon as the user arrives, provided they are offered an effective and immediately accessible right to object (opt-out). We mapped out these differences state by state in Privacy Made in the USA, which as of May 2025 already counted fourteen states with a data protection law on the books, with six more having taken effect since.

That contrast shapes both the user experience and the way the banner behaves, with three display modes available to bring an Axeptio banner in line with the CCPA, described in our dedicated article.

What the divergence hides, however, is a shared requirement: once a user expresses a preference, it has to be broadcast to every partner the page calls.

In Europe, the GDPR took effect in 2018, but it was the investigations and penalties handed down by authorities such as the CNIL that gradually set the bar and drove mass adoption of CMPs.

By bringing lawsuits against high-traffic sports organizations like the NFL, US law firms could well be laying the groundwork for a major new chapter in the evolution of privacy in the United States.

Maître Christophe Landat Lawyer and co-founder of Axeptio

Christophe Landat

 

GPC and GPP: Two Standards for Broadcasting User Preferences, Already Live in the US (and in Axeptio)

Two standards currently handle how user preferences travel across the US ecosystem.

The first is the Global Privacy Control (GPC), a signal emitted by the browser and passed through HTTP headers to every service the site calls. Since January 1, 2026, honoring it has been mandatory in four states: California, Colorado, Connecticut and New Jersey. At Axeptio, detection is enabled by default on every new CCPA configuration, and a toast module tells users their preference has been recognized while giving them the option to change it for that particular site. You'll find the full details in our article on the GPC.

The second is the Global Privacy Protocol (GPP), developed by the IAB Tech Lab primarily for publishers, which encodes user preferences into a single string, the GPP String. It builds on the Multi-State Privacy Agreement (MSPA), a contractual framework that aligns signatories on a single interpretation of the preferences they receive. Axeptio supports the GPP directly from its back-office, and you can read how it works in full in our dedicated article.

That said, in light of Kimmons v. NFL Enterprises LLC, the GPC and the GPP settle the question of transmitting the user's choice, not the question of whether third-party vendors actually act on it. Which leaves one thing to be determined: who, in the United States, will set the bar. In Europe, it was data protection authorities such as the CNIL. The Kimmons case suggests the answer will this time come from the courts, and given the financial exposure at stake, companies operating in the US market have little reason to wait for the first ruling to find out where they stand. All the more reason to talk to our experts.

Elodie Meeuwenberg

Elodie Meeuwenberg

Business Lawyer and Data Protection Officer (DPO)

Elodie Meeuwenberg
Elodie Meeuwenberg

Business Lawyer and Data Protection Officer (DPO)

Check your site's compliance
Receive a monthly summary of the latest news on acquisition, web, and compliance.

Stay up to date on the latest AdTech and MarTech news by subscribing to our newsletter.

Sign up for the newsletter
Clip path group-3