The National Football League has been hit with a class action lawsuit in California state court, with website visitors alleging that the organization secretly embedded hundreds of tracking technologies on its official website to harvest personal information and monitor browsing behavior without proper consent.
The lawsuit, filed in Alameda County Superior Court, names NFL Enterprises LLC as the defendant and accuses the organization of violating both state and federal privacy laws through its data collection practices on NFL.com.
Thelma Kimmons, a California resident serving as the lead plaintiff, alleges that the NFL website automatically transmitted extensive information about users’ browsing behavior and identity to third-party networks. This included page views, product views, content interactions, IP addresses, and device and browser characteristics.
According to the complaint, visitors to NFL.com automatically received tracking technologies developed by major companies including Google and Facebook. These trackers allegedly collected identifying information and detailed behavioral data, which was then shared with third parties for advertising and marketing purposes.
Forensic testing cited in the lawsuit revealed that NFL.com deployed 182 third-party trackers before users could make any privacy choices. This included 24 cookies, four canvas fingerprinting scripts, and one session-recording tool. The session replay software allegedly recorded users’ mouse movements, clicks, scrolling behavior, navigation paths, and keystrokes entered into search fields.
Kimmons, who identifies herself as a San Francisco 49ers fan, states she visited NFL.com in January 2026 to check scores and schedules. During that visit, she claims the website generated a unique device fingerprint, recorded her browsing session, and shared her information with third parties for targeted advertising purposes.
A particularly concerning allegation in the lawsuit is that the website’s cookie consent banner provides users with a false sense of security. The plaintiff contends that trackers begin operating immediately when a visitor lands on the site, before users have any opportunity to opt out of data collection.
Even when users choose to opt out of cookies through the consent banner, the lawsuit alleges that the website continues to run 186 third-party trackers, including 25 cookies, four canvas fingerprints, and one session recorder.
The legal action brings claims under multiple privacy statutes, including the California Invasion of Privacy Act, the federal Electronic Communications Privacy Act, the California Computer Data Access and Fraud Act, the California Constitution’s right to privacy, and California’s unfair competition law.
Kimmons seeks to represent a nationwide class of website visitors whose information was allegedly collected without proper consent. The proposed class, represented by the San Francisco-based firm Potter Handy, is requesting statutory damages, injunctive relief, restitution, and attorneys’ fees.
Under California’s privacy law, the plaintiffs are seeking up to $5,000 per violation, along with statutory damages under the federal Wiretap Act. The lawsuit emphasizes that in the internet context, courts have repeatedly recognized that third parties become unauthorized interceptors when websites embed tracking technology that captures user communications in real time for commercial purposes.
The case highlights growing concerns about online privacy and the methods used by major organizations to collect and monetize user data, particularly when such collection occurs without explicit consent or even after users have attempted to opt out of tracking.

Leave a Reply