Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Substantive rulingFiled Jan. 7, 2025

Rodriguez v. Google LLC

Judge
Richard Seeborg
Docket
3:20-cv-04688
Court
U.S. District Court · Northern District of California
Pages
20
Summary JudgmentTortClass ActionCivil Procedure
In one sentence

Rodriguez v. Google, Judge Seeborg denied Google’s summary-judgment motion, finding factual disputes over privacy disclosures, consent, and alleged data-related harm.

Who this affects

The ruling affects the plaintiffs—members of two subclasses of Android and non-Android mobile-device users whose specified Google privacy settings were turned off—and Google LLC. It allows the plaintiffs’ claims to proceed past summary judgment but does not determine ultimate liability.

What happened

In Anibal Rodriguez, et al. v. Google LLC, users whose Web App and Activity settings were turned off sued Google over its collection of activity data through tools used in third-party apps. They brought claims under the California Constitution, California common law, and the Comprehensive Computer Data Access and Fraud Act.

Google argued that users had consented, its disclosures clearly explained what the settings controlled, it did not use the data to personalize ads, and the collection caused no actionable harm. The court found genuine factual disputes about what the settings promised, whether users revoked permission by turning them off, whether the data was personal, and whether Google suffered legally recognized harm. Those disputes prevented judgment for Google before trial.

Judge Seeborg denied Google’s motion for summary judgment and granted the parties’ motions to seal specified materials. The ruling did not decide whether Google is ultimately liable; it allowed the claims to proceed based on the disputed facts.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Rodriguez v. Google LLC · No. 3:20-cv-04688
Judge
Richard Seeborg
Date
Jan. 7, 2025

Background

This privacy class action concerns Google’s Web App and Activity (WAA) and supplemental Web App and Activity ((s)WAA) account settings. The plaintiffs are members of two subclasses involving people with Android and non-Android mobile devices who had certain privacy settings turned off. They allege that Google’s user-facing privacy representations conflicted with its collection of activity data through Google Analytics for Firebase (GA4F) and related tools used in third-party applications.

The plaintiffs assert three claims: invasion of privacy under the California Constitution, common-law intrusion upon seclusion, and violation of the Comprehensive Computer Data Access and Fraud Act (CDAFA). Google sought summary judgment on all claims. Summary judgment is a decision before trial available when the evidence shows no genuine dispute over facts that could affect the result and the moving party is entitled to judgment under the law.

The data and privacy settings

The WAA setting is described as controlling the saving of web and app activity, including searches, activity from other Google services, location information, and device information. The (s)WAA setting concerns Chrome history and activity from sites, apps, and devices using Google services, and it can be turned on only when WAA is also on.

The opinion states that GA4F automatically sends Google certain ad interactions and identifiers regardless of a user’s (s)WAA settings. Google describes the resulting information as pseudonymous, meaning that it uses generated identifiers rather than directly identifying information. The opinion discusses device identifiers, including Android advertising identifiers and iOS identifiers for advertisers, as well as Google account identifiers that can link information to a particular account holder. Google maintains that it separates pseudonymous data from account-linked data through technical barriers and internal policies.

Google argued that its collection served analytics for third-party developers and involved only non-personally identifiable information. The plaintiffs argued that the collection obtained the very information users reasonably believed would not be collected when they turned (s)WAA off, and that the data could help connect ad interactions with later behavior. They also argued that Google benefited financially from using the data. Google denied using the data to create marketing profiles or personalize advertising for users who had turned the settings off.

Privacy disclosures and consent

The court rejected Google’s argument that the disclosures clearly told users that turning (s)WAA off affected only whether data was linked to a Google account, rather than whether Google collected the data. The court found that the disclosures could reasonably be understood to mean that Google would not collect the relevant app-activity data at all. It also found that the Privacy Policy did not clearly resolve the meaning of the WAA and (s)WAA settings or clearly distinguish the settings’ operation from the treatment of personal and non-personally identifiable information.

The court concluded that a reasonable user could view the collected information, including unique device identifiers, as personal information. It also found a factual dispute about consent. In the court’s view, it was unclear whether a reasonable user understood the disclosures as consenting to the challenged data collection. The court further held that the question under CDAFA was whether turning (s)WAA off revoked permission and whether Google knew or should have known that permission had been revoked. That question could not be resolved as a matter of law because the disclosures and related evidence were open to competing interpretations.

The court rejected Google’s argument that consent obtained by third-party app developers necessarily gave Google permission to collect the data. It found that Google cited no relevant authority establishing that proposition under CDAFA. The court also reasoned that, assuming users revoked permission by turning (s)WAA off, third-party permission would not necessarily allow Google to access the data through another route.

Invasion-of-privacy claims

The California constitutional and common-law privacy claims require a reasonable expectation of privacy and an intrusion that would be highly offensive to a reasonable person. The common-law claim also requires intent to commit the intrusion.

The court found factual disputes about whether the plaintiffs had a reasonable expectation of privacy in the data collected while (s)WAA was off. It explained that information need not directly identify a person to be private. The court also found a factual dispute about whether Google’s conduct was highly offensive. Although the plaintiffs had not shown that Google actually used the data to create highly targeted and invasive marketing profiles, evidence about ambiguous disclosures and internal Google communications could support the plaintiffs’ position that Google knowingly kept the disclosures unclear.

The court rejected Google’s argument that the privacy claims failed because the plaintiffs had only a bare privacy injury or could not show class-wide emotional harm. It explained that privacy torts can be actionable based on the intrusion itself and that the availability of only nominal damages on one theory would not defeat the claims at the summary-judgment stage.

CDAFA claim

CDAFA imposes liability on a person who knowingly accesses and, without permission, takes data from a computer. It also allows a private civil action by an individual who suffers damage or loss because of a violation.

The court found a genuine dispute over the permission requirement. It held that the relevant question was not simply whether users had once permitted data use, but whether turning (s)WAA off revoked that permission and whether Google knew or should have known of the revocation. The court also found factual disputes about whether the plaintiffs suffered damage or loss.

The plaintiffs’ theories included deprivation of privacy, Google’s alleged profits from the data, failure to pay for data with economic value, and depletion of device battery and bandwidth. The court stated that the deprivation-of-privacy theory, standing alone, appeared limited to nominal damages based on emotional harm. But it found that the plaintiffs’ theories concerning Google’s profits and the economic value of their data could satisfy CDAFA’s damage-or-loss requirement. The court also found sufficient evidence at this stage concerning battery and bandwidth depletion, even though the plaintiffs had not quantified that depletion and acknowledged that only nominal damages would be available under that theory.

The court did not find authority supporting the plaintiffs’ separate argument that denial of the benefit of the bargain constituted CDAFA damage or loss without a contract claim. That theory was linked to a breach-of-contract claim that the opinion says had been dismissed. The court nevertheless denied summary judgment on the CDAFA claim because other damage-or-loss theories remained supported by disputed evidence.

Sealing and disposition

The parties filed administrative motions to seal portions of exhibits. The court found that the requests satisfied the required compelling-reasons standard for materials connected to dispositive motions and that the requests were narrowly tailored. The court granted the pending motions to seal.

Judge Seeborg denied Google’s motion for summary judgment and granted the pending motions to seal. The parties were ordered to file public versions of their briefs and related exhibits under the sealing order within one week of the order.

The authoritative version

Read the full 20-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.