Rodriguez v. Google LLC
- Richard Seeborg
- 3:20-cv-04688
- U.S. District Court · Northern District of California
- 18
In Rodriguez v. Google LLC, Judge Seeborg partly granted Google’s motion to dismiss claims about data collected from third-party apps.
The order affects the named plaintiffs’ six claims against Google and the potential class claims they sought to pursue; it allowed some claims to continue and dismissed others at the pleading stage.
What happened
Rodriguez v. Google LLC concerns claims by Anibal Rodriguez, JulieAnna Muniz, and seven other named plaintiffs that Google illegally collected data from their interactions with third-party apps using Google’s Firebase tools. They alleged both that Google collected data despite its Web & App Activity settings and that it used hidden software scripts.
The court found that the plaintiffs plausibly alleged they did not consent to Google’s collection through Google Analytics for Firebase when Web & App Activity was turned off. But the court found that app developers had consented to the collection, and that the plaintiffs’ allegations about hidden scripts did not describe the alleged fraud in enough detail. The court also evaluated each of the six claims separately.
Judge Seeborg granted Google’s motion as to the federal Wiretap Act claim, the California Invasion of Privacy Act’s section 632 claim, and the California Unfair Competition Law claim. He denied the motion as to the section 631 claim, the California Computer Data Access and Fraud Act claim, and the claims for intrusion upon seclusion and invasion of privacy. The plaintiffs were given 21 days to file an amended complaint.
The detailed version
- Rodriguez v. Google LLC · No. 3:20-cv-04688
- Richard Seeborg
- May 21, 2021
Background
Google provides Firebase software-development tools to third-party app developers. One optional tool, Google Analytics for Firebase, automatically sends information such as users’ URL requests, in-app browsing histories, and in-app search queries to Google, which analyzes the data for the developer.
The plaintiffs alleged that Google’s data collection violated representations in Google’s Web & App Activity materials. Those materials stated that Web & App Activity had to be turned on for Google to save information about a user’s activity on sites, apps, and devices using Google services. The plaintiffs used third-party apps supported by Firebase and alleged that Google collected their app activity even when Web & App Activity was turned off.
The plaintiffs advanced two theories. First, they alleged that Google Analytics for Firebase collected data through its disclosed functionality despite Google’s privacy representations. Second, they alleged that Google embedded undisclosed “secret scripts” in the Firebase toolkit that collected and sent data to Google without users’ or app developers’ knowledge. Google moved to dismiss, arguing principally that the collection was covered by consent.
Consent and secret-script allegations
At the motion-to-dismiss stage, the court held that the plaintiffs plausibly alleged that they had not consented to Google’s collection through Google Analytics for Firebase when Web & App Activity was turned off. The court concluded that the phrase “Google services” in the Web & App Activity materials could plausibly include Google Analytics for Firebase, and that the materials did not clearly explain the scope of a “Google Account” or how the feature interacted with data collected through third-party apps.
The court reached the opposite conclusion regarding developer consent. The plaintiffs conceded that app developers knowingly agreed to let Google Analytics for Firebase collect consumer data. The court rejected the plaintiffs’ theory that developer consent depended on every user’s interpretation of Google’s other privacy settings. It held that, on the pleadings, developers had consented to Google’s collection regardless of the plaintiffs’ understanding of or interaction with Web & App Activity.
The court also held that the secret-script allegations did not satisfy Federal Rule of Civil Procedure 9(b), which requires fraud to be pleaded with particularity, including the basic details of who, what, when, where, and how. The complaint did not identify when the alleged plan began, which Google departments or employees were involved, or a particular date, time, or place. The court said the allegations were underdeveloped and did not rely on them in the claim-specific analysis.
Claims and ruling
The plaintiffs brought six claims: a claim under section 2511(1)(a) of the federal Wiretap Act; claims under sections 631 and 632 of the California Invasion of Privacy Act; a claim under the California Computer Data Access and Fraud Act; a common-law intrusion-upon-seclusion claim; a California constitutional invasion-of-privacy claim; and a California Unfair Competition Law claim.
The court granted the motion with respect to the Wiretap Act claim because the alleged interceptions occurred with the consent of the app developers, which the court treated as a complete defense. It also granted the motion as to the section 632 California Invasion of Privacy Act claim. That provision concerns recording or eavesdropping on confidential communications, and the court held that the plaintiffs had not pleaded the specific circumstances needed to overcome California’s presumption that internet communications do not ordinarily create a reasonable expectation of confidentiality.
The court granted the motion as to the California Unfair Competition Law claim for lack of standing. The plaintiffs had alleged that they paid for certain apps through which Google received money, but they did not identify the apps, the dates, or the amounts. The court also concluded that any purchases were not plausibly caused by the apps’ data-collection practices.
The court denied the motion as to the section 631 California Invasion of Privacy Act claim because the plaintiffs plausibly alleged that Google intentionally intercepted the contents of their communications without their consent. It also denied the motion as to the California Computer Data Access and Fraud Act claim because the plaintiffs plausibly alleged that Google knowingly accessed their app-activity data and took or used it without permission. The court further denied the motion as to the common-law intrusion-upon-seclusion and California constitutional invasion-of-privacy claims, finding that the alleged collection of detailed URL requests, app browsing histories, and search queries could support a reasonable expectation of privacy and that the question whether the conduct was highly offensive could not be resolved at the pleading stage.
Disposition
The court granted in part and denied in part Google’s motion to dismiss. The order granted the motion as to the Wiretap Act, section 632 of the California Invasion of Privacy Act, and California Unfair Competition Law claims, and denied it in all other respects. The plaintiffs were given leave to file an amended complaint within 21 days. If they filed one, Google would have 14 days to respond; if they did not, Google would have 14 days after notice of that decision to answer the first amended complaint.
Read the full 18-page opinion on CourtListener, the free public archive maintained by the Free Law Project.