Defense Digest
The Third Circuit Clarifies Article III Standing in Website Replay Litigation
Defense Digest, Vol. 32, No. 3, September 2026
September 30, 2026
Key Points:
• The collection of ordinary website browsing activity does not constitute concrete injury as needed to have standing to bring a claim;
• The unauthorized capture of complete payment card information or similarly sensitive data may constitute a concrete privacy injury sufficient to establish standing;
• Allegations involving anonymous browsing behavior, standing alone, may not satisfy Article III’s concreteness requirement, and;
• Businesses using session replay, analytics, or similar website monitoring technologies should evaluate what information those tools collect, whether sensitive information is masked or excluded, and whether appropriate disclosures and consent mechanisms are in place.
On May 11, 2026, the United Stated Court of Appeals for the Third Circuit issued an important published, precedential opinion in In re BPS Direct LLC, 175 F. 4th 423 (3d. Cir. 2026) for companies that use website analytics and session replay technologies. The main issue in the case concerned whether website users have Article III standing to sue over the unauthorized capture of their online activity through session replay code. The Third Circuit held that plaintiffs who alleged their complete payment card information was secretly captured by website session replay software sufficiently alleged a concrete injury to establish Article III standing. However, plaintiffs who only alleged that their anonymous browsing activity was recorded failed to establish standing.
The decision provides meaningful guidance for the types of alleged privacy harms that may support federal jurisdiction in the growing wave of website tracking and session replay litigation.
Background
Bass Pro Shops and Cabela’s (BPS) embedded JavaScript “Session Replay Code” developed by a third-party provider on their retail websites. The code operated invisibly in users’ browsers and captured the user’s interaction on the website, including mouse movements, clicks, scrolls, keystrokes, and text entries, while recording data at intervals of just milliseconds. Critically, the Session Replay Code intercepted text inputs even if the user did not click “submit” or “enter,” allowing BPS and the third-party providers to create video replays of each user’s website visit.
Eight named plaintiffs filed a putative class action suit claiming that defendant BPS’s use of a JavaScript computer code known as “session replay code” without users’ consent violated various state and federal privacy laws.
Two of the plaintiffs completed purchases on the websites and entered personal identifying information, including names, addresses, and complete payment card information. The remaining six plaintiffs merely browsed the websites and did not submit identifying or financial information. The district court dismissed the action for lack of Article III standing. The Third Circuit affirmed in part, reversed in part, and remanded.
Holding
The Third Circuit held that for plaintiffs to have standing to bring their claim, they must first demonstrate a concrete injury that is closely related to traditional common law privacy torts such as intrusion upon seclusion or public disclosure of private facts. Browsing activity alone was insufficient to prove concrete injury. The court held that although the session replay technology allegedly captured browsing interactions, the information was neither particularly sensitive nor connected to the plaintiffs’ identities. As a result, the alleged injury was not sufficiently analogous to the common-law privacy torts relied upon by the plaintiffs.
The court reached a different conclusion for the two plaintiffs who entered their names, addresses, and complete credit or debit card numbers during online checkout. For these plaintiffs, the court found that the alleged injury closely resembled the common-law tort of intrusion upon seclusion. The court emphasized that complete payment card numbers are private financial information that individuals reasonably expect to remain free from unauthorized observation. Allegations that third-party software secretly recorded that information without the user’s knowledge constituted the type of unauthorized intrusion historically recognized by the common law.
This decision further develops the growing body of federal appellate authority addressing standing in website privacy litigation involving session replay technologies and similar tracking tools.
Saynyenoh is an Associate in our Philadelphia, PA office. She can be reached at (215) 575-2713 or SBWarner@MDWCG.com.
