A significant legal development has placed Shopify, the well-known Canadian e-commerce platform, at the center of renewed scrutiny over data privacy practices. A U.S. federal appeals court has recently revived a data privacy class action lawsuit against the company, marking a pivotal moment in the evolving landscape of digital consumer protection. The case, rooted in allegations of unauthorized data tracking and profiling, has reignited debate about how far state courts in the United States can extend their legal reach over global, internet-based businesses. This revival not only raises pressing questions about jurisdictional authority but also underscores the growing importance of data privacy in a world increasingly shaped by cross-border digital interactions and e-commerce expansion.
Background of the Case
The lawsuit centers on serious allegations brought by Brandon Briskin, a California resident. Specifically, he claims that Shopify installed tracking software—commonly referred to as cookies—on his iPhone without obtaining his consent. This incident reportedly occurred during a purchase he made from the retailer “I Am Becoming.”
As a result, Briskin argues that Shopify used the data collected through these cookies to build a consumer profile about him. Furthermore, he asserts that this profile was later sold to other merchants for commercial gain.
However, Shopify disputes these claims. In its defense, the company maintains that it should not fall under California’s jurisdiction. Instead, Shopify argues that its business operations are nationwide and not specifically directed toward any individual U.S. state. Consequently, the company contends that being subjected to California law in this matter is inappropriate and legally unfounded.
Court’s Decision and Its Implications
In a 10-1 decision, the 9th U.S. Circuit Court of Appeals in San Francisco ruled that Shopify can indeed be sued in California. The court found that Shopify “expressly aimed” its conduct toward California by knowingly installing tracking software onto the devices of California residents, thereby collecting and monetizing their data. This ruling overturns previous decisions by a lower court and a three-judge panel that had dismissed the case due to lack of jurisdiction.
The court’s decision emphasizes that internet-based companies can be held accountable in states where they deliberately engage in activities that affect residents, even if the company is based elsewhere. This sets a precedent that could influence how jurisdiction is determined in cases involving online platforms and data privacy.
Broader Legal and Industry Reactions
The ruling has garnered attention from various stakeholders. A coalition of 30 states and Washington, D.C., supported Briskin, highlighting the importance of upholding state consumer protection laws in the digital age. They argue that companies benefiting from local markets through the internet should be subject to the jurisdiction of those states.
Conversely, the U.S. Chamber of Commerce and other industry groups have expressed concern that this decision could expose internet companies to lawsuits in multiple jurisdictions, potentially leading to a fragmented legal landscape and increased compliance burdens.
Applicable Compliance Regulations and Broader Legal Context
The revival of the class action lawsuit against Shopify does not exist in isolation. It sits at the intersection of several key data privacy regulations that have gained traction globally in recent years. For organizations handling user data across borders, understanding and complying with these regulations is no longer optional—it’s foundational to business sustainability and consumer trust.
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
The lawsuit against Shopify directly intersects with California’s groundbreaking privacy laws, particularly the California Consumer Privacy Act (CCPA) and its successor enhancement, the California Privacy Rights Act (CPRA).
- CCPA, which took effect in 2020, grants California residents robust rights over their personal information. These rights include knowing what data is collected, the ability to opt out of its sale, and the right to deletion.
- CPRA, which became enforceable in 2023, expands the original CCPA and introduces new protections. It also created the California Privacy Protection Agency (CPPA) to enforce compliance. CPRA mandates stricter handling of sensitive personal information, including precise geolocation data, biometric data, and data on health or race.
Shopify’s alleged unauthorized data tracking and profiling could potentially violate multiple aspects of these laws, especially around transparency and user consent.
General Data Protection Regulation (GDPR)
Although this case is rooted in U.S. law, Shopify is a global platform and must also comply with the General Data Protection Regulation (GDPR) when handling data of European Union (EU) citizens.
- GDPR requires companies to obtain clear and affirmative consent before collecting personal data.
- It mandates data minimization, purpose limitation, and the right to be forgotten.
- Violations can lead to penalties of up to €20 million or 4% of global revenue, whichever is higher.
Even though GDPR is not being applied directly in the Shopify case, the legal expectations it establishes have influenced similar privacy expectations worldwide, including in California and other U.S. states.
Other U.S. State Privacy Laws
Several U.S. states have passed or are in the process of enacting data privacy laws similar to CCPA/CPRA. These include:
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Connecticut Data Privacy Act (CTDPA)
- Utah Consumer Privacy Act (UCPA)
These laws are converging on key principles: transparency, consent, access to data, and the right to opt out. As more states adopt these laws, the U.S. is inching toward a patchwork data compliance landscape, increasing complexity for platforms like Shopify that operate nationwide.
Federal Legislative Movement: The American Data Privacy Protection Act (ADPPA)
There have been ongoing bipartisan discussions around introducing a federal data privacy law, the American Data Privacy Protection Act (ADPPA). While not yet law, the ADPPA aims to harmonize data privacy rights across all 50 states, reducing regulatory fragmentation for businesses and improving protections for consumers.
If passed, it could impact how cases like Shopify’s are pursued, potentially creating a more unified standard for what constitutes data misuse and jurisdiction.
Jurisdiction in the Digital Age: A Growing Legal Question
A core issue in the Shopify lawsuit is jurisdiction—whether a company that operates globally can be held accountable under the laws of any specific state or country in which it collects user data. The U.S. Ninth Circuit ruling highlights an emerging judicial consensus: if a company intentionally collects, stores, or processes data from a resident of a given jurisdiction, that jurisdiction may have the right to litigate privacy violations.
This opens the door for more localized privacy claims, even against global firms, and introduces new legal risk for platforms not maintaining region-specific compliance mechanisms.
Similar Historical Cases and Industry Lessons
Facebook and the Cambridge Analytica Scandal
One of the most widely discussed privacy cases, Facebook’s handling of data related to Cambridge Analytica, set a global precedent. The company was fined $5 billion by the Federal Trade Commission (FTC) and faced class action suits after it was revealed that user data was harvested without consent and used for political profiling.
Google’s Location Tracking Lawsuits
Google has faced several lawsuits related to unauthorized location tracking, even when users had disabled such tracking features. In 2022, the company paid $391.5 million in a multistate settlement, the largest internet privacy settlement in U.S. history at that time.
These cases illustrate a clear trajectory: courts are increasingly holding tech companies accountable for non-consensual data collection practices, especially when they conflict with user settings or expectations.
How Businesses Should Respond: A Compliance Checklist
To avoid similar litigation and stay ahead of regulatory developments, digital platforms should consider the following compliance priorities:
- Transparent Consent Mechanisms
Ensure all data collection is preceded by clear, informed user consent, with opt-in models preferred over opt-out. - Region-Specific Privacy Policies
Tailor privacy policies and compliance practices to meet jurisdictional requirements, especially in high-risk regions like California and the EU. - Cookie and Tracker Disclosure
Fully disclose all third-party trackers and cookies used on the platform, with user-friendly controls for disabling them. - Data Mapping and Inventory
Maintain a detailed inventory of what data is collected, why it is collected, where it is stored, and how it is used. - Incident Response and Breach Reporting
Have a clear, actionable plan in place to notify users and regulators in the event of a data breach. - Training and Internal Audits
Regularly train employees and conduct audits to ensure data handling practices align with current laws and industry best practices.
Conclusion: Shopify’s Legal Challenge as a Data Privacy Milestone
Shopify’s revived lawsuit is more than a localized legal case—it represents a turning point in how courts, consumers, and regulators approach digital accountability. With the increasing overlap between consumer rights, data ethics, and regulatory enforcement, this case will likely influence future decisions in both the U.S. and abroad.
Companies must recognize that data privacy is no longer just an IT or legal issue. It is a cross-functional priority that intersects with product design, marketing, customer support, and brand reputation. As Shopify and others face mounting legal scrutiny, the message is clear: proactive, user-centric compliance is not just safer—it’s smarter.