VPPA & Pixels

Privacy & Compliance / Law guide

The Video Privacy Protection Act (VPPA) and Tracking Pixels

Summary

The Video Privacy Protection Act (VPPA) is a 1988 federal law that stops a business offering video from sharing what a person watched, tied to who they are, without consent. When a video page’s pixel sends the video watched with an identifier, plaintiffs argue it disclosed viewing history. A court may award at least $2,500 in liquidated damages.

Congress passed the VPPA after a Washington weekly published a profile of Supreme Court nominee Robert Bork built from his family’s video rental titles. The Meta Pixel and similar tags have brought it into website cases, because a pixel on a page with video can transmit exactly the pairing the law was written to protect: the title of what was watched and something that identifies the watcher.

The sections below cover what the VPPA prohibits, how a tracking pixel creates exposure, and whether the law is settled. They finish with who is exposed and how to reduce VPPA exposure.

What does the VPPA prohibit?

The VPPA, codified at 18 U.S.C. § 2710, prohibits a “video tape service provider” from knowingly disclosing personally identifiable information about a consumer that reveals the specific video materials they requested or watched, unless the consumer gave consent. The cases now before the courts involve online video and websites, and courts are still working out which businesses the definition covers.

Two terms carry the weight. A consumer is someone who rents, buys, or subscribes to goods or services from the provider. Personally identifiable information is information that identifies a person as having watched specific material. The dispute in today’s cases is how broadly each of those reaches, which is where the law is currently unsettled.

How does a tracking pixel create VPPA exposure?

The pattern is specific to pages with video. A visitor watches a video on your site. A pixel on that page sends a request to a third party, often Meta, that includes the video’s title or URL and an identifier for the visitor, such as the Facebook ID stored in a cookie. Put together, that request can reveal that this identifiable person watched this specific video, which is the disclosure the VPPA restricts.

A pixel on a video page sends the episode watched with the viewer's platform user ID: what was watched plus who watched it.

The exposure needs three things present at once: video content, a pixel that captures what was watched, and an identifier sent alongside it. A site with no video is not a VPPA target. A site with video but no identifying pixel on those pages is not either.

Is the law settled?

No, and this matters for how seriously to weigh any single headline. Courts have split on who counts as a “consumer” and on whether pixel data actually identifies a viewer.

The Supreme Court agreed in January 2026 to decide part of it. In Salazar v. Paramount Global, the Court took up who counts as a VPPA “consumer”: whether the “goods or services” that make someone a consumer must be audiovisual, or whether any purchase from a video provider counts. The Court hears argument on October 14, 2026, and a decision is expected by mid-2027. Federal appeals courts have also disagreed on a second question, what counts as personally identifiable information. The Second Circuit held in 2025 (Solomon v. Flipps Media) that video URLs and a Facebook ID sent in code were not personally identifiable information, because an ordinary person could not use them to identify what someone watched. The First Circuit applies a broader test. The result is that identical tracking can be treated differently depending on where a case is filed, and the Supreme Court’s ruling will settle only the “consumer” question.

For specific VPPA lawsuits and settlements by company, see our Enforcement Watch tracker. This page covers the law and how to reduce exposure.

Who is exposed?

Any business with video on its site and a marketing or analytics pixel on those pages. Media and streaming are the obvious cases. Any site that shows video and sends viewing data with an identifier could face the same theory. If a page plays video and a pixel there sends an identifier, the pairing the VPPA restricts can occur.

How to reduce VPPA exposure

Two controls address the fact pattern.

Get the right consent before the pixel fires on video pages. The VPPA’s consent exception requires informed, written consent in a separate form, which can be given online, lasts up to two years, and must be withdrawable. A general cookie banner click has not been shown to meet that standard, so check the form with counsel and keep the pixel from firing on video pages until you have it.

Know what your pixel sends from pages with video. The exposure is a specific payload: the video watched plus an identifier. You reduce it by confirming which pages have both a pixel and video, and what those pixels actually transmit.

DataTrue checks the second part directly. It loads your video pages in a real browser and records what each tag sends, so you can see whether a pixel is transmitting a video title or URL together with an identifier, and whether it fires before consent. Sensitive Data Detection inspects the payloads with fictitious personas, so you learn what leaves the page without using a real visitor. The result is a record of which video pages carry the VPPA pattern and which do not.

See how consent verification works

The VPPA is one of the US laws in our US website tracking compliance hub.

Questions

What is the Video Privacy Protection Act (VPPA)?

The VPPA is a 1988 federal law, at 18 U.S.C. § 2710, that prohibits a business providing video from knowingly disclosing what a consumer watched tied to their identity, without consent. A court may award actual damages but not less than $2,500 in liquidated damages, plus punitive damages and attorney’s fees. Tracking pixels on pages with video have made it a common basis for class actions.

Does the VPPA apply to my website?

It applies if your site offers video and a pixel or tag on those pages shares what a visitor watched along with an identifier. A site with no video, or with no identifying pixel on its video pages, is not a VPPA target.

How much are VPPA damages?

A court may award actual damages but not less than $2,500 in liquidated damages, plus punitive damages and attorney’s fees.

Is the VPPA settled law for pixels?

No. Courts disagree on who counts as a “consumer” and on whether pixel data identifies a viewer. The Second Circuit applies an “ordinary person” test to what counts as personally identifiable information, the First Circuit applies a broader one, and the Supreme Court hears the “consumer” question on October 14, 2026, with a decision expected by mid-2027. Treat any single ruling as part of a moving picture.

30-day free trial

See what your tags do in every consent state

DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue opt-out consent test listing the tags that should be blocked, with pass or fail for each
A consent-state test in DataTrue