← All Articles

De La Torre v. Taboola Tests Whether Ad Tech's Surveillance Violates Federal Data Rules

Plaintiffs Allege Taboola's Tracking Code Intercepted Their Browsing Data and Sent It to Chinese Military-Linked Firms

The class action complaint filed July 24 in the U.S. District Court for the Southern District of New York alleges that Taboola, Inc. operates a "clandestine surveillance network" that intercepts users' browsing data without consent and transmits it to Chinese companies designated as national security threats by the U.S. government. The suit, De La Torre et al. v. Taboola, Inc., targets Taboola's real-time bidding (RTB) system, which the plaintiffs claim broadcasts sensitive personal data to third parties, including companies on the U.S. Department of Defense's 1260H List of Chinese military companies. The complaint alleges that "RTB data is a 'goldmine for foreign intelligence services,' enabling hacking, blackmail, and influence campaigns due to lack of transparency and secondary use controls" (Compl. ¶59). Taboola's practices, the complaint asserts, represent "one of the most pervasive and intrusive consumer surveillance operations on the internet" (Compl. ¶1). The complaint further states, "Taboola intentionally acquires and exploits intimate information about unsuspecting consumers through hidden tracking code" (Compl. ¶2).

Taboola assigns persistent, cross-device profiles tied to unique identifiers like Taboola's "t_gid" (Taboola ID), which the company uses to track users across unrelated websites. These profiles include inferences about users' health, finances, and personal characteristics, which Taboola then assigns to behavioral segments. For example, the complaint alleges that named plaintiff Alessandro De La Torre was assigned segments predicting health conditions, military service, and donor status without his knowledge or consent. The complaint states that Taboola classified De La Torre under segments such as "Type 1 Diabetes Propensity" and "Military > Active > Precision", exposing his sensitive personal data to foreign adversaries (Compl. ¶115–116). The complaint further alleges that Taboola intercepted De La Torre’s browsing data on sites like TurboTax.Intuit.com and HindustanTimes.com without his consent, stating, "Plaintiff De La Torre did not consent to the collection or synchronization of his personal identifiers" (Compl. ¶121). De La Torre’s net asset value was classified by Taboola as $0–$24,999, and he was also assigned to financial distress segments such as "Credit Seeking Card Switcher" and "High Credit Card Balance" (Compl. ¶117). Additionally, the complaint alleges that Taboola mapped De La Torre’s political beliefs via segments provided by i360, a political data firm, including classifications related to the Second Amendment, immigration, and healthcare (Compl. ¶119). The complaint describes Taboola’s profiling practices as creating "comprehensive ‘cradle-to-grave’ user profiles that track individuals’ behaviors, interests, and traits" (Compl. ¶6).

Plaintiff John Baker was similarly profiled, with Taboola classifying him under segments including "Smokers", "Black", "LGBT Donor", and "Newly Single" (Compl. ¶130, 136). The complaint further alleges that Taboola inferred Baker’s household income range as $50,000–$59,999 and his homeowner’s insurance value as $50,000–$74,999 (Compl. ¶139). Taboola also modeled Baker’s relationship status, assigning him segments such as "Newly Single" and "Divorced", and inferred his household composition, including the presence of "2 Children 6-17" and a female child (Compl. ¶137–138). The complaint states that Taboola classified Baker’s credit level as "Poor" and his net asset value as $0–$24,999, while also assigning him to over 1,750 audience segments (Compl. ¶132, 141). The complaint describes the depth of Taboola’s profiling of Baker as "stunning," noting that "the detail of Taboola’s inferred map of Plaintiff Baker’s personal life is stunning" (Compl. ¶139). Taboola sourced Baker’s segments from data brokers including Experian, Equifax, LiveRamp, and others (Compl. ¶140).

Real-Time Bidding System Broadcasts User Data to Dozens of Third Parties, Including Chinese Firms

The complaint focuses on Taboola's synchronization of user data with three Chinese companies: Baidu, Tencent, and Temu. Baidu and Tencent were added to the U.S. Department of Defense's 1260H List in 2026 and 2025, respectively, designating them as Chinese military companies. Temu, an e-commerce platform owned by PDD Holdings, has faced scrutiny from U.S. lawmakers and state attorneys general over its data practices. The complaint alleges that Taboola's transfers to these companies violate the U.S. Department of Justice's Bulk Sensitive Data (BSD) Rule, codified at 28 C.F.R. Part 202, which took effect on April 8, 2025. The BSD Rule prohibits "covered data transactions" involving bulk transfers of sensitive personal data to "countries of concern," including China. The rule defines "bulk" transfers as those involving data linked to more than 100,000 U.S. persons over a twelve-month period (Compl. ¶86). The complaint alleges that Taboola’s activities constitute "covered data transactions involving data brokerage and is unlawful because IP addresses and advertising identifiers, when transferred in bulk, qualify as bulk covered personal identifiers" (Compl. ¶87). The complaint further states that the BSD Rule was issued to address the "unusual and extraordinary threat to the national security and foreign policy of the United States" posed by bulk sensitive data transfers to foreign adversaries (Compl. ¶97).

The complaint provides specific examples of these transfers. In June 2025, plaintiff De La Torre visited HindustanTimes.com, where Taboola's code intercepted and shared his data with Baidu, Tencent, and Temu. The complaint alleges that Taboola's bid requests included De La Torre's cookie IDs, device IDs, IP address, and thousands of audience segment classifications, which were transmitted to these companies. Similarly, plaintiff Baker's data was intercepted on abc7chicago.com in June 2025 and shared with the same Chinese firms. The complaint states that Taboola transmitted Baker’s identifiers, including his IP address and device IDs, to Baidu, Tencent, and Temu (Compl. ¶127). The complaint further alleges that Taboola’s synchronization with these companies enables them to aggregate bidstream data from multiple sources, creating comprehensive profiles of Americans’ browsing behavior, interests, and health concerns (Compl. ¶81). The complaint notes that Taboola’s data transmissions to Baidu, Tencent, and Temu included persistent advertising identifiers and IP addresses, which the BSD Rule explicitly identifies as examples of prohibited bulk transfers (Compl. ¶88).

The complaint also highlights the broader implications of Taboola’s data-sharing practices, alleging that "covertly feeding detailed data on intimate human behavior into an industrial-scale AI profiling engine is highly offensive" (Compl. ¶167). The filing asserts that Taboola’s real-time bidding system broadcasts "bidstream data"—including user identifiers, browsing history, and personal characteristics—to third parties, regardless of whether they win the auction. This data is retained by recipients, enabling cascading privacy violations. The complaint states, "Every third party anywhere in the world that receives a bid request gets the user’s personal data, regardless of whether they win the auction" (Compl. ¶8). The complaint further alleges that Taboola’s practices enable third parties to build independent dossiers of users’ online behavior, describing RTB data as a "goldmine for foreign intelligence services" (Compl. ¶59). The complaint explains that "third parties that receive bid requests retain user data regardless of auction outcome, enabling cascading privacy violations" (Compl. ¶8).

The complaint details Taboola’s partnerships with data brokers and advertisers, including LiveRamp, Experian, Equifax, Neustar, Eyeota, Kantar TGI, Lotame, Swoop, TaxRise, i360, and Havas. These partnerships enable Taboola to enrich its user profiles with additional data, such as health conditions, financial status, and political affiliations. For example, the complaint alleges that TaxRise, a tax debt relief company, shared De La Torre’s tax debt data with Taboola, which then broadcast it to advertisers (Compl. ¶118). The complaint also notes that i360, a political data firm, provided Taboola with segments mapping De La Torre’s political beliefs, including his views on the Second Amendment, immigration, and healthcare (Compl. ¶119). The complaint states that Taboola’s identity synchronization with these partners allows it to merge siloed surveillance profiles, enabling persistent tracking of Americans across the internet (Compl. ¶74–79).

Plaintiffs Allege Violations of Federal and State Privacy Laws, Including the BSD Rule

The complaint asserts five causes of action, including claims under federal wiretapping laws and state privacy statutes. The causes of action are as follows:

  1. First Cause of Action: Intrusion Upon Seclusion Under California Common Law (on behalf of Plaintiff De La Torre and the California Class, defined as all California residents whose personal information was used to create, maintain, or share profiles via Taboola’s advertising exchange). The complaint alleges that Taboola’s creation and dissemination of detailed consumer profiles using intercepted communications constitutes an intrusion upon seclusion, stating, "Committing the tort of intrusion upon seclusion under California common law by using the contents of the intercepted communications to facilitate the creation of highly detailed consumer profiles" (Compl. ¶209(a)).
  2. Second Cause of Action: Invasion of Privacy Under the California Constitution (Art. I, § 1) (on behalf of De La Torre and the California Class). The complaint alleges that Taboola’s practices violate the California constitutional right to privacy by covertly syncing unique identifiers with third parties affiliated with adversarial foreign governments and militaries (Compl. ¶209(c)-(d)).
  3. Third Cause of Action: Violation of California Invasion of Privacy Act (Cal. Penal Code § 631(a)) (on behalf of De La Torre and the California Class). The complaint alleges that Taboola "willfully and without the consent of all parties to the communication, or in any unauthorized manner, reads, or attempts to read, or to learn the contents or meaning of any message" (Compl. ¶178). The complaint further states that "Taboola’s technologies intentionally capture the contents of users’ interactions with these websites and purposefully transmit them to Taboola and its integrated demand-side partners" (Compl. ¶188).
  4. Fourth Cause of Action: Violation of Electronic Communications Privacy Act (ECPA) (18 U.S.C. § 2510, et seq.) (on behalf of De La Torre, Baker, and both Classes). The complaint alleges that Taboola intentionally intercepted and disclosed plaintiffs' communications for the purpose of committing criminal and tortious acts, stating, "Taboola intentionally and knowingly intercepted and disclosed Plaintiff Baker’s and the BSD Class members’ communications for the purpose of committing these criminal and tortious acts" (Compl. ¶208). The complaint argues that Taboola is not shielded by the ECPA "party exception" because its interceptions were intentional and for the purpose of committing tortious acts (Compl. ¶210).
  5. Fifth Cause of Action: Violation of BSD Rule’s Prohibition of Data-Brokerage Transactions (28 C.F.R. § 202.301(a)) (on behalf of Baker and the BSD Class). The complaint alleges that Taboola violated the BSD Rule by engaging in prohibited data-brokerage transactions with Baidu, Tencent, and Temu, stating, "Taboola’s provision of this bulk U.S. sensitive data to Baidu, Temu, and Tencent... constitutes 'covered data transaction[s] involving data brokerage'" (Compl. ¶205).

The BSD Class is defined as all U.S. persons whose personal information was transmitted to Baidu, Tencent, Temu, or other entities based in the People’s Republic of China on or after April 8, 2025. The California Class is defined as all California residents whose personal information was used to create, maintain, or share profiles via Taboola’s advertising exchange (Compl. ¶143). The complaint alleges that the classes are numerous, with exact class size unknown but individual joinder impracticable due to thousands of affected users. Common questions of law and fact include whether Taboola intentionally violated privacy rights, unlawfully collected and disseminated data, and intercepted communications without consent (Compl. ¶144–145). The complaint states that "whether Defendant tracked website visitors and caused details about internet users’ visits to websites and other private behavior to be intercepted and paired with other personal information about such persons, and disseminated and shared with third parties, including entities controlled by adversaries of the United States, without their knowledge or consent" is a central issue (Compl. ¶145(d)). The complaint further alleges that "an expectation that extends not only to their internet browsing activity and online communications, but also to the personal data that Taboola surreptitiously collects, enriches, de-anonymizes, and sells without the knowledge or consent of Plaintiff De La Torre and the California Class members" (Compl. ¶152).

The BSD Rule claim, brought on behalf of plaintiff Baker and the BSD Class, alleges that Taboola violated 28 C.F.R. § 202.301(a) by engaging in prohibited data-brokerage transactions with Baidu, Tencent, and Temu. The complaint alleges that Taboola's transfers of bulk sensitive data to these companies constitute "covered data transactions involving data brokerage" under the rule. The complaint states that Taboola’s provision of bulk U.S. sensitive data to Baidu, Temu, and Tencent "constitutes 'covered data transaction[s] involving data brokerage'" (Compl. ¶205). The complaint further alleges that Taboola knew or should have known it was violating the BSD Rule due to its sophistication and participation in rulemaking, stating, "Taboola knew or reasonably should have known that it had engaged and was engaging in covered data transactions involving data brokerage in violation of the BSD Rule" (Compl. ¶206). The complaint notes that Taboola’s SEC filings acknowledge the collection of IP addresses, cookie IDs, and device identifiers, which may be regulated as personal data under the BSD Rule (Compl. ¶94–95).

The complaint also includes claims for intrusion upon seclusion under state common law and invasion of privacy under the state constitution, brought on behalf of plaintiff De La Torre and the California Class. These claims allege that Taboola's creation and dissemination of detailed consumer profiles using intercepted communications is "highly offensive to a reasonable person." The complaint states that "most people would be shocked to learn that simply opening a webpage could trigger real-time data harvesting and the silent creation of a detailed behavioral profile tied to their identity" (Compl. ¶158). The complaint further asserts that "covertly feeding detailed data on intimate human behavior into an industrial-scale AI profiling engine is highly offensive" (Compl. ¶167). The complaint describes Taboola’s practices as an "egregious breach of social norms," stating that "Taboola’s large-scale development and disclosure of extensive consumer profiles for commercial gain represents an egregious breach of social norms" (Compl. ¶170). The complaint also alleges that "no reasonable person would agree to having secret cradle-to-grave consumer profiles built about them, or to have their personal information diverted to a foreign adversary" (Compl. ¶192).

The plaintiffs seek statutory damages of $5,000 per violation under California law, as well as injunctive relief, disgorgement of profits, and attorneys' fees. The aggregate amount in controversy is $5,000,000 (exclusive of interests and costs) (Compl. ¶185). The complaint also seeks just compensation and injunctive relief for the ECPA violations, stating that plaintiffs "seek (a) preliminary, equitable, and declaratory relief as may be appropriate, (b) the sum of the actual damages suffered and disgorgement of profits... or statutory damages... whichever is greater" (Compl. ¶211). The complaint further requests statutory damages of $5,000 per violation under Cal. Penal Code § 637.2(a) (Compl. ¶185).

Taboola's Data Collection Scale and National Security Implications Highlighted in Filing

The complaint emphasizes the scale of Taboola's data collection, alleging that the company processes 170 terabytes of data daily and stores 99,000 petabytes of user data—an amount the filing describes as 4.1 billion times larger than the English-language Wikipedia. The complaint alleges that this data includes "persistent identifiers, device metadata, and contextual information" that Taboola uses to track users across websites and devices. The complaint states that Taboola’s data storage enables surveillance of users who never consented to its tracking practices, noting that Taboola stores 99,000,000,000 gigabytes of data (Compl. ¶29). The complaint further alleges that Taboola operates 14,000 servers and processes 500,000 recommendation-related requests per second, serving 1.2 trillion recommendations in a single month (Compl. ¶27). The complaint describes Taboola’s AI-powered "recommendation" engine as leveraging the "pulse of the internet" for real-time targeting, stating that nearly 90% of digital ads in the U.S. are delivered via programmatic advertising (Compl. ¶22, 25).

The complaint also highlights the national security implications of Taboola's data transfers to Chinese companies. It cites China's "Military-Civil Fusion" strategy, which the U.S. Department of State describes as compelling civilian tech companies to serve as extensions of the Chinese military. The complaint alleges that Baidu and Tencent, both on the 1260H List, are required by Chinese law to share data with the government, posing risks of hacking, blackmail, and influence campaigns. The complaint states that "the export of Americans' behavioral data to hostile foreign regimes is an unusual and extraordinary threat to the national security and foreign policy of the United States" (Compl. ¶85). The complaint further alleges that RTB data is a "goldmine for foreign intelligence services," enabling hacking, blackmail, and influence campaigns due to the lack of transparency and secondary use controls (Compl. ¶59). The complaint describes Taboola’s synchronization with Baidu and Tencent as channeling "bulk sensitive data to entities formally identified as Chinese military threats" (Compl. ¶66). The complaint also notes that China’s "Military-Civil Fusion" strategy compels civilian tech companies to serve as extensions of its military, stating that "China’s 'Military-Civil Fusion' strategy compels civilian tech companies to serve as extensions of its military" (Compl. ¶63).

The complaint details the regulatory and legislative scrutiny faced by the Chinese companies involved. For example, the Kentucky Attorney General filed a lawsuit against Temu in July 2025, alleging that the company illegally provides the Chinese government with Americans’ data (Compl. ¶72). Additionally, attorneys general from Arizona, Arkansas, Iowa, Nebraska, Oklahoma, and Texas have filed lawsuits against Temu over its data practices (Compl. ¶73). The complaint also notes that U.S. Senators, including Bill Cassidy, Ron Wyden, Kirsten Gillibrand, Mark Warner, Sherrod Brown, Elizabeth Warren, Tom Cotton, and Rick Scott, have raised concerns about the national security risks posed by data transfers to Chinese companies. The complaint highlights that a bipartisan group of U.S. Senators warned digital advertising exchanges about RTB national security risks in April 2021, and that U.S. Senators, including Tom Cotton, wrote to President Biden about Temu’s data practices in April 2024 (Compl. ¶68). The complaint further notes that the House Permanent Select Committee on Intelligence requested FBI and SEC briefings on Temu in September 2024, and that attorneys general from 21 states demanded data disclosure from Temu in August 2024 (Compl. ¶73). The complaint states that Congressman Brian Mast urged the FTC to investigate Temu’s ties to the CCP in April 2024, and that Senator Rick Scott urged the Department of Commerce to investigate Temu in August 2024 (Compl. ¶68, 73).

The complaint also provides context for Taboola’s partnerships with major publishers, noting that the company announced a five-year deal with NBCUniversal News Group in November 2023 and closed a 30-year strategic partnership deal with Yahoo in January 2023. Taboola’s tracking code is embedded on over 100,000 websites, including those of NBCUniversal, Yahoo, Apple News, HindustanTimes.com, abc7chicago.com, and TurboTax.Intuit.com (Compl. ¶21). The complaint alleges that Taboola’s tracking technologies intercept and redirect user data during website communications, without knowledge or consent, stating that "Taboola’s technologies intentionally capture the contents of users’ interactions with these websites and purposefully transmit them to Taboola and its integrated demand-side partners" (Compl. ¶188). The complaint further alleges that Taboola’s JavaScript intercepts first-party communications during browser rendering, before users can detect or prevent transmissions, and that Taboola reads and redistributes full-page URLs as part of the RTB auction process (Compl. ¶181–183). The complaint states that Taboola’s code on HindustanTimes.com executed identity synchronization with Baidu, Tencent, and Temu for Plaintiff De La Torre, and that Taboola’s code on abc7chicago.com silently executed and synced Plaintiff Baker’s identity with the same companies (Compl. ¶106, 123).

The complaint also details the technical mechanisms of Taboola’s tracking, alleging that the company’s "t_gid" (Taboola ID) is a persistent identifier stored in cookies for long-term tracking. The complaint states that "Taboola’s 't_gid' (Taboola ID) is a persistent identifier stored in cookies for long-term tracking" (Compl. ¶36). The complaint further alleges that Taboola’s claim of "pseudonymized" data is misleading, as identifiers enable re-identification, stating that "Taboola’s 'pseudonymized' data claim is misleading; identifiers enable re-identification" (Compl. ¶38). The complaint notes that Taboola syncs identifiers with third parties possessing names and emails, eliminating pseudonymity (Compl. ¶40). The complaint also alleges that Taboola assigns users to behavioral segments such as "Expectant Mothers" and "LGBT Donor", which follow users across websites and devices, deepening profiles with each page view (Compl. ¶45–46).

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.

From the Complaint Public Court Record

1 IN THE UNITED STATES DISTRICT COURT FOR THE SOUTHERN DISTRICT OF NEW YORK ALESSANDRO DE LA TORRE and JOHN BAKER, individually and on behalf of all others similarly situated, Plaintiffs, v. TABOOLA, INC., a Delaware corporation, Defendant. Case No. CLASS ACTION COMPLAINT AND DEMAND FOR JURY TRIAL Plaintiffs Alessandro De La Torre and John Baker bring this Class Action Complaint and Demand for Jury Trial on behalf of themselves and all others similarly situated against Taboola, Inc. for unlawfully intercepting users’ online communications, using that data to build highly detailed, persistent “cradle-to-grave” consumer profiles, and disseminating their data to numerous third parties, including foreign adversaries, in violation of state and federal law and fundamental privacy rights. Plaintiffs allege as follows based on personal knowledge as to themselves and on information and belief as to all other matters. NATURE OF THE ACTION 1. This case challenges Defendant Taboola’s operation of a sweeping and nearly invisible “commercial surveillance” system targeting U.S. consumers. 1 Taboola runs one of the most pervasive and intrusive consumer surveillance operations on the internet: a platform that 1 The Federal Trade Commission defines “commercial surveillance” as the business of collecting, analyzing, and profiting from information about people. Commercial Surveillance and Data Security Rulemaking, Fed. Trade Comm’n (Aug. 11, 2022), https://www.ftc.gov/legal- library/browse/federal-register-notices/commercial-surveillance-data-security-rulemaking.

2 silently tracks hundreds of millions of users across thousands of unrelated websites, intercepting the private browsing activity of millions of Americans, amassing details about their personal lives, and building rich individual-level behavioral profiles on each. Taboola aggressively monetizes these profiles, transmitting these sensitive details to numerous third pa

Questions about this topic: david@newmanbrunk.com

Practice areas