Carol Price v. WeWork Claims WeWork secretly shared her browsing data with LiveRamp for $5,000 per violation
Carol Price, individually and on behalf of a proposed class, filed a class action complaint in the United States District Court for the Southern District of New York against WeWork Inc. and unnamed defendants—including DOES 1 through 10—alleging the company installed data-broker software on its website that secretly collected and transmitted visitors’ personal identifiers—including names, emails, and browsing history—to third parties without consent. The complaint seeks over $5,000,000 in damages, statutory damages of $5,000 for each violation of California’s Trap and Trace Law (Cal. Penal Code § 638.51), and injunctive relief. The global data brokerage industry, valued at $270.4 billion in 2024, underscores the scale of the alleged misconduct, with projections estimating the industry will reach $473.35 billion by 2032 (Compl. ¶28).
The suit contends WeWork’s use of LiveRamp Holdings, Inc.’s “Data Broker Code” constitutes a trap-and-trace device under § 638.51(a), which prohibits the use of such devices without a court order or consent. According to the complaint, the software employs “browser fingerprinting” to assign visitors a persistent “RampID” that tracks them across websites and devices even after cookies are cleared, and the data is allegedly sold or licensed to entities including government agencies such as U.S. Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP). The complaint alleges that "government agencies may purchase personal data to further their exercise of coercive powers, including the ability to deport, arrest, incarcerate, or even use lethal force" (Compl. ¶41).
Price alleges that on October 5, 2025, her data was transmitted to LiveRamp without her knowledge or consent, and that WeWork neither obtained a court order nor secured express or implied consent from her or class members before deploying the tracking technology. The complaint also asserts a claim for intrusion upon seclusion, arguing the conduct was “highly offensive to a reasonable person.”
WeWork’s Installation and Use of LiveRamp’s Data Broker Code for Secret Data Collection
The complaint alleges that WeWork Inc. installed LiveRamp Holdings, Inc.’s Data Broker Code on its website to secretly collect and transmit visitor data—including personal identifiers such as names, email addresses, and browsing history—to third parties without consent. According to the filing, this technology was deployed to enable real-time tracking and monetization of user information, in violation of California privacy laws. The global data brokerage industry, valued at $270,400,000,000 in 2024 and projected to reach $473,350,000,000 by 2032, underscores the scale of the alleged misconduct (Compl. ¶28).
On October 5, 2025, plaintiff Carol Price visited WeWork’s website, and her data was allegedly transmitted to LiveRamp without her knowledge or consent. The complaint states that this transmission occurred as part of a broader practice of surreptitious data collection, where WeWork’s website acted as a conduit for LiveRamp’s tracking infrastructure. The complaint alleges that the "RampID" persists despite clearing cookies or switching devices, a critical detail enabling long-term tracking of individuals (Compl. ¶35). The filing further specifies that "Plaintiff was subjected to the Data Broker Code on 2025-10-05 when visiting the Website" (Compl. ¶37).
The Data Broker Code, the complaint alleges, employs "browser fingerprinting" to uniquely identify visitors by aggregating device and browser traits. As the filing notes, "Your browser fingerprint is a collection of innocuous information about your PC that, when put together, is unique enough that it could identify an individual" (Compl. ¶21). This method allows LiveRamp to create a persistent identifier, known as a "RampID," which tracks individuals across websites and devices, even after cookies are cleared. The complaint cites research published by Texas A&M University on June 26, 2025, which further explores the mechanics and implications of browser fingerprinting (Compl. ¶23).
The complaint further alleges that LiveRamp combines incoming device data with pre-existing personal data—such as names, email addresses, and browsing history—to construct comprehensive profiles of website visitors. These profiles are then used for targeted advertising and other commercial purposes. The filing states that "with impressions matched to a persistent people-based ID, data are stitched across devices and not lost over time with new cookies or phones," enabling ongoing surveillance of users. The complaint also emphasizes that "identification of website visitors through the Data Broker Code happens in ‘real-time,’" underscoring the immediacy and scope of the alleged tracking (Compl. ¶36). Data brokers, the complaint explains, cross-reference data using unique identifiers such as device IDs and cookies to build these profiles (Compl. ¶28).
The plaintiff contends that WeWork’s use of this technology constitutes a violation of California’s Trap and Trace Law (Cal. Penal Code § 638.51), which prohibits the use of such devices without a court order or consent. The complaint alleges that WeWork neither obtained a court order nor secured the consent of visitors before deploying the Data Broker Code. The filing highlights that the electronic communication at issue is the transfer of data between Plaintiff and Class members’ devices and WeWork’s website (Compl. ¶62).
Monetization and Economic Impact of Plaintiff’s and Class Members’ Data
The complaint alleges that WeWork Inc.’s deployment of LiveRamp Holdings, Inc.’s Data Broker Code enabled the monetization of visitor data through ongoing tracking across websites for advertising and other purposes. According to the filing, LiveRamp’s technology assigns a persistent “RampID” to individuals, allowing their activity to be monitored across devices and websites even after cookies are cleared. This tracking, the complaint contends, facilitates the sale or licensing of personal data to third parties, including law enforcement and government agencies such as U.S. Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP).
The complaint quotes a data broker executive describing the scope of this surveillance: “We know who she is, what she watches, what she reads, and who she lives with... why she buys” (Compl. ¶29). It further alleges that government agencies may use such data to “further their exercise of coercive powers, including the ability to deport, arrest, incarcerate, or even use lethal force” (Compl. ¶41). The filing notes that no clear legal authority prevents data brokers from selling or disseminating user data to federal agencies, raising concerns about the potential misuse of personal information. The complaint explicitly states, "There is no clear legal authority that prevents data brokers from selling or disseminating user data to the federal government" (Compl. ¶44).
The economic stakes of this practice are substantial, the complaint asserts. The global data brokerage industry was valued at $270,400,000,000 in 2024 and is projected to reach $473,350,000,000 by 2032 (Compl. ¶28). The complaint alleges that the data collected from visitors—including Plaintiff Carol Price—has inherent economic value, which was diminished by WeWork’s unauthorized transfer of that data to LiveRamp. In its words, “In the modern economy, identity information has been described as the business of buying and selling information as a commodity” (Compl. ¶49). By surreptitiously deploying the Data Broker Code, the complaint contends, WeWork deprived Plaintiff and Class members of the ability to “participate in that market on informed terms,” stating that “Defendant’s surreptitious and unlawful transfer of personal information... diminished Plaintiff’s and Class members’ ability to participate in that market on informed terms” (Compl. ¶50).
The complaint also highlights the broader consequences of this data transfer, including the loss of anonymity and the imposition of real costs on visitors. For example, it alleges that browser fingerprinting—used to uniquely identify individuals—can lead to tailored pricing or other forms of economic discrimination. The filing frames these practices as part of a larger pattern of unauthorized data monetization, stating that "the loss of anonymity via browser fingerprinting imposes real costs on visitors, such as tailored pricing" (Compl. ¶48). The complaint cites prior lawsuits and regulatory actions to underscore the illegality and invasiveness of WeWork’s alleged conduct. These related proceedings include California v. Sephora USA, Inc. (filed 08/24/2022 by California Attorney General), which resulted in a settlement addressing similar data privacy violations. The complaint quotes California Attorney General Rob Bonta, who stated in that case, “Consumers are constantly tracked when they go online... without the knowledge or consent of the consumer” (Compl. ¶25). Other cited cases include Lewis v. Magnite, Inc. (2025 U.S. Dist. LEXIS 263675), Hassid v. Alex & Ani, LLC (2026 U.S. Dist. LEXIS 11238), Casillas v. Lucky Opco LLC (2026 Cal. Super. LEXIS 24132), Santoro v. Lulu & Georgia, Inc. (2025 Cal. Super. LEXIS 84529), Zhizhi Xu v. Reuters News & Media, Inc. (2025 Cal. Super. LEXIS 76169), Schallert v. RocketGenius (2026 Cal. Super. LEXIS 25177), and Biglang-Awa-Castro v. SBE Restaurant Group (2026 Cal. Super. LEXIS 29752).
Parties and Roles in the Alleged Data Collection Scheme
The class action complaint names Carol Price, individually and on behalf of all others similarly situated, as the sole plaintiff. Price alleges that on October 5, 2025, she visited WeWork Inc.’s website, where her personal data was collected and transmitted to third parties without her consent. The complaint seeks to represent a proposed class of all individuals whose data was similarly collected by WeWork through the use of LiveRamp Holdings, Inc.’s Data Broker Code.
WeWork Inc., a Delaware corporation, is the sole named corporate defendant. The complaint alleges that WeWork installed LiveRamp’s Data Broker Code on its website to secretly collect and transmit visitor data, including personal identifiers such as names, emails, and browsing history, to third parties. The filing further alleges that WeWork’s conduct violated California’s Trap and Trace Law (Cal. Penal Code § 638.51) by using a trap-and-trace device without a court order or consent. The complaint also names DOES 1 through 10 as defendants, representing unknown entities involved in the alleged scheme, though their identities are not yet known.
LiveRamp Holdings, Inc., a California-registered data broker, is identified as a key non-party in the complaint. The filing alleges that WeWork installed LiveRamp’s Data Broker Code on its website, which enabled the collection and transmission of visitor data to third parties. The complaint describes LiveRamp’s technology as employing "browser fingerprinting" to uniquely identify visitors by aggregating device and browser traits and assigning a persistent "RampID" to track individuals across websites and devices. According to the complaint, LiveRamp’s Data Broker Code identifies website visitors in "real-time" and enables ongoing tracking for advertising and monetization purposes. The complaint states, "[W]ith impressions matched to a persistent people-based ID, data are stitched across devices and not lost over time with new cookies or phones" (Compl. ¶36).
The complaint references several non-party entities alleged to be involved in the broader data brokerage ecosystem. These include California Attorney General Rob Bonta, whose prior regulatory action against Sephora USA, Inc. on August 24, 2022, underscored the illegality of similar data privacy violations. The filing also cites U.S. Immigration and Customs Enforcement (ICE), Palantir Technologies, Meta, Google, the U.S. Department of Homeland Security (DHS), and Custom and Border Protection (CBP) as entities that may purchase or use personal data collected through data brokerage practices. The complaint alleges that government agencies may use such data for coercive purposes, including deportation, arrest, or other law enforcement actions, stating that "government agencies may purchase personal data to further their exercise of coercive powers, including the ability to deport, arrest, incarcerate, or even use lethal force" (Compl. ¶41).
On March 3, 2026, a news report revealed that Customs and Border Protection (CBP) purchased tracking data from the online advertising ecosystem, further illustrating the potential government use of such data. Additionally, on February 13, 2026, The New York Times reported that the Department of Homeland Security (DHS) subpoenaed Google and Meta for user data, highlighting the broader context of government access to personal information (Compl. ¶41).
Count 1: Violation of California’s Trap and Trace Law (Cal. Penal Code § 638.51)
The complaint alleges that WeWork Inc. violated California’s Trap and Trace Law by installing and operating LiveRamp’s Data Broker Code on its website without a court order or user consent. Under Cal. Penal Code § 638.51(a), it is unlawful to use a trap and trace device to capture the origin of electronic communications unless authorized by a court order or consent. The complaint contends that WeWork’s deployment of the Data Broker Code meets the statutory definition of a trap and trace device, as it captures the source of electronic communications transmitted between visitors’ devices and WeWork’s website. The filing specifies that the "electronic communication at issue is the transfer of data between Plaintiff and Class members’ devices and the Website" (Compl. ¶62).
According to the filing, WeWork did not obtain a court order before installing or using the Data Broker Code. The complaint states, “Defendant did not obtain a court order before using or installing the Data Broker Code on the Website” (Compl. ¶65). Nor, the complaint alleges, did WeWork secure express or implied consent from Plaintiff Carol Price or the proposed class members for the data-sharing or data-selling facilitated by LiveRamp. The filing asserts, “Defendant did not obtain the express or implied consent of Plaintiff or Class members to be subjected to data-sharing or data-selling with or by or through LiveRamp” (Compl. ¶66).
The complaint further alleges that WeWork is ineligible for the statutory consent exemption under Cal. Penal Code § 638.51(b)(5), which applies only to “a provider of electronic or wire communication service.” The filing states, “Defendant is not such a provider” (Compl. ¶67). As a result, the complaint contends that WeWork’s conduct constitutes a per-se violation of the statute, entitling Plaintiff and the proposed class to statutory damages of $5,000 for each violation. The complaint explicitly states, "Plaintiff and Class members are entitled to statutory damages of $5,000 for each of Defendant’s violations of § 638.51" (Compl. ¶70).
The complaint cites prior regulatory action under the same statute to underscore the illegality of WeWork’s alleged conduct. That action, California v. Sephora USA, Inc., resulted in a settlement and injunctive relief requiring disclosure of data-sharing practices and opt-out mechanisms for consumers. The filing also references related proceedings such as Lewis v. Magnite, Inc. (2025 U.S. Dist. LEXIS 263675), Hassid v. Alex & Ani, LLC (2026 U.S. Dist. LEXIS 11238), and Casillas v. Lucky Opco LLC (2026 Cal. Super. LEXIS 24132), among others, to provide legal context for the claims. The Federal Trade Commission’s findings on consumer data use for pricing, released on January 17, 2025, are also cited to highlight the broader regulatory scrutiny of data collection practices (Compl. ¶48).
Count 2: Intrusion Upon Seclusion
The complaint alleges that WeWork Inc. deployed LiveRamp Holdings Inc.’s Data Broker Code on its website in a manner that intentionally intruded into the private communications and matters of plaintiff Carol Price and the proposed class members. According to the filing, the code captured and transmitted personal identifiers—including names, email addresses, and browsing history—without consent, constituting an invasion of privacy under the common-law tort of intrusion upon seclusion. The complaint quotes the conduct directly: “Defendant’s deployment of the Data Broker Code on the Website intentionally intruded into a private conversation or matter Plaintiff and the Class members were involved in” (Compl. ¶73).
Plaintiff and class members are alleged to have had no knowledge of, nor did they authorize, the third-party cookies or tracking technology initiated by the Data Broker Code. The complaint states, "Plaintiff and Class members never authorized the third-party cookies or tracking technology initiated by the Data Broker Code" (Compl. ¶74). The complaint further asserts that they maintained an “objectively reasonable expectation of privacy” regarding their interactions with WeWork’s website, given the absence of conspicuous disclosures or consent mechanisms. The filing characterizes WeWork’s actions as intentional and motivated by economic benefit, arguing that the company sought to monetize the collected data through sales or licensing to third parties, including advertisers and government agencies such as U.S. Immigration and Customs Enforcement (ICE). The complaint alleges that "Defendant’s intrusion was intentional and for economic benefit" (Compl. ¶76).
The complaint contends that the intrusion would be “highly offensive to a reasonable person,” citing the persistent and cross-device tracking enabled by LiveRamp’s “RampID” system, which assigns a unique identifier to individuals even after cookies are cleared. The alleged injuries extend beyond mere privacy violations, encompassing loss of control over personal data, diminution in the economic value of that data, unauthorized profiling, mental anguish, and a chilling effect on free expression (Compl. ¶79). The filing emphasizes that these harms are not speculative but flow directly from WeWork’s alleged failure to obtain consent or provide notice of its data collection practices. The complaint states, "The intrusion described herein would be highly offensive to a reasonable person" (Compl. ¶78).
The claim relies on California common law, which recognizes intrusion upon seclusion where a defendant intentionally intrudes into a private space or matter in a manner that would be offensive to a reasonable person. The complaint does not cite a specific statutory provision for this count but instead grounds the claim in long-standing tort principles, distinguishing it from the statutory violation alleged in Count 1 under Cal. Penal Code § 638.51. The Law Institute’s updated report on the value of identity in the modern economy, released on October 27, 2025, is cited to contextualize the economic impact of the alleged misconduct (Compl. ¶49).
Distinctive Pleading: Government Access to Data and Industry Practices
The complaint alleges that WeWork’s use of LiveRamp’s Data Broker Code extends beyond commercial tracking, enabling the sale of personal data to government agencies for coercive purposes. According to the filing, the data collected—including names, emails, and browsing history—may be purchased by entities such as U.S. Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP) to facilitate actions like deportation or arrest. The complaint states, in its words, that “government agencies may purchase personal data to further their exercise of coercive powers, including the ability to deport, arrest, incarcerate, or even use lethal force” (Compl. ¶41). The filing further notes that on March 3, 2026, a news report revealed that Customs and Border Protection (CBP) purchased tracking data from the online advertising ecosystem, illustrating the government’s reliance on such data sources.
The filing further contends that no clear legal authority restricts data brokers from selling or disseminating user data to federal agencies, leaving individuals with no control over how their information is used. This alleged practice is framed within broader industry trends, including the $270,400,000,000 global data brokerage market in 2024, projected to grow to $473,350,000,000 by 2032 (Compl. ¶28). The complaint cites a 2025 article quoting a data broker executive: “We know who she is, what she watches, what she reads, and who she lives with... why she buys” (Compl. ¶29). The article, published by Gizmodo on March 15, 2025, highlights the invasive nature of data brokerage practices and their implications for consumer privacy (Compl. ¶29).
The complaint also highlights the economic consequences of this surveillance, alleging that the loss of anonymity through browser fingerprinting imposes real costs on visitors, such as tailored pricing. It references prior regulatory action by California Attorney General Rob Bonta, which stated, “Consumers are constantly tracked when they go online... without the knowledge or consent of the consumer” (Compl. ¶25). The filing asserts that the ramifications of third-party surveillance “can go beyond ordinary consumer profiling,” implicating not only commercial exploitation but also government access to sensitive personal data (Compl. ¶39). On February 13, 2026, The New York Times reported that the Department of Homeland Security (DHS) subpoenaed Google and Meta for user data, further illustrating the intersection of corporate data collection and government surveillance (Compl. ¶41).
The complaint cites multiple related proceedings to underscore the legal context of its claims, including California v. Sephora USA, Inc. (filed 08/24/2022), Lewis v. Magnite, Inc. (2025 U.S. Dist. LEXIS 263675), Hassid v. Alex & Ani, LLC (2026 U.S. Dist. LEXIS 11238), Casillas v. Lucky Opco LLC (2026 Cal. Super. LEXIS 24132), Santoro v. Lulu & Georgia, Inc. (2025 Cal. Super. LEXIS 84529), Zhizhi Xu v. Reuters News & Media, Inc. (2025 Cal. Super. LEXIS 76169), Schallert v. RocketGenius (2026 Cal. Super. LEXIS 25177), and Biglang-Awa-Castro v. SBE Restaurant Group (2026 Cal. Super. LEXIS 29752). These cases provide a backdrop for the allegations against WeWork, illustrating the broader legal landscape surrounding data privacy and tracking practices.
Relief Sought and Procedural Posture
The complaint seeks certification of a class with Carol Price as the representative plaintiff and her attorneys as class counsel. It demands statutory damages of $5,000 for each violation of California Penal Code § 638.51, as the law provides for such recovery. The filing states, "Plaintiff and Class members are entitled to statutory damages of $5,000 for each of Defendant’s violations of § 638.51" (Compl. ¶70). The total matter in controversy exceeds $5,000,000, satisfying jurisdictional requirements under the Class Action Fairness Act of 2005, 28 U.S.C. § 1332(d)(2).
The plaintiff further seeks punitive damages, nominal damages, and full restitution for the plaintiff and class members. The complaint also requests disgorgement of both the data unlawfully obtained by WeWork and the revenues and profits the company allegedly derived from its use of LiveRamp’s Data Broker Code. The complaint asks the court to enjoin WeWork from continuing the conduct described in the filing, award reasonable attorneys’ fees and costs, and grant "all other just and proper relief" the court deems appropriate. The plaintiff has demanded a jury trial.
The case was filed on July 28, 2026, in the United States District Court for the Southern District of New York as Carol Price, individually and on behalf of all others similarly situated v. WeWork Inc. et al., docket number 1:26-cv-06436. Jurisdiction is premised on the Class Action Fairness Act of 2005, 28 U.S.C. § 1332(d)(2), with the matter in controversy exceeding $5,000,000. Venue is proper under 28 U.S.C. § 1391. No defendants have yet responded to the allegations.
The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.
The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.
David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.
From the Complaint Public Court Record
1 UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF NEW YORK CAROL PRICE, individually and on behalf of all others similarly situated, Plaintiff, vs. WEWORK INC., a Delaware corporation; and DOES 1 through 10, inclusive, Defendants. Case No. CLASS ACTION COMPLAINT FOR (1) USE OF A TRAP AND TRACE DEVICE IN VIOLATION OF THE CALIFORNIA INVASION OF PRIVACY ACT (CAL. PENAL CODE § 638.51); (2) INTRUSION UPON SECLUSION INTRODUCTION 1. Plaintiff, on her behalf and on behalf of a class of similarly situated persons, brings this action against Defendant WeWork Inc. (“Defendant” or “WeWork”). WeWork markets “workspace solutions” such as renting desks and office spaces at co-working locations through its website, found at https://wework.com/ (the “Website”). 2. Defendant has installed and deployed software developed by a California- registered data broker, LiveRamp Holdings, Inc. (“LiveRamp”), on the Website to secretly collect data about visitors, their devices, locations and views of webpages to identify who they are, target them with unwanted marketing and track them on an ongoing basis. 3. The data broker software identifies visitors based on the data collected from visitors’ devices and browsers, sometimes linking the data received to data already in the possession of data brokers, such as email addresses, physical addresses and name. 4. Both Defendant and LiveRamp benefit commercially and financially from this activity. They benefit because collected visitor data, and the identification of visitors using that data, are used to, among other things, target Website visitors for specific marketing. LiveRamp benefits because it uses the data to, inter alia, compile more comprehensive profiles of visitors, which it may sell to third parties for advertising and other purposes. 5. Defendant’s installation and use of data broker software without obtaining consent
2 or authorization therefore violated California Penal C
Questions about this topic: david@newmanbrunk.com