Data privacy laws are intended to put consumers in control of whether their identifying data can be sold and used for targeted advertising. However, these laws do not provide adequate protections in the era of generative artificial intelligence (AI). This Note examines one way that existing privacy law permits companies to profit from selling data for targeted advertising without obtaining user consent: transferring video watching data in a pixel code. Some U.S. Courts of Appeals have determined that these data transfers do not sufficiently identify users and the videos they watched to constitute violations of user privacy. This has led to a circuit split over the Video Privacy Protection Act’s (VPPA) definition of personally identifiable information (PII). The VPPA requires consent before disclosing PII but does not precisely define which data constitutes PII. The U.S. Court of Appeals for the First Circuit uses a reasonable foreseeability standard to determine whether data constitutes PII, and the U.S. Courts of Appeals for the Second, Third, and Ninth Circuits use the ordinary person standard. There is a further split among the courts that apply the ordinary person standard over whether the ability of AI tools to decode the pixel data should factor into a court’s analysis.
In addressing this issue, this Note considers widespread access to generative AI that can decode pixel code. It poses two possible solutions to the circuit split and AI’s impact on the encryption of pixel code: implementing a new federal privacy law and clarifying whether pixel codes constitute personally identifiable information according to the U.S. Supreme Court. This Note argues that courts should use the ordinary person standard with consideration of the availability and advancement of generative AI.