A consumer is appealing a district court ruling in a lawsuit alleging that Hearst's mobile app violated the Video Privacy Protection Act by sharing geolocation data and Android advertising IDs with third-party analytics providers. The case hinges on whether the transmitted data constitutes personally identifiable information under the 1988 law.
The outcome of this appeal will clarify whether modern metadata like advertising IDs and GPS coordinates qualify as personally identifiable information under decades-old federal law. For the streaming industry, a ruling against Hearst could significantly increase litigation risk for any app utilizing third-party analytics or engagement platforms like Braze and Google. This case highlights the growing tension between standard ad-tech data practices and consumer privacy protections originally designed for physical video rentals. Watch for the 1st Circuit's ruling to determine if 'de-anonymization' capabilities by tech partners create a new liability threshold for streaming publishers.
The Hearst appeal arrives amid a broader wave of Video Privacy Protection Act litigation targeting media companies that embed third-party analytics SDKs in their video apps. In 2024, the 1st Circuit ruled in a separate VPPA case that sharing viewing data with Facebook via a mobile app could constitute a disclosure of personally identifiable information, establishing precedent that the same court will now apply to Hearst's geolocation and advertising ID claims. That earlier decision narrowed the safe harbor that publishers had relied on since the statute's 1988 enactment, and the Hearst appeal tests whether the reasoning extends to non-viewing metadata such as GPS coordinates and device identifiers transmitted alongside video content.
On the business side, the VPPA's statutory damages of $2,500 per violation create outsized exposure for publishers with large app install bases. Hearst Television operates 34 local stations whose apps collectively reach tens of millions of monthly users, meaning a class certification in the Therrien case could produce nine-figure liability if the 1st Circuit reverses the dismissal. The financial stakes have pushed several media companies to audit their SDK integrations; Braze disclosed in its 2025 annual report that media and entertainment clients represented its fastest-growing vertical, underscoring how deeply engagement platforms are embedded in publisher apps that stream video content.
Competing privacy frameworks are also shaping the regulatory backdrop. The Federal Trade Commission filed an amicus brief in a 2025 VPPA case arguing that advertising identifiers can constitute personally identifiable information when combined with other data points, a position that would directly support the plaintiff's theory in the Hearst appeal. Meanwhile, the 9th Circuit reached a narrower reading in a 2024 ruling involving a streaming service, holding that device identifiers alone do not identify a specific person without additional linking data, creating a circuit split that the 1st Circuit's Hearst decision could either widen or resolve. For streaming publishers evaluating their analytics stacks, the divergence means compliance strategies must account for jurisdiction-specific risk until the Supreme Court or Congress clarifies the statute's scope.
For related background, see StreamingMeme's prior coverage of Federal judge blocks Montana anti-deepfakes law over First Amendment concerns.
The Hearst video privacy lawsuit has reached the 1st Circuit Court of Appeals, challenging a lower court's dismissal. The case examines whether sharing geolocation data and Android advertising IDs via the WMUR app violates the 1988 Video Privacy Protection Act, potentially setting a new liability threshold for streaming publishers using third-party analytics.
The case centers on whether sharing geolocation data and Android advertising IDs with Google and Braze through the WMUR app constitutes a violation of the 1988 Video Privacy Protection Act.
Judge Richard Stearns dismissed the case, ruling that a single location data point shared with Braze was insufficient to identify the user.
The VPPA carries statutory damages of $2,500 per violation. Given Hearst Television's large app user base, a class certification could result in nine-figure liability.
Plaintiff Charles Therrien argues that 856 geolocation data points shared with Braze create a digital fingerprint capable of de-anonymizing users.
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source