Statutory damages are sums of money that a law sets in advance for each violation, which a court can award without the claimant proving how much harm was actually suffered. They exist because some injuries are real but hard to price. A person whose browsing was secretly recorded, or whose novel was copied into a training dataset, may struggle to show a measurable loss. Legislators answered by writing a figure into the statute. Multiplied across millions of website visitors or hundreds of thousands of books, those figures explain why tracking pixels and AI training have become some of the most expensive legal questions in advertising and technology.
How the mechanism works
Every statutory damages provision contains three elements: a defined violation, a unit that is counted, and a sum or range attached to each unit. The unit, where most litigation happens, can be a phone call, a text message, a disclosure, a copyrighted work, a day of interception, or an affected person.
The main US statutes relevant to marketing:
- California Invasion of Privacy Act (CIPA), Penal Code Section 637.2: the greater of $5,000 per violation or three times actual damages. No proof of harm is required.
- Video Privacy Protection Act (VPPA), 18 USC 2710: actual damages but not less than $2,500, plus punitive damages and legal fees, for disclosing which videos a person requested.
- Telephone Consumer Protection Act (TCPA), 47 USC 227: $500 per unlawful call or text, which a court may treble to $1,500 if the violation was wilful or knowing.
- Illinois Biometric Information Privacy Act (BIPA): $1,000 per negligent violation and $5,000 per intentional or reckless one.
- Federal Wiretap Act, 18 USC 2520: the greater of $100 a day for each day of violation or $10,000, as an alternative to actual damages and profits.
- Copyright Act, 17 USC 504(c): $750 to $30,000 per work infringed, raised to as much as $150,000 if infringement is wilful and lowered to $200 if it is innocent.
Some statutes, such as CIPA and the TCPA, fix a single figure. Others, such as copyright, set a range and leave the number to a jury. In copyright the claimant also chooses: under Section 504(c), statutory damages can be elected "at any time before final judgment" instead of proving actual losses and the infringer's profits, but only for works registered before the infringement began.
A worked example shows the arithmetic. If a website with 100,000 California visitors is found to have let a third-party script intercept their communications, the CIPA floor is 100,000 multiplied by $5,000, or $500 million, before any argument about how many violations each visit contained.
Origin and evolution
The idea is older than the advertising industry. Britain's Statute of Anne in 1710 imposed a penalty of one penny for every sheet of a pirated book, and the first US Copyright Act of 1790 copied the model at 50 cents per sheet. The Copyright Act of 1976 replaced per-copy penalties with the modern per-work range, originally $250 to $10,000, with $50,000 for wilful infringement. Congress doubled those figures in 1988 and lifted them to the current levels in 1999.
Privacy law followed a separate path. California enacted CIPA in 1967 to stop secret taping of phone calls. Congress passed the federal Wiretap Act in 1968 and expanded it to electronic communications in 1986. The VPPA was signed on November 5, 1988, after a Washington newspaper published the video rental history of Supreme Court nominee Robert Bork. The TCPA followed on December 20, 1991, and Illinois passed BIPA in 2008.
None was written with websites in mind. Plaintiffs argued that a Meta Pixel sending a video title to Facebook was a VPPA disclosure, that analytics and chat scripts were CIPA wiretaps, and that face-tagging features collected biometric identifiers. The Illinois Supreme Court made BIPA especially potent in Rosenbach v. Six Flags on January 25, 2019, holding that a procedural violation alone allowed a claim. Facebook settled its BIPA tag-suggestions case for $650 million, approved on February 26, 2021.
Why it matters for marketing
Statutory damages turn tracking code into class-action exposure because they remove the hardest element to prove: individual loss. In August 2025 a federal jury in San Francisco found that Meta violated CIPA by receiving reproductive health data from the Flo app through its software development kit. The plaintiffs then asked Judge James Donato for a partial judgment of about $1.1 billion for roughly 222,000 California class members, a figure that is essentially 222,000 multiplied by $5,000, according to MLex. Meta opposed it on September 29, 2026.
Filings under CIPA's pen register section rose from about 600 to nearly 4,000 after February 2025. A May 2026 class action alleged that ChatGPT sent user queries to Meta and Google, and in July 2026 Granola was sued over AI meeting recordings.
In copyright, Judge William Alsup ruled on June 23, 2025 that training on books was fair use but downloading pirated copies was not, sending the piracy claims towards a damages trial. With roughly 500,000 works at up to $150,000 each, theoretical exposure exceeded $75 billion. Anthropic, which had appealed the class certification in July 2025, agreed to pay at least $1.5 billion, about $3,000 per work, or four times the statutory minimum. Judge Araceli Martinez-Olguin gave final approval on July 20, 2026 for 482,460 works, according to Pearl Cohen.
Limitations and disputes
The central criticism is disproportion: a sum calibrated for one individual can become ruinous when aggregated. Courts test this against the Supreme Court's 1919 decision in St. Louis, Iron Mountain and Southern Railway v. Williams, which allows a statutory award to be struck down if it is "so severe and oppressive as to be wholly disproportioned to the offense." The Eighth Circuit applied that test in Golan v. FreeEats in 2019, upholding the reduction of a $1.6 billion TCPA award for about 3.2 million calls to $10 per call. In Wakefield v. ViSalus, decided on October 20, 2022, the Ninth Circuit vacated the denial of a due process challenge to a $925 million TCPA award for about 1.85 million calls and held that aggregate awards may be unconstitutional "in certain extreme circumstances", according to the Congressional Research Service. The Supreme Court has not resolved how the test applies to class-wide totals.
Standing is a second limit. In TransUnion v. Ramirez on June 25, 2021, the Supreme Court held that a statutory violation alone does not create federal standing without a concrete harm. Defendants argue that pixel claims fail this test.
Legislatures have intervened too. After the Illinois Supreme Court held in Cothron v. White Castle on February 17, 2023 that each biometric scan could be a separate violation, a theory White Castle said could cost $17 billion, Illinois passed SB 2979, signed on August 2, 2024, making repeated collection from the same person a single violation. The Seventh Circuit held in April 2026 that the amendment applies to pending cases, according to Davis Wright Tremaine. Defenders counter that without statutory damages, privacy laws would be unenforceable, since few individuals could show losses large enough to justify suing.
Not the same as
Actual damages compensate for proven loss. Statutory damages substitute for them, and several statutes let the claimant take whichever is greater.
Punitive damages punish egregious conduct and require findings of malice or similar culpability. Due process limits from State Farm v. Campbell in 2003 apply to them; statutory awards face the more deferential Williams test.
Liquidated damages are, strictly, sums agreed in a contract in advance. The VPPA and BIPA confusingly use the phrase for what are functionally statutory damages, so the label in a statute does not settle the category.
Regulatory fines are paid to the state, not to the injured person, and are imposed by an authority. California's Attorney General fined PlayOn Sports $1.1 million and reached a $1.55 million settlement with Healthline under the California Consumer Privacy Act, which also carries per-violation civil penalties. The European Union offers a further contrast. Article 82 of the General Data Protection Regulation (GDPR) grants compensation for "material or non-material damage" but sets no fixed sum. The Court of Justice of the European Union held in Osterreichische Post (C-300/21) on May 4, 2023 that a GDPR breach alone does not create a right to compensation, and Germany's Federal Court of Justice required proof of actual damage on January 28, 2025.
Recent developments
California narrowed one route on September 30, 2026. Governor Gavin Newsom signed SB 690, which from January 1, 2027 removes private suits under the pen register section while leaving the $5,000 formula untouched for Sections 631 and 632. An analysis distributed by the IAB on October 1 argued that websites still face $5,000 wiretap claims; its authors at FTI Consulting sell compliance services.
Copyright exposure shrank in one respect on March 25, 2026, when the Supreme Court unanimously limited contributory liability in Cox v. Sony, effectively ending Sony's bid to revive a $1 billion statutory award against the internet provider, according to Cooley. The VPPA's reach is next: the Supreme Court hears Salazar v. Paramount Global, on who counts as a "consumer", on October 14, 2026.
In Europe, compensation claims are growing without statutory figures. German courts have awarded Facebook users between EUR 250 and EUR 5,000, including EUR 5,000 in Leipzig in July 2025, a final EUR 1,500 per plaintiff in Dresden in February 2026 and EUR 3,000 in Jena on March 2, 2026. Each sum had to be justified by harm.
Timeline
- 1710 - Britain's Statute of Anne sets a penalty of one penny per pirated sheet.
- 1790 - The first US Copyright Act sets 50 cents per infringing sheet.
- 1967 - California enacts the Invasion of Privacy Act.
- 1968 - Congress passes the federal Wiretap Act, later extended by the Electronic Communications Privacy Act of 1986.
- 1976 - The Copyright Act introduces per-work statutory damages of $250 to $10,000, or $50,000 if wilful.
- November 5, 1988 - The Video Privacy Protection Act is signed with $2,500 minimum damages.
- 1988 - Copyright statutory damages double on US accession to the Berne Convention.
- December 20, 1991 - The Telephone Consumer Protection Act is signed with $500 per violation.
- March 31, 1998 - Feltner v. Columbia Pictures confirms a jury right for copyright statutory damages.
- 1999 - Copyright ranges rise to $750 to $30,000, and $150,000 for wilful infringement.
- 2008 - Illinois enacts the Biometric Information Privacy Act.
- January 25, 2019 - Rosenbach v. Six Flags allows BIPA claims without actual harm.
- 2019 - The Eighth Circuit upholds reduction of a $1.6 billion TCPA award in Golan v. FreeEats.
- February 26, 2021 - Facebook's $650 million BIPA settlement is approved.
- June 25, 2021 - TransUnion v. Ramirez requires concrete harm for federal standing.
- October 20, 2022 - The Ninth Circuit vacates and remands in Wakefield v. ViSalus.
- February 17, 2023 - Cothron v. White Castle treats each biometric scan as a violation.
- May 4, 2023 - The CJEU rules that a GDPR breach alone does not create a right to compensation.
- August 2, 2024 - Illinois signs SB 2979, limiting BIPA to one recovery per person.
- June 23, 2025 - Judge Alsup splits fair use from piracy in Bartz v. Anthropic.
- August 2025 - A jury finds Meta violated CIPA in Frasco v. Flo Health.
- September 5, 2025 - Anthropic agrees to a $1.5 billion settlement.
- March 25, 2026 - The Supreme Court limits contributory liability in Cox v. Sony.
- July 20, 2026 - Final approval of the Anthropic settlement.
- September 29, 2026 - Meta opposes a proposed $1.1 billion partial judgment in the Flo case.
- September 30, 2026 - Governor Newsom signs SB 690.
- October 14, 2026 - The Supreme Court hears Salazar v. Paramount Global on the VPPA.
- January 1, 2027 - SB 690 becomes operative.
Related PPC Land coverage
- Newsom bans one kind of private web tracking lawsuit as claims near 4,000 - The signing of SB 690 and the CIPA damages formula it leaves in place.
- Websites still face $5,000 wiretap claims after SB 690, IAB paper says - Why $5,000 per violation is a floor, not a cap.
- California lawmakers pass SB 690, cutting CIPA tracking lawsuits - Filing volumes and the bill's legislative history.
- Jury finds Meta violated privacy law collecting health data - The Flo Health CIPA verdict against Meta.
- ChatGPT sued over secret data transfers to Meta and Google - CIPA claims extended to an AI chatbot.
- Granola sued for recording meetings without consent to train AI models - All-party consent claims against an AI notetaker.
- Court finds fair use in AI training but rejects piracy defense - Judge Alsup's June 2025 ruling in Bartz v. Anthropic.
- Anthropic appeals largest copyright class action certification - The challenge to the class that drove settlement pressure.
- Anthropic agrees to $1.5 billion settlement in largest copyright case - Settlement terms set against statutory exposure.
- PlayOn Sports hit with $1.1M fine for forcing students to accept tracking - A regulatory penalty under California privacy law.
- Healthline settles largest CCPA violation case for $1.55 million - The Attorney General's settlement over ad tracking.
- German court ruling clarifies standards for GDPR compensation claims - The Federal Court of Justice requires proof of damage under Article 82.
- German court awards Facebook user EUR 5,000 for data protection violations - Leipzig's award over Meta Business Tools.
- German court blocks Meta's appeal, awards EUR 1,500 for Business Tools tracking - The first final German rulings on Business Tools damages.
- Thuringia's court hits Meta with EUR 3,000 damages for tracking without consent - The highest German appellate award so far.
Summary
Who. Legislatures set statutory damages; private plaintiffs and class-action firms invoke them against publishers, retailers, platforms such as Meta and Google, and AI developers such as Anthropic and OpenAI. Courts police their size, and regulators such as California's Attorney General operate a parallel system of fines.
What. A fixed sum or range per violation, awarded without proof of actual loss: $5,000 under CIPA, $2,500 under the VPPA, $500 to $1,500 under the TCPA, $1,000 to $5,000 under BIPA and $750 to $150,000 per work under US copyright law.
When. The concept dates to the 1710 Statute of Anne. The privacy statutes used against ad tech were written between 1967 and 2008, and their application to pixels, SDKs and AI accelerated after 2019, with SB 690 taking effect on January 1, 2027.
Where. Chiefly in US federal and state courts, especially California and Illinois. The EU has no equivalent: GDPR Article 82 compensates proven damage only.
Why. Statutory damages exist to make laws enforceable where harm is real but hard to measure. For the marketing community, they matter because per-violation sums multiplied by audiences of millions turn routine tracking and data practices into potential liabilities of billions of dollars.
Discussion