Rodriguez v. Google LLC 11 20-cv-04688-RS (N.D. Cal. Jan. 3, 2024) and setting and the intruder's motives and objectives.” Opp. at 13 (quoting Shulman, 18 Cal.4th at 236). Again, Google fails to make a case for why these additional questions supersede the central inquiry: whether a reasonable person would find the intrusion by Google highly offensive. Instead, Google invokes two cases decided under the California Invasion of Privacy Act (CIPA) section 632, which protects communications made over a “wire, line, or cable,” to argue that both claims require a factspecific inquiry incapable of class-wide treatment. See Kight v. CashCall, Inc., 231 Cal.App.4th 112 (2014); Hataishi v. First Am. Home Buyers Prot. Corp., 223 Cal.App.4th 1454 (2014). Both cases Google identifies pertain to secretly overheard phone conversations that were listened to surreptitiously. Plaintiffs' CIPA section 632 claim, while previously dismissed, does not control *11 the analysis of the intrusion upon seclusion and invasion of privacy claims. Factual inquiries underscoring a § 632 analysis are inapplicable here. There are no similar individual issues about whether each plaintiff “reasonably believed their calls were not being monitored.” Kight, 231 Cal.App.4th at 119. Here, the relevant inquiries are primarily Google's uniform disclosures and users' uniform conduct. Furthermore, CIPA § 632 is not, as Google contends, an analog for the common law privacy tort. As stated above, the test under the state intrusion upon seclusion and invasion of privacy claims is an objective one, capable of resolution class-wide, and while analysis of surrounding circumstances may sometimes be necessary to determine whether a user maintained their reasonable expectation of privacy, here, that question is eclipsed by the undisputed fact that all class members switched off their sWAA settings. Cf. Hart v. TWC, 2023 WL 3568078 at *9. c. CDAFA CDAFA makes certain computer-related crimes a public offense, including to ��knowingly access[] and without permission take . . . any data from a computer.” Cal. Penal Code § 502(c)(2). Access “means to gain entry to, instruct, cause input to, cause output from, cause data processing with, or communicate with, the logical, arithmetical, or memory function resources of a computer, computer system, or computer network.” Cal. Penal Code 502(b)(1). Further, to show “damage or loss” under CDAFA, a plaintiff need not have suffered a corresponding loss, as “California law recognizes a right to disgorgement of profits resulting from unjust enrichment.” Facebook Tracking, 956 F.3d at 599-600. Google first argues, incorrectly, that CDAFA provides for “highly individualized . . . compensatory damages” limited to the victim's expenditure, i.e. what was “reasonably and necessarily incurred by the owner or lessee to verify that a computer system, computer network, computer program, or data was or was not altered, deleted, damaged, or destroyed by the access.” Opp. at 15 (quoting Cal. Penal Code § 502(b) (11)). However, the statute provides for compensatory damages including victim expenditures. Cal. Penal Code § 502(e)(1). 12 Next, Google asserts that it cannot be all class members who used apps with Firebase *12 and/or Google Mobile Ads SDKs suffered “damage or loss,” as their information was collected for “runof-the-mill record-keeping” and was not “sensitive, confidential, or even meaningful to users.” Opp. at 16. Plaintiffs, on the other hand, argue that they need not prove the at-issue data was sensitive or not-anonymous, but that “any damage or loss” is sufficient for standing under the CDAFA3. Reply at 3; see Facebook Tracking, 956 F.3d at 599-600. Google's definition is too restrictive, while Plaintiff's is too permissive. In order to maintain entitlement to the disgorged profits, plaintiffs must show that they have standing, i.e. that they “retain a stake in the profits garnered.” Facebook Tracking, 956 F.3d at 599- 7

Select target paragraph3