Privacy · Lawsuit Filed

Lenovo Class Action Says Website Trackers Sent Shoppers’ Browsing Data to Its China-Based Parent

Published September 27, 2026

People in the U.S. who visited Lenovo.com on or after April 8, 2025 may be covered by a proposed class action alleging Lenovo (United States) Inc. let website trackers capture their browsing data and made it available to its China-based parent. No class has been certified and there is nothing to file yet.

Laptop computer on a desk
▼ Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. Lenovo (United States) Inc. has not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

A San Francisco man who shopped on Lenovo.com and bought a Legion gaming desktop filed a proposed class action on February 5, 2026, against Lenovo (United States) Inc., the computer maker’s U.S. subsidiary. The case, Christy v. Lenovo (United States) Inc., Case No. 3:26-cv-01133, is pending in the U.S. District Court for the Northern District of California, San Francisco Division.

The complaint alleges that tracking code on Lenovo.com captured visitors’ IP addresses, cookie and device identifiers, advertising IDs and the full URLs of the pages they viewed, and that Lenovo made that data available to its parent company, Hong Kong-incorporated Lenovo Group Limited, which the complaint describes as having its principal operations in Beijing. The plaintiff claims that transfer violated a Justice Department national-security rule restricting bulk transfers of Americans’ sensitive data to entities tied to China. Lenovo has not been found liable, and the allegations have not been tested in court.

Status Complaint Filed Filed February 5, 2026 · N.D. Cal. · No class certified
Who It Covers (Proposed) U.S. visitors to Lenovo.com on or after April 8, 2025 Plus a California subclass and a California purchaser subclass
Can I Claim? No — nothing to claim yet

What the Complaint Alleges

The case is built on the Justice Department’s Data Security Program, codified at 28 C.F.R. Part 202 and effective April 8, 2025. The rule bars or restricts U.S. companies from giving “covered persons” — including companies organized in, or headquartered in, China — access to bulk U.S. sensitive personal data. For identifiers such as IP addresses, cookie data and advertising IDs, the complaint says the “bulk” threshold is data on more than 100,000 U.S. persons in a 12-month period.

According to the complaint:
The named plaintiff says he browsed Lenovo.com several times in November and December 2025 while shopping for a discounted gaming computer, and that his identifiers and the product pages he viewed were intercepted and passed along without his knowledge.

The Legal Claims

The complaint pleads eight counts: the federal Electronic Communications Privacy Act (the Wiretap Act), sections 631 and 632 of the California Invasion of Privacy Act, California’s Comprehensive Computer Data Access and Fraud Act, California’s Unfair Competition Law, unjust enrichment, invasion of privacy and intrusion upon seclusion.

The federal wiretap count depends on a specific theory. The Wiretap Act normally allows interception when one party to the communication consents, and a website is a party to its own traffic. That consent defense does not apply when the interception is done to commit a criminal or tortious act, and the plaintiff argues that the alleged DOJ-rule violation is exactly that kind of act. Whether courts accept that theory is one of the central questions in the case.

Who Could Be Included?

The complaint proposes three groups:
These are the plaintiff’s proposed definitions. A judge decides whether any class is certified, and the definitions often narrow along the way.

What the Lawsuit Seeks

The plaintiff asks for class certification, an order stopping the alleged conduct, and money. Under the Wiretap Act he seeks the greater of actual damages plus Lenovo’s profits or statutory damages, along with punitive damages. For California subclass members, he seeks the greater of $5,000 per violation or three times actual damages under the California Invasion of Privacy Act. The purchaser subclass also seeks restitution. These are amounts the complaint requests, not amounts anyone has been awarded.

What Happens Next?

Website-tracking cases under the Wiretap Act and California’s wiretap law commonly face an early motion to dismiss, and the crime-tort theory here — tying the claim to a national-security regulation — is newer than most. If the case survives, it would move to discovery and, later, a class certification motion. There is nothing to sign up for or file now.

Questions

Does a visitor have to have bought something from Lenovo to be in the proposed class?

No. The proposed nationwide class covers people in the United States whose communications with Lenovo.com were intercepted and used on or after April 8, 2025. A purchase matters only for the proposed California Purchaser Subclass. No class has been certified, and these definitions can change.

What is the DOJ bulk data rule the complaint relies on?

It is a Justice Department national-security regulation, 28 C.F.R. Part 202, effective April 8, 2025, that prohibits or restricts U.S. companies from giving entities tied to countries of concern, including China, access to bulk sensitive personal data such as IP addresses, cookie data and advertising IDs. The complaint uses an alleged violation of that rule to support its federal wiretap claim.

Has Lenovo responded to the lawsuit?

The complaint is a one-sided account, and Lenovo has not been found liable for anything. Any defense or motion to dismiss would appear on the court docket for Case No. 3:26-cv-01133 in the Northern District of California.

How would someone find out if the Lenovo case settles?

If the case settles or a class is certified, the court would approve a notice plan, and class members would typically be notified by email or through an official settlement website. A settlement with a claim form would also appear in our settlements listing.

Sources


For more class actions keep scrolling below.
Status Complaint Filed
Case Title Christy v. Lenovo (United States) Inc.
Case Number 3:26-cv-01133
Court U.S. District Court, Northern District of California
Date Filed February 5, 2026

More Website Tracking & Privacy Lawsuits