Milberg Opens a Privacy Inventory Against Yahoo Over ConnectID
The claim is that an email address became a permanent tracking identifier that survived cookie deletion. The procedural point is that the campaign was launched as a mass arbitration from the outset, with claimant recruitment running through a partner intake platform rather than a class definition.
Economics Desk··3 min read
Milberg, with the intake platform Class Action U, announced on 7 April 2026 that it had launched a mass arbitration campaign against Yahoo. The subject is ConnectID, Yahoo's identity-resolution product.
The claim
The allegation is that ConnectID took the email address a user supplied when logging into a Yahoo service — or gave to a participating third-party site — and converted it into a persistent, unique identifier. That identifier, the claimants say, let Yahoo and its advertising partners follow activity across websites, apps and devices, and kept working after the user deleted or blocked cookies.
Two Milberg senior partners framed the campaign in the press release. Marc Grossman put it on disclosure: consumers expect transparency about how their personal data is collected and used. Gary Klinger put it on procedure — mass arbitration, he said, gives consumers a real path to accountability notwithstanding clauses that foreclose class treatment.
The second framing is the one worth dwelling on, because it describes what is actually being built.
Recruitment as claim construction
Eligibility for the campaign is not stated as a class definition. It is stated as three intake criteria: at least 18 years old, a current or recent Yahoo account holder, and use of Yahoo services within the past two years. Prospective claimants register through a portal, and eligibility is assessed there.
That is a materially different object from a putative class. A class definition is a legal proposition that must survive a certification motion, in which the defendant gets to argue that individual questions predominate. An intake criterion is an operational filter, and the individualised nature of each claim is not a vulnerability — it is the premise. Every claimant is separately identified, separately signed, and separately filed.
The consequence is that the defence-side arguments developed for privacy class actions do not transfer cleanly. Ascertainability, predominance, and standing-by-class-member arguments all presuppose a certification stage. Here there isn't one. What replaces it is a fight over the clause: the batching provisions, any condition precedent, verification of each claimant's account and use, and — increasingly — funding disclosure.
Both the recruitment channel and the recruitment terms are also, after the New York anti-SLAPP ruling in SCPS v. Ben Travis Law, harder to attack directly. A respondent that dislikes how an inventory was assembled is left contesting it inside the arbitration rather than in a collateral tort suit.
Why privacy keeps producing inventories
Privacy claims have three properties that make them the natural raw material for this model, and they are worth naming because they predict where the next campaigns come from.
Uniform conduct across an enormous population. The alleged tracking mechanism is the same for every user. There is no individualised course of dealing to reconstruct, which makes 100,000 demands substantively identical and therefore cheap to prepare.
Statutory damages. State privacy and wiretapping statutes frequently fix per-violation figures. A claim that would be worth almost nothing on actual damages becomes worth pursuing when the statute supplies the number — which converts a negative-value claim into a positive-value one without any aggregation at all.
Documented membership. An account holder is a fact the respondent's own systems can confirm. Claimant verification, the soft spot in consumer campaigns built on purchase records or self-attestation, is comparatively hard to contest here.
Add a further wave of state comprehensive privacy statutes coming into force, and the supply of qualifying conduct is expanding rather than contracting.
What to watch
The disclosed facts do not include the number of demands filed, the provider, or the terms of the Yahoo clause that governs them — and each of those determines what the campaign actually costs both sides. A clause with a JAMS-style escalating batch ladder produces a very different fee curve from one that predates the 2024 provider rule changes.
Two things are worth tracking as the campaign develops: whether the demands are batched, and on what ladder; and whether Yahoo responds by rewriting its own terms. The pattern established over the past two years is that a large privacy campaign is followed within months by a clause amendment from the respondent — which does nothing for the pending inventory, and everything for the next one.
Published for legal professionals. Analysis and summaries only — not legal advice, and no attorney-client relationship is created by use of this site.
Read next
The Premise That Turned Out to Be Contingent
Litigation theory held that claims worth less than the cost of bringing them cannot be litigated without a procedural aggregation device. Mass arbitration showed that premise depended on institutional design — and everything since has been an attempt to restore it.
Research Desk · 4 min
Nothing You Draft After the Demands Arrive Will Help
The defence bar has converged on one point: mass arbitration is a drafting problem, and the drafting window closes the moment the first tranche is filed. What a clause reviewed with mass exposure in mind actually contains.
Practice Desk · 4 min
Glover's Taxonomy: Why Mass Arbitration Is Not a Variation on Anything
The first systematic account of mass arbitration argued it constitutes a genuinely new model of dispute resolution — and documented defendants abandoning the clauses they had spent two decades securing.
Research Desk · 3 min