US Law Firm Accuses Lenovo of Bulk Data Transfers to China
A class action lawsuit has been filed against Lenovo United States Inc., alleging violations of the Justice Department's Data Security Program rules. The case claims that Lenovo's website tracking and advertising infrastructure facilitated the transfer…
A class action lawsuit has been filed against Lenovo United States Inc., alleging violations of the Justice Department's Data Security Program rules. The case claims that Lenovo's website tracking and advertising infrastructure facilitated the transfer of Americans' sensitive data to entities linked to China.
The lawsuit, initiated by Almeida Law Group on behalf of a San Francisco resident, Spencer Christy, was filed in the U.S. District Court for the Northern District of California. It seeks to represent a nationwide class of U.S. users whose electronic communications with Lenovo's website were allegedly intercepted and used starting April 8, 2025.
The complaint references the DOJ's Bulk Sensitive Data Transfer Rule (28 C.F.R. Part 202), which was implemented in April 2025. This rule aims to restrict data transactions that allow countries of concern, or entities linked to them, access to Americans' sensitive personal data.
The complaint alleges that Lenovo incorporated various tracking technologies on its website, including pixels, scripts, cookies, and real-time bidding components. These tools reportedly collect persistent identifiers and full-string URLs, which reveal pages and products viewed.
A class action lawsuit has been filed against Lenovo United States Inc., alleging violations of the Justice Department's Data Security Program rules.
Lenovo is accused of integrating tracking from major ad-tech and analytics vendors, facilitating large-scale data collection. The data allegedly involved more than 100,000 U.S. persons, meeting the regulation's "bulk" threshold for covered personal identifiers, and was made accessible to entities associated with China.
Lenovo is described as a "U.S. person" under the rule, while Lenovo Group is categorized as a "covered person" due to its connections with a country of concern. The complaint argues that certain data transfers would be prohibited unless specific security requirements are met.
Lenovo's privacy statement acknowledges the transfer of personal information within the Lenovo Group and to China. The complaint asserts that contractual clauses alone do not fulfill the DOJ rule's controls for restricted transactions.
The lawsuit also cites federal and California privacy claims, including alleged violations of the Electronic Communications Privacy Act (ECPA) and California privacy statutes, based on the interception and use/disclosure of web communications without consent.
Based on reporting by Cyber Security News.
