Oracle's massive advertising database operates without user consent, lawsuit claims
Rights organisers have accused Oracle of collecting an undue level of sensitive data to identify consumers online


Oracle is facing a class-action lawsuit over its alleged use of extensive data aggregation to match the sensitive information of hundreds of millions of customers without informed consent.
In addition to its role as a data management, cloud, and enterprise solutions firm, Oracle also acts as a data broker, and runs Oracle Data Marketplace - the largest third-party data marketplace in the world.
RELATED RESOURCE
The trusted data centre and storage infrastructure
Invest in infrastructure modernisation to drive improved outcomes
The complaint alleges that Oracle’s current notice of consent for data collection does not justify the use of the Oracle’s BlueKai Data Management Platform cookies and tracking pixels to collect and store sensitive data of individuals including address, life events such as marriage or childbirth, education, and purchase history.
This, it states, builds up an excessively-detailed picture of each of the many millions of customers within its database. The major grievance outlined in the complaint is with the aggregation of this data within Oracle’s 'ID graphing', which matches sensitive data drawn from disaggregated sources to existing data profiles on US citizens and individuals around the world, in order to inform targeted advertising.
Oracle chairman Larry Ellison is credited as having claimed that there were five billion people in Oracle’s ID graph by 2016.
Internal documentation published by Oracle credits its BlueKai cookies and ID graphing with the successful collection of data of more than 155 million US households. Other tools such as AddThis, a widget service that Oracle acquired in 2016, tracks user activity on over 15 million websites, enabling the identification of 1.9 billion unique users.
The complaint notes that the cookies and pixels bundled with AddThis are utilised without prior notice or user consent.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Much of the complaint focuses on this issue of consent. The plaintiffs allege that Oracle is guilty of an invasion of privacy under the California constitution, which lists “privacy” as an inalienable right of the citizens of California, and of violating the California Invasion of Privacy Act.
“Oracle knows, or reasonably should know, that Internet users such as Plaintiffs and Class members have insufficient knowledge or basis to reasonably comprehend the extent to which Oracle is obtaining their data, tracking their activity, and compiling it into digital dossiers, nor the deeply invasive and detailed nature of those dossiers,” the complaint reads.
Unlike the UK and EU GDPR, the US has no federal digital privacy legislation, so state privacy laws are one of the few avenues by which individuals can assert rights to privacy in court.
In 2020, a lawsuit filed in the the Netherlands accused Oracle of GDPR violations in its handling of personal data through third-party cookies. BlueKai was specifically named in this lawsuit, with one expert noting that "Everyone who has ever used the internet is at risk from this technology".
“It may be largely hidden but it is far from harmless," said Dr Rebecca Rumbul, class representative and a claimant on the suit in England.
At the time, Oracle dubbed the lawsuit a "meritless action based on deliberate misrepresentations of the facts". Earlier in 2022, the suit was dismissed, although the new complaint claims that in response to the UK/NL suit, Oracle did “cease certain of the practices complained of in that lawsuit only weeks after it was filed”.
Oracle declined to provide comment to IT Pro.

Rory Bathgate is Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He can also be found co-hosting the ITPro Podcast with Jane McCallion, swapping a keyboard for a microphone to discuss the latest learnings with thought leaders from across the tech sector.
In his free time, Rory enjoys photography, video editing, and good science fiction. After graduating from the University of Kent with a BA in English and American Literature, Rory undertook an MA in Eighteenth-Century Studies at King’s College London. He joined ITPro in 2022 as a graduate, following four years in student journalism. You can contact Rory at rory.bathgate@futurenet.com or on LinkedIn.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Oracle breach claims spark war of words with security researchers
News A war of words has erupted between Oracle and cybersecurity researchers following claims the company suffered a security breach.
By Ross Kelly
-
“By this time next year, Oracle employees won't be using passwords” — Larry Ellison wants a biometric future in cybersecurity
News The Oracle CTO hit out at passwords, calling them insecure and easy to steal
By George Fitzmaurice
-
NetSuite vulnerability could leave thousands of websites exposed
News The issue stems from a misconfiguration of access controls in NetSuite's SuiteCommerce instances
By George Fitzmaurice
-
Oracle joins Cloudflare's Bandwidth Alliance
News Database giant will adjust cloud transfer fees for Cloudflare customers
By Danny Bradbury
-
Oracle won't let you turn off security ever again
News Larry Ellison: It was a mistake to let customers manage security features
By Joe Curtis
-
Two more zero-day Java bugs discovered
News Polish researchers find more flaws in Java 7 browser plug-in.
By Rene Millman
-
Microsoft warns users to be wary of fake Java updates
News Cybercriminals set malware trap for users worried by Java zero-day exploits.
By Jane McCallion
-
Calls for Java overhaul grow as more security flaws emerge
News Security experts suggest problems in the development cycle of Java could be to blame for recent security woes.
By Caroline Donnelly