Two of the five smart TV makers Texas sued for tracking what people watch have now agreed to stop doing it without asking first. If your app, channel, or ad integration runs on Samsung's Tizen platform, LG's webOS, or any CTV surface that leans on automatic content recognition data, the consent rules under your feet just changed twice in three months, and three more manufacturers are still fighting the same claim in the same court.
Texas Attorney General Ken Paxton filed suit against Samsung, LG, Sony, Hisense, and TCL on December 15, 2025, alleging each company used Automatic Content Recognition (ACR) to capture what was on-screen, on television broadcasts, streaming apps, game consoles, and anything cast or mirrored from a phone, without adequately telling owners or getting real consent. The complaints seek statutory penalties under the Texas Deceptive Trade Practices Act of up to $10,000 per violation, rising to $250,000 per violation affecting a consumer 65 or older. Samsung settled first, on February 26, 2026. LG followed on May 11, 2026. Sony, Hisense, and TCL have not.
Key Takeaways
- Samsung (February 26, 2026) and LG (May 11, 2026) both agreed to stop collecting or monetizing ACR viewing data without express, informed, opt-in consent, and to replace buried settings with a prominent disclosure screen.
- Sony, Hisense, and TCL remain in active litigation; Hisense is also under a December 17, 2025 temporary restraining order barring it from collecting, using, or selling Texas ACR data while the case proceeds.
- Neither settlement carries a monetary fine. The remedy is entirely behavioral: rebuilt consent UI and a ban on future collection without opt-in, which is the same operational bar CTV publishers and ad-tech partners on these platforms now need to audit against.
What ACR actually is, and why it isn't the same problem as a tracking cookie
Automatic Content Recognition works by sampling what's rendering on a television's screen, roughly twice a second according to court filings, converting each sample into a compact fingerprint, and matching that fingerprint against a reference database of known shows, movies, channels, and ads. It doesn't need a stored identifier the way a cookie or mobile ad ID does; it identifies content directly from the pixels and audio the screen is already displaying, which is why it also picks up whatever a viewer connects over HDMI, casts from a phone, or watches through a doorbell or security camera feed routed to the TV. Dr. Anna Mandalari, who co-authored a University College London study on ACR data flows, put the core problem plainly: "Automatic content recognition technology has been around for a while, though the average user is unlikely to know what it is or that they can opt-out from it if they want to." That gap, technology running by default that almost nobody consciously agreed to, is exactly what Texas's Deceptive Trade Practices Act claim targets.
For a CTV publisher, the distinction matters operationally. A cookie-consent audit checks whether a script fires before a banner click. An ACR audit has to check whether the television platform itself, not just your app, is capturing screen content your app renders, and whether that capture happens regardless of what consent your own consent management platform collects at the app layer.
Start by pulling a list of every ACR-adjacent data feed your integration touches across the five platforms below, before reading the rest of this article. That list is what the audit checklist further down asks you to score.
The settlements: what Samsung and LG actually agreed to
Samsung's February 26, 2026 settlement requires the company to stop collecting or monetizing ACR viewing data from Texas users without express prior consent, and to rebuild its on-screen setup flow so the consent request is prominent rather than several menus deep. The state's filing had alleged Samsung's prior flow relied on dark patterns, requiring as many as 200 clicks across nested menus to even reach the relevant privacy disclosure, which is the specific defect the new consent screen is meant to fix. No monetary penalty was assessed; the remedy is entirely about future conduct and UI.
The stakes for that fix go beyond ad targeting. Because ACR reads whatever is rendering on screen, it doesn't distinguish a streaming show from a banking app or a password field displayed during a HDMI-connected session; the same capture mechanism that identifies a rerun can just as easily sample financial account details or login credentials if they happen to be on screen when the sample is taken.
LG's May 11, 2026 settlement, still awaiting formal approval from the Bell County district court at time of writing, follows the same shape with one addition. LG must display a pop-up disclosure explaining what viewing data is collected and how, post the same disclosure on its own website, and provide what Texas's announcement called a clear, simple opt-out, not one requiring a support call or a buried settings path. The LG agreement also prohibits transferring viewing data to Chinese Communist Party-linked entities in any form, a provision aimed at the same cross-border data-flow concern that runs through the parallel Hisense and TCL suits.
Neither settlement created a new legal standard on paper. Both simply enforce, through consent-decree terms, the notice-and-choice requirement Texas already argued the Deceptive Trade Practices Act implies. What they did create is a working template: two of the five largest smart TV platforms in US homes now operate under an express, opt-in ACR consent requirement, enforced by an active state attorney general.
Why a two-manufacturer settlement pattern functions like a national baseline
Samsung and LG do not build one TV firmware for Texas and another for the other 49 states. Shipping a state-specific consent flow at the SKU or region level is possible in principle but operationally wasteful next to shipping one compliant flow everywhere, the same economic logic that made GDPR's consent requirements bleed into US-facing products long before any US federal privacy law existed. That's the mechanism, not a legal requirement, that turns a Texas settlement into a de facto floor other manufacturers, and the publishers building on their platforms, should plan around regardless of where their own users live.
This is also the same consent-before-collection principle Secure Privacy customers already implement for GDPR and the ePrivacy Directive: consent has to be obtained before non-essential processing starts, not implied by continued use of the device. A CMP that only blocks cookies until consent is clear on the web layer doesn't touch ACR running in TV firmware, but the underlying compliance posture, documented opt-in before collection, is identical, and it's worth checking now whether your existing consent logging already covers CTV app-layer events the same way it covers your website.
Sony, Hisense, and TCL: what "still litigating" actually means right now
Sony's case has seen no reported motions or settlement talks since the December filing. TCL's case is in a similar posture. Hisense is the outlier: the December 17, 2025 temporary restraining order remains the most concrete court action against any of the three still-litigating manufacturers, barring the company from collecting, using, selling, sharing, or transferring Texas ACR data while the underlying case is decided. None of the three has publicly signaled a settlement timeline.
For a publisher or ad-tech partner distributing across all five platforms, the practical read is not "wait for the other three to settle." It's that the two manufacturers representing a substantial share of the US smart TV installed base have already locked in an opt-in standard, the third is under a court order that achieves functionally the same restriction inside Texas, and the remaining two have given no public indication that their current ACR data practices will hold up if Texas's claims are eventually tested at trial rather than settled.
Don't wait for a third settlement to find out your integration assumed implied consent. Run the audit below against whichever of the five platforms you touch today.
Audit checklist: where each platform stands today
| Manufacturer | Litigation status | Consent standard now in effect | What a publisher or ad-tech partner should check |
|---|---|---|---|
| Samsung | Settled February 26, 2026 | Express, opt-in consent required before ACR collection or monetization; consent screen must be prominent | Confirm your app or SDK integration doesn't assume implied consent from Samsung's platform-level ACR data feed |
| LG | Settlement announced May 11, 2026, pending court approval | Same opt-in standard, plus mandatory pop-up disclosure and a simple opt-out; CCP data-transfer ban | Review any webOS ad-targeting integration that ingests LG ACR data for downstream vendor data-sharing exposure |
| Hisense | Litigating; TRO in effect since December 17, 2025 | Collection, use, and sale of Texas ACR data currently barred by court order | Treat Texas traffic as ACR-data-restricted now, not pending a future settlement |
| Sony | Litigating; no reported settlement activity | Pre-lawsuit practices, unchanged as of this writing | Do not assume current practices are stable; build for an opt-in requirement landing without much notice |
| TCL | Litigating; no reported settlement activity | Pre-lawsuit practices, unchanged as of this writing | Same posture as Sony, with added scrutiny given TCL's China-based ownership and the data-transfer issue raised in LG's settlement |
If you're integrating against any of these five platforms today, this is the point to pull your ACR-adjacent data flows into the same audit-ready consent logging you already maintain for web and mobile, rather than treating CTV as a separate compliance track that catches up later.
How this connects to implementation work already underway
None of this requires rebuilding a CTV consent stack from scratch. Secure Privacy's existing coverage of how Android TV consent differs from mobile apps and iOS vs tvOS consent management already walks through the platform-level differences that make CTV consent harder to standardize than web or mobile, including the fact that Apple's tvOS ships with no ACR at all, unlike Roku, Fire TV, or Samsung's own platform. Those pieces are the implementation companion reading for the compliance shift described here: this article covers what the law now requires; that coverage covers how to actually build the consent flow that satisfies it.
Common issues and fixes when auditing ACR consent exposure
Publishers running this audit for the first time tend to hit the same three snags.
You don't control the TV platform's consent screen, only your own app. That's expected. You can't fix Samsung's or LG's disclosure UI from inside your integration, but you can confirm your own data-sharing agreements with the platform or ad-tech partner require them to pass along only data collected under a valid opt-in, and document that check the same way you'd document a vendor's GDPR data processing agreement.
Your engineering team owns the SDK integration, but compliance owns the audit. This usually stalls at the handoff. Send engineering a specific, narrow ask, a list of which ACR-derived fields your integration ingests from each platform, rather than a general "check for compliance issues" request, and it moves faster.
Legacy integrations predate the lawsuits and nobody remembers the original consent assumptions. If documentation doesn't exist, don't guess. Treat any pre-2026 integration with Samsung, LG, or the platforms still in litigation as unverified until someone actually checks the current data-sharing terms, rather than assuming it was fine when it was built.
FAQ
Did Texas fine Samsung or LG over the ACR lawsuits?
No. Both settlements are behavioral consent decrees, not monetary penalties. Samsung and LG each agreed to stop collecting or monetizing ACR data without express opt-in consent and to rebuild their disclosure screens, but neither paid a fine to the state.
Does the Samsung or LG settlement apply outside Texas?
The settlements are legally binding only for Texas consumers, but both companies would need a separate, non-compliant firmware build to keep serving other states differently, which is operationally impractical. Expect the revised consent flows to ship broadly rather than be geofenced to Texas.
What is Automatic Content Recognition, in one sentence?
ACR is software built into most smart TVs that samples on-screen audio and video roughly twice a second, converts it into a fingerprint, and matches that fingerprint against a database of known content to identify what's being watched, regardless of the source.
Are Sony, Hisense, and TCL still collecting ACR data without consent?
Hisense is barred from collecting, using, or selling Texas ACR data under a December 2025 court order while its case proceeds. Sony and TCL have no reported change to their pre-lawsuit ACR practices as of this writing.
Does this affect CTV app publishers who don't build the TV firmware themselves?
Yes. The consent requirement lands on the manufacturer's ACR data collection, but any publisher, channel developer, or ad-tech partner whose integration ingests or depends on that ACR-derived data inherits the same exposure if the underlying collection wasn't properly consented.
How is this different from the cookie consent rules CTV publishers already follow?
Cookie consent governs what your own app or website does after a user interacts with your consent banner. ACR operates at the television platform layer, capturing screen content independent of any app-level consent flow, which means a compliant in-app banner does not by itself make the platform's ACR collection lawful.
Is there a private right of action under the Texas Deceptive Trade Practices Act here?
No. These cases were brought by the Texas Attorney General under the state's DTPA enforcement authority; consumers did not sue directly. Enforcement runs through the AG's office, not private litigation.
Where to start
If ACR-adjacent data flows into your CTV stack from Samsung, LG, or the platforms still in litigation, the audit above is the starting checklist, not the full compliance program. Secure Privacy's cookie and consent platform already handles consent logging that stays audit-ready across web, mobile, and CTV surfaces, so the same documentation standard now required of Samsung and LG's own consent screens can sit behind your integration too, before the next settlement, or the next state, makes it mandatory.




