CIPA Website Tracking Lawsuits: What a ‘Pen Register’ Claim Is, Who’s Being Sued, and How to Defend Your Website

Table of Contents

A statute written in 1967 to stop people from clipping alligator leads onto telephone lines is now the busiest privacy litigation engine in the United States. The California Invasion of Privacy Act (CIPA) generated a wave of website wiretapping suits starting in 2022, then mutated into something bigger: by legislative estimates, CIPA pen register and trap-and-trace claims alone now account for roughly two-thirds of all active California privacy litigation, with filings under Section 638.51 surging from about 600 to more than 4,000 in the span of a single legislative session. Class actions against household-name publishers are settling for millions while state courts dismiss near-identical complaints with prejudice, sometimes in the same month.

This guide is the complete picture of CIPA website tracking lawsuits as they stand in mid-2026: what the statute says, how the wiretap and pen register theories actually work, the case law on both sides, the appellate decisions and legislation that could reshape everything within months, and the specific website configuration that ends the exposure.

What Is CIPA? The Statute Behind Website Tracking Lawsuits

The California Invasion of Privacy Act, Cal. Penal Code §§ 630–638.55, was enacted in 1967 to criminalize telephone wiretapping and eavesdropping on confidential communications. Two features make this criminal statute the plaintiff bar’s favorite civil weapon:

  • A private right of action with statutory damages. Section 637.2 lets any person sue for the greater of $5,000 per violation or three times actual damages — with no requirement to prove any actual harm or financial loss. Plaintiffs routinely allege that each website visit, each tracking tool, or even each third-party recipient of data constitutes a separate violation, turning ordinary web traffic into eight-figure theoretical exposure.
  • All-party consent. Unlike federal wiretap law’s one-party consent rule, CIPA requires every party to a communication to consent. A website operator consenting to its own vendor’s data collection does not consent on the visitor’s behalf.

Two provisions carry essentially all current website litigation.

Section 631(a): The Website Wiretapping Theory

Section 631(a) prohibits intentionally intercepting or attempting to read the contents of a communication while in transit, without all-party consent — and separately prohibits aiding, agreeing with, or conspiring with anyone who does. Applied to websites, the theory runs: a visitor types something into a search bar, chat widget, or form; embedded third-party code (session replay, analytics, a pixel) transmits that input to an outside vendor in real time; the vendor has “intercepted” the contents of a communication, and the website owner aided and abetted by installing the code. The Ninth Circuit’s Javier v. Assurance IQ decision supercharged this theory by holding that consent obtained after the interception begins — a banner or privacy policy encountered mid-session — is not consent under CIPA. Content-capturing tools are the targets here: session replay software, chat transcripts routed through vendors, and form or search inputs flowing to analytics and CRM platforms.

Section 638.51: The CIPA Pen Register Theory

This is the newer theory and the one driving today’s filing volume. Section 638.51 prohibits installing or using a “pen register” or “trap-and-trace device” without a court order. Section 638.50 defines a pen register as a device or process that records dialing, routing, addressing, or signaling information from an electronic communication — historically, the gadget law enforcement attached to a phone line to log outgoing numbers, with a trap-and-trace device capturing incoming ones.

The modern claim recasts everyday web tracking as digital pen registers. The data at issue is not message content but the metadata of a visit:

  • IP addresses and derived approximate location;
  • Device and browser identifiers;
  • Cookies and advertising IDs;
  • Referring URLs and page navigation paths;
  • Timestamps and session information; and
  • Attributes combined into device fingerprints.

The doctrinal foothold came from Greenley v. Kochava (S.D. Cal. 2023), where a federal court reasoned that the statute’s word “process” is broad enough to cover software — opening the door for complaints framing pixels, SDKs, analytics scripts, and trackers as unauthorized pen registers. Because Section 638.51’s exceptions center on consent and provider operations, and its default mechanism is a court order that no website could ever obtain, plaintiffs argue nearly any pre-consent tracker is a per se violation. That is the theory’s greatest strength and, as the dismissals below show, its greatest vulnerability.

Who Is Filing CIPA Website Tracking Lawsuits?

Two parallel streams feed the surge, and a business can face both over the identical website configuration:

  1. Class action firms filing against consumer-facing brands and publishers, seeking classwide statutory damages. Legislative testimony attributes much of the filing surge to a small number of firms using repeat plaintiffs. The headline result: on June 26, 2026, a federal judge granted final approval to a $3.85 million settlement against the Los Angeles Times in Mirmalek v. Los Angeles Times Communications LLC — a pure Section 638.51 pen register case over three programmatic ad-tech trackers (TripleLift, GumGum, and Audiencerate). The Times conceded no liability and paid to exit legal uncertainty.
  2. Serial individual claimants sending pre-litigation demand letters at industrial scale — most prolifically the pro se litigant Vivek Shah, who has sent thousands of letters nationwide, pivoting from Section 631 search-bar claims to Section 638.51 pen register claims as the broader bar did. Our full profile of that campaign, including his case history and a step-by-step response plan, is here: Vivek Shah CIPA Demand Letters: What They Are and How to Beat Them.

Targeting is not limited to California businesses. CIPA follows the California visitor, not the company: when a California resident reaches a publicly accessible website and a tracker captures data from that visit, the statute attaches to the California side of the communication regardless of where the business operates or who it thinks its audience is. Manufacturers, schools, nonprofits, dealerships, and B2B firms in every state have been hit.

CIPA Pen Register Case Law: A Body of Law at War With Itself

No area of privacy litigation is producing more contradictory outcomes. The pattern as of mid-2026:

California State Courts: Increasingly Hostile to the Pen Register Theory

  • Rodriguez v. Ink America Int’l Group (L.A. Super. Ct.): Section 638.51 claims dismissed without leave to amend — the statute targets telephonic-style surveillance, and the plaintiff’s reading would criminalize conduct the CCPA expressly permits.
  • Heiting v. Wildflower Brands: entire CIPA complaint dismissed with prejudice; the pen register provisions were enacted in 2015, when the internet was ubiquitous, and the Legislature said nothing about websites.
  • Blaker v. Netscout Systems: Section 638.51 claims against an SDK dismissed with prejudice, emphasizing that the statute’s court-order machinery (Section 638.52) makes sense for telephone surveillance and none for websites.
  • Balabbo v. Wildflower Brands: same result on CIPA — but a common-law invasion of privacy claim survived, a warning that sensitive data flows can keep a case alive even when the statutory theory dies.

Federal Courts: More Permissive, but Fraying

Federal courts in California have historically let pen register claims past the pleading stage more readily, following Greenley‘s broad reading of “process” — and because no California appellate court has ruled, federal judges don’t consider themselves bound by the state trial-court dismissals. But the consensus is cracking: In re USA Today Co. Internet Tracking Litigation dismissed a Section 638.51 claim, and in Shah v. Talentbridge, Inc. (C.D. Cal. May 28, 2026) the court dismissed the most prolific serial claimant’s case for lack of Article III standing, holding that typing generic search terms into a public website implicates no protectable privacy interest — and denied leave to amend as futile. The ruling is on appeal to the Ninth Circuit, but it reframed the settlement calculus for every recipient of a templated demand.

What actually separates winners from losers at the trial level, across both court systems:

  • What was collected — bare IP addresses and data necessary for basic site operation get dismissed; persistent fingerprinting, profile-building, and sensitive-category data survive;
  • Who received it and why — transmissions to advertising ecosystems fare worse than operational vendors;
  • When the tool fired — pre-consent collection is the recurring fact in every adverse ruling; and
  • What the consent flow actually did — a banner that appears after trackers fire is disclosure, not consent, and post-hoc consent has been dead on arrival since Javier.

In CIPA website tracking litigation, configuration is destiny.

The Two Events That Could End (or Entrench) CIPA Pen Register Claims

  1. The first binding appellate rulings. Every dismissal above is a trial-court decision; none binds anyone. Variety Media, LLC v. Superior Court (Second Appellate District) and Reuters News & Media, Inc. v. Superior Court (Sixth Appellate District) squarely present whether a website pixel is a pen register under Section 638.51. Business groups including the Association of Corporate Counsel have filed amicus briefs warning the plaintiffs’ reading would cause “operational paralysis.” Either decision would be the first California appellate authority on the question — and would bind the state trial courts generating today’s chaos.
  2. SB 690, revived and retroactive. As amended July 1, 2026, California’s SB 690 would eliminate the private right of action under Sections 638.50 and 638.51 entirely, vest enforcement exclusively in the Attorney General, and apply retroactively for two years — wiping out most pending pen register claims. The bill’s sponsor has framed retroactivity as an answer to the filing surge itself. The Legislature reconvenes August 3, 2026 and must pass it by the August 31 adjournment. Critically, SB 690 does not touch Section 631: the wiretap theory over session replay, chat, and form capture survives regardless.

For defendants facing pen-register-only claims, these timelines create a genuine strategic decision — settle at pre-appellate prices or wait — that did not exist six months ago. That decision belongs with experienced counsel, made against the specific complaint, venue, and website configuration.

Defending a CIPA Website Tracking Lawsuit: The Arguments That Are Working

  • Standing — no concrete injury from generic, voluntarily entered data (Talentbridge);
  • Statutory scope — Section 638.51 was built for telephonic surveillance and its court-order architecture is incoherent for websites (Rodriguez, Heiting, Blaker);
  • No “content” intercepted — under Section 631, routing metadata is not the contents of a communication, and data must be read while genuinely “in transit”;
  • The party exception — a website owner is a party to its own visitors’ communications and cannot eavesdrop on itself (contested where vendors allegedly use data for their own purposes);
  • Consent — dispositive where, and only where, valid opt-in consent preceded any data transmission; and
  • Statutory harmony — the plaintiff’s reading would criminalize routine data practices the CCPA expressly regulates and permits.

Notice what every defense except consent has in common: it costs a motion to win. Consent is the only argument that prevents the complaint from being filed at all — because it removes the exhibit.

How to Protect Your Website From CIPA Claims: The Compliance Checklist

Every successful CIPA theory — wiretap or pen register, class action or demand letter — rests on one operative fact: a tracking technology transmitted visitor data before valid consent existed. That fact is fully within the operator’s control.

  1. Inventory every script, pixel, tag, SDK, and widget live on your site — including tools installed by past agencies and theme defaults nobody remembers adding.
  2. Map what each tool collects and every third party receiving it, flagging user-entered content (search, chat, forms) and anything health-, employment-, or finance-adjacent — the categories where pen register metadata claims escalate into Section 631 content claims.
  3. Deploy a consent management platform that blocks all non-essential trackers until affirmative opt-in, with opt-out exactly as easy as opt-in and Global Privacy Control signals honored.
  4. Test like a plaintiff. Incognito window, DevTools network tab recording, reload: nothing non-essential fires before consent, and behavior matches each choice (accept, reject, customize). That network capture is exactly the Exhibit A a claimant builds — run it before they do.
  5. Harden sensitive pages — checkout, login, patient portals, job applications, financial forms — with stricter tag configurations than informational pages.
  6. Prune ruthlessly. Orphaned, duplicative, and outdated tags are pure liability with zero business value; removal is the cheapest defense available.
  7. Reconcile the privacy policy to actual data flows — an inaccurate policy is a second, independent claim, not a shield.
  8. Monitor continuously. Tag stacks drift with every deployment; a compliant configuration in January can be firing pre-consent by June, and no one will tell you before the demand letter does.

CIPA Website Tracking Lawsuits: Frequently Asked Questions

What is a CIPA pen register claim?
It is a lawsuit alleging that a website tracking tool — a pixel, analytics script, SDK, or cookie-based tracker — is an illegal “pen register” under California Penal Code Section 638.51 because it captures routing and addressing information (IP address, device identifiers, browsing activity) from visitors without a court order or consent. The theory adapts a 1960s telephone surveillance concept to modern web tracking, and courts are split on whether it is viable.

Is Google Analytics a pen register under CIPA?
Unresolved. Plaintiffs allege that analytics tools collecting IP addresses and device data qualify; several California state courts have dismissed that theory with prejudice, while some federal courts have allowed similar claims past the pleading stage. The pending Variety Media and Reuters appellate decisions should produce the first binding answer. What is clear from the rulings: analytics that fire only after affirmative consent are dramatically harder to attack than those firing on page load.

What damages are available in CIPA lawsuits?
The greater of $5,000 per violation or three times actual damages, plus injunctive relief, under Section 637.2 — with no proof of actual harm required. Plaintiffs multiply exposure by alleging each visit, tool, or third-party recipient is a separate violation, which is why class settlements reach seven figures and individual demands cluster in the four-to-five-figure range.

Can I be sued under CIPA if my business isn’t in California?
Yes. CIPA protects the California visitor, not the business’s home state. If your website is publicly accessible, Californians can reach it, and the statute attaches to their side of the communication. Businesses in every state, many with no California customers, have received CIPA demand letters and complaints.

Will SB 690 end CIPA website tracking lawsuits?
Partially, if it passes. The amended bill would retroactively eliminate private pen register claims under Section 638.51 — the bulk of current filing volume — but leaves Section 631 wiretap claims over session replay, chat, and form capture fully intact. It must pass by August 31, 2026 for enactment this year, and a pending bill resolves nothing for a demand letter on your desk today.

What should I do if my business receives a CIPA demand letter?
Route it to experienced privacy litigation counsel immediately (and to no one else), calendar every deadline, preserve the website’s current configuration before changing anything, notify insurers, and do not pay before counsel tests the claim against what your site actually transmits. Our complete seven-step protocol — including the case law that has beaten these claims — is in our guide to responding to Vivek Shah CIPA demand letters.

The Bottom Line

CIPA website tracking lawsuits are unstable in both directions — seven-figure settlements and with-prejudice dismissals from the same theory in the same month — and the appellate rulings and SB 690 will redraw the map within a year. What will not change is the underlying obligation: know what your website collects, where it goes, and whether consent genuinely preceded collection. The businesses that exit this wave untouched are the ones whose sites simply cannot generate the exhibit — because nothing fires before consent, the policy matches reality, and the configuration is monitored every day instead of audited once.

That is what Captain Compliance builds: an IAB TCF-validated consent management platform that blocks trackers until consent exists, honors Global Privacy Control, and pairs with continuous website privacy monitoring that catches configuration drift before a plaintiff’s DevTools session does — plus consent records that give defense counsel affirmative evidence instead of explanations. Find out what your website is transmitting right now, before someone else documents it for you: book a free compliance audit with Captain Compliance.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.