CIPA vs CCPA: Understanding the Biggest Privacy Litigation Risk for Websites

Table of Contents

It may only look like a CIPA claim can cost you $5,000 in statutory damages but thats not true. This comprehensive guide on how website tracking creates massive exposure for your company and our litigation prevention can help protect your organization from paying out thousands if not millions of dollars from these nuisance claims.

A practical resource from Captain Compliance

The California Invasion of Privacy Act (CIPA) has become one of the most significant legal threats facing companies that operate websites or apps accessible to California residents. What began as a 1967 anti-wiretapping statute is now routinely applied to modern tracking technologies. Plaintiffs’ attorneys successfully argue that pixels, analytics scripts, session replay tools, chatbots, and similar technologies can constitute illegal interception or recording when deployed without proper consent.

This expanded guide explains the legal landscape in greater depth, the serial litigants behind these now common privacy claims, the real financial exposure, the most common failure points, detailed statutory comparisons, a complete auditing checklist, and practical steps you can take to reduce risk for your company or clients if you’re a lawyer.

CIPA Wiretapping Claims

Why CIPA Is Especially Dangerous

Three structural features drive the volume of claims and make CIPA uniquely aggressive compared with most modern privacy statutes:

  • Statutory damages of $5,000 per violation — calculated per user, per incident. Courts and plaintiffs treat each discrete interception or recording event as a separate violation.
  • Private right of action — any individual (or their attorney) can sue without waiting for a government agency to investigate or bring an enforcement action. This dramatically lowers the barrier to litigation and has fueled a cottage industry of demand letters and arbitration claims.
  • Broad territorial reach — CIPA applies to any website or app accessible to California residents, regardless of where the company is headquartered, incorporated, or how small it is. There is no revenue threshold, visitor threshold, or size exemption.

A site receiving just 10,000 California visitors in a month that fires a tracking pixel before consent could theoretically face $50 million in statutory exposure for that single month. A session-replay tool running without adequate masking or disclosure across 100,000 California visitors produces theoretical exposure measured in the hundreds of millions. These figures are not abstract. Plaintiffs’ attorneys calculate maximum statutory exposure first, then negotiate downward from that number. Even modest-traffic sites therefore receive demand letters seeking tens or hundreds of thousands of dollars.

Because CIPA claims can be brought in private arbitration as well as court, many settlements never appear in public records. The opacity makes it difficult for companies to benchmark their true risk until a demand letter arrives. It also makes it hard for outsiders to know how many companies received one of these “shakedown” arbitration demand letters, called their counsel and got a quote for $15,000 and decided to just pay out the plaintiff instead of defending the matter.

CIPA Penalties and Statutory Damages in Detail

CIPA’s penalty structure is one of the primary reasons the statute has become a preferred vehicle for privacy plaintiffs.

Under California Penal Code §637.2, a person injured by a violation of the relevant CIPA provisions may bring a civil action for the greater of:

  • Actual damages suffered, or
  • Statutory damages of $5,000 for each violation.

Importantly, the $5,000 figure is not a per-lawsuit or per-plaintiff ceiling in the way many people assume. Each interception of a communication, each recording of a confidential communication, or each collection of pen-register-style metadata can be pleaded as a separate violation. In a class-action or mass-arbitration setting, the aggregation of these individual statutory awards creates extreme theoretical exposure.

How To Prevent CIPA Litigation?

Additional consequences frequently flow from a CIPA claim:

  • Plaintiffs may seek injunctive relief requiring the defendant to stop the challenged tracking practices and implement specific compliance measures.
  • Prevailing plaintiffs can recover reasonable attorney’s fees and costs.
  • Because many claims also allege parallel violations of the Electronic Communications Privacy Act (ECPA), California’s constitutional right to privacy, common-law intrusion upon seclusion, or unjust enrichment, the total potential recovery can exceed pure CIPA statutory damages.

The statute of limitations for CIPA claims is generally one year from the date of the violation or discovery, though plaintiffs often argue continuing-violation theories when tracking technologies remain active. Demand letters commonly cite the full theoretical exposure based on estimated California visitor volume multiplied by $5,000, then offer to settle for a fraction of that amount. Companies frequently settle at the demand-letter stage because the cost of defending even a weak claim can exceed the settlement demand.

The Three CIPA Provisions Most Frequently Used

Plaintiffs almost always rely on three sections of the California Penal Code:

§631 (Wiretapping)

Prohibits any person from intentionally intercepting, attempting to intercept, or employing any device to intercept a communication without the consent of all parties, or from aiding another person in doing so. In the website context, this is the most common claim. It covers pixels, analytics scripts, SDKs, and real-time bidding tools that transmit visitor data to Google, Meta, TikTok, or other vendors before consent is obtained. Plaintiffs argue that the website operator “aids” the third party by embedding the code that enables the interception while the communication is still in transit.

§632 (Unlawful Recording)

Prohibits the intentional recording of a confidential communication without the consent of all parties. California is a two-party (all-party) consent state. Session replay tools, chatbots, live-chat widgets, search bars, fillable forms, and any technology that captures keystrokes, form inputs, or conversation content fall into this category. Plaintiffs emphasize that users reasonably expect privacy in their interactions with healthcare, financial, or personal forms, making the communications “confidential.”

§638.51 (Pen Register / Trap and Trace)

Focuses on the installation or use of a pen register or trap-and-trace device without a court order. In practice, plaintiffs apply this section to the collection of metadata—IP addresses, screen dimensions, device identifiers, unique cookie values, and similar non-content data—sent to third parties. No content is required. A California Court of Appeal decision expected in mid-to-late 2026 may clarify the precise scope of this section as applied to ordinary website activity. Until then, plaintiffs continue to plead it routinely.

These claims are brought even against companies that believe they are fully CCPA-compliant. CCPA compliance does not automatically satisfy CIPA’s consent and interception standards.

Geographic Scope

CIPA applies if your website or digital service is accessible to California residents. Nationwide companies with no physical presence in California, international companies operating English-language sites, and small businesses all face the same exposure. Geofencing, IP blocking, or disclaimers do not eliminate the risk if the site remains reachable via ordinary internet access. Courts have shown little sympathy for arguments that a company “did not target” California when the site is publicly available in English.

Scale of Litigation and Notable Settlements

Because many claims settle in private arbitration, exact numbers are hard to pin down. Estimates based on law-firm data suggest roughly 7,500 companies settled CIPA-related claims between 2022 and 2025, with the annual volume rising sharply year over year. Public settlements that have been disclosed illustrate both the size of the exposure and the types of practices that attract claims:

  • Kaiser Permanente — $46 million (January 2026). Allegations centered on third-party tracking code on websites and mobile apps that transmitted sensitive health-related data (search terms for symptoms and medications, portal navigation data, names, IP addresses) to Google, Microsoft, Meta, and others without opt-in consent. Up to 13.4 million individuals were affected. The case is one of the largest healthcare privacy settlements on record.
  • Aspen Dental — $18.5 million (2025). Session replay tools and advertising pixels allegedly intercepted appointment requests and health-related form submissions in real time. Key risk factors included online appointment scheduling forms, unmasked session replay, third-party advertising pixels receiving sensitive data, and vague privacy disclosures.
  • Fubo — $3.4 million (2025). Combined VPPA and CIPA claims arising from Meta Pixel, Google Analytics, and related technologies that allegedly shared video-viewing data tied to identifiable users. With 1.6 million U.S. subscribers at the time, pure VPPA exposure at $2,500 per violation could have reached into the billions had the case proceeded to trial.

Even when pure CIPA claims are dismissed, as occurred in a 2026 MyFitnessPal case involving advertising cookies, remaining claims under the California constitutional right to privacy, common-law intrusion upon seclusion, and unjust enrichment can keep litigation alive and expensive. Defense costs alone in such matters routinely reach six figures before any settlement discussions begin.

Related federal statutes frequently appear in the same complaints. An estimated 50% of CIPA lawsuits also allege Electronic Communications Privacy Act (ECPA) violations. The Video Privacy Protection Act (VPPA) is commonly paired with CIPA in cases involving video content; more than 20 public VPPA settlements ranging from $1 million to $20 million have been reported since 2023.

CCPA vs. CIPA Differences

Feature CCPA / CPRA CIPA
Primary enforcement California Attorney General / CPPA (regulatory) + limited private right of action Pure private right of action by any individual
Consent model Opt-out for sale/share; opt-in for sensitive personal information in many cases All-party (two-party) consent for interception/recording
Statutory damages Up to $7,500 per intentional violation (certain data-breach / security contexts); civil penalties in AG actions $5,000 per violation (or actual damages), stacked per user/incident
Scope of “violation” Focused on notice, access, deletion, opt-out rights, and certain sharing practices Interception, recording, or pen-register-style collection of communications/metadata
Thresholds Business thresholds (revenue, data volume, or percentage of revenue from selling data) No revenue or visitor thresholds; applies if site is accessible to CA residents
Common defenses Notice and opportunity to cure (in some contexts); compliance with regulations Consent of all parties; argument that activity is not a “communication” or “confidential”
Typical plaintiffs AG enforcement + consumers in limited private actions Individual plaintiffs and class/arbitration counsel
Overlap with tracking tech Strong focus on “sale” or “share” of personal information and sensitive data Direct focus on real-time interception and recording via pixels, session replay, chatbots

CIPA claims are frequently filed alongside CCPA claims, but the statutes protect different interests and carry different remedies. CCPA compliance does not immunize a company from CIPA liability.

CIPA vs. ECPA Differences

Feature CIPA (California) ECPA (Federal)
Consent standard All-party (two-party) consent Generally one-party consent
Statutory damages $5,000 per violation $10,000 (or actual damages/profits, whichever greater) under Wiretap Act provisions
Primary focus Interception and recording of communications; pen-register metadata Interception of wire, oral, or electronic communications; stored communications
Private right of action Yes, broad Yes
Geographic reach California-accessible sites/apps Nationwide (federal)
Typical pairing Often pleaded together with ECPA Frequently added to CIPA complaints to increase leverage
Ease of dismissal Higher bar because of two-party consent Sometimes easier to defeat on one-party consent or other federal doctrines, but higher damages create settlement pressure

Plaintiffs like the combination: CIPA supplies the stricter consent rule and California jury pool advantages, while ECPA supplies higher per-violation statutory damages. Roughly half of CIPA lawsuits also include ECPA claims for this reason.

The Full Cost of Non-Compliance

Headline settlement numbers understate total exposure. Costs begin long before a class-action settlement and apply to companies of every size.

  1. Statutory damages — $5,000 per violation, stacked across users and incidents. Theoretical exposure for even mid-sized sites quickly reaches tens of millions.
  2. Demand-letter response — Outside privacy counsel review ($10,000–$50,000+), internal technical investigation to determine whether the alleged violation occurred, CMP and website audits, and negotiation costs. Many companies settle at this stage because the cost of settlement is lower than the cost of mounting a defense, regardless of the ultimate merits.
  3. Litigation defense — Outside counsel through a motion to dismiss often runs $150,000–$500,000+. Through trial or arbitration the range climbs to $500,000–$2 million+. Expert witnesses and technical consultants add $50,000–$200,000+. Internal resource diversion (legal, privacy, engineering) and reputational harm are significant but harder to quantify.
  4. Class-action settlements — Direct settlement funds (examples: $46 million, $18.5 million, $3.4 million) plus plaintiffs’ attorneys’ fees (typically 25–33% of the fund), settlement administration costs, injunctive relief obligations that force operational changes, and follow-on regulatory scrutiny from the California Attorney General, CPPA, or FTC.

Prevention versus Reaction Cost Comparison

Scenario Estimated Cost Range
Structured / automated privacy auditing (annual) $25,000 – $75,000
Manual privacy audit (annual) $50,000 – $150,000+
Demand-letter response and settlement $50,000 – $500,000+
CIPA litigation defense (through dismissal) $150,000 – $500,000+
Class-action settlement $1,000,000 – $50,000,000+

The cost of prevention is a fraction of the cost of a single demand letter, let alone a class action. The companies that paid the largest CIPA settlements often had consent banners and CMPs in place. What they lacked was continuous verification that tracking technologies were not firing before consent and that disclosures matched actual data flows. That gap is where CIPA exposure lives.

Why Companies Keep Getting Sued: The CMP Gap

Consent Management Platforms are designed to present banners and enforce user choices. We have been sounding the alarm bell before almost anybody else about Swigart Law, Vivek Shah, and the risks behind faulty cookie banners & wrongful collection claims. Those that listened to Captain Compliance’s privacy team have saved by not having to endure legal costs and settlement payments. Those who did not have realized that just because you have a cookie banner running on your site you need to know that they are not designed to verify that the rest of the technology stack actually respects those choices. Common failures include:

  • Tracking pixels or scripts firing before the CMP script loads.
  • Cookies miscategorized or left uncategorized by the CMP.
  • Session replay tools capturing sensitive inputs without masking.
  • Privacy disclosures that do not accurately describe real-time third-party sharing.
  • Opt-out signals (including Global Privacy Control) not fully honored for advertising cookies and network requests.
  • Third-party tags loaded via tag managers that bypass consent logic.

Manual audits cannot keep pace with weekly marketing changes, tag-manager updates, and third-party script modifications. Continuous, systematic checking is required.

Top CIPA Risk Factors

Use of third-party advertising technology combined with any of the following significantly elevates risk:

  • Vague privacy disclosures that fail to inform users that communications are being intercepted and shared with third parties in real time.
  • Sharing of sensitive health, financial, or location data without explicit consent.
  • Click-through surveys or forms whose inputs are transmitted to third parties.
  • User-inputted data (including search terms) embedded in URLs and captured by tracking tools.
  • Online appointment or intake forms that transmit health or personal information in real time.
  • Session replay tools (Hotjar, FullStory, and similar) without adequate masking and disclosure.
  • Third-party chatbots that process user communications without clear notice that the conversation may be shared or processed by third parties.

The common legal theory is that any technology intercepting and transmitting user communications to a third party in real time without clear consent constitutes illegal wiretapping under CIPA. The more sensitive the data and the less transparent the disclosure, the greater the litigation risk.

Complete Web Privacy Auditing Checklist

Websites should be audited weekly or monthly. Marketing teams continuously add tags; third parties change cookie behavior; new pages and forms appear. The following checks address the highest-risk areas (CIPA-relevant items marked High).

High-Priority Checks

  • CMP script precedence — Confirm the CMP script fires before any third-party script, pixel, or tag capable of setting cookies, local storage, or sending tracking data. Place the CMP at the top of the <head> or use a Consent Initialization trigger in Google Tag Manager.
  • Session replay tool usage — Identify all session-replay tools. Verify sensitive data is masked and that users receive adequate disclosure before recording begins.
  • Third-party chatbot disclosures — Ensure users are informed before engagement that chat communications may be intercepted or shared with third parties.
  • Sensitive data sharing — Map every personal data element shared with each third party. Flag health, financial, or location data shared without explicit opt-in consent.
  • User-inputted data in URLs — Scan for tracking tools that capture URL parameters containing search terms or form data and transmit them to third parties.
  • Online appointment / form data sharing — Identify all forms. Confirm third-party pixels do not receive sensitive form inputs in real time without consent.
  • Opt-out / CCPA compliance — Verify third-party advertising cookies and network requests are blocked on traditional opt-out and on Global Privacy Control (GPC) signals. Check for uncategorized or miscategorized cookies. Flag any advertising pixels that continue collecting data after opt-out.
  • Video viewing data sharing — Track video-viewing data shared with third parties and confirm explicit consent where required (VPPA risk).
  • Privacy disclosure adequacy — Compare privacy policy and consent-banner language against actual third-party data flows. Flag discrepancies.
  • Consent banner compliance — Confirm the banner provides clear disclosures, a visible opt-out/reject button, and sufficient color contrast. Avoid dark patterns that make opting out more difficult than opting in.

Medium- and Lower-Priority Checks

  • Google Consent Mode verification (correct signals on opt-out and GPC).
  • Unapproved vendors (maintain a current inventory and contract database).
  • Data-sharing conflicts with third-party contracts.
  • Google Analytics Signals usage when users have opted out of sharing.
  • Privacy-policy link and “Do Not Sell or Share My Personal Information” / “Your Privacy Choices” link visibility.

Quick Prevention Checklist

  • CMP script loads first.
  • Clear, early disclosure that interactions may be shared with third parties.
  • Sensitive inputs masked in forms and session-replay tools.
  • User opt-outs (including GPC) fully honored for advertising technologies.
  • Sensitive personal data blocked from advertising partners regardless of consent status where appropriate.
  • Regular automated or structured audits performed; manual spot-checks miss hidden tracking.

CIPA Exposure

CIPA exposure is not primarily a problem of missing banners. It is a problem of unverified technology stacks. Continuous monitoring that confirms consent is collected before data leaves the browser, that disclosures match reality, and that high-risk tools are properly configured is the practical defense against both demand letters and class actions.

At Captain Compliance we help organizations understand these risks, build durable compliance processes, and stay current with the evolving interpretation of CIPA, CCPA, VPPA, ECPA, and related statutes. Regular auditing, accurate disclosures, and disciplined third-party management remain the most effective ways to keep statutory-damage exposure theoretical rather than real.

Frequently Asked Questions

Does having a CMP protect me from CIPA claims?
No. A CMP manages consent banners and preference signals. It does not verify that tracking technologies actually wait for consent, that cookies are correctly categorized, or that session-replay and chatbot tools are properly configured. Verification requires separate auditing.

Can I avoid CIPA by blocking California IP addresses?
Geofencing and IP blocking reduce but do not eliminate risk. If the site remains accessible to California residents through ordinary means (VPN, travel, etc.), exposure remains. Courts have been skeptical of pure technical-blocking defenses when the site is publicly available.

Is CIPA limited to healthcare or sensitive data?
No. While sensitive data increases settlement value and plaintiff interest, ordinary advertising pixels, analytics, and session-replay tools on e-commerce, media, and SaaS sites have all generated claims.

How often should we audit?
Weekly or monthly is advisable for most organizations because marketing teams and third-party vendors change tags frequently. High-traffic or high-risk sites (healthcare, finance, video) benefit from more frequent checks.

What is the single highest-impact fix?
Ensure the CMP script loads and executes before any other third-party script, pixel, or tag that can set cookies or transmit data. This one change eliminates a large percentage of the most common CIPA theories.

Does CCPA compliance equal CIPA compliance?
No. The statutes have different consent standards, different private-right structures, and different theories of liability. Meeting CCPA notice and opt-out requirements does not automatically satisfy CIPA’s all-party consent and interception rules.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.