When Website Tracking Becomes a Wiretap Claim

Table of Contents

How California’s 1967 wiretap statute became a central weapon in website-tracking litigation, what plaintiffs are actually alleging under Sections 631 and 638.51, and where the law stands after the latest cases and SB 690

California just cracked down on CIPA Privacy Lawsuits and we covered that and the latest about serial lawsuit filer Vivek Shah on a recent webinar with thousands of lawyers. If you need a privacy audit or help protecting against CIPA related lawsuits reach out to our team today for a complimentary privacy audit to understand what your risks are. 

The California Invasion of Privacy Act was not written for Meta Pixel, TikTok Pixel, Microsoft Clarity, FullStory, Google Analytics, chat widgets, browser fingerprinting, or any of the other technologies now appearing in CIPA complaints.

California enacted CIPA in 1967. The Legislature said advances in science and technology had produced new methods of eavesdropping and that their increasing use threatened privacy. The statute was written in the language of telephone wires, electronic listening devices, messages in transit, and secret recording.

Nearly six decades later, plaintiffs have applied that language to browser communications.

That shift has produced one of the most active and unsettled areas of U.S. privacy litigation. A website visitor opens a page. JavaScript executes. A browser communicates with the website and, frequently, with third-party services. Those services may receive URLs, IP addresses, cookie identifiers, search terms, product selections, form entries, chat messages, event information, or other data. Plaintiffs then ask a question the Legislature could not have contemplated in 1967: did one of those machine-to-machine transmissions amount to an unlawful wiretap?

Sometimes courts have said the allegations are enough.

Sometimes they have not.

The difference increasingly turns on what the third party actually received, whether that information was the “contents” of a communication, when it acquired the information, what it did with it, whether it was functioning independently or merely as a tool of the website operator, and what the user had actually consented to.

Those distinctions matter more than broad statements that a website “used tracking.”

Section 631 is the center of the website wiretapping theory

California Penal Code § 631(a) is unusually dense. Courts commonly break it into several clauses.

The first prohibits intentionally tapping or making an unauthorized connection with a telegraph or telephone wire, line, cable, or instrument.

The second reaches a person who, willfully and without the consent of all parties or in an unauthorized manner, reads, attempts to read, or learns the contents or meaning of a message or communication while it is in transit, passing over a wire, line, or cable, or being sent from or received in California.

The statute then addresses the use of information obtained that way and imposes liability on someone who aids, agrees with, employs, or conspires with another person to commit the prohibited acts.

That last provision explains why many modern complaints are framed differently against the website and the technology provider.

The plaintiff may allege that Meta, TikTok, FullStory, Salesforce, Hotjar, Microsoft, another analytics vendor, or another third party was the actual interceptor. The website operator is then accused of aiding or enabling the interception by putting the third-party code on its website.

That structure allows plaintiffs to work around an important limitation in California wiretap law: a party ordinarily cannot “eavesdrop” on its own communication.

The Ninth Circuit applied that principle directly in Thomas v. Papa John’s International, Inc. in June 2025. The plaintiff alleged that Papa John’s itself violated § 631 through session-replay technology. The court affirmed dismissal because Papa John’s was a party to the communications with its website visitors. Critically, the plaintiff had not alleged that Papa John’s aided a separate third party in eavesdropping.

The pleading lesson is obvious. A modern § 631 complaint is often strongest when it identifies an allegedly independent third-party recipient and then pleads the website operator as an aider rather than pretending the website secretly intercepted a communication to which it was itself a party.

Thomas is unpublished and therefore not precedential except as permitted by Ninth Circuit Rule 36-3, but the reasoning follows the longstanding participant rule recognized in California cases and in In re Facebook Internet Tracking Litigation.

What a website wiretap allegation looks like technically

A typical complaint tries to translate ordinary browser architecture into the elements of § 631.

The sequence usually looks something like this:

  1. A California user visits a website.
  2. The browser requests a page from the website.
  3. The returned page contains first-party code and one or more third-party scripts, tags, pixels, SDKs, APIs, or embedded services.
  4. As the visitor interacts with the page, code running in the browser generates additional network requests.
  5. Those requests send information to the website operator, a third-party service, or both.
  6. The plaintiff alleges that the third party obtained information contemporaneously with the visitor’s communication with the website.
  7. The plaintiff characterizes the information as protected “contents” rather than technical metadata.
  8. The plaintiff alleges the third party had an independent ability or purpose to read, process, profile, retain, analyze, monetize, or otherwise use the information.
  9. The website is accused of aiding the interception by deploying or configuring the third-party technology.

The specific data matters.

A bare allegation that “tracking occurred” is increasingly vulnerable. A complaint identifying the exact request, destination domain, payload, event, form field, URL parameter, cookie value, or chat content has a different posture.

The May 2026 decision in In re Meta Android Privacy Litigation illustrates how detailed those allegations can become. Plaintiffs alleged that Meta Pixel transmitted page URLs, search-bar information, actions such as opening an article or adding a product to a cart, and the contents of common form fields. The Northern District of California held that those categories plausibly constituted the contents of communications and allowed federal Wiretap Act and CIPA interception claims to proceed at the pleading stage.

That case involved unusually detailed allegations concerning Meta’s Android tracking architecture, but its treatment of “contents” matters well beyond Android.

The four recurring fights under Section 631

Most website § 631 cases eventually converge on four questions: who was a party, what constituted contents, when the information was obtained, and whether there was legally sufficient consent.

Was the vendor an interceptor or merely a tool?

This has been one of the deepest divisions in the session-replay cases.

In Graham v. Noom, Inc., the Northern District of California addressed FullStory software that recorded keystrokes, mouse clicks, scrolling, and other website interactions. The court treated FullStory largely as a tool used by Noom, comparing its role to a recorder employed by a party to preserve its own communications. The § 631 theory was dismissed.

Other courts were less receptive to the idea that every technology provider becomes an extension of the website merely because the website hired it.

Cases including Saleh v. Nike, Inc. and Yoon v. Lululemon USA, Inc. took a more plaintiff-friendly view where the allegations suggested the third-party provider contemporaneously acquired website communications and was not simply a passive recorder under the website’s control.

The divide is not semantic. It asks what the vendor actually does.

Does it merely process data on behalf of the website?

Can it independently access the information?

Does it retain the data?

Does it use the data for its own purposes?

Does it combine the information with other datasets?

Is the allegedly intercepted information intelligible to the provider?

Those facts can alter the party analysis substantially.

What counts as the “contents” of a communication?

Section 631 does not protect every bit transmitted over the internet in the same way.

The statute refers to the “contents or meaning” of a communication. That makes the distinction between content and metadata central.

A chat message is an intuitive example of content. So is text typed into a form. Search terms may reveal what the visitor is asking the website. Product selections, medical information, appointment requests, or substantive URL paths may sometimes convey the subject of the communication.

IP addresses, browser characteristics, device identifiers, timestamps, and routing information present a different question. Those categories may be personal information under privacy statutes, but that does not automatically make them the “contents” of a communication under wiretap law.

The Ninth Circuit’s June 2025 decision in Mikulsky v. Bloomingdale’s is important here. The court held that the plaintiff had adequately alleged an aiding claim because the complaint described real-time capture of the contents of her communications by session-replay providers, rather than merely information about the characteristics of those communications. The disposition is unpublished, but the distinction is direct and useful.

That difference is also why a single tracker may produce more than one statutory theory. A plaintiff may characterize a search query or form entry as “contents” for § 631 while using an IP address or routing field to support a pen-register theory under § 638.51.

Did the third party acquire the communication while it was in transit?

Section 631’s second clause focuses on information read or learned while the communication is in transit or being sent or received.

Modern JavaScript can make this difficult to describe in ordinary language. A website interaction may produce multiple network requests within milliseconds. One goes to the website. Another goes to an analytics endpoint. Another may carry an advertising event.

Plaintiffs typically allege contemporaneous duplication: the visitor communicates with the website and third-party code causes substantially the same information to be transmitted to another entity at the same time.

Defendants often attack whether this is actually interception “in transit” rather than later access to stored information.

This distinction becomes particularly important after discovery. It is one thing to allege that a vendor “intercepted” a message. It is another to prove through source code, logs, vendor testimony, architecture, or packet evidence when acquisition occurred and what the vendor could actually read.

Could the third party actually read or learn the communication?

Gutierrez v. Converse Inc. provides perhaps the clearest recent example of the difference between capability and proof.

The plaintiff alleged that Salesforce, which helped operate Converse’s website chat functionality, violated § 631 and that Converse aided the violation.

The case reached summary judgment.

The Ninth Circuit held that evidence showing Salesforce could read chat messages was not enough to establish that Salesforce actually read or attempted to read the plaintiff’s messages. Because the plaintiff could not establish an underlying violation by Salesforce, the aiding theory against Converse also failed.

Judge Bybee wrote separately to advance an even broader defense argument: in his view, the first clause of § 631, written around “telegraph or telephone” wires and instruments, does not apply to ordinary internet communications at all. That was a concurrence, not the holding of the panel, but it captures a statutory interpretation argument that remains unresolved at the California appellate level.

The combination of Mikulsky and Gutierrez is instructive. Detailed allegations of real-time content capture can survive a motion to dismiss. At summary judgment, however, the plaintiff may need evidence that the alleged interceptor actually engaged in conduct covered by the statute.

Session replay, chat, pixels, analytics and form tracking are not identical cases

The phrase “website tracking litigation” obscures important technical differences.

Session replay

Session-replay products such as FullStory, Hotjar, Microsoft Clarity and similar tools can record or reconstruct user behavior including clicks, scrolling, page navigation, cursor movement and, depending on configuration and masking, text interaction.

Plaintiffs tend to plead session replay as the closest website analogue to traditional eavesdropping because the technology may reconstruct a visitor’s interaction rather than merely log an advertising conversion.

But the cases do not establish that session replay is inherently unlawful.

Noom favored the service-provider/extension theory. Mikulsky allowed an aiding claim where the complaint alleged real-time capture of actual contents. Gutierrez, although involving chat rather than conventional session replay, shows that proof of vendor access remains significant.

Configuration matters at least as much as the product name.

Chat widgets and chatbots

Chat presents a stronger intuitive “communication” than many analytics events.

A user types words intended for the business. If a third-party platform is simultaneously receiving those messages, a plaintiff has an easier factual story than one based solely on an IP address.

Yet Gutierrez shows why that story still requires evidence. The fact that Salesforce infrastructure handled a chat did not establish that Salesforce actually read or attempted to read the plaintiff’s message.

The vendor’s role, contractual rights, technical access and actual processing remain central.

Meta Pixel and TikTok Pixel

Pixel cases commonly allege that page activity, identifiers, search information, form information, purchase events, health-related information or other data were sent to Meta or TikTok.

The Northern District of California’s August 13, 2026 decision in Ramirez v. Trusper, Inc., involving the telehealth business Musely, is a current example. The plaintiff alleged that Facebook Pixel and TikTok Pixel transmitted personally identifiable and health-related information to Meta and TikTok. The court declined to dismiss portions of the CIPA theory, while emphasizing that consent depends on whether the disclosures actually covered the conduct alleged.

The court specifically rejected the idea that merely telling users what information the company itself collected necessarily established consent to disclosure of that information to third parties. That distinction should matter to privacy lawyers reviewing notices: collection language and third-party disclosure language are not interchangeable.

Google Analytics and ordinary analytics

Analytics cases can be harder to generalize because implementations vary widely.

A Google Analytics request may contain URLs, event names, device information, identifiers and custom parameters. Another implementation may transmit much less. A generic statement that “Google Analytics was installed” does not answer what a particular visitor communicated, what Google received, or whether the payload contained substantive content.

This is one reason network-level evidence has become so important.

Search bars and form fields

Search fields have become a recurring basis for CIPA demand letters because they can produce easily recorded evidence.

A visitor types a term. The website or a third-party script generates a request. The demand attaches developer-tools screenshots or network captures purporting to show the search term traveling to a third-party domain.

The legal question still depends on the details: whether the third party received the search term, whether receipt occurred contemporaneously, whether it was readable, what role the third party played, and whether the user consented to the challenged conduct.

Form fields can carry greater risk when they contain substantive personal information. Health, finance, account, appointment and lead-generation forms have therefore generated particularly consequential litigation.

Consent is important, but CIPA litigation cannot be reduced to a banner-firing test

The Ninth Circuit’s 2022 decision in Javier v. Assurance IQ, LLC established an important rule for § 631: the court predicted that the California Supreme Court would require prior consent to the challenged interception. A plaintiff who allegedly gave consent only after ActiveProspect’s TrustedForm technology had already captured his interaction had sufficiently pleaded the absence of valid express prior consent. The Ninth Circuit did not resolve whether there was implied consent, whether ActiveProspect was truly a third party, or several of the defendants’ other arguments.

But Javier does not convert every CIPA analysis into the simplistic question of whether a tag executed before or after a cookie banner appeared.

Privacy lawyers should ask a more exact question: consent to what?

What technology was disclosed?

What categories of information were described?

Which recipients were identified or reasonably encompassed?

What uses were explained?

What action manifested consent?

Which version of the notice or interface did the plaintiff encounter?

Can the business prove that version was live on the date of the alleged visit?

Did the challenged processing fall within the scope of what the user agreed to?

Ramirez is useful on that issue because the court distinguished disclosure that the website collected medical information from disclosure that the information would be sent to third parties such as Meta and TikTok.

That is why a privacy policy can be legally important without being sufficient by itself.

Section 632 remains relevant, particularly for confidential communications

Section 631 receives most of the attention in website cases, but § 632 should not be ignored.

Section 632 prohibits intentionally using an electronic amplifying or recording device to eavesdrop upon or record a confidential communication without the consent of all parties.

The additional word “confidential” changes the analysis. Courts ask whether the circumstances reasonably indicated that a party desired the communication to be confined to the parties.

The 2025 Flo Health litigation showed the potential reach of § 632 in the software context. Users alleged that intimate menstrual and reproductive-health information entered into the Flo app was transmitted through SDK integrations. Google and Flurry settled before trial, Flo settled during trial, and the jury found Meta liable on the remaining § 632 claim. Judge James Donato later declined to overturn the verdict.

The case was an app case involving particularly sensitive communications, not a ruling that ordinary web analytics violate § 632. Its importance lies elsewhere: software-mediated communications can fall within CIPA’s eavesdropping framework when the facts satisfy the statutory elements.

The pen-register theory under Sections 638.50 and 638.51

The second major branch of modern CIPA website litigation grew out of provisions that look even less like conventional cookie law.

Section 638.50 defines a “pen register” as a device or process that records or decodes dialing, routing, addressing or signaling information transmitted by the instrument or facility from which a wire or electronic communication is sent, but not the contents of the communication. A trap-and-trace device captures incoming information identifying the source of a communication.

Section 638.51 generally prohibits installing or using a pen register or trap-and-trace device without a court order, subject to specified provider exceptions, including certain operational, security and fraud purposes and circumstances where user consent has been obtained.

The modern website theory developed because the statute says “device or process” and expressly refers to electronic communications.

In Greenley v. Kochava, Inc., the Southern District of California rejected a categorical argument that these provisions were limited to traditional telephone equipment. The allegations involved software that identified users, gathered information and correlated data through device fingerprinting.

That reasoning helped fuel a new class of claims asserting that website scripts and pixels operate as unauthorized pen registers when they capture IP addresses, identifiers, routing information or similar metadata.

Shah v. Fandom, Inc. followed that broader reading in 2024. The court allowed a § 638.51 theory based on website trackers and IP-address collection to proceed. The litigation later resulted in a class settlement covering California GameSpot visitors and identifying GumGum, Audiencerate and TripleLift trackers.

Other decisions, including Moody v. C2 Educational Systems Inc. and Zarif v. Hwareh.com, Inc., likewise allowed website-based pen-register allegations to move forward.

Not every court has agreed. Some California trial courts have taken a narrower view of the statutory architecture. In 2026, Blaker v. NetScout Systems added to the defense-side authority questioning whether § 638.51 sensibly applies to ordinary website SDKs.

The divide finally reached the California Court of Appeal in Variety Media, LLC v. Superior Court.

Variety Media may narrow the theory, but there is no final appellate decision yet

Variety Media is one of the most important pending CIPA matters because California appellate courts have not squarely resolved the modern website pen-register theory.

The Second District issued a tentative ruling on August 21, 2026. Oral argument occurred on August 25, and the matter was submitted. As of August 31, the docket still does not show a final opinion.

The tentative ruling did not simply declare that § 638.51 can never apply to websites.

Instead, it focused on what information a pen register must capture.

The court tentatively reasoned that source information such as the visitor’s IP address is not enough, standing alone, to establish use of a pen register, because a pen register concerns outgoing or destination-identifying metadata. A complaint may therefore need allegations that the process captured destination information, such as a target URL, rather than merely identifying the source of the communication.

If that reasoning appears in the final opinion, it could eliminate many complaints built almost entirely around IP-address collection while leaving more technically developed theories available.

Several federal courts have already stayed § 638.51 litigation to await Variety. An Eastern District of California order in August noted that the appellate ruling was likely to simplify a central question of law, and an August 26 order stayed a separate Adidas matter for the same reason.

For now, however, the tentative ruling is not the final opinion.

SB 690 could remove the private website pen-register claim almost entirely

The Legislature may resolve much of the § 638.51 fight before the courts do.

SB 690 passed the California Assembly on August 28, 2026 by a 66-0 vote. The Senate concurred that same day, 40-0, and the bill was ordered to enrollment. As of August 31, it has not yet been signed by Governor Gavin Newsom.

Earlier versions of SB 690 were much broader. They proposed “commercial business purpose” exceptions that would have changed Sections 631, 632, 632.7 and 638.50.

That is not what the final legislative version does.

Those provisions were removed.

The enrolled bill amends only § 637.2, CIPA’s civil-remedies provision. For a § 638.51 claim against a private actor arising from conduct on an internet website, online application or mobile application, the bill provides that an action under § 637.2 may be brought only by the Attorney General.

It also makes that limitation retroactive to pending claims in actions commenced within two years before the legislation’s operative date.

That would dramatically alter the current pen-register litigation market if Newsom signs it.

It would not repeal CIPA.

It would not eliminate § 631.

It would not create a general website-tracking safe harbor.

It would not erase federal ECPA claims, VPPA claims, § 632 theories or other state wiretap statutes.

It addresses a specific private remedy that became unusually prolific: website and app claims under § 638.51.

Why plaintiffs keep bringing these cases even when the law is divided

CIPA’s economics matter.

Section 637.2 currently permits an injured person to seek the greater of $5,000 per violation or three times actual damages. Actual damages are not a prerequisite to suit. The definition of a separate “violation,” classwide proof, standing and other limitations can become heavily contested, so multiplying $5,000 by every page view or visitor is not a legally established damages calculation. Still, statutory damages give even a disputed theory settlement leverage. The current SB 690 text preserves that private remedy generally while carving out the specified website/app § 638.51 claims.

The litigation has therefore developed its own ecosystem.

Tauler Smith, Swigart Law Group and Manning Law are among the firms publicly identified as bringing website-tracking CIPA claims. Defense firms have also documented a substantial volume of demands and proceedings involving self-represented plaintiff Vivek Shah.

Shah’s theories changed over time. Some demands focused on search terms allegedly transmitted to companies such as Google, Meta or HubSpot under § 631. Later demands increasingly invoked the pen-register provisions.

On July 20, 2026, Judge R. Gary Klausner of the Central District of California declared Shah a vexatious litigant in Shah v. Crain Communications, Inc. and imposed a prefiling requirement for new CIPA and related digital-privacy actions in that federal district. The order did not prohibit demand letters, does not govern every California court, and did not establish that every claim Shah has asserted is legally invalid.

Captain Compliance’s own prior reporting and demand-letter review has also documented recurring claimant names including Robert Bell and Srinivas Rangam. Those names should be understood in context: the existence of repeated demands does not decide the merits of a particular claim. Each claim still turns on the technology, evidence, jurisdiction, statutory elements and applicable case law.

There are legitimate arguments on both sides of the larger CIPA debate.

Plaintiffs argue that a technology-neutral privacy statute should not become obsolete merely because modern surveillance occurs through JavaScript rather than copper telephone wires. Section 630 itself expressly refers to technological advances and the continuing development of eavesdropping techniques.

Defendants respond that courts should not turn criminal statutes written around telephone interception and judicial pen-register orders into a comprehensive internet privacy code, especially when California has since enacted detailed statutes such as the CCPA.

Both arguments have found receptive courts.

CIPA, ECPA and VPPA are different theories even when they arise from the same pixel

The decline of one CIPA theory does not necessarily end a tracking case.

Plaintiffs increasingly combine CIPA with the federal Electronic Communications Privacy Act, usually through the federal Wiretap Act, 18 U.S.C. § 2511. They also plead the Florida Security of Communications Act, Pennsylvania’s wiretap statute, privacy torts, state consumer-protection laws and, where video is involved, the Video Privacy Protection Act.

The federal Wiretap Act and § 631 overlap in their focus on interception of communications, contents and acquisition during transmission, but their consent and party exceptions are not identical in every respect.

Flo Health provides a useful example. The court granted Meta summary judgment on the federal Wiretap Act theory because Flo itself had consented to Meta’s data collection, invoking the federal statute’s party-consent provision. The California § 632 claim nevertheless went to a jury and produced a verdict against Meta.

VPPA is different again.

A VPPA plaintiff generally alleges disclosure of personally identifiable information concerning video materials obtained by a consumer from a video tape service provider. A Meta Pixel event carrying a Facebook identifier and the title or URL of a viewed video can therefore produce a VPPA theory even though the legal question is disclosure of video-viewing information rather than interception under § 631.

Privacy lawyers reviewing a tracking demand should identify the statute first, not simply ask whether “the pixel was consented to.”

A privacy policy is evidence, not a force field

One recurring defense mistake is assuming that a broad privacy policy resolves the technical dispute.

Policies matter. Consent language matters. Cookie notices matter.

But the legal inquiry is often narrower than the policy document.

If the claim concerns a search term sent to a third party, counsel should determine whether the policy covered that specific disclosure and use.

If the claim concerns session replay, determine what the user was told about recording or reconstruction of interactions.

If the allegation involves medical information, determine whether the notice actually described disclosure of that information to the relevant advertising or analytics recipient.

If a business says data is used only for one purpose while its implementation does something materially different, the policy can create an additional evidentiary problem rather than solve the original one.

Javier makes clear that consent cannot simply be retroactively supplied after an alleged interception. Ramirez shows that notice of collection does not necessarily amount to notice of disclosure to third parties.

The better legal inquiry compares three things: what the notice said, what the user did, and what the network traffic actually shows.

What defense counsel should preserve and investigate

When a demand letter or complaint arrives, the most valuable evidence may disappear quickly because websites change constantly.

Counsel should consider preserving and investigating:

  • the exact website version and relevant pages from the alleged visit date;
  • the plaintiff’s stated date, time, location, device, browser and interactions;
  • historical consent-banner and privacy-notice versions;
  • consent and preference records associated with the relevant session, where available;
  • tag-manager versions and publication history;
  • JavaScript and third-party technologies actually present;
  • HAR files, network requests, request payloads and destination domains;
  • cookies, local-storage values and identifiers involved;
  • the precise data fields allegedly transmitted;
  • whether sensitive or substantive content was masked, filtered, hashed or excluded;
  • whether a vendor received readable contents or only event/metadata information;
  • whether acquisition occurred contemporaneously with the communication;
  • whether the third party could independently use the information;
  • contracts, data-processing terms and product documentation describing the vendor’s role;
  • whether the plaintiff can establish a California nexus and Article III standing where suit is in federal court;
  • applicable limitations, arbitration and class-waiver issues;
  • the party/extension doctrine;
  • whether an underlying third-party § 631 violation exists before analyzing aiding liability;
  • whether the alleged data is “contents” for § 631 or routing/addressing information for § 638.51;
  • the status of Variety Media if a pen-register theory is pleaded; and
  • SB 690’s status and potential retroactive effect if the dispute includes a private website/app § 638.51 claim.

Preservation should come before aggressive remediation destroys evidence of what the site actually did.

A technical review is therefore part of litigation analysis, not merely a compliance exercise.

Where privacy technology fits into the defense

Software does not answer the legal question of whether a particular transmission violated § 631. It can make the factual question much easier to answer.

That distinction is the reason a combination of continuous scanning, consent management, configurable blocking controls, historical consent evidence and monitoring is more useful than a banner standing by itself.

Captain Compliance’s scanning technology can identify cookies, pixels, scripts and other third-party technologies operating across a site. Consent controls can govern technologies according to the organization’s selected regional and legal configuration. Consent records give counsel evidence about the choice presented and the visitor’s recorded preference. Ongoing monitoring helps identify changes introduced by marketing teams, agencies, developers or third-party vendors after the initial implementation.

For litigation purposes, those tools address a recurring evidentiary problem: reconstructing what the website was doing when the plaintiff says the interception occurred.

The objective is not to adopt the broad proposition that every third-party request on every website must be disabled until every visitor affirmatively opts in. CIPA’s requirements depend on the statutory theory, the data, technology, jurisdiction, consent framework and circumstances.

The objective is control and evidence.

A business should know what technologies are present, what they transmit, under what conditions they operate, what choices were presented to the user and what evidence exists to establish those facts later.

Captain Compliance’s Compliance Shield adds a litigation-focused protection layer for qualifying deployments, while the underlying platform provides the technical controls and records counsel needs when a website’s implementation becomes evidence in a privacy dispute.

No privacy platform can prevent a plaintiff from sending a demand letter. A well-instrumented privacy program can materially change the quality of the response.

What survives if SB 690 becomes law

The current website-tracking litigation cycle is likely to change substantially if Governor Newsom signs SB 690.

The easiest prediction is that private § 638.51 website and app claims would lose much of their usefulness because the enrolled bill reserves the § 637.2 action for that conduct to the Attorney General and applies the limitation retroactively to a defined set of pending claims.

The harder question is what replaces them.

Section 631 remains.

Plaintiffs can continue testing whether pixels, session-replay services, chat vendors and other technologies obtain substantive communications in real time.

Section 632 remains available where confidential communications are involved.

Federal ECPA theories remain.

VPPA remains relevant to video-tracking cases.

Other state wiretap statutes remain in play.

Health-data cases continue to present their own statutory and common-law theories.

And ordinary privacy torts can sometimes survive even where a statutory theory does not.

The cases decided over the last several years point toward a more technically demanding phase of website privacy litigation. A complaint built only around the proposition that a website transmitted an IP address to an analytics service may face increasing difficulty, particularly if Variety Media ultimately narrows the pen-register definition and SB 690 becomes law.

A complaint alleging that a third party contemporaneously received readable search terms, private chat messages, health information, form contents or other substantive communications presents a different question.

That is the distinction privacy lawyers should watch.

CIPA website litigation began by asking whether 1967 wiretap law could reach modern websites at all. Courts are now asking more specific questions: what communication, what data, what recipient, what access, what timing, and what consent?

Those questions are harder for plaintiffs to plead with precision.

They are also harder for defendants to answer if nobody knows what the website actually did.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.