CALIFORNIA INVASION OF PRIVACY ACT
California turned everyday website tracking into a litigation target.
Pixels, analytics tools, session replay, chat software, advertising tags, and other third-party technologies can transmit information as soon as a visitor lands on a page. If that transmission occurs before meaningful consent, plaintiffs may allege that the website intercepted or disclosed a communication in violation of CIPA.
A scan identifies technical risk indicators. It does not determine legal liability or provide legal advice.
What a CIPA claim can put on the table.
Potential statutory damages per violation under California Penal Code §637.2.
No CCPA-style revenue or consumer-volume threshold applies under CIPA.
Individuals may bring civil claims under CIPA.
A privacy disclosure shown after a tracker fires may be too late for certain interception theories.*
* In Javier v. Assurance IQ, the Ninth Circuit held that consent obtained after an alleged interception is not retroactive. Courts have reached different conclusions across CIPA theories, and this decision does not resolve every website-tracking claim.
Your company does not need to sell data to receive a CIPA demand letter.
Many CIPA claims do not begin with a data breach or a regulator. They begin when a visitor—or a person acting as a privacy tester—loads a publicly available website and records the technologies that activate. A claimant may then allege that one or more third parties received communications, identifiers, or browsing activity before the visitor gave meaningful consent.
No business-size safe harbor
CIPA does not use the revenue and consumer thresholds found in the CCPA. Smaller businesses, nonprofits, publishers, retailers, healthcare organizations, professional services firms, and national brands have all faced website-tracking allegations.
California visitors create reach
A business does not necessarily need a California headquarters or physical location to face a claim involving alleged conduct directed at or occurring through a California visitor’s device.
Ordinary tools are being named
Claims increasingly focus on widely deployed analytics, advertising, chat, replay, and optimization technologies—not only unusual surveillance software.
Private claimants drive the risk
A regulator does not need to initiate the matter. Claims may begin with a demand letter, individual lawsuit, class action, or mass-arbitration filing.
If your website is accessible to California visitors and deploys third-party code, you should evaluate the risk.
A tracker can transmit evidence before anyone reads your privacy policy.
Visitor arrives
A visitor opens a page from a California device or location.
Third-party code activates
A pixel, analytics script, replay tool, chat service, or advertising tag loads.
Information is transmitted
The technology may receive an IP address, cookie ID, page URL, device details, events, form interactions, or other information.
Consent is challenged
The claimant alleges the transmission occurred before valid consent or was not adequately disclosed.
A claim follows
The company receives a demand letter, lawsuit, arbitration demand, or preservation request citing CIPA or related statutes.
The exact legal outcome is highly fact-specific. Courts examine what was collected, whether it constituted communication content or addressing information, who received it, whether the recipient was a party to the communication, when consent occurred, and which CIPA section is asserted.
The risk may already be inside your tag manager.
These technologies can have legitimate business uses. CIPA risk depends on their configuration, timing, disclosures, recipients, consent controls, and the information transmitted.
Meta PixelOn load
TikTok PixelOn load
Google Analytics & ad tagsOn load
Session-replay softwareOn load
Chat & support widgetsOn load
Call-tracking toolsOn event
Fingerprinting & identity resolutionOn load
Marketing automationOn event
Heatmaps & behavioral analyticsOn load
Embedded video playersOn event
Form analyticsOn event
Data-broker & audience matchingOn load
One statute. Several website-tracking theories.
California Penal Code §631 — Wiretapping and interception
Plaintiffs may allege that a third-party technology read, learned, or intercepted the contents of a communication while it was in transit without the required consent. Disputes often focus on whether the third party was an independent eavesdropper, an extension of the website operator, or a party to the communication.
California Penal Code §632 — Confidential communications
Some claims allege that software recorded or eavesdropped on a confidential communication without all-party consent. Whether an online interaction was reasonably confidential is often contested.
California Penal Code §638.51 — Pen registers and trap-and-trace devices
Plaintiffs have argued that pixels, cookies, scripts, and similar processes collect routing, addressing, or signaling information without a court order. Federal and California state courts have reached conflicting results about applying this provision to ordinary website activity.
Other claims may accompany CIPA allegations, including federal ECPA claims, California Computer Data Access and Fraud Act claims, VPPA claims, common-law privacy claims, and other state wiretap statutes.
CCPA compliance does not automatically solve CIPA risk.
| Issue | CCPA / CPRA | CIPA |
|---|---|---|
| Law type | Comprehensive consumer privacy law | Communications privacy and anti-wiretapping law |
| Applicability | Uses defined business and processing thresholds | No comparable CCPA-style revenue or consumer threshold |
| Primary model | Notice, rights, opt-out, consent in specified situations | Focuses on interception, recording, consent, and communication privacy |
| Private lawsuits | Generally limited, including certain data-security incidents | Private civil actions are authorized under §637.2 |
| Potential damages | Depend on the provision and enforcement route | Greater of $5,000 per violation or three times actual damages under §637.2 |
| Website timing | Notices and opt-out controls are central | Whether a technology transmitted data before consent may be critical |
| Privacy policy alone | Not sufficient for overall compliance | May not establish prior consent to an alleged interception |
A website can have a detailed CCPA notice and still face allegations that a third-party technology activated before consent. CIPA risk management requires examining code execution—not only policy language. For the consumer-rights side of California privacy law, see our CCPA compliance and DSAR management resources.
Control the code before it becomes evidence.
Real-time tracker and pixel scanning
Identify cookies, pixels, scripts, chat tools, replay technologies, and unexpected third-party connections across the site.
Pre-consent auto-blocking
Prevent designated nonessential technologies from activating until the required consent condition has been satisfied.
Tag-manager governance
Apply consent triggers and firing rules to technologies deployed through Google Tag Manager and other supported implementations.
Consent management
Present clear choices and record the visitor’s consent decision. Support opt-in configurations where the organization’s counsel determines they are appropriate.
Consent and configuration logs
Maintain timestamped evidence of banner behavior, consent choices, relevant configurations, and changes over time.
Dynamic technology disclosures
Keep cookie and tracking disclosures aligned more closely with the technologies observed on the website.
Ongoing monitoring
Detect when a new marketing tag, pixel, or vendor appears after the initial deployment.
Rapid-response evidence
Help legal and technical teams identify what was deployed, how it was configured, and what remediation was performed when a demand arrives.
No technical control can prevent a claimant from sending a demand or filing a lawsuit. These controls are designed to reduce exposure, improve implementation, and preserve evidence that can help counsel evaluate and respond to a claim.
What changes when CIPA risk controls are on.
- Unknown third-party scripts
- Tags firing immediately on page load
- Consent banner disconnected from tag behavior
- Generic policy language
- No evidence showing when consent occurred
- New pixels added without review
- Legal and technical teams reconstructing events after a demand
- Documented tracker inventory
- Defined pre-consent blocking rules
- Consent state connected to tag execution
- Technology-specific disclosures
- Timestamped consent and configuration records
- Monitoring for newly introduced technologies
- Organized technical evidence for counsel and insurers
Already received a CIPA demand letter?
Do not immediately delete evidence, admit liability, or assume the demand accurately describes your website. Preserve the letter, relevant logs, tag-manager versions, consent records, policies, scanner results, and website configurations. Then coordinate technical review with qualified counsel.
Is California changing CIPA?
The July 2, 2026 amended version of SB 690 would remove the private right of action for website, online-application, and mobile-application claims brought under Penal Code §638.51, leaving enforcement of those specific claims to the California Attorney General. The current version does not eliminate private civil claims under §631. Unless and until this or similar legislation is enacted and becomes operative, businesses must evaluate the law as currently written and enforced.
CIPA website risk, answered plainly.
Is CIPA the same as the CCPA?+
Does CIPA apply only to California companies?+
Does every website tracker violate CIPA?+
Is a privacy policy enough?+
Does a cookie banner prevent CIPA lawsuits?+
What damages can a claimant seek?+
What should I scan for?+
What if we already received a demand?+
Recent CIPA litigation activity.
The demand letters targeting website tracking
An overview of demand-letter campaigns naming common analytics and advertising tags.
Session replay, Meta Pixel, and the wiretapping wave
How replay tools and ad pixels became central to recent digital-wiretapping claims.
The pen-register theory and IP address collection
A closer look at §638.51 arguments applied to ordinary website analytics.
CIPA chat-widget claims
Why chat and support widgets have drawn their own wave of CIPA allegations.
Find the trackers before a claimant does.
Scan your website for pixels, scripts, cookies, chat tools, session replay, and other technologies that may transmit information before consent. Then document and control what happens next.