Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo

Solutions / CIPA

CALIFORNIA INVASION OF PRIVACY ACT

California turned everyday website tracking into a litigation target.

Pixels, analytics tools, session replay, chat software, advertising tags, and other third-party technologies can transmit information as soon as a visitor lands on a page. If that transmission occurs before meaningful consent, plaintiffs may allege that the website intercepted or disclosed a communication in violation of CIPA.

CIPA risk: CIPA contains no CCPA-style revenue threshold and provides a private right of action with potential statutory damages of $5,000 per violation.
Which technologies loadWhat fires before consentWhere transmissions may need review

A scan identifies technical risk indicators. It does not determine legal liability or provide legal advice.

What a CIPA claim can put on the table.

$5,000
Per violation

Potential statutory damages per violation under California Penal Code §637.2.

No minimum
Business size

No CCPA-style revenue or consumer-volume threshold applies under CIPA.

Private actions
Who can sue

Individuals may bring civil claims under CIPA.

Before consent
Timing matters

A privacy disclosure shown after a tracker fires may be too late for certain interception theories.*

* In Javier v. Assurance IQ, the Ninth Circuit held that consent obtained after an alleged interception is not retroactive. Courts have reached different conclusions across CIPA theories, and this decision does not resolve every website-tracking claim.

Your company does not need to sell data to receive a CIPA demand letter.

Many CIPA claims do not begin with a data breach or a regulator. They begin when a visitor—or a person acting as a privacy tester—loads a publicly available website and records the technologies that activate. A claimant may then allege that one or more third parties received communications, identifiers, or browsing activity before the visitor gave meaningful consent.

1

No business-size safe harbor

CIPA does not use the revenue and consumer thresholds found in the CCPA. Smaller businesses, nonprofits, publishers, retailers, healthcare organizations, professional services firms, and national brands have all faced website-tracking allegations.

2

California visitors create reach

A business does not necessarily need a California headquarters or physical location to face a claim involving alleged conduct directed at or occurring through a California visitor’s device.

3

Ordinary tools are being named

Claims increasingly focus on widely deployed analytics, advertising, chat, replay, and optimization technologies—not only unusual surveillance software.

4

Private claimants drive the risk

A regulator does not need to initiate the matter. Claims may begin with a demand letter, individual lawsuit, class action, or mass-arbitration filing.

If your website is accessible to California visitors and deploys third-party code, you should evaluate the risk.

A tracker can transmit evidence before anyone reads your privacy policy.

1

Visitor arrives

A visitor opens a page from a California device or location.

2

Third-party code activates

A pixel, analytics script, replay tool, chat service, or advertising tag loads.

3

Information is transmitted

The technology may receive an IP address, cookie ID, page URL, device details, events, form interactions, or other information.

4

Consent is challenged

The claimant alleges the transmission occurred before valid consent or was not adequately disclosed.

5

A claim follows

The company receives a demand letter, lawsuit, arbitration demand, or preservation request citing CIPA or related statutes.

The exact legal outcome is highly fact-specific. Courts examine what was collected, whether it constituted communication content or addressing information, who received it, whether the recipient was a party to the communication, when consent occurred, and which CIPA section is asserted.

The risk may already be inside your tag manager.

These technologies can have legitimate business uses. CIPA risk depends on their configuration, timing, disclosures, recipients, consent controls, and the information transmitted.

Meta PixelOn load

Function: Tracks conversions and builds advertising audiences for Meta platforms.
May receive: Page URL, device data, hashed identifiers, and event actions.
Captain Compliance: Detects presence, maps firing rules, and can gate activation behind consent.

TikTok PixelOn load

Function: Measures ad performance and builds custom audiences for TikTok campaigns.
May receive: Page URL, device identifiers, event data, and hashed contact information.
Captain Compliance: Flags the tag in scans and can delay firing until consent is recorded.

Google Analytics & ad tagsOn load

Function: Measures site traffic and powers Google Ads targeting and remarketing.
May receive: IP address, cookie identifiers, page views, and device or browser data.
Captain Compliance: Inventories every Google tag variant and applies consent-based firing rules.

Session-replay softwareOn load

Function: Records mouse movement, clicks, scrolling, and sometimes form input for UX analysis.
May receive: On-screen interactions, form field activity, and session-level identifiers.
Captain Compliance: Identifies replay scripts and can block recording until consent is given.

Chat & support widgetsOn load

Function: Powers live chat, chat bots, and support ticketing embedded on the site.
May receive: Chat transcripts, page context, device data, and sometimes visitor identity.
Captain Compliance: Detects chat vendors and can delay widget load until consent conditions are met.

Call-tracking toolsOn event

Function: Assigns dynamic phone numbers to track which marketing source drove a call.
May receive: Call metadata, page and campaign source, and sometimes call recordings.
Captain Compliance: Surfaces call-tracking scripts and documents when and how they activate.

Fingerprinting & identity resolutionOn load

Function: Builds a probabilistic device or user identifier from browser and device signals.
May receive: Device, browser, and network characteristics used to construct an identifier.
Captain Compliance: Flags fingerprinting behavior for review given its higher scrutiny under CIPA theories.

Marketing automationOn event

Function: Triggers emails, forms, and lead-scoring workflows based on site activity.
May receive: Form submissions, email identifiers, and behavioral event data.
Captain Compliance: Maps which automation tags fire on which events and under what consent state.

Heatmaps & behavioral analyticsOn load

Function: Visualizes scrolling, clicks, and attention patterns across a page.
May receive: Interaction coordinates, session identifiers, and page-level browsing data.
Captain Compliance: Detects heatmap scripts and applies pre-consent blocking where configured.

Embedded video playersOn event

Function: Hosts and plays video content from third-party platforms.
May receive: Viewing activity, device data, and sometimes cross-site identifiers.
Captain Compliance: Identifies embedded players and documents their data-sharing configuration.

Form analyticsOn event

Function: Tracks field-level interaction, abandonment, and completion on web forms.
May receive: Field interaction data and, in some configurations, entered form values.
Captain Compliance: Reviews form-analytics scripts for scope and consent alignment.

Data-broker & audience matchingOn load

Function: Matches site visitors against third-party audience or identity databases.
May receive: Identifiers, hashed contact data, and browsing activity used for matching.
Captain Compliance: Flags these tags as higher priority for review and documentation.

One statute. Several website-tracking theories.

California Penal Code §631 — Wiretapping and interception

Plaintiffs may allege that a third-party technology read, learned, or intercepted the contents of a communication while it was in transit without the required consent. Disputes often focus on whether the third party was an independent eavesdropper, an extension of the website operator, or a party to the communication.

California Penal Code §632 — Confidential communications

Some claims allege that software recorded or eavesdropped on a confidential communication without all-party consent. Whether an online interaction was reasonably confidential is often contested.

California Penal Code §638.51 — Pen registers and trap-and-trace devices

Plaintiffs have argued that pixels, cookies, scripts, and similar processes collect routing, addressing, or signaling information without a court order. Federal and California state courts have reached conflicting results about applying this provision to ordinary website activity.

Other claims may accompany CIPA allegations, including federal ECPA claims, California Computer Data Access and Fraud Act claims, VPPA claims, common-law privacy claims, and other state wiretap statutes.

CCPA compliance does not automatically solve CIPA risk.

Issue CCPA / CPRA CIPA
Law type Comprehensive consumer privacy law Communications privacy and anti-wiretapping law
Applicability Uses defined business and processing thresholds No comparable CCPA-style revenue or consumer threshold
Primary model Notice, rights, opt-out, consent in specified situations Focuses on interception, recording, consent, and communication privacy
Private lawsuits Generally limited, including certain data-security incidents Private civil actions are authorized under §637.2
Potential damages Depend on the provision and enforcement route Greater of $5,000 per violation or three times actual damages under §637.2
Website timing Notices and opt-out controls are central Whether a technology transmitted data before consent may be critical
Privacy policy alone Not sufficient for overall compliance May not establish prior consent to an alleged interception

A website can have a detailed CCPA notice and still face allegations that a third-party technology activated before consent. CIPA risk management requires examining code execution—not only policy language. For the consumer-rights side of California privacy law, see our CCPA compliance and DSAR management resources.

Control the code before it becomes evidence.

1

Real-time tracker and pixel scanning

Identify cookies, pixels, scripts, chat tools, replay technologies, and unexpected third-party connections across the site.

2

Pre-consent auto-blocking

Prevent designated nonessential technologies from activating until the required consent condition has been satisfied.

3

Tag-manager governance

Apply consent triggers and firing rules to technologies deployed through Google Tag Manager and other supported implementations.

4

Consent management

Present clear choices and record the visitor’s consent decision. Support opt-in configurations where the organization’s counsel determines they are appropriate.

5

Consent and configuration logs

Maintain timestamped evidence of banner behavior, consent choices, relevant configurations, and changes over time.

6

Dynamic technology disclosures

Keep cookie and tracking disclosures aligned more closely with the technologies observed on the website.

7

Ongoing monitoring

Detect when a new marketing tag, pixel, or vendor appears after the initial deployment.

8

Rapid-response evidence

Help legal and technical teams identify what was deployed, how it was configured, and what remediation was performed when a demand arrives.

No technical control can prevent a claimant from sending a demand or filing a lawsuit. These controls are designed to reduce exposure, improve implementation, and preserve evidence that can help counsel evaluate and respond to a claim.

What changes when CIPA risk controls are on.

Before

  • Unknown third-party scripts
  • Tags firing immediately on page load
  • Consent banner disconnected from tag behavior
  • Generic policy language
  • No evidence showing when consent occurred
  • New pixels added without review
  • Legal and technical teams reconstructing events after a demand
Controlled and documented

  • Documented tracker inventory
  • Defined pre-consent blocking rules
  • Consent state connected to tag execution
  • Technology-specific disclosures
  • Timestamped consent and configuration records
  • Monitoring for newly introduced technologies
  • Organized technical evidence for counsel and insurers

Already received a CIPA demand letter?

Do not immediately delete evidence, admit liability, or assume the demand accurately describes your website. Preserve the letter, relevant logs, tag-manager versions, consent records, policies, scanner results, and website configurations. Then coordinate technical review with qualified counsel.

Preserve the demand and attachments
Record the date and response deadline
Preserve the relevant website version
Export tag-manager and consent configurations
Identify the specific technologies named
Determine what information each technology received
Establish whether and when the technology fired
Preserve consent and preference records
Review applicable contracts and insurance coverage
Coordinate remediation and legal response
Do not communicate directly with the claimant without counsel’s direction

Get CIPA response support

Is California changing CIPA?

BillCalifornia Senate Bill 690 (2025–2026)
Current statusPending. Not law. Active in the Assembly, in the Committee on Appropriations.
Last actionAugust 5, 2026 — set for its first Appropriations hearing and placed on the suspense file. A hearing is scheduled for August 13, 2026.
Last verifiedAugust 9, 2026

The July 2, 2026 amended version of SB 690 would remove the private right of action for website, online-application, and mobile-application claims brought under Penal Code §638.51, leaving enforcement of those specific claims to the California Attorney General. The current version does not eliminate private civil claims under §631. Unless and until this or similar legislation is enacted and becomes operative, businesses must evaluate the law as currently written and enforced.

CIPA website risk, answered plainly.

Is CIPA the same as the CCPA?+
No. CCPA is a comprehensive consumer privacy law. CIPA is a communications privacy statute that includes wiretapping, recording, and pen-register provisions. A company can face CIPA allegations even when it is not subject to every CCPA requirement.
Does CIPA apply only to California companies?+
Not necessarily. Businesses outside California have been targeted when their websites allegedly interacted with or collected information from California visitors. Geographic application remains fact-specific.
Does every website tracker violate CIPA?+
No. The use of a tracker is not automatically a violation. Risk depends on the technology, information collected, recipients, timing, consent, disclosures, configuration, and legal theory asserted.
Is a privacy policy enough?+
Not necessarily. A footer policy may disclose practices, but disclosure after a technology activates may not establish prior consent to an alleged interception.
Does a cookie banner prevent CIPA lawsuits?+
No system can prevent someone from filing a claim. A properly configured consent system can help control when technologies activate and create evidence of visitor choices, but a banner that is disconnected from the underlying tags may offer little technical protection.
What damages can a claimant seek?+
California Penal Code §637.2 authorizes the greater of $5,000 per violation or three times actual damages. The statute states that actual damages are not a necessary prerequisite. How damages apply in a particular case is a legal question.
What should I scan for?+
Review pixels, cookies, analytics tools, session replay, chat widgets, advertising tags, form-tracking technology, embedded media, tag-manager configurations, and transmissions to third parties.
What if we already received a demand?+
Preserve evidence and involve qualified counsel. Captain Compliance can assist with the technical investigation, documentation, remediation, and coordination needed to help counsel evaluate the allegations.

Recent CIPA litigation activity.

The demand letters targeting website tracking

An overview of demand-letter campaigns naming common analytics and advertising tags.

Session replay, Meta Pixel, and the wiretapping wave

How replay tools and ad pixels became central to recent digital-wiretapping claims.

The pen-register theory and IP address collection

A closer look at §638.51 arguments applied to ordinary website analytics.

CIPA chat-widget claims

Why chat and support widgets have drawn their own wave of CIPA allegations.

Find the trackers before a claimant does.

Scan your website for pixels, scripts, cookies, chat tools, session replay, and other technologies that may transmit information before consent. Then document and control what happens next.