The California Invasion of Privacy Act (CIPA) is a 1967 wiretapping law that makes it illegal to intercept or record communications without all-party consent. Since 2022, plaintiffs have applied it to website tracking tools like pixels, cookies, session replay, and chat widgets. This exposes businesses to up to $5,000 in damages per violation.
If you run a website or app that serves visitors in California, CIPA applies to you. It was written for telephone wiretaps, tape recorders, and parabolic microphones, not pixels. However, the language is broad, the consent rule is strict, and the damages don’t require proof of harm. This made it the engine of a litigation wave against ordinary marketing technology.
Key takeaways
- CIPA is a decades-old California wiretap law that now applies to website tracking.
- Consent must come before any data moves.
- CIPA follows the California resident, not your office location.
- CCPA compliance does not protect you.
- Private plaintiffs, not regulators, enforce CIPA.
- Courts are split on whether pixels count as illegal pen registers, and pending reform legislation would end that theory
- A one-year statute of limitations makes point-in-time proof decisive.
- Plaintiffs build CIPA cases from network captures of your own website.
What is the California Invasion of Privacy Act (CIPA)?
California’s wiretapping statute sits at Penal Code sections 630 through 638. It bans: intercepting, recording, or eavesdropping on a confidential communication when not every party has consented.
A 1967 law built for “new devices and techniques”
Section 630 explains why the legislature bothered: “advances in science and technology have led to the development of new devices and techniques for the purpose of eavesdropping upon private communications,” creating “a serious threat to the free exercise of personal liberties and cannot be tolerated in a free and civilized society.”
That forward-looking phrase, “new devices and techniques,” is the textual hook plaintiffs rely on. The court held that CIPA’s wiretap section “applies to ‘new technologies'” (both telephone and online communications) and must be construed broadly to protect privacy. The Ninth Circuit’s 2022 decision in Javier v. Assurance IQ, LLC then established that consent must come before interception, not after, and the modern website-tracking docket took shape.
Is California a two-party consent state?
Yes, though all-party consent is the more accurate term. Everyone in a confidential communication has to consent before it’s recorded or monitored.
That diverges sharply from federal law, which permits recording where one party consents (18 U.S.C. § 2511(2)(d)), as do most states. So conduct that’s perfectly lawful under federal law, and lawful in the state where your business sits, can still break California law the moment a Californian is on the other end.
What counts as a confidential communication?
Section 632(c) treats a communication as confidential when the circumstances reasonably indicate that a party wants it confined to the people involved. It isn’t confidential where the parties could reasonably expect it to be overheard: a conversation in a public place, a legislative hearing, a courtroom.
The California Supreme Court set the governing standard in Flanagan v. Flanagan (2002). A communication is confidential if a party has an objectively reasonable expectation that nobody is overhearing or recording it.
What websites and tools trigger CIPA lawsuits?
Complaints and demand letters in the 2023-2026 wave focus on a consistent set of tools. The common thread is a third-party script that receives data about a visitor’s interaction before consent.
The tools named most often are advertising pixels (Meta, TikTok), analytics (Google Analytics), session-replay software, chat widgets, and fingerprinting scripts, typically transmitting data before consent or sending page contents to third parties.
CIPA follows the California resident
You don’t need a California office, server, or subsidiary to face exposure. In Kearney v. Salomon Smith Barney (2006), the California Supreme Court held that California’s all-party consent rule governed calls a Georgia brokerage recorded with California clients, even though Georgia permits one-party consent. California’s stronger privacy interest controls when a communication involves a California resident.
The logic transfers directly to websites. An out-of-state business communicating with a California visitor is in the same position as the Georgia broker. No court has held that operating outside California is a defense by itself. Nor does the statute set a minimum visitor threshold. Because § 637.2 awards damages per violation, exposure scales with California traffic.
Which CIPA sections actually get pleaded?
CIPA is a criminal statute. It also hands private plaintiffs one of the most aggressive civil remedies in American privacy law, which is why the provisions below matter for websites in 2026.
Not every CIPA claim is the same. The section a plaintiff pleads decides what they have to prove, which defenses you can raise, and whether the pending reform bill touches your situation at all.
| Provision | What it prohibits |
| § 631 – wiretapping | Four prongs: tapping or making an unauthorized connection to a wire; willfully reading or learning the contents of a communication in transit without all-party consent; using information so obtained; and aiding, agreeing with, employing, or conspiring with anyone to do the above. The last prong is the hook for nearly all website claims: plaintiffs say the site operator aided a third-party vendor’s interception. |
| § 632 – confidential communications | Intentionally using an electronic amplifying or recording device to eavesdrop on or record a confidential communication without all-party consent. “Confidential” is an objective expectation test, and courts treat ordinary internet communications as presumptively not confidential, which limits this section’s web reach. |
| §§ 632.5 / 632.6 / 632.7 – cellular and cordless interception | §§ 632.5 and 632.6 require malice; § 632.7 needs neither malice nor confidentiality, and “communication” includes voice, data, or image. The California Supreme Court held in Smith v. LoanMe (2021) that it binds parties to the call, not just outside eavesdroppers (opinion, courts.ca.gov). |
| § 632.01 – healthcare communications | An aggravated offense for disclosing or distributing – including on websites and social media – the contents of a confidential communication with a healthcare provider obtained in violation of § 632. |
| § 637.2 – private right of action | Any injured person may sue for statutory penalties for the greater of $5,000 per violation or three times actual damages, plus injunctive relief; § 637.2(c) makes actual damages not a prerequisite to suit. |
| §§ 638.50 / 638.51 – pen register and trap and trace | § 638.50 defines a pen register as a “device or process” that records dialing, routing, addressing, or signaling information – not the contents of a communication. A trap-and-trace device is the mirror image, capturing signals sent from the monitored line. § 638.51 bans installing or using one without explicit consent or a court order. The word “process” is what plaintiffs use: they argue pixels and fingerprinting scripts are pen registers. |
What are the penalties for CIPA violations?
Every offense below feeds the same § 637.2 civil remedy; what differs is the conduct and the criminal exposure.
| Provision | Conduct | Criminal fine (first offense) | Imprisonment | Enhanced fine (prior conviction) | Civil remedy |
| § 631 | Wiretap/interception | Up to $2,500 | Up to 1 year county jail, or state prison | Up to $10,000 | § 637.2: greater of $5,000 per violation or 3x actual damages, plus injunction |
| § 632 | Eavesdrop/record confidential communication | Up to $2,500 per violation | Up to 1 year county jail, or state prison | Up to $10,000 per violation | Same via § 637.2 |
| § 632.5 | Malicious cellular interception | Up to $2,500 | Up to 1 year, or state prison | Up to $10,000 | Same via § 637.2 |
| § 632.6 | Malicious cordless interception | Up to $2,500 | Up to 1 year, or state prison | Up to $10,000 | Same via § 637.2 |
| § 632.7 | Cellular/cordless intercept + record (no malice or confidentiality needed) | Up to $2,500 | Up to 1 year, or state prison | Up to $10,000 | Same via § 637.2 |
| § 632.01 | Disclose illegally recorded healthcare communication | Up to $2,500 per violation | Up to 1 year, or state prison | Up to $10,000 per violation | Same via § 637.2 |
| § 638.51 | Pen register/trap and trace without court order | Up to $2,500 | Up to 1 year, or state prison | – | Same via § 637.2 |
Who actually enforces CIPA?
Criminal enforcement of CIPA against websites is effectively nonexistent. There’s no public record of the California Attorney General bringing a website-tracking case under the statute.
The real engine is the § 637.2 private right of action: thousands of individual and class claims filed by private plaintiffs on the same per-violation formula. One practical limit applies. The statute of limitations is one year, generally running from discovery.
CIPA vs CCPA (California Consumer Privacy Act)
Many businesses assume a mature California Consumer Privacy Act (CCPA) program covers their website tracking risk. That assumption is wrong. The CCPA, at Cal. Civ. Code § 1798.100 et seq., and CIPA regulate different conduct, use opposite consent models, and have different enforcers.
A site can honor every CCPA deletion and opt-out request and still violate CIPA the moment a script transmits a California visitor’s communication before consent. That mismatch is the tension SB 690 tries to resolve. Prior consent before scripts fire is the only control that closes it. The absence of any regulatory gatekeeper is why plaintiffs’ firms use a 1967 wiretap law as California’s de facto website privacy law.
CIPA vs CCPA comparison table
| CIPA | CCPA | |
| Year enacted | 1967 (wiretap and eavesdropping statute) | 2018, operative January 1, 2020 |
| Consent model | All-party consent obtained before interception or recording (prior opt-in) | Notice plus consumer right to opt out of sale or sharing (notice/opt-out) |
| What it regulates | Interception and recording of communications, now applied to pixels, session replay, and chat tools | Consumer rights in personal information: know, delete, correct, opt out of sale or sharing |
| Private right of action | Broad: any injured person may sue for the greater of $5,000 per violation or three times actual damages, with no proof of harm required (§ 637.2) | Narrow: data breaches caused by unreasonable security only, $100 to $750 per consumer per incident, with a 30-day cure notice (§ 1798.150) |
| Enforcement reality | Private plaintiffs and the class-action bar drive virtually all cases | The California Privacy Protection Agency (CPPA) administers and enforces through administrative actions (§ 1798.199.40), and the Attorney General enforces through civil actions (§ 1798.199.90) |
CIPA vs the federal Wiretap Act (ECPA)
The federal Wiretap Act, part of the Electronic Communications Privacy Act (ECPA), prohibits intentional interception of wire, oral, and electronic communications under 18 U.S.C. § 2511. The core divergence is consent. Federal law permits interception when any one party to the communication consents (§ 2511(2)(c)-(d)).
CIPA requires every party’s consent, so a practice that satisfies the federal standard can still violate California law. Civil exposure is comparable: 18 U.S.C. § 2520 authorizes the greater of actual damages plus profits, or statutory damages of the greater of $100 per day or $10,000.
Plaintiffs’ firms that built practices on CIPA now lead with ECPA claims in demand letters and complaints.
CIPA litigation in 2026
The demand-letter economy
Filed cases are the visible tip. Plaintiffs’ firms and self-represented claimants have sent tens of thousands of pre-suit demand letters. Hundreds of brands receive them every week. Concentration is extreme.
Arbitration is the second channel. Where website terms include arbitration clauses, claimants file mass individual demands instead of class actions. The American Arbitration Association counted 92 mass arbitrations covering roughly 280,000 claims in 2024 and about 104,556 consumer demands across 81 caseloads in 2025. Of the consumer merits cases closed in 2025, 72% settled, and 96% of those settled before a merits arbitrator was appointed (AAA, 2026).
Settlements and exposure math
CIPA class actions routinely settle in the high six to seven figures. Fandom’s $1.2 million GameSpot tracker settlement won preliminary approval in December 2025.
Sector exposure: who gets sued
- Healthcare carries the highest risk – pixels on appointment, symptom, or patient-portal pages triggered the In re Meta Pixel Healthcare Litigation, and § 632.01 adds a specific healthcare offense.
- Retail and e-commerce generated the defining web-tracking rulings.
- Media and publishing produced the biggest settlements, driven by ad-tech stacks.
- Financial services face claims over login and account pages.
- Customer-service call recording under §§ 632 and 632.7 also remains a staple claim pattern.
Serial plaintiffs
Vivek Shah is a self-represented litigant. He is also the most prolific individual CIPA claimant, and since fall 2025 he has sent thousands of demand letters to businesses nationwide. On July 20, 2026, the Central District of California declared him a vexatious litigant. He voluntarily dismissed the case on July 23, 2026, and appealed to the Ninth Circuit.
Where do CIPA claims actually come from?
Three patterns generate almost all CIPA exposure. The third dominates by volume, but the first two haven’t gone anywhere, and they’re where the binding California case law lives.
- Customer service call recording: The original CIPA claim, and still active. All-party consent applies to inbound and outbound customer calls, and notice has to come before any substantive conversation. Not after the agent connects.
- Employee and workplace monitoring: CIPA applies to employers, and the all-party consent rule doesn’t soften for an employment relationship. The live risk areas are quality-assurance recording in contact centers, collaboration-tool and meeting transcription, and AI notetakers that join calls automatically.
- Third-party vendors and website trackers: The technologies at issue are ordinary. Session replay, chat widgets and chatbots, tracking pixels including the Meta Pixel, analytics tags, and ad-tech trackers loaded through a tag manager.
Where CIPA reform stands: SB 690, the CIPA reform bill
Status as of July, 2026. We update this section as the bill moves.
SB 690 (Sen. Anna Caballero) is alive and sitting in the Assembly Appropriations Committee. It passed the Assembly Privacy and Consumer Protection Committee 14-0 on July 1, 2026, in a heavily amended, much narrower form. It has not passed the Assembly and has not been signed. It is not law. If the Legislature does not send it to the governor by August 31, 2026, it dies for this session.
SB 690 is the Legislature’s answer to the website-tracking litigation wave. What it would do has changed dramatically since its introduction. Much online coverage stops before July 2026. We verify the dates and votes below against the official bill record.
How SB 690 got here
| Date | What happened |
| Feb 21, 2025 | Introduced by Sen. Caballero with bipartisan coauthors. The original bill created a broad “commercial business purpose” exemption spanning §§ 631, 632, 632.7, 638.50, and 637.2, expressly retroactive to any case pending as of January 1, 2026. |
| May 29-June 3, 2025 | Senate amendments struck the retroactivity clause after opposition from consumer groups including the Electronic Frontier Foundation, ACLU California Action, and Privacy Rights Clearinghouse; the Senate then passed the bill 35-0, with five senators not voting (official vote record). |
| July 2025 | Passed Assembly Public Safety 9-0, then stalled in the Assembly Privacy and Consumer Protection Committee. It became a two-year bill, eligible for reconsideration in 2026. |
| July 1, 2026 | Revived. The Privacy and Consumer Protection Committee passed an amended, narrowed version 14-0 and sent it to Appropriations. |
| July 2, 2026 | Read a second time, amended, and re-referred to Assembly Appropriations, where it remains today. |
What SB 690 would do (as amended July 2, 2026)
The amended bill text now changes only § 637.2, the private right of action. The broad commercial-purpose exemption is gone. In its place, a new § 637.2(d):
- Narrows the scope to web conduct – only alleged § 638.51 (pen register and trap and trace) violations “arising from conduct occurring on an internet website, online application, or mobile application.”
- Eliminates the private right of action for that theory – such claims against a private actor “may be brought … only by the Attorney General.”
- Restores retroactivity – applicable “to any pending claim in an action commenced within two years before the operative date,” with a severability clause (SEC. 2) anticipating constitutional challenges.
Because SB 690 is a non-urgency measure, a 2026 signature means a January 1, 2027 effective date. The two-year look-back would reach pending § 638.51 claims filed on or after January 1, 2025. That is the entire pixel-litigation wave.
What happens next
The remaining path: Assembly Appropriations (hearing expected in August 2026, after summer recess), an Assembly floor vote, Senate concurrence in the Assembly amendments, then Gov. Newsom. The hard deadline is August 31, 2026, the final day of session. Signature sets a January 1, 2027 operative date. Expect a constitutional fight over retroactive application if the bill passes.
Why SB 690 would not end website privacy litigation
Even if enacted, SB 690 closes one door and leaves the rest open:
- § 631(a) wiretap claims survive untouched – session-replay, chat-interception, and content-capture theories are outside the bill.
- Plaintiffs are already pivoting to the federal Wiretap Act (ECPA), the Video Privacy Protection Act, California’s anti-hacking statute (CDAFA), and unfair-competition (UCL) claims.
- AG-exclusive enforcement is the point, and the gamble – there is no public record of the Attorney General ever bringing a website-tracking CIPA case, so routing § 638.51 claims to the AG functionally ends that theory unless enforcement priorities change.
- The national trend runs both ways – Tennessee, New Hampshire, and Alaska have amended their wiretap statutes to exclude pixels and cookies (per Fox Rothschild), while plaintiffs expand into similar laws in Florida, Pennsylvania, and Illinois.
CIPA compliance checklist: 8 steps that hold up in 2026
Plaintiffs build most CIPA claims from one artifact: a network capture showing what your website transmitted, and when. Close the capture gap first and train the teams on privacy practices. The remaining steps build the evidence trail that makes the fix provable later.
This is an operational framework, not legal advice.
Step 1: Inventory every tracker, including the ones you didn’t install
Start from what the browser actually loads, not from your vendor register. Trackers arrive through tag managers, embedded SDKs, partner scripts, and vendor code that loads further vendor code. An inventory built from procurement records misses exactly the trackers that generate claims.
Scan every property, not just the main domain. Campaign microsites and regional subdomains run their own tag stacks. Staging environments do too, and they rarely see the same scrutiny. For each tool, three fields do the work: who owns it internally, what it’s for, and who receives the data.
Step 2: Map where the data goes after it leaves
For each tracker, work out who receives the data and who they pass it to. Fourth-party recipients, meaning your vendor’s vendor, get visitor data under no contract with you. And you’re the one who gets sued.
Step 3: Gate California visitors behind prior, opt-in consent
Timing is the whole issue. In Javier v. Assurance IQ, LLC, the Ninth Circuit read § 631 to require the prior consent of all parties, and held that retroactive consent doesn’t cover what was already transmitted. The plaintiff had assented to a privacy policy only after a session-recording tool started capturing his interactions. By then, the recording had happened.
So for California traffic, collect an affirmative opt-in before any covered tool runs. A privacy policy shown after collection begins doesn’t reach backward.
Step 4: Block non-essential trackers until consent, then prove it
The question isn’t “do we have a consent banner?” It’s what loads before anyone clicks it.
Pre-consent firing is the specific failure mode CIPA punishes.
- Configure your tag manager or consent platform so covered tags don’t load until consent is recorded. Then verify it rather than assuming it.
- Capture HAR files, which are browser network logs showing which requests fired and what they carried.
- Minimize data collection in sensitive areas like websites’ search bars.
- Pull your tag manager debug export, run both from a California IP, and walk the firing order request by request.
One distinction worth testing for: a tag that’s genuinely blocked versus a tag that merely receives a signal saying consent was denied. Those look identical in a consent dashboard and completely different in a network capture. Consider geo-conditional loading for California traffic while you’re in there.
What counts as consent?
Not all “consent” is equal. In Camplisson v. Adidas America, terms buried in a website footer were no consent at all. Applying Nguyen v. Barnes & Noble, the court held browsewrap binds only if the site puts a reasonably prudent user on inquiry notice of its terms.
Clickwrap – a clear notice plus an affirmative click or toggle before data flows – is defensible. A footer link is not.
Step 5: Honor Global Privacy Control as non-consent
A visitor arriving with Global Privacy Control switched on has already told you something, at the browser level, before your page finished loading: don’t sell or share my data.
California’s CCPA regulations require businesses to process opt-out preference signals, and since 1 January 2026 the rules go further. You now have to visibly indicate that the signal was processed, for example by showing an “Opt-Out Request Honored” message to a visitor who arrives with one. See the California Privacy Protection Agency’s regulations.
The CIPA angle sits apart from the CCPA one. A GPC signal you passed over is evidence against any later argument that the visitor impliedly consented. Treat it as non-consent and suppress covered tools.
Step 6: Mask PII in session replay, and get vendor attestations
Enable field-level masking for names, emails, payment details, and health inputs. Then test the masks in a real recorded session instead of trusting vendor defaults, because a default that held last quarter may not have survived the last release.
For every third party with code on your site, get answers in writing:
- Does the tool record communication content, or only routing and addressing data?
- Does it honor consent signals, and at what point in page load?
- Does it retain, enrich, or resell the data?
- Who else receives it? (the fourth-party question)
- Will you be told when any of the above changes?
Pair this with contractual terms: CIPA-specific vendor obligations, data processing agreements, restrictions on onward transfer, and indemnity. Check each vendor’s retention settings while you’re there.
One honest limit. An attestation is evidence of diligence, not a defense. The plaintiff sues you, not your vendor.
Step 7: Name every tool and recipient in your privacy policy
Plaintiffs read your privacy policy against what your site actually transmits, then plead the difference as deception. That’s the part worth sitting with: a disclosure gap doesn’t just weaken the CIPA defense, it hands over a second cause of action.
- Build the list from your Step 1 inventory. Name each analytics, advertising, session-replay, and chat tool, and the categories of recipients.
- Re-verify whenever the tag stack changes, which for most teams means whenever marketing ships a campaign.
As website technology and data privacy regulations evolve, privacy policies and terms and conditions should be regularly reviewed and updated.
Step 8: Retain consent and configuration evidence for 12+ months
CIPA claims carry a one-year limitations period under CCP § 340(a), generally running from discovery. That makes point-in-time proof decisive. The question in litigation is what your site did on a specific date, not what it does today.
- Retain consent logs with timestamps, banner and policy versions, tag-manager snapshots, and your verification captures on a rolling window past one year.
- Keep monitoring after that, because tracker inventories decay. A campaign adds a pixel, a vendor updates a script, a partner integration goes live. A point-in-time audit starts expiring the day it’s finished, and an audit that’s quietly gone stale is worse than no audit at all, because it reads like proof.

Three questions that matter more than the eight steps
The steps above are implementation. These test whether the implementation would survive contact with a demand letter.
- Can you produce a list of every third-party script loading on your properties right now, generated from browser behavior rather than from a spreadsheet?
- Can you show what fired before consent on a specific date twelve months ago?
- Would you know next week if a new tracker appeared?
Implementation you can’t evidence is a claim, not a defense.
Run a data-journey scan of your site
Received a CIPA demand letter? A first-response playbook
A demand letter is not a lawsuit, but it typically becomes a complaint or an arbitration demand if ignored. The first 72 hours matter more than the eventual legal argument. What you preserve, what you stop changing, and what you can prove about your own site set your negotiating position.
The first 72 hours
- Route to counsel before responding to anything.
- Issue a litigation hold.
- Capture a forensic snapshot of your current tracker configuration before changing anything.
- Preserve consent management logs and tag manager version history.
- Notify your cyber and E&O carriers, since notice conditions are usually time-limited.
- Verify the specific allegations against your actual configuration.
- Identify which vendors are implicated and what your contracts say.
- Only then decide on remediation, with counsel.
How does Melurna help with CIPA exposure?
CIPA plaintiffs don’t guess. They build cases from network captures of exactly what your website transmitted, to whom, and whether consent came first.
That’s the same evidence you need, and most teams can’t produce it. Melurna traces data journeys from entry point through third and fourth parties, surfacing vendors and geolocations that appear in no vendor register. Those are the trackers that arrive through a tag container rather than a contract.
It classifies what each flow carries, separating PII from non-PII, which turns a raw tracker list into a prioritized remediation queue instead of an undifferentiated inventory.
Monitoring runs continuously, so tracker drift surfaces as it happens rather than in a demand letter. That also builds the evidence history described in the previous section: what your site did on a given date, not just what it does today.
Findings map across frameworks, so CIPA work connects to your CCPA obligations rather than sitting in a silo. Insurers use the same visibility to assess web privacy exposure across portfolios.
Melurna shows you what your site sends, so you and your counsel work from facts. See your site’s data flows: book a 30-minute demo.
FAQs
Does CIPA apply to websites and businesses outside California?
Yes. California’s Supreme Court held that CIPA protects California residents even when the other party is out of state. Any business with California website visitors should assume exposure.
Is CIPA the same as CCPA?
No. CIPA is distinct from the California Consumer Privacy Act, which focuses on data privacy. CIPA protects the confidentiality of communications and requires all-party consent before interception or recording. The CCPA governs personal information and uses an opt-out model. They are separate statutes with different tests, and CCPA compliance does not establish CIPA compliance.
Does CIPA apply to cookies and tracking pixels?
Courts are actively divided. Plaintiffs argue pixels function as pen registers under section 638.51 by capturing IP addresses and device identifiers. Some courts have accepted the theory, and at least one California Superior Court has rejected it for routine web analytics. Appellate guidance is pending.
What is a pen register under CIPA?
Under § 638.50(b), a pen register is a device or process that records “dialing, routing, addressing, or signaling information” from a communication, but not its contents. Plaintiffs argue tracking pixels qualify. Several California trial courts read the provision as telephones-only. The split remains unresolved on appeal.
What is SB 690 and did it pass?
Not yet, as of July 28, 2026. SB 690 passed the Senate unanimously in June 2025, stalled, then returned on July 1, 2026, in a narrowed form. That form would eliminate the private right of action for pen-register (§ 638.51) claims arising from website or app conduct, leaving those claims to the Attorney General only. An Assembly Appropriations vote is expected in August 2026.
DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.
