Florida's 1969 Wiretapping Law Is Being Used to Sue E-Commerce Sites — Here's How to Actually Comply

MP
Marc Parrish
Florida's Security of Communications Act is behind a wave of "pen register" website-tracking lawsuits against online retailers. Why a decorative cookie banner won't save you — and how to block trackers before consent and prove it.

A decades-old anti-eavesdropping statute has become the basis for hundreds of lawsuits against online retailers. The good news: the entire theory hinges on one thing you can control.

If you run an e-commerce site and you've never heard of the Florida Security of Communications Act, you're not alone — until recently, almost no one outside a courtroom had. It's a wiretapping law written in 1969 to stop people from secretly recording phone calls and planting bugs. Today, plaintiffs' firms are using it to sue online retailers over the ordinary tracking scripts running on their websites.

Hundreds of these cases and demand letters have landed on businesses across Florida, and a growing share target companies that aren't even based there — any out-of-state retailer whose site is reachable by a Florida shopper. If your site runs a Meta pixel, Google Analytics, Klaviyo, Pinterest, or similar tags, this is worth ten minutes of your attention.

What the law actually says

The Florida Security of Communications Act (FSCA), codified at Chapter 934 of the Florida Statutes, is Florida's wiretapping law. Two pieces of it are driving the litigation:

"Pen register / trap and trace" (Fla. Stat. § 934.31). Originally the devices that recorded the phone numbers you dialed — the routing information, not the conversation. Plaintiffs argue that a modern tracking script capturing a visitor's IP address is the digital equivalent of one of those devices, "installed" on the visitor's browser without permission. It's the same theory driving trap-and-trace claims under California's CIPA.

Interception of communications (§ 934.03). The classic wiretap prohibition: you can't intercept an electronic communication unless all parties consent. Florida is an all-party-consent state. Plaintiffs argue the scripts intercept and forward a visitor's data the moment the page loads, without that consent.

The reason these suits get filed is the remedy. The FSCA lets a plaintiff recover the greater of $100 per day or $1,000, plus attorney's fees and costs. The individual dollar amounts are small by design — the strategy relies on the cost of hiring counsel and defending exceeding a quick settlement, so many businesses pay to make the case disappear regardless of whether it has merit.

It's an aggressive, novel reading of a statute that was never written with websites in mind, and Florida courts have not settled whether it holds up. But "unsettled" is not the same as "safe": some of these cases have survived early motions to dismiss, which is exactly why the smart move is to not be a target in the first place.

The one thing every one of these claims depends on

Here's the part worth internalizing: every count in these lawsuits turns on the absence of consent.

The pen-register provision has a consent exception. The interception provision requires all-party prior consent. Strip the consent question away and there's very little left. That's good news, because consent is the one thing you fully control — if you handle it correctly.

The catch is in that word: correctly.

Why a "decorative" cookie banner won't save you

This is the mistake that turns a defensible site into a defendant. A cookie banner that simply appears — while the Meta pixel, Google tags, and analytics scripts fire in the background the instant the page loads — is not consent. It's decoration.

Courts looking at these cases increasingly separate real consent from ornamental disclosure. They ask a concrete question: did the tracking tags actually wait for the visitor to opt in, or did they fire anyway? A banner that collects a click but doesn't change what already happened on page load provides no protection. Worse, a buried "we may collect website usage data" line in a privacy policy has been argued to not constitute the prior consent the statute requires.

If your tags fire before the visitor agrees, the banner is theater. The whole defense evaporates.

What "doing it right" actually looks like

Real compliance — the kind that holds up when someone asks what your site was doing at the moment a visitor arrived — comes down to a handful of things:

  • Block non-essential and third-party tags until the visitor opts in. Not hide the banner UI while tags run underneath — actually withhold the scripts at the loader level so nothing fires before consent.
  • Honor Global Privacy Control (GPC) signals. A growing list of states require it, and it's a strong signal of good faith.
  • Apply this everywhere it matters — including states people forget. Many consent tools only gate trackers in "regulated" states and do nothing elsewhere. If Florida (or any all-party-consent-risk state) isn't in your block set, you have a gap precisely where these suits are being filed.
  • Name your tracking tools in your privacy policy and keep it accurate. Contradictory or vague policies get disregarded.
  • Keep timestamped consent records. If a claim ever comes, being able to show when consent controls went live and what a visitor's browser did is the difference between a quick dismissal and an expensive discovery fight.
  • Re-scan continuously. Marketing teams add new tags all the time. A site that was compliant last quarter can quietly drift out of compliance the moment someone drops in a new pixel.

The part almost no one does: prove it

Most consent tools stop at "we generated a banner and blocked some cookies." That's a claim. In litigation, a claim isn't worth much — evidence is.

The strongest position isn't just having a consent banner. It's being able to demonstrate, at the network level, that the trackers named in a complaint never fired before consent — backed by timestamped records showing your consent controls were live and working. That's the difference between telling a court you were compliant and showing it.

This is the gap we built PieEye to close. Our scanner runs your site the way a real visitor's browser does and reports what actually fires before consent, blocks third-party tags until a visitor opts in, honors GPC, and keeps the consent records that turn "we think we were fine" into "here's the proof." Their tools suggest and manage. Ours proves.

If a demand letter or lawsuit shows up anyway

A few practical steps, none of which are a substitute for a lawyer. (Much of our guide to CIPA demand letters applies here too.)

  • Don't quietly change your site, tag manager, or code first. Preserve the current state — altering it can look like spoliation and destroys the evidence that may help you.
  • Note the deadlines immediately. These filings often set a fast, mandatory pretrial or response date.
  • Engage counsel licensed in the relevant state. For an FSCA matter, that means a Florida-licensed attorney.
  • Pull your consent and tag records. A clean, timestamped record of what your site blocked and when is the single most useful thing you can hand your lawyer.
  • Loop in your consent vendor. If your platform can produce evidence of pre-consent blocking, get it into your counsel's hands early.

The bottom line

The Florida wiretapping wave feels unfair — a 1969 law repurposed against routine web analytics — and in many ways it is. But the businesses that get hurt are usually the ones running a banner that looks compliant while the trackers fire underneath it. The ones that don't are the ones who actually blocked the tags before consent and can prove it.

You don't need to guess which one you are. Scan your site and see exactly what fires before a visitor ever clicks "accept."

This article is for general informational purposes and is not legal advice. Laws and their interpretation change, and how they apply to your business depends on your specific facts. Consult a licensed attorney about your situation.

For a walkthrough of how PieEye handles FSCA compliance, book a demo.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.