CIPA & Wiretap Litigation

What is CIPA (California Invasion of Privacy Act)?

The California Invasion of Privacy Act (CIPA) is a 1967 California wiretapping statute, codified at Penal Code section 630 and following, that plaintiffs now use to sue websites over tracking pixels, session replay, chatbots, and other pre-consent tracking technologies.

CIPA was written to stop telephone wiretapping and eavesdropping. Its key provisions are section 631 (wiretapping — intercepting the contents of a communication in transit), section 632 (eavesdropping on confidential communications), and sections 638.50-638.51 (installing a pen register or trap and trace device without a court order). California is an all-party consent state: everyone on the line must agree to the recording or interception.

What makes CIPA the center of a modern litigation wave is its remedy. Under Penal Code section 637.2, any person injured by a violation can bring a civil action for $5,000 per violation or three times actual damages, whichever is greater — and the statute says plaintiffs do not need to have suffered any actual damages at all. That combination of statutory damages and a private right of action makes CIPA claims cheap to file and expensive to defend.

Since roughly 2022, plaintiff firms have recast ordinary website technologies as CIPA violations: session replay software as wiretapping, live-chat vendors as third-party eavesdroppers, and analytics or advertising trackers as illegal pen registers or trap and trace devices. Most cases begin as pre-litigation demand letters seeking a quick settlement, sent in bulk to eCommerce brands whose sites fire trackers before the visitor consents.

The defense picture is unsettled. Some California courts have dismissed pen-register theories as a stretch of a telephone-era statute; others have allowed them past the pleading stage. Because outcomes vary by courtroom, the practical mitigation is technical: do not let third-party trackers capture visitor data before consent.

Why it matters for eCommerce

eCommerce sites are the primary target of CIPA demand letters because they run dense stacks of pixels, session replay, and chat widgets — and because they transact with California consumers at volume. A store that fires the Meta Pixel or a session-replay script before its cookie banner records consent is exposed at $5,000 per claimed violation. Scanning your own storefront the way a plaintiff's expert would is the fastest way to know your exposure.

Frequently asked questions

What damages are available under CIPA?
Penal Code section 637.2 allows a civil action for $5,000 per violation or three times actual damages, whichever is greater. The statute expressly states that actual harm is not required to sue, which is why CIPA supports high-volume demand-letter campaigns.
Does CIPA apply to companies outside California?
Yes, as a practical matter. CIPA protects California residents, so any website that serves California visitors — regardless of where the company is based — can be named in a CIPA suit or demand letter.
How do websites reduce CIPA risk?
Block third-party tracking scripts, session replay, and chat data-sharing until the visitor gives consent, and disclose the technologies in your privacy policy. Consent is a statutory exception under CIPA, so a properly gated tag stack removes the core allegation.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free CIPA exposure scan

← Back to all glossary terms