CIPA & Wiretap Litigation

What is Wiretapping (California Penal Code § 631)?

California Penal Code section 631 is CIPA's wiretapping provision, which prohibits intercepting or reading the contents of a communication in transit without the consent of all parties — the statute behind lawsuits claiming session replay and chat tools 'wiretap' website visitors.

Section 631(a) reaches four kinds of conduct: physically tapping a communication line; willfully reading or learning the contents of a communication in transit without the consent of all parties; using information obtained through such an interception; and aiding or conspiring with anyone who does any of these. Because California requires all-party consent, one side of a conversation agreeing is not enough.

The modern application is the 'third-party eavesdropper' theory. When a website embeds a session-replay script or a live-chat widget operated by an outside vendor, plaintiffs argue the vendor is a third party listening in on the visitor's 'conversation' with the site — capturing keystrokes, form entries, mouse movements, and chat transcripts in transit without the visitor's consent. The website operator is then sued for aiding the interception under the fourth prong.

Courts distinguish between vendors that merely store data as a tool of the website (more like a tape recorder, generally permissible) and vendors that use the intercepted data for their own purposes, such as improving their products or building advertising profiles (more like an eavesdropper). The line is fact-intensive, which is precisely why these cases survive motions to dismiss often enough to keep the demand-letter economy running.

Remedies come from Penal Code section 637.2: $5,000 per violation or treble actual damages, with no injury requirement, plus the leverage of class-action aggregation. Consent from the visitor before the recording or interception begins defeats the claim, which is why consent-gating chat and replay tools is the standard mitigation.

Why it matters for eCommerce

Session replay and live chat are near-universal on eCommerce sites — they are also the two technologies most often named in section 631 suits. A replay script that captures checkout-form keystrokes before consent, or a chat vendor that mines transcripts for its own AI training, maps directly onto the eavesdropper theory. Review vendor contracts for data-use terms and hold both tools until consent is recorded.

Frequently asked questions

Is California a two-party consent state?
Yes — in fact it is an all-party consent state. Under CIPA, every party to a confidential communication must consent to its interception or recording. For websites, that means the visitor must consent before tools that capture communication content, like session replay or chat monitoring, begin recording.
Can a website be liable for a vendor's wiretapping?
Yes. Section 631(a) separately punishes anyone who 'aids, agrees with, employs, or conspires with' a party that intercepts communications. Plaintiffs routinely sue the website operator for embedding the vendor's script, even when the vendor did the technical capturing.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Check your site for wiretap-claim exposure

← Back to all glossary terms