CIPA Overview

The California Invasion of Privacy Act creates real liability for websites running analytics, pixels, chatbots, and session replay. Find the resource that matches your situation.

Find your situation

📬

I received a CIPA demand letter

You've been served. Understand your options, response timeline, and what to do in the first 48 hours.

🔍

I'm evaluating CIPA risk for our website

Start with the basics: what CIPA is, who it applies to, and what compliance actually requires.

📊

We use Meta Pixel or Facebook ads tracking

Meta Pixel creates specific CIPA exposure. Learn how it works and what consent architecture you need.

🖱️

We run session replay, heatmaps, or UX tools

Session replay tools capture user behavior in real time. Here's the CIPA risk and how to run them compliantly.

💬

We have a website chatbot or AI chat

AI chatbots create the most direct CIPA exposure. Understand the 2025 cases and compliance requirements.

⚖️

We're in arbitration or facing mass arbitration

Most CIPA claims resolve in arbitration. Learn how mass arbitration works and what your response protocol needs.

📱

We do SMS marketing or call recording

Section 632.7 covers mobile communications. AI phone agents, cloud contact centers, and two-way SMS.

I need a step-by-step compliance checklist

Actionable checklist for CIPA compliance — prior consent, GPC, vendor contracts, and policy disclosure.

🛠️

I want the full technical implementation guide

Complete architecture for website tracking compliance — pixels, replay, consent gating, and vendor review.

⚖️

What about the Frasco v. Flo Health verdict?

The first major CIPA jury verdict. What it means for SDK liability, consent, and your compliance program.

📜

Will SB 690 end CIPA lawsuits?

California's legislative reform. What it would do, the timeline, and why waiting isn't a compliance strategy.

🔄

How does CIPA differ from CCPA?

Two California laws, different requirements. When each applies and how they interact.

🎬

I'm concerned about VPPA (video privacy)

Video Privacy Protection Act — pixels on video pages, consent for video viewing data. The complete 2026 guide.

⚖️

What about the Salazar v. Paramount Supreme Court case?

The Supreme Court is clarifying who can sue under VPPA. Circuit split, three scenarios, and what to do now.

Not sure where you stand?

Run a free PieEye compliance scan. It takes minutes, requires no code changes, and shows you exactly what a plaintiffs' attorney's scanning tool would find.

Run a free compliance scan