FSCA · Florida Security of Communications Act

Florida is the new CIPA. Scan before the demand letter arrives.

Free instant scan for FSCA (Fla. Stat. § 934.03) violations. See exactly which trackers intercept visitor data before consent — the same evidence Florida plaintiffs' firms collect before sending a demand letter.

Which law do you want to check?

Need help fixing the issues?

Book a 20-min call with our compliance team to walk through your results.

Book a call →

About FSCA

The Florida Security of Communications Act (FSCA, Fla. Stat. § 934.03) prohibits intercepting wire, oral, or electronic communications unless ALL parties consent first — stricter than the federal one-party rule, and the same all-party-consent structure that powers California's CIPA wave. Florida plaintiffs' firms now apply it to website tracking: chat widgets, session replay, and advertising pixels that capture visitor interactions before consent. A March 2025 federal ruling in the Middle District of Florida allowed FSCA web-tracking claims to survive dismissal, opening the current wave, and the first pixel case is headed to trial. The civil remedy under § 934.10 is the greater of $1,000 in liquidated damages or $100 per day of violation, plus punitive damages and attorneys' fees — fee-shifting that makes even individual claims economical for plaintiffs' firms.

What the scanner checks

The scan loads your site the way a first-time visitor would — before any consent is given — and records every tracker that fires. It flags advertising pixels (Meta, TikTok, Google Ads), analytics (GA4), session replay tools (Hotjar, FullStory, Microsoft Clarity), and chat widgets that transmit visitor data to third parties pre-consent. Chat transcripts, keystrokes, and form input are the "contents of communications" at the center of Florida wiretap claims, so those tool classes get particular scrutiny. These are the same signals plaintiffs' firms collect with their own scanning tools before sending a demand letter.

Why Florida claims are surging

For years Florida courts rejected website-wiretap theories, and FSCA stayed quiet while CIPA claims exploded in California. That changed in March 2025, when a federal court in the Middle District of Florida allowed FSCA claims over tracking pixels to move forward, finding the data captured could qualify as the contents of communications rather than mere metadata. Since then, filings and pre-litigation demand letters have accelerated, the first pixel case has reached trial scheduling, and Florida's damages formula — the greater of $1,000 or $100 per day, plus attorneys' fees and punitive damages under § 934.10 — gives plaintiffs' firms the same economics that fueled the CIPA wave.

What to do next

First, gate every non-essential tracker behind prior consent — under an all-party-consent statute, a banner that doesn't actually block scripts until opt-in provides little protection. Second, audit chat widgets and session replay vendors: they capture communication contents directly and are the most commonly named tools in Florida suits. Third, if you already received an FSCA demand letter, do not ignore it and do not pay reflexively — the underlying violation is usually fixable within days, and remediation strengthens your negotiating position. PieEye's consent platform automates script gating for exactly this scenario.

FSCA scanner FAQ

What is the Florida Security of Communications Act?
The FSCA (Fla. Stat. § 934.01 et seq.) is Florida's wiretap statute. Section 934.03 makes it unlawful to intentionally intercept wire, oral, or electronic communications unless all parties to the communication consent in advance — one of the strictest consent standards in the country. Plaintiffs' firms now argue that website chat widgets, session replay tools, and tracking pixels "intercept" visitor communications when they transmit interactions to third parties without prior consent.
What is an FSCA demand letter?
An FSCA demand letter is a pre-litigation notice from a plaintiffs' firm alleging that your website intercepted a Florida visitor's communications without all-party consent, in violation of Fla. Stat. § 934.03. It typically cites the trackers found on your site — chat widgets, session replay, or advertising pixels firing before consent — claims damages under § 934.10, and offers to settle before filing. Like CIPA letters in California, they are usually based on an automated scan of your site's pre-consent tracking behavior.
How much are FSCA damages?
Section 934.10 provides liquidated damages of $1,000 or $100 per day of violation, whichever is greater, plus punitive damages, attorneys' fees, and litigation costs. The fee-shifting provision matters most: it makes individual claims economical for plaintiffs' firms even before class treatment, which is the same dynamic that fueled California's CIPA demand-letter wave.
Which website trackers create FSCA risk?
Third-party chat and chatbot widgets and session replay tools (Hotjar, FullStory, Microsoft Clarity) carry the most direct risk, because they capture the contents of communications — transcripts, keystrokes, form input. Advertising pixels like Meta and TikTok that transmit visitor interactions before consent are the subject of the current wave of pixel claims. Anything that fires before your banner gets consent is what a plaintiffs' firm's scan will flag.
How is FSCA different from California's CIPA?
Same theory, different statute. Both are all-party-consent wiretap laws applied to website tracking. CIPA carries $5,000 per violation in statutory damages and has driven demand letters since 2022; FSCA damages are the greater of $1,000 or $100 per day plus attorneys' fees, and the Florida wave started later — after a March 2025 federal ruling let pixel-interception claims proceed. If your site has both California and Florida visitors, the same pre-consent trackers expose you under both statutes.
Is this FSCA scan really free?
Yes. The scan runs in about 60 seconds, requires no signup or credit card, and reports which trackers fire before consent on your site. It checks FSCA alongside CIPA, GDPR, CCPA/CPRA, and Washington MHMD in a single pass.

Also check

The scan above evaluates all five regimes at once. Switch the framing for a different audience: