California Wiretapping Claims Against Website Tracking: What Privacy Leaders Need to Know
CIPA wiretapping claims have driven nearly 4,000 lawsuits against common website tracking technologies like Meta Pixels, Google Analytics, and session replay tools. Learn which trackers carry the most risk, what recent court decisions mean, and how to reduce your exposure.
Concord Team · Published Wed Jul 29 2026

Most organizations with a California-facing website are running tracking technologies that could expose them to wiretapping claims under a law written before the internet existed.
The California Invasion of Privacy Act (CIPA), enacted in 1967 to address telephone wiretapping and unauthorized surveillance, has become the basis for nearly 4,000 lawsuits targeting common website technologies. Meta Pixels, Google Analytics tags, session replay tools, and even search bar functionality have all been named in litigation alleging that these tools intercept user communications without proper consent.
For privacy, compliance, and legal leaders, this is not a theoretical risk. An estimated 800-plus CIPA claims were filed in 2025 alone, and the pace has not slowed in 2026. With statutory damages of $5,000 per violation (or three times actual damages, whichever is greater), the financial exposure for organizations with significant web traffic is substantial. And unlike data breach litigation, these claims do not require a security incident to proceed.
This guide breaks down how courts are applying CIPA to modern web tracking, which technologies carry the most risk, what recent decisions mean for your compliance posture, and the concrete steps you should take now. (For a broader overview of the statute itself, see our California Invasion of Privacy Act (CIPA) guide.)
How a 1960s Wiretapping Law Applies to Website Tracking
CIPA was designed to prevent the unauthorized interception of telephone conversations. Its core provision, Section 631(a), prohibits any person from reading or attempting to read the contents of a communication while it is in transit, without the consent of all parties. A separate provision, Section 638.51, addresses "pen register" and "trap and trace" devices that capture metadata (like the numbers dialed on a phone call) rather than the content of a conversation.
Plaintiffs' attorneys have argued, with increasing success, that modern website tracking technologies function as the digital equivalent of these prohibited devices. The theory works on two tracks:
Section 631 (wiretap theory): When a user types into a search bar, fills out a form, or interacts with a web page, that activity constitutes a "communication." Third-party tools that capture and transmit this data to external servers are "intercepting" the communication in transit, without the user's knowledge or consent.
Section 638.51 (pen register theory): Even when trackers do not capture the content of a communication, they may collect routing information, IP addresses, device identifiers, and browsing patterns. Plaintiffs argue this metadata collection functions as a pen register or trap-and-trace device.
The 2022 Ninth Circuit decision in Javier v. Assurance IQ, LLC gave these theories significant momentum. The court reversed the lower court's dismissal of a CIPA claim against an insurance-quoting website that deployed session replay software to record user interactions before presenting a privacy policy. The ruling established that retroactive consent, where tracking fires immediately and users encounter a privacy policy only after data has already been collected, does not satisfy Section 631. While the decision did not resolve the case on the merits, its rejection of after-the-fact consent has been widely cited in subsequent CIPA tracking litigation as support for the principle that consent must precede tracking.
Which Tracking Technologies Carry the Most Risk
Not all tracking technologies face equal litigation exposure. Based on filed complaints and court decisions through mid-2026, these categories appear most frequently:
Highest risk:
- Meta/Facebook Pixel (the most frequently named technology in CIPA complaints)
- Session replay and screen recording tools (Hotjar, Microsoft Clarity, FullStory)
- Google Ads conversion and remarketing tags
- TikTok Pixel
Elevated risk:
- Google Analytics (when configured to fire before consent)
- LinkedIn Insight Tag
- Heatmap and behavior analytics tools
- Chat widgets that transmit conversation data to third-party servers
The common factor: In each case, the controlling question is whether a third party receives user data before the visitor has made an informed choice about tracking. A tracking pixel that fires on page load, before any consent interaction, creates exposure. The same pixel, gated behind a consent mechanism that blocks it until the user opts in, materially reduces that exposure.
It is worth noting that courts have begun to draw a meaningful line between content and metadata. In Casillas v. Transitions Optical (2024), a California trial court found that collecting a visitor's IP address in the ordinary course of accessing a website does not violate CIPA's pen register provision. The distinction matters: tools that capture what a user types (form inputs, search queries) face greater scrutiny than tools that log technical metadata.
The Case Law Is Split, and That Is the Problem
The most challenging aspect of CIPA compliance is that courts have not reached consensus on how the statute applies to website tracking. Recent decisions illustrate the divergence.
Decisions Favoring Defendants
Lakes v. Ubisoft (N.D. Cal., 2025): The court dismissed the complaint with prejudice, holding that the plaintiff's consent, delivered through a layered combination of a cookie banner, account creation screen, privacy policy acceptance, and checkout flow, defeated the CIPA and related privacy claims. Because users affirmatively accepted terms that disclosed Ubisoft's data-sharing practices, there was no "secret interception." The decision is now on appeal to the Ninth Circuit (No. 25-2857), so it is not yet the final word on whether layered consent flows satisfy CIPA.
Casillas v. Transitions Optical (Cal. Super. Ct., 2024): IP address collection was deemed normal website functionality, not a CIPA violation. The court held that obtaining IP addresses from ordinary user access does not violate the pen register statute, reasoning that CIPA "did not, and does not, criminalize the process by which all websites communicate with all users." As a Superior Court ruling, it is persuasive rather than binding appellate precedent.
Gutierrez v. Converse (9th Cir., July 2025): In an unpublished, nonprecedential decision, the Ninth Circuit affirmed summary judgment for Converse on evidentiary grounds. The plaintiff failed to show that Salesforce made an unauthorized connection, or that it actually read (rather than merely had the ability to read) her chatbot messages in transit. The broader view that Section 631's wiretap clause does not reach internet communications at all came from Judge Bybee's separate concurrence, not the panel's holding, so it should not be read as settled Ninth Circuit law.
Decisions and Settlements Favoring Plaintiffs
Mikulsky v. Bloomingdale's (9th Cir., June 2025): In an unpublished decision, the Ninth Circuit revived a CIPA claim where session replay technology allegedly captured user interactions, including mouse movements, keystrokes, and page views, and transmitted them to a third-party vendor without consent. The court found that the complaint adequately alleged that Bloomingdale's conspired with session replay providers to enable them to read the contents of communications. This was a pleading-stage ruling that the allegations could proceed, not a finding that Bloomingdale's is liable.
Mirmalek v. LA Times settlement (June 2026): A federal court granted final approval to a $3.85 million settlement resolving pen register claims under CIPA Section 638.51, not the Section 631 wiretap theory, tied to third-party trackers (TripleLift, GumGum, and Audiencerate) alleged to have collected data without consent. This is a settlement, not a merits ruling: the LA Times denied any wrongdoing and the court made no finding that the tracking was unlawful. It shows the financial exposure these claims create, not that plaintiffs prevailed on the law.
What This Means for Compliance Teams
The split creates a difficult planning environment. A consent banner that satisfies one court may not satisfy another. The safest position is to assume the most protective interpretation and build your tracking infrastructure accordingly: no non-essential tracking fires before affirmative user consent.
Legislative Reform Efforts: SB 690 and Its Limits
California's legislature has attempted to clarify CIPA's application to website tracking through Senate Bill 690.
As originally introduced in early 2025, SB 690 would have created a broad "commercial business purpose" exemption, effectively shielding businesses using standard tracking technologies from CIPA liability. That version stalled.
A July 2, 2026 amendment significantly narrowed the bill's scope. The current version focuses only on pen register and trap-and-trace claims under Section 638.51, giving the California Attorney General exclusive jurisdiction over those claims when they arise from website or mobile application activity. The amendment does not touch Sections 631 or 632, the provisions under which the overwhelming majority of website tracking lawsuits are filed.
In practical terms: even if SB 690 passes in its current form, it will not resolve the core wiretapping liability that drives most CIPA tracking litigation. Organizations cannot wait for legislation to solve this problem.
A Compliance Checklist for Reducing CIPA Exposure
Based on current case law and the patterns that have led to both successful defense and costly settlements, these steps materially reduce your organization's exposure to CIPA wiretapping claims.
1. Consent Must Come Before Tracking
This is the single most important control. No non-essential tracking technology should fire before the user has made an affirmative consent choice. A consent banner that loads after tracking has already started is not a valid defense.
For California visitors specifically, this means implementing an opt-in model for tracking, even though the CCPA/CPRA generally uses an opt-out framework for most adult data collection. The distinction matters: CIPA's "all-party consent" requirement is stricter than the CCPA/CPRA's notice-and-opt-out approach.
2. Verify That Consent Signals Actually Control Your Trackers
Having a consent banner is necessary but not sufficient. The banner's consent signals must be wired to your tag management system so that tracking scripts are genuinely blocked until consent is granted. Test this in a clean browser session:
- Open your browser's network tab before the page loads
- Confirm that only essential, first-party resources fire before any user interaction
- Click "Reject" or decline tracking
- Confirm that non-essential trackers remain blocked
If advertising or analytics requests appear in the network tab before you interact with the consent banner, your implementation has a gap.
3. Categorize Your Tags Accurately
Every tracking technology on your site should be categorized (essential, analytics, advertising, social media) and mapped to the correct consent category. Miscategorized tags, such as an advertising pixel labeled as "essential," undermine the entire consent framework.
4. Provide a Privacy Policy That Matches Your Actual Practices
Your privacy policy must disclose the specific tracking technologies you use, what data they collect, and which third parties receive that data. A generic disclosure that mentions "cookies and similar technologies" without specifics has been insufficient in recent litigation.
5. Offer Persistent Preference Controls
Users must be able to revisit and change their consent choices at any time, not only on the first visit. A preference center that is accessible from every page (typically linked in the footer) satisfies this requirement.
6. Honor Global Privacy Control (GPC) Signals
The CCPA/CPRA requires businesses to treat GPC signals as valid opt-out requests. From a CIPA perspective, ignoring a GPC signal while continuing to track a user who has expressed a preference against tracking strengthens plaintiffs' arguments about unauthorized interception.
7. Audit and Document Regularly
Maintain records of your consent configuration, tag inventory, and compliance testing. If a demand letter arrives, contemporaneous documentation of your compliance posture is your strongest defense.
What to Do if You Receive a CIPA Demand Letter
CIPA demand letters have become a volume practice. Many target small and mid-sized businesses running common tracking technologies. If your organization receives one, a structured response matters more than speed.
Preserve evidence immediately. Screenshot your website, export your consent platform configuration, capture your tag manager setup, and pull consent logs for the date referenced in the letter. Preserve your privacy policy version from that date.
Check your insurance coverage. Cyber liability, media liability, technology errors and omissions, and general commercial liability policies may cover CIPA claims. Review your policies early, as many insurers have begun adding tracking and wiretapping exclusions.
Conduct a self-audit before responding. Verify whether the tracking technology named in the letter actually existed on your site, whether it fired before consent, what data it collected, and whether your consent logs support your compliance posture on the referenced date.
Engage right-sized legal counsel. Not every demand letter requires a full litigation team. California offers several referral resources for limited-scope legal consultations. The San Francisco-Marin Bar Association, Santa Clara County Bar Association, and many privacy-focused firms offer reduced-fee initial consultations for these claims.
Fix root causes in parallel. Do not wait for the legal process to resolve before addressing technical gaps. Block non-essential trackers from firing before consent, remove hard-coded tracking pixels, and align your privacy disclosures with your actual data practices.
The Business Trade-Off: Opt-In Tracking and Data Loss
There is a real cost to the most privacy-protective approach. Implementing opt-in consent for California visitors will reduce the volume of analytics data, advertising audience sizes, and conversion tracking reliability for that segment. Most visitors do not affirmatively opt in to tracking.
This is a strategic decision, not a purely legal one. Organizations should evaluate where they want to sit on the consent spectrum, document that decision, and build their analytics and advertising strategies around it. A consent management platform that supports granular, region-specific rules, allowing opt-in for California while maintaining different approaches for other jurisdictions, gives organizations the flexibility to balance compliance with business needs.
Key Takeaways
-
CIPA litigation is not slowing down. Nearly 4,000 cases have been filed in California, with 800+ in 2025 alone. Legislative reform through SB 690 is unlikely to address the core Section 631 wiretapping claims that drive most litigation.
-
Consent timing is the critical control. The single most important step is ensuring that no non-essential tracking fires before the user has made an affirmative consent choice. Retroactive consent does not satisfy CIPA.
-
The case law is divided, which means the safest path is the most protective one. Some courts have questioned whether CIPA applies to web tracking at all; others have approved multi-million-dollar settlements. Until the law settles, assume the strictest interpretation.
-
A consent banner alone is not enough. The banner must actually control your tracking technologies, not just display a notice. Test your implementation, verify that consent signals block scripts, and audit regularly.
-
If you receive a demand letter, respond with structure. Preserve evidence, check insurance, self-audit your tracking setup, and fix technical gaps while the legal process unfolds.
Frequently Asked Questions
Does CIPA Only Apply to California-Based Companies?
No. CIPA applies to communications that occur in California. If your website is accessible to California visitors and your tracking technologies collect their data, CIPA claims can be brought regardless of where your company is headquartered.
Is a Cookie Consent Banner Enough to Prevent CIPA Claims?
A consent banner is necessary but not sufficient. The banner must load before any non-essential tracking fires, its consent signals must actually control your tracking scripts, and users must have the ability to decline or withdraw consent. A banner that appears after tracking has already started does not satisfy CIPA.
How Does CIPA Differ from the CCPA/CPRA?
The CCPA/CPRA generally uses an opt-out model for most adult data collection and focuses on how personal information is used, shared, and sold. CIPA is a wiretapping statute that focuses on the interception of communications and requires all-party consent before tracking begins. They impose different obligations, and compliance with one does not guarantee compliance with the other.
Are First-Party Analytics Tools Subject to CIPA Claims?
Generally, website owners are not considered to be "wiretapping" their own communications. The risk arises when third-party vendors receive the data for their own independent purposes. First-party analytics that do not transmit data to external servers carry significantly less CIPA exposure than third-party tracking pixels.
Which Industries Are Most Targeted by CIPA Claims?
Retail leads by a wide margin, with over 1,800 CIPA cases filed as of mid-2026. Technology companies are the second most targeted sector, with more than 500 cases. The pattern tracks with the prevalence of tracking pixels and session replay tools: industries with heavy e-commerce and digital advertising activity face the greatest volume of claims.
What Damages Can Plaintiffs Seek Under CIPA?
CIPA provides for statutory damages of $5,000 per violation, or three times actual damages, whichever is greater. Because each user's data being intercepted can constitute a separate violation, the aggregate exposure for websites with significant California traffic can be substantial, even from a single tracking technology.
This content is for informational purposes only and does not constitute legal advice. It reflects legal developments as of July 2026. CIPA litigation is evolving rapidly, and new decisions may alter the analysis above. For specific guidance on your organization's tracking practices and CIPA exposure, consult with qualified legal counsel experienced in California privacy and wiretapping litigation.
Concord's consent management platform blocks tracking technologies in real time, before they fire, with location-aware rules that let you apply opt-in consent for California visitors while maintaining your preferred approach in other jurisdictions. Book a demo to see how it works.