Skip to main content

There’s a law from 1967 sitting in California’s penal code. It was written to stop people from bugging telephone lines. Cold War-era stuff — listening devices, wiretaps, the kind of thing you’d see in a spy thriller set in a smoky government office.

Nobody updated it much. Nobody thought they had to.

Then the internet happened. Cookies happened. Analytics platforms, session replay tools, marketing pixels — the whole modern ad-tech stack landed on top of a legal framework that was designed around rotary phones. And now that 1967 law — the California Invasion of Privacy Act, or CIPA — has become one of the most litigated privacy statutes in the United States.

If your website touches California visitors (and whose doesn’t?), this matters to you.

What CIPA Actually Is

CIPA was enacted to protect Californians from eavesdropping on private communications. At the time, that meant phone calls. The law prohibits intercepting or recording confidential communications without consent, and it was later expanded in 2015 to cover “pen registers” — devices that log the source or destination of electronic communications.

Here’s the part that turns this into a business problem: CIPA isn’t just a regulatory law that government agencies enforce. It has a private right of action. Anyone whose communications were allegedly intercepted can sue directly, and the statutory damages are **$5,000 per violation** — no proof of actual harm required.

Compare that to the CCPA, California’s modern consumer privacy law. Under the CCPA, most tracking violations are handled by regulators, not individual plaintiffs. CIPA has no such filter. That gap is exactly what plaintiffs’ lawyers have been exploiting.

CIPA compliance illustration showing a website browser, privacy shield and wiretapping device for the California Invasion of Privacy Act and website privacy laws.How a Phone Wiretapping Law Became a Website Problem

Starting around 2022, something shifted. Law firms began sending demand letters — and then filing lawsuits, and arbitration claims — arguing that standard website tracking tools violated CIPA’s wiretapping and pen register provisions.

The theory goes like this: when a website loads a third-party analytics tag, a Meta Pixel, or session replay software, that tool “intercepts” the user’s communication with the site in real time and sends it to a third party. That, plaintiffs argue, is essentially wiretapping — and doing it without prior consent violates CIPA.

The tools in the crosshairs include things that are completely routine across the web:

  • Google Analytics and similar platforms
  • Meta Pixel and other advertising trackers
  • Session replay tools like Hotjar, FullStory, or LogRocket
  • Live chat and chatbot software
  • Heat maps and conversion tracking tags

Since 2022, plaintiffs’ firms have filed an estimated 50,000 to 100,000 or more claims under CIPA — lawsuits, arbitration demands, and pre-suit settlement letters. CIPA is now described as one of the most litigated statutes in the digital age, with claims increasingly targeting Google Analytics and similar tools for “intercepting” user communications.

Cookie Consent Manager | Take a 2 week free trial

Take a 2 week free trial for our paid plans or create a free account …

Create an accountView our plans

The “Pen Register” Angle

One of the more creative legal arguments in this wave of litigation is that tracking pixels and web beacons function as illegal “pen registers.” The pen register provisions were added to CIPA in 2015 to cover devices that record routing or signaling information from electronic communications.

Plaintiffs argue that a tracking pixel records a user’s IP address, browsing path, and device identifiers as they navigate a site — which, they claim, makes it functionally equivalent to a pen register.

Courts haven’t been buying this wholesale. Two California courts in 2024 and 2025 dismissed pen register claims after finding that IP addresses alone are not “outgoing communications” and that CIPA’s pen register provision does not extend to internet communications as currently written. So the pen register theory is shakier ground than the wiretapping theory — but it hasn’t disappeared from the complaints.

The Legal Landscape: Genuinely Uncertain

Here’s the honest answer to “are these lawsuits winning?”: it depends on the judge, the specific tool, and how the plaintiff pleads the case.

Four judges recently tackled nearly identical questions about whether CIPA applies to the kind of third-party tracking tools that millions of websites use every day — and reached strikingly different conclusions.

Some courts have been skeptical. In *Torres v. Prudential Financial* (2025), a federal court ruled at summary judgment that session replay software doesn’t violate CIPA because the captured data only becomes readable after it’s been stored and reassembled — not while it’s in transit, which is what the statute requires. That’s a significant win for defendants.

Other courts have let cases proceed. In *Heerde v. Learfield Communications* (2024), a court allowed a claim to move forward where search terms were being transmitted in real time to third parties. And in *D’Antonio v. CNN*, a federal judge denied CNN’s motion to dismiss a CIPA class action over third-party trackers on CNN.com, finding that aggregating tracking data into detailed user profiles bore enough resemblance to traditional privacy violations to survive early dismissal.

The result is a patchwork of outcomes that often turn on the specific tracking technologies and legal theories alleged. The same statute, applied to nearly identical facts, has produced opposite results in different courtrooms. That’s not a stable situation for businesses trying to figure out what’s actually allowed.

What’s at Stake Financially

The $5,000-per-violation figure sounds manageable for one claim. It’s not manageable for a class action.

Federal class actions in the pixel-tracking wave have settled between $1 million and $15 million for mid-market defendants. Healthcare and financial services class actions have occasionally exceeded $25 million, with the Meta Pixel healthcare cases of 2023 to 2024 producing multiple eight-figure settlements.

Healthcare is a particular hot spot. Patient portals, appointment booking pages, symptom checkers — these combine CIPA risk with HIPAA obligations, making them priority targets for plaintiff firms.

And it’s not just large companies. Small and mid-size businesses have been receiving demand letters too. The economics of CIPA litigation favor plaintiffs even for smaller settlements, because the cost of defending a lawsuit often exceeds the cost of settling early.

What About Legislative Reform?

California lawmakers saw what was happening and tried to do something about it. Senate Bill 690, introduced in 2025, would have narrowed CIPA’s scope so that “routine commercial tracking” — the kind of tracking already regulated under CCPA — didn’t also trigger CIPA liability.

SB 690 passed the California Senate unanimously, although without any retroactive effect. In the Assembly, however, the bill stalled. It was passed as a two-year bill, meaning it carries over into the 2026 legislative session — but it’s not law yet, and there’s no safe harbor right now.

The bill’s failure leaves businesses to navigate the same patchwork of inconsistent rulings that has characterized the past two years. And in the meantime, some attorneys have reportedly accelerated their filings, wanting to get cases in before any reform actually passes.

Cookie Consent Manager | Take a 2 week free trial

CookieFirst’s automated approach provides significant value here as our Cookie banner detects GPC and Do Not Track signals automatically, it removes implementation complexity. When CookieFirst detects these signals, it immediately adjusts behavior to prevent tracking, ensuring your cookie banner requirements and consent mechanisms respect browser-level preferences without additional configuration.

Create an accountView our plans

What This Means in Practice

A CIPA claim doesn’t require the plaintiff to prove you did anything malicious. It doesn’t require proof that they were actually harmed. It requires proof that a third-party tool intercepted their communication with your site without prior consent. That standard — murky as it is legally — covers an enormous portion of how websites are currently built.

The practical exposure comes down to a few things:

**Consent timing.** Under CIPA, loading tracking scripts before a user gives consent is the core of most complaints. An opt-out disclosure after the fact — even a clear one — doesn’t fix this. The question is whether you have affirmative consent *before* the scripts load.

**Third-party access.** Courts have found that the more viable CIPA theory is that the website operator aids and abets a third-party vendor that itself intercepts the communication — meaning the issue isn’t just what you collect, but whether the vendor can use that data for their own purposes.

**Session replay tools specifically.** These are high-risk. They record keystrokes, mouse movements, clicks. If a user is typing a search query or filling out a form, and that data is being transmitted in real time to a third party, you’re squarely in the zone that courts have allowed to proceed.

**AI and chatbots.** Plaintiffs are beginning to extend these theories to generative-AI and chatbot tools, arguing that AI systems “listen” to or repurpose user inputs without appropriate consent. This is a newer development, but one to watch.

What You Can Actually Do

You cannot control what courts decide. You can’t rush SB 690 through the legislature. What you can control is your consent setup.

The single most effective thing a website can do to reduce CIPA exposure is also the most straightforward: **don’t load non-essential tracking scripts until the user has actively consented.**

That means a properly implemented consent management platform — one that actually blocks scripts from firing until consent is recorded, not one that just shows a banner and hopes for the best. The distinction matters legally. A cookie banner that loads Google Analytics in the background while displaying consent options isn’t consent management; it’s decoration.

Beyond the technical implementation, a few other things help:

  • Audit what’s actually running on your site. Many organizations don’t have a complete picture of their third-party tags.
  • Make sure your consent records are stored. If you’re ever served with a demand letter, you want to be able to demonstrate that consent was collected and logged.
  • Look hard at session replay tools and live chat. These carry more exposure than basic analytics and deserve specific review.
  • If you’re in healthcare, finance, or any sector with sensitive data, take this more seriously than average. Plaintiff firms prioritize these verticals.

Preparing for the Future

CIPA is a 1967 law being applied to 2026 technology, in courts that can’t agree on what it means. That uncertainty isn’t going away soon — SB 690 is delayed, the lawsuits are still coming, and the legal theories keep evolving.

What’s clear is that doing nothing is a real risk. The companies getting hit with demand letters and class actions aren’t doing anything exotic. They’re running standard analytics, standard ad tracking, standard chat tools — the exact same setup that hundreds of thousands of websites use. The difference between them and the companies that aren’t getting sued often comes down to whether consent was properly handled before those tools loaded.

That’s a solvable problem. It’s not comfortable or cheap to fix, but it’s fixable — and the cost of fixing it is a fraction of what a class action settlement runs.

CookieFirst is a consent management platform built to handle exactly this kind of compliance problem. It blocks non-essential scripts until consent is collected, logs consent records, and keeps up with changing legal requirements — so you’re covered as the law evolves.

CookieFirst

Get consent before loading third party tracking scripts

Ready to ensure your website respects Global Privacy Control? CookieFirst’s advanced cookie consent management platform automatically detects and honors GPC and Do Not Track signals, keeping you compliant with evolving privacy regulations. Start your free trial today and join 60,000+ customers that prioritize user privacy while maintaining compliance across all major privacy laws.