The California Invasion of Privacy Act (CIPA) was first passed in 1967, as a reaction to the boom in cheap and portable recording technology (think classic movie hidden microphones and tape recorders). One of the early cases under CIPA was Rogers v. Ulrich (1975, which covered a San Jose city official who secretly recorded a phone call with a city council candidate. The candidate sued under both the CIPA wiretapping section 631. The court held that it didn’t apply to a participant recording their own call, and only third party interception would count as “wiretapping”.
Fun fact: Instead of suing under section 631 (3rd party wiretapping), Rogers should have sued under section 632 of the same statute for having a confidential conversation recorded without consent. He tried to amend his complaint 18 months after his initial filing right before trial to section 632, but the court denied it because it came too late.
So basically CIPA says that a third party can’t record you, nor can a first party record a conversation, without knowledge and consent of the recording. Of course there are some exemptions like if you are documenting evidence of certain crimes like violent felonies, domestic violence victims gathering evidence, and law enforcement.
“This call may be recorded for quality purposes.” Thank you, CIPA.
Ok so why are hundreds, if not thousands, of companies being suddenly sued under a 1960s wiretapping law? The number of CIPA filings in 2022 was just 54, but in 2026 it’s projected to be over 3,500. The reason isn’t generally a legal problem, moreso a technical one. The surge is because CIPA is a strict liability statue, that is, it doesn’t care about your intent, it only cares about a single technical fact: did your website intercept a user’s interaction before you gave them your explicit prior consent to do so?
It’s really about the order of operations. It’s not a question for a legal brief, it’s a question for your site architecture. Did a third-party chat widget load and start recording your keystrokes before the consent banner even finished rendering? Most organizations believe their Consent Management Platform (CMP) handles this, because they see the banner load, they see the dashboard of he CMP, and they assume they’re good. That’s a dangerous assumption.
A CMP is a great tool (and necessary) for asking for permission, and then recording a user’s answer, but it is not a comprehensive technical enforcement layer, that blocks every other script on your site until that answer is given.
Lots of your scripts and tags, especially the ones hardcoded on the page, can fire the instant the page starts to load. That means they can fire before any choice has been recorded by the CMP. The script doesn’t even need to be malicious, it’s just not integrated into your consent framework, and CIPA doesn’t care about these distinctions. The interception happened, and the liability was created.
The companies settling these lawsuits and writing seven-figure checks are not bad actors. They simply had their technical implementations fail to match their legal promises. The right intentions, the wrong order of operations.
Your legal counsel can tell you what a law like CIPA requires, but only a full inventory of your site, a coverage scan, can tell you if your technology is actually meeting that requirement. Only one of those things gives your developers an actionable list of problems to fix.