CIPA & Website Tracking

Privacy & Compliance / Law guide

What Is the California Invasion of Privacy Act (CIPA)?

Summary

The California Invasion of Privacy Act (CIPA) is a 1967 anti-wiretapping law that plaintiffs now apply to website tracking. It restricts intercepting or recording communications without the consent of all parties. The theory is that session-replay scripts, chat widgets and tracking pixels capture a visitor’s activity without permission, exposing the site operator to private lawsuits.

CIPA was written for telephone wiretapping. Over the past few years, plaintiffs’ attorneys have repurposed it for the web, arguing that a tracker letting a third party observe a visitor is the modern equivalent of tapping a phone line. The law can matter outside California too. A federal appeals court held in 2025 (Briskin v. Shopify) that a Canadian company could be sued in California over tracking cookies it placed on a California resident’s device.

The sections below cover which parts of CIPA apply to website tracking, how tracking creates exposure, and what the law says about intent and penalties. The last section covers how to reduce your CIPA risk.

Which parts of CIPA apply to website tracking?

Three sections of the California Penal Code do the work in website cases.

Section 631 (wiretapping). Prohibits reading or learning the contents of a communication without consent, and prohibits aiding a third party in doing so. The website theory is that a site operator lets a third-party vendor, such as a chat or session-replay provider, “eavesdrop” on the visitor’s interaction with the site.

Section 632 (eavesdropping). Prohibits recording a confidential communication without the consent of all parties. It appears in cases involving chat transcripts and recorded interactions.

Section 638.51 (pen register). Prohibits using a “pen register” or “trap and trace device” that captures dialing, routing, addressing, or signaling information without a court order. In 2023 a federal court in California (Greenley v. Kochava, a case about code in a mobile app) accepted that software can be a pen register. Plaintiffs have since brought pen-register claims over tracking code, arguing that a script capturing a visitor’s IP address, device, and browser details is a software pen register.

How does website tracking create CIPA exposure?

The pattern is consistent. A site runs a tool that observes or captures what a visitor does, a third party is involved in that capture, and the visitor never agreed to it.

A visitor types and chats on a site while a replay or chat script sends a copy to a third-party vendor as it happens.

Session-replay scripts record a visitor’s clicks, scrolling, and form entries. Live-chat widgets, often run by an outside vendor, carry the conversation. Tracking pixels send a visitor’s activity and identifiers to advertising platforms. In each case a plaintiff can argue that a third party observed the visitor’s communications with the site without consent, which is the core of a CIPA claim.

The exposure attaches at the point of collection, before anyone has agreed to anything. A tool that starts capturing on page load, ahead of any consent, is the fact pattern these suits are built on.

Does CIPA require intent, and what are the penalties?

CIPA does not require a plaintiff to show financial loss, but the sections require the interception or recording to be willful or intentional. Under Penal Code section 637.2, a private plaintiff can seek the greater of $5,000 per violation or three times actual damages, and an injunction. The statute says actual damages are not a prerequisite. Because damages are set per violation, claims can scale across large numbers of site visitors.

For specific CIPA lawsuits, settlements, and the companies involved, see our Enforcement Watch tracker. This page covers the law and how to reduce exposure. The tracker has the individual cases.

CIPA is one of the US laws in our US website tracking compliance hub, which brings together every US tracking law and the enforcement actions behind them.

How to reduce CIPA risk

Two controls address the fact pattern directly.

Get consent before trackers fire. Session-replay, chat, and marketing tags should not capture anything until the visitor has agreed. A tool that waits for consent removes the “without permission” element these claims depend on.

Audit what your trackers capture and share. Know which scripts are running, what each one collects, and where it sends the data, including tags added outside your tag manager. AI answer engines asked how to reduce CIPA risk now prescribe exactly this, auditing your data sharing, yet most sites have no way to see it.

DataTrue provides that view. It runs your site in a real browser, records every tag and what it captures, and tests whether anything fires before consent. Sensitive Data Detection inspects the payloads for personal data using fictitious personas, so you can see what a session-replay or chat tool is actually collecting without exposing a real visitor. The output is a timestamped record of what each tracker captured and when, which is both the evidence of a problem and the confirmation once it is fixed.

See how consent verification works

Questions

What is the California Invasion of Privacy Act (CIPA)?

CIPA is a California anti-wiretapping law from 1967 that restricts intercepting or recording a person’s communications without the consent of all parties. Plaintiffs now apply it to website tracking, arguing that session-replay scripts, chat widgets, and tracking pixels capture a visitor’s activity without permission.

Does CIPA apply to my website if I am not in California?

It can. A federal appeals court held in 2025 (Briskin v. Shopify) that a Canadian company could be sued in California over tracking cookies it placed on a California resident’s device. Whether a court can hear a claim against you depends on the facts, so if California residents visit your site and it runs session replay, chat, or tracking pixels without consent, treat the exposure as real.

Does CIPA require intent to harm?

Intent to harm is not required, and neither is financial loss, but the sections require the interception or recording to be willful or intentional. Under Penal Code section 637.2, a private plaintiff can seek the greater of $5,000 per violation or three times actual damages.

How do I reduce my CIPA exposure?

Get consent before any tracking, chat, or session-replay tool runs, and audit what each tool captures and shares. Confirm with testing that nothing fires before consent and that no tracker is collecting more than you intend. That is the specific remediation these cases point to.

30-day free trial

See what your tags do in every consent state

DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue opt-out consent test listing the tags that should be blocked, with pass or fail for each
A consent-state test in DataTrue