The California Invasion of Privacy Act, Explained for Lead Generators
Most compliance attention in lead generation points at the phone. The fastest-growing litigation risk right now points at your landing page.
Plaintiffs are applying the California Invasion of Privacy Act — a wiretapping statute — to ordinary website technology: advertising pixels, chat widgets, and session-replay scripts. The claim is that a third-party script watching a visitor interact with your site is intercepting a communication without permission. Courts have split on it, no appellate decision has settled it, and the statute sets damages per violation without requiring anyone to prove they were harmed.
That combination is why this front opened so quickly, and why it reaches operators who have never placed a single outbound call.
Not Legal Advice
This is an operator's read, not legal advice.
What is the California Invasion of Privacy Act?
CIPA is a California wiretapping and eavesdropping statute, codified at Penal Code section 630 and following. It predates the commercial internet by decades and was written for telephone lines.
The provision doing most of the work is section 631(a), which reaches a person who "willfully and without the consent of all parties to the communication, or in an unauthorized manner, reads, or attempts to read, or to learn the contents or meaning of a message, report, or communication while the same is in transit."
Two features of that text matter enormously:
California requires the consent of all parties. In a one-party consent jurisdiction, the website operator's own participation in the interaction would end the analysis. In California it does not — the visitor's consent is also in play.
Section 631(a) also reaches anyone who "aids, agrees with, employs, or conspires with" another person to do the prohibited act. That aiding clause is what lets a plaintiff sue the website operator for what an embedded vendor's script did.
Why the statute's age is the point
The plaintiff's argument does not depend on CIPA having anticipated web tracking. It depends on the words "in transit" and "all parties" being broad enough to cover it. That is a question of statutory interpretation, which is exactly why courts have reached different answers on similar facts.
Why is an old wiretapping law being used against websites?
Because of the remedy, which is covered in detail below: a fixed sum per violation with no requirement to show harm. A statute with those mechanics turns routine traffic volume into arithmetic, and arithmetic is what makes a class action worth filing.
It is worth being precise about who gets sued. The theory does not require that you sold data, that you were breached, or that anyone suffered a loss. It requires only that a third party was in a position to read a communication between you and your visitor without the visitor's consent. On a modern lead-gen landing page, that describes a substantial amount of ordinary marketing infrastructure.
How does the section 631 wiretap theory work?
The argument runs in three steps.
First, the visitor's interaction with your site — form keystrokes, page navigation, chat messages — is characterized as a communication between the visitor and the site operator.
Second, a third-party script embedded in the page receives that interaction contemporaneously. Because the script transmits to a vendor's servers as the visitor acts, the plaintiff argues the contents are being read "while the same is in transit" rather than retrieved afterward from your records.
Third, because the vendor is a third party to that conversation and the visitor never consented, the interception is without the consent of all parties. The site operator is then pulled in under the aiding clause for embedding the script.
The most contested step is the second. A well-known defense is that a vendor acting purely as the operator's tool is not a third party at all, any more than a tape recorder is a separate eavesdropper. Whether that holds tends to turn on what the vendor does with the data — a vendor that uses the data for its own purposes looks much less like a passive extension of the operator.
Chat widgets are the archetype
A live-chat or AI-chat widget is the cleanest version of the plaintiff's fact pattern: an actual conversation, an actual third-party vendor receiving it in real time, and often no disclosure at all before the visitor starts typing. If you run one, it deserves review before anything else on the page.
The Operator’s Compliance Brief
What changed in lead-gen compliance, and what to do about it. Free, no spam.
How does the section 638.51 pen register theory work?
This is the newer and, in some ways, more aggressive theory, and it sidesteps the hardest part of the section 631 argument.
Section 638.51(a) states that a person "may not install or use a pen register or a trap and trace device without first obtaining a court order." A pen register historically captured the routing and signaling information of a call — the numbers dialed — rather than the contents of the conversation.
The move is to characterize a tracking script as a device that captures identifying and routing signals about a visitor: IP address, device and browser fingerprint, referral path. Under that framing the plaintiff never has to prove anyone read the contents of anything, which removes the interception-in-transit fight entirely.
The statute lists exceptions, and one is decisive for operators: use is permitted where "the consent of the user of that service has been obtained." Consent is not a side issue here. It is written into the exception.
What is a CIPA claim actually worth?
Penal Code section 637.2 sets the civil remedy, and it is the engine of the whole phenomenon. A person injured by a violation may recover the greater of:
- Five thousand dollars ($5,000) per violation, or
- Three times the amount of actual damages, if any.
And then the provision that changes everything, quoted directly: "It is not a necessary prerequisite to an action pursuant to this section that the plaintiff has suffered, or be threatened with, actual damages."
No harm needs to be shown. The damages are fixed. So exposure scales with the number of affected visitors rather than with anything you did wrong in a moral sense. A modest California traffic volume produces a number large enough to make settlement the rational choice regardless of the merits — which is precisely the dynamic that attracts repeat filers.
Traffic volume is your exposure
Unlike a call program, where you control how many numbers you dial, your website's exposure is a function of how many Californians visit. You cannot manage this risk down by doing less outreach. The only levers are what runs on the page and what the visitor agreed to.
Does consent defeat these claims?
It is the central defense, and it is the one thing entirely within your control — but the quality of the consent matters more than its existence.
Section 631 turns on the consent of all parties, and section 638.51's exception turns on consent of the user having been obtained. In both cases the question a court asks is whether this visitor actually agreed to this collection before it happened, not whether a policy existed somewhere on the site.
What tends to hold up better:
- Disclosure that appears before trackers fire, not after the page has already loaded them.
- Language that describes what actually happens in plain terms — third parties receive information about your visit — rather than a generic reference to cookies.
- A record of what the visitor was shown and when, which is the same discipline as proof of consent on the lead-capture side.
What tends to hold up poorly: a privacy policy linked in the footer, a banner that only offers "OK," or a consent tool that is configured to fire everything immediately and record the acceptance afterward.
Test what actually fires, and when
Open your own landing page with the browser network tab recording and watch which third-party requests go out before any interaction. Operators are routinely surprised. The gap between what a consent tool is configured to do and what the page actually does is where the claim lives.
Would SB 690 make this go away?
Not today, and not completely even if it passes. This is the part most commentary gets wrong, so it is worth stating carefully from the bill itself.
As of July 2026, SB 690 is not law. It was amended on July 2, 2026, read a second time, and re-referred to the Assembly Appropriations Committee. It is an active bill in fiscal review, not enacted relief.
As currently amended, the bill would amend Penal Code sections 631, 632, 632.7, 637.2, and 638.50. Two changes matter:
A commercial business purpose exemption. The bill would exempt communication intercepts undertaken for a "commercial business purpose," defined as processing personal information either to further a business purpose or subject to a consumer's opt-out rights. This is the broad change, and it reaches the intercept provisions.
A narrower private-right-of-action removal. New section 637.2(d)(1) would provide that an action against a private actor for a violation of section 638.51 arising from conduct on a website or application "may be brought under this section only by the Attorney General," and that this limitation applies retroactively to pending claims commenced within two years before the operative date.
Read those together carefully. The removal of the private right of action is limited to section 638.51 — the pen register theory. Claims under sections 631 and 632 would retain their private right of action. An operator reading headlines about SB 690 ending CIPA website litigation would be drawing the wrong conclusion twice over: the bill is not enacted, and even as drafted it does not close the door on the wiretap theory.
Do not plan around an unpassed bill
A bill in Appropriations is not relief, and its scope can change again before any floor vote. Build for the statute as it reads today. If SB 690 is enacted later with retroactive effect, that is upside on conduct you have already made defensible — not a reason to leave the page unfixed now.
What should an operator do about it now?
In rough order of return on effort:
- Inventory what is on the page. Every third-party script on any page that collects lead information, including tag-manager-injected ones nobody remembers adding.
- Look hardest at chat and session replay. These are the cleanest fact patterns for a plaintiff. Note that session-replay tooling is often sold as a compliance and optimization asset, which is true — and separately it is the specific technology at the center of this litigation. Both things are the case at once.
- Fix the firing order. Trackers should not run before the visitor has been given the disclosure. This is a configuration problem far more often than a vendor problem.
- Keep the record. What was displayed, what was chosen, and when — the same standard applied to consent everywhere else in the funnel.
- Treat California traffic as the trigger, not your headquarters. The statute follows the visitor.
The self-audit scorecard includes the pixel and tracker consent question if you want a scored read on where this sits against the rest of your funnel.
Sources
- California Penal Code § 631 — Wiretapping — California Legislative Information (accessed 2026-07-27)
- California Penal Code § 638.51 — Pen registers and trap and trace devices — California Legislative Information (accessed 2026-07-27)
- California Penal Code § 637.2 — Civil action — California Legislative Information (accessed 2026-07-27)
- SB 690 — Crimes: invasion of privacy (bill text, as amended July 2, 2026) — California Legislative Information (accessed 2026-07-27)
- SB 690 — Bill status and history — California Legislative Information (accessed 2026-07-27)
30+ years in lead gen · BRSG Founder
Bill Rice has spent 30+ years in mortgage, lending, and performance marketing — generating leads, buying them, and building the systems that route and work them. He founded a performance-marketing agency, owned a direct-to-consumer lender, and wrote The Lead Buyer's Playbook. He built Lead Compliance Hub to help operators navigate the legal landmines of online lead generation from an operator's seat, not a law firm's. Nothing he writes here is legal advice.
The Operator’s Compliance Brief
What changed in lead-gen compliance, and what to do about it. Free, no spam.