Website Tracking & Wiretap Claims

1 article

The fastest-moving litigation front in lead generation has nothing to do with how you call people — it is about what runs on your landing page. Plaintiffs are applying the California Invasion of Privacy Act, a wiretapping statute written for telephone lines, to advertising pixels, chat widgets, and session-replay scripts. The theory is that a third-party tracker reading a visitor’s interaction is an unauthorized interception of a communication. Courts have split, no appellate ruling has settled it, and the statute carries fixed damages per violation with no requirement to prove harm. This cluster covers how the theory works, what it costs, and where the consent defense actually sits.

All Articles

Frequently Asked Questions

What is the California Invasion of Privacy Act?

CIPA is a California wiretapping and eavesdropping statute at Penal Code section 630 and following. Section 631 reaches anyone who, without the consent of all parties to a communication, reads or attempts to learn its contents while it is in transit. California is an all-party consent state, which is the feature that makes the statute usable against website technology that a one-party consent rule would not reach.

Why are website trackers being sued as wiretaps?

Two theories. Under section 631, plaintiffs argue a third-party script that reads a visitor’s interaction with your site is intercepting a communication in transit without all parties consenting. Under section 638.51, they argue a tracker that captures identifying signals about a visitor functions as a pen register, which the statute says may not be installed or used without a court order. Section 638.51 lists an exception where the consent of the user has been obtained, which is why consent design is the center of the defense.

What does a single CIPA claim cost?

Penal Code section 637.2 allows the greater of five thousand dollars per violation or three times actual damages. The same section states that suffering or being threatened with actual damages is not a necessary prerequisite to bringing the action. Fixed per-violation damages with no harm requirement is what turns routine site traffic into class-scale exposure.

Does SB 690 end these lawsuits?

Not today, and not entirely even if enacted. As of July 2026 SB 690 has not been enacted; it was amended on July 2, 2026 and re-referred to the Assembly Appropriations Committee. As amended it would add a commercial business purpose exemption across the intercept and pen-register provisions, and would remove the private right of action for section 638.51 claims arising from website or app conduct, leaving those to the Attorney General and applying retroactively to pending claims commenced within two years of the operative date. That removal is limited to section 638.51 — claims under sections 631 and 632 would keep their private right of action.

The Operator’s Compliance Brief

What changed in lead-gen compliance, and what to do about it. Free, no spam.