Key Facts
Does this apply to your site?
CIPA claims center on what a chat widget, session-replay tool, or ad pixel actually does before a visitor consents. Scan your site to see which of those tools fire first, free and instant.
Overview
The California Invasion of Privacy Act (CIPA) is not a website law. It is a roughly 30-section 1967 chapter of the Penal Code covering phone wiretapping, eavesdropping, cellular and cordless phone interception, disclosure of telephone messages, voice prints, cable TV monitoring, GPS tracking devices, and more. Since 2022, plaintiffs' firms have applied two of those sections, wiretapping and eavesdropping, to website chat tools, analytics, and ad pixels, arguing a vendor that receives visitor data "intercepts" it the way a phone tap intercepts a call. That extension is contested and only partly settled, but it has not slowed the lawsuits, and the volume of demand letters is now among the largest sources of US privacy litigation.
What This Means for Your Website
- The strongest claims are under Penal Code Section 631 (wiretapping), on an aiding-and-abetting theory: a site cannot wiretap its own traffic, but is alleged to have helped a third-party vendor (chat, analytics, session-replay, ad pixels) intercept it
- Architecture matters more than tool category. Courts are actively split on whether data captured "in transit," meaning a script sends it to a third party in real time before your server sees it, differs from data a vendor only receives after it reaches your own server. At least one California federal court granted summary judgment for a defendant on exactly this basis
- A second, weaker claim runs through Section 632 (eavesdropping), which requires a "confidential communication." Courts have generally found ordinary web browsing is not confidential, so these claims are dismissed more often than Section 631 claims
- A newer, contested theory applies the pen-register statute (Section 638.51) to pixels and SDKs that capture IP addresses or routing data; courts disagree on whether this reaches ordinary web telemetry at all
- There is no size cutoff. A solo-operator site with one visitor from California faces the same exposure as an enterprise
Key Requirements
CIPA has no dedicated regulator and no notice-and-cure period. Penal Code Section 637.2 lets any person sue directly for statutory damages of $5,000 per violation or three times actual damages, whichever is greater, and misdemeanor exposure also attaches to Sections 631 and 632. The Ninth Circuit has recently split on how far the theory reaches: it affirmed dismissal in Thomas v. Papa John's (June 2025) where the plaintiff did not adequately allege the site aided a vendor's interception, but reversed dismissal in Mikulsky v. Bloomingdale's (June 2025) where it did. Because enforcement runs through private lawsuits instead of an agency, a single visitor complaint can become a filed case with no warning first.
How ConsentStack Handles This
ConsentStack blocks chat widgets, session-replay scripts, and ad pixels from loading until a California visitor makes a consent choice, and reject actually stops them rather than just hiding the banner. That directly addresses the Section 631 in-transit theory for client-side scripts. Run a free scan at ConsentStack to see which of these tools your site fires before that choice is made.
Penalties
$5,000 per violation or three times actual damages, whichever is greater (Penal Code 637.2); Sections 631 and 632 violations can also carry misdemeanor criminal exposure.
Key Requirements
- Section 631 (wiretapping, the strongest theory): a site is alleged to have aided a third-party vendor in intercepting visitor data "in transit"
- Architecture matters: courts are split on whether server-side data processing counts as "in transit" the way a real-time client-side script does
- Section 632 (eavesdropping) is weaker: it requires a "confidential communication," and courts often find ordinary web browsing is not one
- No revenue or visitor-count threshold; private right of action lets any visitor sue directly with no regulator or cure period first
- Statutory damages of $5,000 per violation or three times actual damages, whichever is greater (Penal Code 637.2)
Notable Provisions
- CIPA is a roughly 30-section chapter (Penal Code 630-638.55) covering phone wiretapping, eavesdropping, cellular interception, voice prints, cable TV monitoring, GPS tracking, and pen registers, not a website-specific law
- Section 631 (wiretapping) carries the strongest website claims via an aiding-and-abetting theory against the site; Section 632 (eavesdropping) is weaker since it requires a "confidential communication"
- A newer, contested theory applies the pen-register statute (Section 638.51) to pixels and SDKs that capture IP addresses or routing data; courts are inconsistent
- Ninth Circuit split in June 2025: dismissal affirmed in *Thomas v. Papa John's*, dismissal reversed in *Mikulsky v. Bloomingdale's*, both turning on whether the site adequately aided a vendor's interception
US State Specifics
Other North America Regulations
Frequently Asked Questions
Stay compliant with CIPA
ConsentStack helps you implement Opt-in consent for California, United States automatically.