CIPA

California Invasion of Privacy Act

Key Facts

Effective Date
January 1, 1967
Enacted
January 1, 1967
Enforcing Authority
No dedicated regulator. Enforced entirely through private civil lawsuits under the Penal Code Section 637.2 private right of action, with limited misdemeanor prosecution by California district attorneys.
Consent Model
Opt-in
Applies To
Any website using a chat widget, analytics tool, session-replay tool, or ad pixel that sends a California visitor's activity to a third-party vendor. Exposure depends on architecture (real-time client-side capture faces the strongest claims) more than on any specific tool category. No revenue or visitor-count threshold; a single visitor can bring a claim.

Does this apply to your site?

CIPA claims center on what a chat widget, session-replay tool, or ad pixel actually does before a visitor consents. Scan your site to see which of those tools fire first, free and instant.

2,440 sites scanned and counting

Overview

The California Invasion of Privacy Act (CIPA) is not a website law. It is a roughly 30-section 1967 chapter of the Penal Code covering phone wiretapping, eavesdropping, cellular and cordless phone interception, disclosure of telephone messages, voice prints, cable TV monitoring, GPS tracking devices, and more. Since 2022, plaintiffs' firms have applied two of those sections, wiretapping and eavesdropping, to website chat tools, analytics, and ad pixels, arguing a vendor that receives visitor data "intercepts" it the way a phone tap intercepts a call. That extension is contested and only partly settled, but it has not slowed the lawsuits, and the volume of demand letters is now among the largest sources of US privacy litigation.

What This Means for Your Website

  • The strongest claims are under Penal Code Section 631 (wiretapping), on an aiding-and-abetting theory: a site cannot wiretap its own traffic, but is alleged to have helped a third-party vendor (chat, analytics, session-replay, ad pixels) intercept it
  • Architecture matters more than tool category. Courts are actively split on whether data captured "in transit," meaning a script sends it to a third party in real time before your server sees it, differs from data a vendor only receives after it reaches your own server. At least one California federal court granted summary judgment for a defendant on exactly this basis
  • A second, weaker claim runs through Section 632 (eavesdropping), which requires a "confidential communication." Courts have generally found ordinary web browsing is not confidential, so these claims are dismissed more often than Section 631 claims
  • A newer, contested theory applies the pen-register statute (Section 638.51) to pixels and SDKs that capture IP addresses or routing data; courts disagree on whether this reaches ordinary web telemetry at all
  • There is no size cutoff. A solo-operator site with one visitor from California faces the same exposure as an enterprise

Key Requirements

CIPA has no dedicated regulator and no notice-and-cure period. Penal Code Section 637.2 lets any person sue directly for statutory damages of $5,000 per violation or three times actual damages, whichever is greater, and misdemeanor exposure also attaches to Sections 631 and 632. The Ninth Circuit has recently split on how far the theory reaches: it affirmed dismissal in Thomas v. Papa John's (June 2025) where the plaintiff did not adequately allege the site aided a vendor's interception, but reversed dismissal in Mikulsky v. Bloomingdale's (June 2025) where it did. Because enforcement runs through private lawsuits instead of an agency, a single visitor complaint can become a filed case with no warning first.

How ConsentStack Handles This

ConsentStack blocks chat widgets, session-replay scripts, and ad pixels from loading until a California visitor makes a consent choice, and reject actually stops them rather than just hiding the banner. That directly addresses the Section 631 in-transit theory for client-side scripts. Run a free scan at ConsentStack to see which of these tools your site fires before that choice is made.

Penalties

$5,000 per violation or three times actual damages, whichever is greater (Penal Code 637.2); Sections 631 and 632 violations can also carry misdemeanor criminal exposure.

Maximum Fine
$5,000 per violation

Key Requirements

  • Section 631 (wiretapping, the strongest theory): a site is alleged to have aided a third-party vendor in intercepting visitor data "in transit"
  • Architecture matters: courts are split on whether server-side data processing counts as "in transit" the way a real-time client-side script does
  • Section 632 (eavesdropping) is weaker: it requires a "confidential communication," and courts often find ordinary web browsing is not one
  • No revenue or visitor-count threshold; private right of action lets any visitor sue directly with no regulator or cure period first
  • Statutory damages of $5,000 per violation or three times actual damages, whichever is greater (Penal Code 637.2)

Notable Provisions

  • CIPA is a roughly 30-section chapter (Penal Code 630-638.55) covering phone wiretapping, eavesdropping, cellular interception, voice prints, cable TV monitoring, GPS tracking, and pen registers, not a website-specific law
  • Section 631 (wiretapping) carries the strongest website claims via an aiding-and-abetting theory against the site; Section 632 (eavesdropping) is weaker since it requires a "confidential communication"
  • A newer, contested theory applies the pen-register statute (Section 638.51) to pixels and SDKs that capture IP addresses or routing data; courts are inconsistent
  • Ninth Circuit split in June 2025: dismissal affirmed in *Thomas v. Papa John's*, dismissal reversed in *Mikulsky v. Bloomingdale's*, both turning on whether the site adequately aided a vendor's interception

US State Specifics

Private Right of Action
Yes
Global Opt-out Required
No
Sensitive Data Opt-in
No

Other North America Regulations

CPRACalifornia, United States
The CPRA is the most comprehensive US state privacy law with a dedicated enforcement agency (CPPA). Cross-context behavioral advertising via cookies constitutes sharing personal information, triggering opt-out obligations. GPC signals must be honored as valid opt-out requests.
CCPACalifornia, United States
The CCPA was the first comprehensive consumer privacy law in the United States, giving California residents the right to know what personal information businesses collect and to opt out of its sale. It established the opt-out consent model that most subsequent US state privacy laws adopted.
PIPEDACanada
Canada's federal private-sector privacy law based on 10 fair information principles. Requires express consent for sensitive data and implied consent for less sensitive data. OPC guidance addresses cookies and online behavioral advertising. The CPPA replacement bill died January 2025; a new bill is expected.
Quebec Law 25Quebec, Canada
The most GDPR-like privacy law in the Americas. Requires explicit, granular consent per purpose before deploying ANY tracking technology. Implied consent is explicitly prohibited for cookies and tracking. Features extraterritorial scope, mandatory PIAs, and GDPR-level penalties (4% worldwide turnover). The strictest cookie consent requirements in North America.
CPAColorado, United States
Colorado's CPA features the highest per-violation penalties among US state privacy laws at $20,000. Must honor GPC signals since July 2024. Participated in a joint GPC enforcement sweep with California and Connecticut in September 2025. The cure period was eliminated in January 2025.
TDPSATexas, United States
The TDPSA is the broadest US state privacy law — no revenue thresholds and no minimum consumer data volume thresholds. Applies to any non-small-business processing personal data of Texas residents. Must honor GPC signals since January 2025. This breadth means far more businesses are captured than under any other state law.

Frequently Asked Questions

Stay compliant with CIPA

ConsentStack helps you implement Opt-in consent for California, United States automatically.