CRANDALL CONSULTING
HomeWebsite Tracking Laws › California Invasion of Privacy Act (CIPA)

California Invasion of Privacy Act (CIPA) & Website Tracking Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

Cal. Penal Code § 630 et seq. (notably §§ 631, 632.7, 638.51)
Citation
All-party
Consent Standard
Yes
Private Right of Action
$5,000 per violation or three times actual damages (Cal. Penal Code § 637.2)
Statutory Damages
Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

What This Statute Says (Plain Language)

CIPA is California's electronic interception statute. Section 631 addresses wiretapping and reading or attempting to read the contents of a communication in transit without the consent of all parties; § 632.7 has been raised regarding communications involving cellular devices; and § 638.51 restricts the use of 'pen registers' and 'trap and trace' devices that capture routing and addressing information. CIPA provides a private right of action with statutory damages of $5,000 per violation, which materially shapes the economics of class litigation.

Why It Appears in Website Tracking Litigation

CIPA is the most heavily litigated statute in website tracking cases. Plaintiffs have advanced § 631 'aiding and abetting' theories against website operators whose third-party scripts allegedly read communications in transit, and more recently § 638.51 'pen register' theories aimed at trackers that capture IP addresses and device information. Courts have split on many of these theories, including whether a third-party service provider is an eavesdropper or merely an 'extension' of the website operator. The volume of filings and demand letters citing CIPA remains high.

Practical Implications for Website Operators

CIPA is the single most frequently cited statute in the website tracking matters we track. A large share of activity never reaches a courtroom: plaintiff-side firms run automated scans that detect session replay scripts, chat widgets, and advertising pixels, then send pre-suit demand letters citing sections 631, 632.7, or 638.51. Because the theories focus on where the website visitor is located, businesses with no California offices, employees, or registrations receive these letters routinely — an online store in Ohio serving California visitors is squarely inside the pattern.

The economics explain the volume. Section 637.2 provides $5,000 in statutory damages per violation without requiring proof of actual harm, and plaintiffs' theories multiply violations across visitors and page views. Even where a legal theory is untested, the arithmetic of a potential class action creates settlement pressure that is largely independent of the merits.

The technology mix has shifted over time. Earlier waves focused on session replay and chat transcripts under section 631; the more recent wave asserts section 638.51 'pen register' theories against ordinary trackers that capture IP addresses and device information on page load — a lower factual bar than capturing message contents, which is precisely why plaintiffs adopted it. Courts have divided on whether those theories state a claim, and the split itself sustains filing activity.

Litigation Risk in Plain Language

Four structural features combine to make CIPA the center of gravity in this area: an all-party consent standard, a private right of action, per-violation statutory damages, and California's class action infrastructure. Public decisions are genuinely mixed — some courts have dismissed claims because routine browsing data was held not to be the 'contents' of a communication, or because the third-party service was treated as an extension of the website operator rather than an eavesdropper; others have allowed materially similar claims past the pleading stage. That unresolved landscape, not any single ruling, is what drives risk.

For operators, the practical exposure question is factual rather than legal: what do the third-party tools on the site actually transmit, and when does the transmission occur relative to any consent choice? Matters that survive early motions tend to involve transmission of typed input, chat content, or identifying information before the visitor has interacted with a consent tool. Detection of a tracker is an informational risk indicator that warrants configuration review — it is not a finding that any law was violated.

What Operators Commonly Review

These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:

How This Statute Compares

Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:

StatuteConsent StandardPrivate Right of ActionStatutory Damages
Federal Wiretap Act (ECPA Title I)One-partyYesThe greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520)
Florida Security of Communications Act (FSCA)All-partyYesThe greater of actual damages, $100 per day of violation, or $1,000 (Fla. Stat. § 934.10)
Illinois Eavesdropping ActAll-partyYesActual and punitive damages; injunctive relief (720 ILCS 5/14-6)
Maryland Wiretapping and Electronic Surveillance ActAll-partyYesThe greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (§ 10-410)
Massachusetts Wiretap ActAll-partyYesActual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees
Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA)All-partyYesThe greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725)
Washington Privacy ActAll-partyYesActual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060)

Jurisdiction Context

See the full California website tracking litigation page for the current risk guideline (Very High), tracked matter counts, and trend data.

Tracked Cases Invoking This Statute

Torres v. SeatGeek, Inc.

United States District Court for the Northern District of California (Magistrate Judge Laurel Beeler) · 2026-05-22 · Lawsuit

A Northern District of California magistrate judge granted a Rule 12 motion to dismiss Torres v. SeatGeek for lack of Article III standing, holding that routine metadata collected via tracking pixels (IP, device/browser metadata, cookie IDs) did not constitute a concrete injury under the Popa framework. The court found aggregation across three recipients and receipt of targeted ads insufficient to transform the non-sensitive technical data into a cognizable privacy injury.

Caldwell v. InMobi Pte. Ltd.

United States District Court, Northern District of California · 2026-04-29 · Lawsuit

The Northern District of California denied InMobi’s motion to dismiss a putative class action alleging CIPA pen register violations and California privacy torts, holding the pleading sufficiently alleges modern tracking technologies can satisfy CIPA’s definitions and that privacy claims survive at the pleading stage. The court left factual questions (e.g., consent, app identity, linkage to real-world identity) for later stages of the case.

Javier v. Assurance IQ

United States Court of Appeals for the Ninth Circuit · Reported claim

This guide explains the distinction between CIPA (California Penal Code Section 631) and the CCPA/CPRA opt-out regime, discusses an unpublished Ninth Circuit decision (Javier v. Assurance IQ) that suggested Section 631 applies to internet communications and may require consent before recording, and summarizes pending California legislation (SB 690) that would limit private pen-register claims but not Section 631 claims. It advises operational steps for CMPs to block high-risk third-party capture and to properly honor Global Privacy Control and Do Not Sell/Share controls.

Javier v. Assurance IQ, LLC and Active Prospect Inc.

United States Court of Appeals for the Ninth Circuit · Lawsuit

The ArentFox Schiff blog reports on an unpublished Ninth Circuit panel decision in Javier v. Assurance IQ, holding that California Penal Code Section 631 requires prior express consent before recording web interactions, and that retroactive consent is insufficient. The decision reversed the district court's conclusion on retroactive consent, but left other district-court rulings (such as whether a website operator is a party to communications) unaddressed. The post recommends website operators obtain opt-in consent before recording.

Fregosa v. Mashable Inc.

United States District Court for the Northern District of California · 2025-10-09 · Lawsuit

A federal district court in the Northern District of California denied Mashable’s motion to dismiss a Second Amended Complaint alleging that third-party web trackers installed on Mashable’s site recorded IP addresses and device identifiers in violation of CIPA’s pen-register provisions. The court concluded the statute’s text and precedent permit treating software processes that record addressing information as pen registers at the pleading stage, and the case remains pending.

Crano v. Sojern, Inc.

United States District Court for the Northern District of California · 2026-06-09 · Lawsuit

A California federal judge dismissed the Second Amended Complaint in Crano v. Sojern, Inc. for lack of Article III standing, finding the plaintiff failed to allege a concrete injury. The court rejected theories based on intangible privacy harms from collection of technical identifiers and an unjust-enrichment economic harm theory, relying on Ninth Circuit precedent and distinguishing In re Facebook.

E.H. et al v. Lifelong Adoptions, Inc.

United States District Court for the Eastern District of California · 2026-07-24 · Lawsuit

The federal district court granted LifeLong’s motion to dismiss in part and denied it in part on July 24, 2026. Several claims were dismissed (some with leave to amend, others without), while multiple privacy-related claims under California common law, the California Constitution, CIPA, and the federal ECPA survived the pleading challenge and will proceed subject to further amendment or litigation.

Blaker v. Netscout Systems

Los Angeles Superior Court · 2026-05-27 · Lawsuit

A Loeb & Loeb analysis describes a Los Angeles Superior Court decision in Blaker v. NetScout where the court dismissed a CIPA class action with prejudice, holding that the pen-register/trap-and-trace statutory provision does not reach ordinary website SDKs and tracking. The article contrasts that outcome with earlier cases where defendants engaged in highly technical defenses and lost ground.

Vivek Shah

California federal court · Lawsuit

The provided page text is largely site navigation and practice-area links. The page title states that a California federal court declared serial CIPA plaintiff Vivek Shah a vexatious litigant, but the article body and case details are not present in the supplied text.

Popa v. Microsoft Corp.

U.S. Court of Appeals for the Ninth Circuit; U.S. District Courts for the Northern, Central, and Southern Districts of California · Lawsuit

This Holland & Knight alert describes conflicting rulings in California over whether web-based tracking technologies (e.g., pixels and IP-address collection) fall within CIPA Section 638.51. It highlights the Ninth Circuit's Popa v. Microsoft decision tightening Article III standing requirements and notes divergent district-court outcomes applying Popa to CIPA claims.

Common Questions

Why do so many website tracking demand letters cite CIPA?

CIPA combines an all-party consent standard, a private right of action, and $5,000-per-violation statutory damages with California's active privacy plaintiff bar. Demand letters are inexpensive to generate — many are based on automated scans of a website's third-party scripts — so detection of a common tracker is often all it takes to receive one. Receiving a letter is not a finding of liability; it is a signal to review what your site transmits and to consult qualified counsel.

Our business is not in California. Can CIPA still be asserted against us?

Plaintiffs' theories generally focus on the location of the website visitor, not the business. A website operated from any state that serves California visitors can — and in tracked matters regularly does — face CIPA demands. Whether the statute actually applies to a given operator is a fact- and law-specific question for qualified counsel.

What is a CIPA 'pen register' claim?

Section 638.51 restricts devices that capture routing and addressing information — historically, dialed phone numbers. Beginning around 2023, plaintiffs began arguing that website trackers which capture IP addresses and device data function as unauthorized 'pen registers.' Courts have split on the theory, and the question remains unsettled. This description is informational, not legal advice.

Related Intelligence

Further Reading

Sources

Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website