California Invasion of Privacy Act (CIPA) & Website Tracking Litigation
What This Statute Says (Plain Language)
CIPA is California's electronic interception statute. Section 631 addresses wiretapping and reading or attempting to read the contents of a communication in transit without the consent of all parties; § 632.7 has been raised regarding communications involving cellular devices; and § 638.51 restricts the use of 'pen registers' and 'trap and trace' devices that capture routing and addressing information. CIPA provides a private right of action with statutory damages of $5,000 per violation, which materially shapes the economics of class litigation.
Why It Appears in Website Tracking Litigation
CIPA is the most heavily litigated statute in website tracking cases. Plaintiffs have advanced § 631 'aiding and abetting' theories against website operators whose third-party scripts allegedly read communications in transit, and more recently § 638.51 'pen register' theories aimed at trackers that capture IP addresses and device information. Courts have split on many of these theories, including whether a third-party service provider is an eavesdropper or merely an 'extension' of the website operator. The volume of filings and demand letters citing CIPA remains high.
Practical Implications for Website Operators
CIPA is the single most frequently cited statute in the website tracking matters we track. A large share of activity never reaches a courtroom: plaintiff-side firms run automated scans that detect session replay scripts, chat widgets, and advertising pixels, then send pre-suit demand letters citing sections 631, 632.7, or 638.51. Because the theories focus on where the website visitor is located, businesses with no California offices, employees, or registrations receive these letters routinely — an online store in Ohio serving California visitors is squarely inside the pattern.
The economics explain the volume. Section 637.2 provides $5,000 in statutory damages per violation without requiring proof of actual harm, and plaintiffs' theories multiply violations across visitors and page views. Even where a legal theory is untested, the arithmetic of a potential class action creates settlement pressure that is largely independent of the merits.
The technology mix has shifted over time. Earlier waves focused on session replay and chat transcripts under section 631; the more recent wave asserts section 638.51 'pen register' theories against ordinary trackers that capture IP addresses and device information on page load — a lower factual bar than capturing message contents, which is precisely why plaintiffs adopted it. Courts have divided on whether those theories state a claim, and the split itself sustains filing activity.
Litigation Risk in Plain Language
Four structural features combine to make CIPA the center of gravity in this area: an all-party consent standard, a private right of action, per-violation statutory damages, and California's class action infrastructure. Public decisions are genuinely mixed — some courts have dismissed claims because routine browsing data was held not to be the 'contents' of a communication, or because the third-party service was treated as an extension of the website operator rather than an eavesdropper; others have allowed materially similar claims past the pleading stage. That unresolved landscape, not any single ruling, is what drives risk.
For operators, the practical exposure question is factual rather than legal: what do the third-party tools on the site actually transmit, and when does the transmission occur relative to any consent choice? Matters that survive early motions tend to involve transmission of typed input, chat content, or identifying information before the visitor has interacted with a consent tool. Detection of a tracker is an informational risk indicator that warrants configuration review — it is not a finding that any law was violated.
What Operators Commonly Review
These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:
- Test whether chat widgets transmit transcripts — or keystroke-level 'typing previews' — to the vendor before the visitor presses send.
- Verify session replay masking covers every input field, including custom form components where default masking rules often fail.
- Confirm the consent banner actually blocks tracker network requests for California visitors before opt-in, rather than merely hiding the banner UI.
- Inventory which tags capture IP address and device parameters on page load — the exact behavior section 638.51 pen-register theories target.
- Check whether advertising pixels have 'advanced matching' enabled, transmitting hashed emails or phone numbers captured from forms.
- Re-run the review after every tag manager change; CIPA demand letters are frequently triggered by newly added or misconfigured tags.
How This Statute Compares
Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:
| Statute | Consent Standard | Private Right of Action | Statutory Damages |
|---|---|---|---|
| Federal Wiretap Act (ECPA Title I) | One-party | Yes | The greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520) |
| Florida Security of Communications Act (FSCA) | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000 (Fla. Stat. § 934.10) |
| Illinois Eavesdropping Act | All-party | Yes | Actual and punitive damages; injunctive relief (720 ILCS 5/14-6) |
| Maryland Wiretapping and Electronic Surveillance Act | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (§ 10-410) |
| Massachusetts Wiretap Act | All-party | Yes | Actual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees |
| Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725) |
| Washington Privacy Act | All-party | Yes | Actual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060) |
Jurisdiction Context
See the full California website tracking litigation page for the current risk guideline (Very High), tracked matter counts, and trend data.
Tracked Cases Invoking This Statute
Torres v. SeatGeek, Inc.
A Northern District of California magistrate judge granted a Rule 12 motion to dismiss Torres v. SeatGeek for lack of Article III standing, holding that routine metadata collected via tracking pixels (IP, device/browser metadata, cookie IDs) did not constitute a concrete injury under the Popa framework. The court found aggregation across three recipients and receipt of targeted ads insufficient to transform the non-sensitive technical data into a cognizable privacy injury.
Caldwell v. InMobi Pte. Ltd.
The Northern District of California denied InMobi’s motion to dismiss a putative class action alleging CIPA pen register violations and California privacy torts, holding the pleading sufficiently alleges modern tracking technologies can satisfy CIPA’s definitions and that privacy claims survive at the pleading stage. The court left factual questions (e.g., consent, app identity, linkage to real-world identity) for later stages of the case.
Javier v. Assurance IQ
This guide explains the distinction between CIPA (California Penal Code Section 631) and the CCPA/CPRA opt-out regime, discusses an unpublished Ninth Circuit decision (Javier v. Assurance IQ) that suggested Section 631 applies to internet communications and may require consent before recording, and summarizes pending California legislation (SB 690) that would limit private pen-register claims but not Section 631 claims. It advises operational steps for CMPs to block high-risk third-party capture and to properly honor Global Privacy Control and Do Not Sell/Share controls.
Javier v. Assurance IQ, LLC and Active Prospect Inc.
The ArentFox Schiff blog reports on an unpublished Ninth Circuit panel decision in Javier v. Assurance IQ, holding that California Penal Code Section 631 requires prior express consent before recording web interactions, and that retroactive consent is insufficient. The decision reversed the district court's conclusion on retroactive consent, but left other district-court rulings (such as whether a website operator is a party to communications) unaddressed. The post recommends website operators obtain opt-in consent before recording.
Fregosa v. Mashable Inc.
A federal district court in the Northern District of California denied Mashable’s motion to dismiss a Second Amended Complaint alleging that third-party web trackers installed on Mashable’s site recorded IP addresses and device identifiers in violation of CIPA’s pen-register provisions. The court concluded the statute’s text and precedent permit treating software processes that record addressing information as pen registers at the pleading stage, and the case remains pending.
Crano v. Sojern, Inc.
A California federal judge dismissed the Second Amended Complaint in Crano v. Sojern, Inc. for lack of Article III standing, finding the plaintiff failed to allege a concrete injury. The court rejected theories based on intangible privacy harms from collection of technical identifiers and an unjust-enrichment economic harm theory, relying on Ninth Circuit precedent and distinguishing In re Facebook.
E.H. et al v. Lifelong Adoptions, Inc.
The federal district court granted LifeLong’s motion to dismiss in part and denied it in part on July 24, 2026. Several claims were dismissed (some with leave to amend, others without), while multiple privacy-related claims under California common law, the California Constitution, CIPA, and the federal ECPA survived the pleading challenge and will proceed subject to further amendment or litigation.
Blaker v. Netscout Systems
A Loeb & Loeb analysis describes a Los Angeles Superior Court decision in Blaker v. NetScout where the court dismissed a CIPA class action with prejudice, holding that the pen-register/trap-and-trace statutory provision does not reach ordinary website SDKs and tracking. The article contrasts that outcome with earlier cases where defendants engaged in highly technical defenses and lost ground.
Vivek Shah
The provided page text is largely site navigation and practice-area links. The page title states that a California federal court declared serial CIPA plaintiff Vivek Shah a vexatious litigant, but the article body and case details are not present in the supplied text.
Popa v. Microsoft Corp.
This Holland & Knight alert describes conflicting rulings in California over whether web-based tracking technologies (e.g., pixels and IP-address collection) fall within CIPA Section 638.51. It highlights the Ninth Circuit's Popa v. Microsoft decision tightening Article III standing requirements and notes divergent district-court outcomes applying Popa to CIPA claims.
Common Questions
Why do so many website tracking demand letters cite CIPA?
CIPA combines an all-party consent standard, a private right of action, and $5,000-per-violation statutory damages with California's active privacy plaintiff bar. Demand letters are inexpensive to generate — many are based on automated scans of a website's third-party scripts — so detection of a common tracker is often all it takes to receive one. Receiving a letter is not a finding of liability; it is a signal to review what your site transmits and to consult qualified counsel.
Our business is not in California. Can CIPA still be asserted against us?
Plaintiffs' theories generally focus on the location of the website visitor, not the business. A website operated from any state that serves California visitors can — and in tracked matters regularly does — face CIPA demands. Whether the statute actually applies to a given operator is a fact- and law-specific question for qualified counsel.
What is a CIPA 'pen register' claim?
Section 638.51 restricts devices that capture routing and addressing information — historically, dialed phone numbers. Beginning around 2023, plaintiffs began arguing that website trackers which capture IP addresses and device data function as unauthorized 'pen registers.' Courts have split on the theory, and the question remains unsettled. This description is informational, not legal advice.
Related Intelligence
Further Reading
- Your website may be sharing more than you think — our plain-language overview of hidden tracking, wiretap exposure, and Global Privacy Control.
- Website wiretap lawsuits by state — risk guidelines and tracked matter counts for all 50 states.
Sources
Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website