Florida Security of Communications Act (FSCA) & Website Tracking Litigation
What This Statute Says (Plain Language)
The FSCA is Florida's all-party consent statute governing the interception of wire, oral, and electronic communications. Modeled in part on the federal Wiretap Act, it generally requires the consent of all parties to a communication and provides civil remedies including statutory damages. Florida courts have addressed what qualifies as an 'electronic communication' and whether particular website interactions fall within the statute.
Why It Appears in Website Tracking Litigation
FSCA claims have been asserted against website operators using session replay and similar technologies. A number of Florida decisions have examined whether routine website browsing data constitutes the 'contents' of a communication under the statute, with several courts dismissing claims on that basis — while other theories continue to be tested. Filing activity is meaningful but has produced more defense-favorable outcomes than in some other all-party consent states.
Practical Implications for Website Operators
Florida experienced one of the earliest large waves of website session-replay lawsuits under the FSCA, aimed heavily at retail and e-commerce operators. The distinctive feature of the Florida docket is how those early cases resolved: a substantial number were dismissed on the ground that routine browsing data — mouse movements, clicks, page views — did not constitute the 'contents' of a communication under the statute. That body of decisions made Florida comparatively defense-favorable for pure browsing-analytics claims.
Filing and demand activity did not stop; it adapted. Later theories concentrate on interactions where captured data more plausibly carries substance: chat transcripts, text typed into forms and transmitted before submission, and search queries embedded in page URLs. Operators whose implementations capture typed input occupy a different risk posture than those whose tools record only navigation.
Litigation Risk in Plain Language
The FSCA is an all-party consent statute with statutory damages (the greater of actual damages, $100 per day, or $1,000) and a private right of action, so the structural ingredients for volume litigation exist. What has moderated outcomes is the contents requirement — courts asking whether what the tracker captured actually conveyed the substance of a communication. Early dismissals were frequently without prejudice, and amended complaints with sharper factual allegations about captured content followed.
The practical dividing line for operators is what the deployed tools capture. Navigation-only analytics has fared better in Florida's public decisions; keystroke capture, chat transcript routing, and pre-submission form transmission are the behaviors that keep matters alive. A dismissal-heavy docket is not immunity — it is a map of which implementations drew claims that failed and which allegations courts allowed forward.
What Operators Commonly Review
These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:
- Test empirically whether any tool captures typed input before form submission — synthetic marker values typed into forms reveal this immediately.
- Check whether site-search terms or form-prefill values leak to third parties through page URLs and query strings.
- Review chat vendor configuration for transcript routing and typing-preview features that transmit unsent text.
- Confirm session replay masking on checkout, account, and any payment-adjacent pages, where captured input is least defensible as routine navigation.
- Verify consent tooling gates recording tools for Florida visitors before a consent choice.
How This Statute Compares
Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:
| Statute | Consent Standard | Private Right of Action | Statutory Damages |
|---|---|---|---|
| California Invasion of Privacy Act (CIPA) | All-party | Yes | $5,000 per violation or three times actual damages (Cal. Penal Code § 637.2) |
| Federal Wiretap Act (ECPA Title I) | One-party | Yes | The greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520) |
| Illinois Eavesdropping Act | All-party | Yes | Actual and punitive damages; injunctive relief (720 ILCS 5/14-6) |
| Maryland Wiretapping and Electronic Surveillance Act | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (§ 10-410) |
| Massachusetts Wiretap Act | All-party | Yes | Actual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees |
| Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725) |
| Washington Privacy Act | All-party | Yes | Actual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060) |
Jurisdiction Context
See the full Florida website tracking litigation page for the current risk guideline (Elevated), tracked matter counts, and trend data.
Tracked Cases Invoking This Statute
W.W. v. Orlando Health
A Wiley Rein alert describes a surge in litigation alleging that common website technologies (cookies, analytics, pixels, chat, etc.) give rise to claims under pre‑internet state wiretap statutes such as California's CIPA and Florida's FSCA. The alert cites specific court actions: a March 6, 2025 M.D. Fla. order denying in part a motion to dismiss under the FSCA and a Jan. 7, 2026 N.D. Cal. order transferring a case to E.D. Va. based on a forum‑selection clause.
C.B. v. Planned Parenthood Federation of America, Inc.
A proposed class action filed June 19, 2026 in SDNY alleges Planned Parenthood and regional affiliates transmitted appointment-booking selections and related details to third parties (notably Google) via embedded trackers and that tracking continued into a MyChart patient portal. The complaint asserts multiple state and federal statutory claims and seeks a nationwide class and several subclasses; defendants had not responded at time of reporting.
W.W. v. Orlando Health, Inc., No. 6-24-cv-1068-JSS-RMU
A Robinson+Cole blog post reports a 2025 Middle District of Florida decision (W.W. v. Orlando Health) that found allegations that website tracking tools captured substantive healthcare communications sufficiently alleged interception under the Florida Security of Communications Act. The article says that decision has spurred hundreds of similar FSCA claims in small claims court and may signal more surviving pleadings in Florida federal courts.
Cobbs v. PetMed Express, Inc.
This law‑firm analysis describes a surge of Florida FSCA and Wiretap Act litigation alleging website tracking technologies intercepted URLs, form inputs, and PII. It notes a shift from earlier dismissals to recent filings and some claims surviving motions to dismiss, highlights unresolved statutory‑interpretation questions, and recommends business mitigations (audits, consent mechanisms, data minimization).
Magenheim et al. v. Nike, Inc.
A March/April 2026 industry article reports that Salpeter Gitkin filed a proposed class action on December 16, 2025 in the Southern District of Florida (Magenheim et al. v. Nike) alleging that third-party scripts on nike.com installed code and transmitted user data without consent under the Florida Security of Communications Act and related tort theories. The filing is presented as part of a broader pattern of FSCA 'digital wiretapping' lawsuits targeting sites that use tag managers and third-party advertising/analytics tools.
Common Questions
Haven't Florida courts dismissed most website wiretap cases?
Many early session-replay cases were dismissed on the ground that routine browsing data was not the 'contents' of a communication — but not all, and dismissals were often without prejudice. Later filings allege capture of chat text, form input, or search queries, which present different facts. A defense-favorable pattern in past decisions is not immunity for any particular implementation.
What is the difference between 'contents' and metadata under the FSCA?
'Contents' generally refers to the substance or meaning of a communication — what was said or typed — while records like page views, timestamps, and mouse movements are closer to metadata. Florida courts have often treated navigation data as non-contents, while typed text is more plausibly contents. The edges of that line remain contested and fact-specific; this is an informational summary, not legal advice.
What damages does the FSCA provide?
The statute provides civil remedies of the greater of actual damages, $100 per day of violation, or $1,000, with punitive damages and fees available under the statute's terms. As elsewhere, class-action multiplication across a website's visitor base — not the per-person figure — is what creates meaningful exposure.
Related Intelligence
Further Reading
- Your website may be sharing more than you think — our plain-language overview of hidden tracking, wiretap exposure, and Global Privacy Control.
- Website wiretap lawsuits by state — risk guidelines and tracked matter counts for all 50 states.
Sources
Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website