CRANDALL CONSULTING
HomeWebsite Tracking Laws › Massachusetts Wiretap Act

Massachusetts Wiretap Act & Website Tracking Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

Mass. Gen. Laws ch. 272, § 99
Citation
All-party
Consent Standard
Yes
Private Right of Action
Actual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees
Statutory Damages
Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

What This Statute Says (Plain Language)

Massachusetts' interception statute generally prohibits the secret interception of wire and oral communications without consent, and provides civil remedies. The statute's language and history focus on 'secret' recording, and Massachusetts' highest court has examined how the statute maps onto modern website tracking.

Why It Appears in Website Tracking Litigation

In widely reported 2024 appellate authority, Massachusetts' highest court addressed whether website activity tracking constitutes 'interception' of person-to-person communication under the statute, reaching a conclusion generally viewed as narrowing the statute's application to routine website browsing — while leaving other theories (including federal claims) available. The decision materially changed the filing calculus for Massachusetts-focused claims.

Practical Implications for Website Operators

Massachusetts is the clearest example of a state where a single appellate decision materially changed the filing calculus. In widely reported 2024 authority, the state's highest court concluded that tracking a visitor's website browsing activity is not the interception of a person-to-person 'communication' the wiretap act was aimed at — a holding generally viewed as foreclosing the statute's application to routine browsing analytics. Filings resting purely on browsing-activity theories under this statute dropped accordingly.

The decision did not end website privacy litigation against Massachusetts-facing operators; it redirected it. The court's reasoning turned on browsing activity not being person-to-person communication — which leaves genuinely conversational features, such as live chat and messaging, on different footing. Plaintiffs have also shifted the same underlying facts into other vehicles: federal Wiretap Act claims and Massachusetts consumer protection theories tied to the accuracy of privacy disclosures.

Litigation Risk in Plain Language

For pure browsing-analytics tracking, statute-specific risk in Massachusetts is now materially lower than in the active all-party consent states. The residual exposure concentrates in two places: first, conversational content — chat transcripts, typing previews, and message routing through third-party vendors — which the 2024 decision did not bless; second, non-wiretap theories, where the same technical facts (undisclosed third-party transmission) are pleaded as unfair or deceptive practices.

The practical implication is that Massachusetts operators should not read the 2024 decision as a reason to skip technical review. The same detections that once supported state wiretap claims now feed alternative theories, and the state attorney general has been active on tracking-disclosure accuracy. The review surface is unchanged even though the lead statute has receded.

What Operators Commonly Review

These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:

How This Statute Compares

Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:

StatuteConsent StandardPrivate Right of ActionStatutory Damages
California Invasion of Privacy Act (CIPA)All-partyYes$5,000 per violation or three times actual damages (Cal. Penal Code § 637.2)
Federal Wiretap Act (ECPA Title I)One-partyYesThe greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520)
Florida Security of Communications Act (FSCA)All-partyYesThe greater of actual damages, $100 per day of violation, or $1,000 (Fla. Stat. § 934.10)
Illinois Eavesdropping ActAll-partyYesActual and punitive damages; injunctive relief (720 ILCS 5/14-6)
Maryland Wiretapping and Electronic Surveillance ActAll-partyYesThe greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (§ 10-410)
Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA)All-partyYesThe greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725)
Washington Privacy ActAll-partyYesActual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060)

Jurisdiction Context

See the full Massachusetts website tracking litigation page for the current risk guideline (Elevated), tracked matter counts, and trend data.

Tracked Cases Invoking This Statute

No tracked cases currently link to this statute in our source set. This reflects our tracked sources, not an absence of litigation.

Common Questions

Did the 2024 decision end website wiretap lawsuits in Massachusetts?

It substantially narrowed the state wiretap act's application to routine website browsing tracking, and filings on that theory dropped. It did not resolve claims involving genuinely conversational content like chat, and it has no effect on federal Wiretap Act or consumer-protection theories, which plaintiffs continue to assert on similar facts.

Does the Massachusetts Wiretap Act still matter for chat widgets?

The 2024 decision addressed browsing-activity tracking, reasoning it was not person-to-person communication. Chat is person-to-person by design, so claims involving transcript or typing-preview capture present a distinct question the decision did not foreclose. How that plays out is unsettled; operators with chat features should review vendor configuration and consult counsel.

What should Massachusetts-facing operators review now?

The same technical surface as before: what third-party tools transmit, when transmission begins relative to consent, and whether the privacy policy describes it accurately. The 2024 decision shifted which statutes appear in complaints — it did not change the underlying data flows that draw claims.

Related Intelligence

Further Reading

Sources

Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website