CRANDALL CONSULTING
HomeWebsite Tracking Laws › Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA)

Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) & Website Tracking Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 23, 2026

18 Pa. C.S. § 5701 et seq.
Citation
All-party
Consent Standard
Yes
Private Right of Action
The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725)
Statutory Damages
Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

What This Statute Says (Plain Language)

WESCA is Pennsylvania's all-party consent interception statute. It generally prohibits the intentional interception, disclosure, or use of wire, electronic, or oral communications without the prior consent of all parties, and it provides a civil action for persons whose communications are unlawfully intercepted. Pennsylvania courts have examined where an interception 'occurs' for jurisdictional purposes and what counts as a device used for interception.

Why It Appears in Website Tracking Litigation

WESCA gained prominence in website tracking litigation after federal appellate authority interpreted the statute's reach in the context of online tracking, including the view that the point of interception can be the visitor's browser in Pennsylvania. Plaintiffs have applied WESCA theories to session replay, advertising pixels, and chat features. As with other states, decisions turn heavily on consent, the nature of the captured data, and procedural posture — public decisions are mixed.

Practical Implications for Website Operators

Pennsylvania's profile in website tracking litigation changed when federal appellate authority interpreting WESCA concluded that the point of interception can be the visitor's browser in Pennsylvania. The practical effect: an operator with no Pennsylvania presence can face WESCA claims from Pennsylvania visitors, because the alleged interception is located where the visitor sits. That holding broadened the plaintiff map and made Pennsylvania a recurring venue in multi-state filings.

A significant share of tracked Pennsylvania matters involves healthcare-adjacent websites — hospital systems, insurers, and provider portals — where the recurring allegation is that advertising pixels transmitted condition- or service-specific page URLs to third parties. On sites like these, the URL itself is alleged to reveal something sensitive about the visitor, which changes the character of an otherwise routine analytics transmission.

WESCA provides the greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and attorney's fees, and it is enforced through private civil actions. As in California, class multiplication across a website's visitor base is what turns modest per-person figures into meaningful exposure.

Litigation Risk in Plain Language

WESCA pairs an all-party consent standard with the browser-side interception view, which is a plaintiff-favorable combination on paper. The counterweight in public decisions has been consent: courts have dismissed WESCA claims where the operator's privacy notice expressly disclosed the third-party tracking at issue, reasoning that visitors were on notice. The quality, specificity, and placement of privacy disclosures has therefore mattered more in tracked Pennsylvania outcomes than in most states.

The open questions — what counts as an intercepting 'device,' when a policy disclosure amounts to consent, and how posture-specific early rulings translate to the merits — keep outcomes mixed and fact-driven. For operators, the highest-leverage variables are what is transmitted (especially page URLs on sensitive pages) and what the privacy notice actually says about it.

What Operators Commonly Review

These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:

How This Statute Compares

Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:

StatuteConsent StandardPrivate Right of ActionStatutory Damages
California Invasion of Privacy Act (CIPA)All-partyYes$5,000 per violation or three times actual damages (Cal. Penal Code § 637.2)
Federal Wiretap Act (ECPA Title I)One-partyYesThe greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520)
Florida Security of Communications Act (FSCA)All-partyYesThe greater of actual damages, $100 per day of violation, or $1,000 (Fla. Stat. § 934.10)
Illinois Eavesdropping ActAll-partyYesActual and punitive damages; injunctive relief (720 ILCS 5/14-6)
Maryland Wiretapping and Electronic Surveillance ActAll-partyYesThe greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (§ 10-410)
Massachusetts Wiretap ActAll-partyYesActual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees
Washington Privacy ActAll-partyYesActual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060)

Jurisdiction Context

See the full Pennsylvania website tracking litigation page for the current risk guideline (Moderate), tracked matter counts, and trend data.

Tracked Cases Invoking This Statute

Adair, et al. v. Cigna Corporate Services, LLC and the Cigna Group

Court not identified · Lawsuit

A Klein Moynihan Turco blog post summarizes a Pennsylvania federal judge's dismissal of plaintiffs' ECPA, WESCA, and invasion of privacy claims against Cigna on the ground that plaintiffs consented to use of third-party tracking technologies by agreeing to Cigna's Terms of Use and incorporated Privacy Notice. The post highlights that the court found post-loading consent could be sufficient for dismissal and notes a trend of courts scrutinizing whether tracking software supports wiretapping claims.

Delong v. PHE, Inc.

U.S. District Court for the Eastern District of Pennsylvania · 2026-07-16 · Lawsuit

A federal district court in the Eastern District of Pennsylvania denied a motion to dismiss an amended complaint alleging that the Adam Eve website used Google Analytics to collect intimate user data, finding the plaintiff sufficiently alleged Article III standing, personal jurisdiction, and a plausible claim under Pennsylvania's WESCA. The case was allowed to proceed to discovery; the court did not resolve the merits or class issues.

Muraski v. Penn Highlands Healthcare, Inc.

United States District Court for the Western District of Pennsylvania · 2026-02-09 · Lawsuit

On February 9, 2026 the U.S. District Court for the Western District of Pennsylvania issued an opinion in Muraski v. Penn Highlands Healthcare granting the defendant's motion to dismiss without prejudice and stating an appropriate order will be entered. The source summary does not describe merits resolution or list specific claims in the opinion summary available on the page.

Delsignore v. Zazzle, Inc.

Court not identified · Lawsuit

A proposed class action filed Oct. 13, 2022 (Delsignore v. Zazzle, Inc.) alleges Zazzle used session-replay software on www.zazzle.com to record visitors' mouse movements, clicks, keystrokes, search terms and other inputs without disclosure or consent. The complaint asserts this conduct violated the Pennsylvania Wiretapping and Electronic Surveillance Control Act and seeks to represent Pennsylvania residents whose electronic communications were allegedly intercepted.

Birdsall v. PNC Bank NA; Erakat v. PNC Bank, National Association

Court of Common Pleas of Allegheny County, Pennsylvania (Birdsall v. PNC); U.S. District Court for the Eastern District of California (Erakat v. PNC) · 2026-03-23 · Lawsuit

LegalClarity reports that PNC faces two proposed class actions alleging pixel trackers and session-replay/form-capture technologies on its website transmitted browsing data to third-party advertising platforms. One suit was filed in Pennsylvania invoking WESCA and was removed to federal court then remanded back to state court; a second was filed in federal court in California citing state and federal privacy statutes. Both matters were described as pending with no settlements reported as of mid-2026.

Petris v. Sportsman’s Warehouse, Inc., et al.

Court of Common Pleas of Washington County, Pennsylvania · Lawsuit

This is a court-authorized class notice for a proposed settlement in Petris v. Sportsman’s Warehouse, alleging Defendants disclosed firearm-purchase information on their website to third parties in violation of Pennsylvania statutes (WESCA and the UFA). The Settlement Class is limited to Pennsylvania residents who ordered and reserved firearms online from January 1, 2020 through March 13, 2024; eligible class members who submit timely claims may receive up to $107. Key deadlines include a claims deadline of June 19, 2026, an exclusion/objection deadline of June 4, 2026, and a fairness hearing on July 31, 2026.

Adair v. Cigna Corporate Services, LLC

U.S. District Court for the Eastern District of Pennsylvania · Lawsuit

A federal district court in Adair v. Cigna granted in part a motion to dismiss, concluding that plaintiffs' ECPA, WESCA, and invasion-of-privacy claims were defeated by consent in Cigna's Privacy Notice and Terms of Use, while finding plaintiffs had pleaded Article III standing. The court dismissed unjust enrichment without prejudice and left other merits issues for later proceedings.

Popa v. Harriet Carter Gifts, Inc.

United States District Court for the Western District of Pennsylvania · Lawsuit

A Lynch Law Group article summarizes Popa v. Harriet Carter Gifts, Inc., in which a federal district court granted summary judgment for the retailer and its vendor after concluding the website's privacy disclosures and ordinary internet-user expectations defeated a WESCA-based interception claim. The article notes the case is on appeal to the Third Circuit and advises businesses to review privacy disclosures and vendor contracts.

Shawn Delong v. PHE, Inc.

United States District Court for the Eastern District of Pennsylvania · 2025-08-25 · Lawsuit

The Eastern District of Pennsylvania dismissed Delong v. PHE, Inc. (Aug. 25, 2025) without prejudice because the plaintiff failed to allege a concrete Article III injury from the defendant's use of Google Analytics on its Adam & Eve website. The court alternatively held it lacked specific personal jurisdiction over PHE for the web-browsing-based claim and did not reach the merits of the WESCA claim.

OLIVER v. NOOM, INC.

United States District Court for the Western District of Pennsylvania · 2026-07-10 · Lawsuit

The U.S. District Court for the Western District of Pennsylvania granted Noom's renewed motion to dismiss because the plaintiff failed to plausibly allege a concrete Article III injury from the asserted interception by session-replay code. The court dismissed the WESCA claim without prejudice and had previously dismissed the intrusion-upon-seclusion claim.

Common Questions

We have no Pennsylvania offices. Why would WESCA apply to our website?

Federal appellate authority interpreting WESCA located the point of interception at the visitor's browser, meaning a Pennsylvania resident browsing your site can allegedly be 'intercepted' in Pennsylvania regardless of where your business operates. Whether the statute applies in any particular case is a question for qualified counsel; the practical takeaway is that Pennsylvania visitors put a site within the theory's reach.

Does disclosing tracking in our privacy policy protect us under WESCA?

Public decisions have dismissed WESCA claims where privacy notices expressly disclosed the specific third-party tracking at issue, and have declined to do so where disclosures were vague or missing. That makes disclosure quality unusually consequential in Pennsylvania — but whether any particular notice suffices is fact-specific and a question for qualified counsel, not something this page can answer.

Which technologies appear most often in tracked WESCA matters?

Session replay tools, the Meta Pixel, Microsoft Clarity, and chat widgets recur most often in our tracked Pennsylvania matters, with healthcare-adjacent websites disproportionately represented. The common thread is transmission of page context or visitor interactions to a third party before or without an effective consent choice.

Related Intelligence

Further Reading

Sources

Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.

About This Page

Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.

How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.

Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.

Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website