All Blog Posts

California Invasion of Privacy Act: CIPA Requirements

Close
Read time
11 mins
Published
Jul 14, 2026
Share

  • What it is: CIPA is a 1967 California anti-wiretapping law now being applied to website cookies, chatbots, and session replay tools.
  • Who's exposed: Any business interacting with California residents online, particularly those using tracking or recording technologies without clear consent.
  • The legal risk: Unlike the CCPA, CIPA lets individuals sue directly, with statutory damages up to $5,000 per violation, and each site visit can arguably count separately.
  • Where it splits from CCPA: CCPA generally allows data collection with an opt-out; CIPA can require consent before collection starts at all.
  • Reform in progress: SB 690 would exempt CCPA-regulated tracking from CIPA, but no relief until at least 2027.
  • What actually helps: Clear visitor notice, documented consent choices, and a consent management platform are the most direct ways to reduce exposure today.

If your website runs cookies, a chat widget, or session replay software, there's a decent chance it has quietly become a legal target. The California Invasion of Privacy Act (CIPA) began life in 1967 as a rule about tapping phone lines.

However, since 2022, plaintiffs' law firms have used it to file thousands of lawsuits and demand letters against ordinary websites, arguing that everyday tracking tools amount to unlawful wiretapping.

For businesses running a standard mix of analytics, chat, and marketing pixels, understanding what CIPA actually requires, where it diverges sharply from the CCPA, and why CCPA compliance won’t protect you from a CIPA demand letter, is now a practical necessity, not a legal curiosity.

What Is CIPA, and Why Does It Now Cover Websites?

The California Invasion of Privacy Act (CIPA) dates back to 1967, when the concern was phone taps and hidden recording devices, not cookies or chat widgets. The law protects the confidentiality of communications between California residents, requiring the consent of everyone involved before a conversation can be recorded or intercepted.

Nothing in that 1967 text mentions websites. But plaintiffs' attorneys have spent the past several years arguing that its language — “communication,” “interception,” “recording” — is broad enough to cover tools nearly every website runs today: analytics scripts, chat widgets, session replay software, and marketing pixels. 

Courts have split on whether that argument holds up, but the sheer volume of lawsuits filed under this theory means the practical risk is real regardless of how the underlying legal question eventually gets resolved.

What CIPA Actually Prohibits

CIPA was built around five goals: 

  1. Deterring unauthorized surveillance
  2. Setting clear consent requirements
  3. Creating accountability for violators
  4. Protecting privacy rights
  5. Adapting as technology changes

In practice, that translates into several specific statutory sections that keep coming up in website litigation:

Compliance

Section 631 (the “anti-wiretapping” rule): prohibits intercepting or recording any wired or electronic communication, video calls included, without consent from everyone involved.

Section 632: prohibits recording confidential conversations — ones where participants reasonably expect privacy — again without all-party consent.

Sections 632.5 and 632.6: extended the same rule to cellular (1985) and cordless (1992) phone calls.

Section 632.01: added in 2017, criminalizes recording and disclosing confidential healthcare communications without consent.

Section 637.2: gives individuals a private right to sue for damages, up to $5,000 or three times actual damages, whichever is greater.

Section 638.51: bars installing or using a “pen register” or “trap and trace” device without consent or a court order. This is the section plaintiffs now argue covers cookies and other website trackers.

Key CIPA Terms Website Owners Should Know

A handful of definitions in the statute do most of the work in modern CIPA claims, and they're worth understanding:

  • Confidential communication: one made in circumstances where the parties reasonably expect it to stay private, not something said somewhere it could obviously be overheard or recorded.
  • Electronic communication: any transfer of signs, signals, images, sounds, or data by wire, radio, or similar means, with a few carve-outs (wire communications, tone-only paging, tracking devices, and certain financial transfer data).
  • Pen register: a device or process that records dialing, routing, or addressing information, but not the content of a communication.
  • Trap and trace device: captures incoming signals that identify the source of a communication, again without capturing content. Plaintiffs argue website trackers fit this definition.
  • Tracking device: an electronic or mechanical device that permits tracking the movement of a person or object.

Does CIPA Apply to Your Website?

CIPA's reach is broad by design. It applies to individuals, employers, businesses, technology providers, and government entities, essentially anyone who intercepts, records, or monitors communications, or who builds and operates the equipment used to do so.

For a website owner, that means CIPA exposure isn't limited to obvious cases like recording customer support calls. If your site uses a chat widget, session replay tool, or third-party analytics script that captures visitor interactions, you're operating in the same territory that plaintiffs' firms have been targeting since 2022.

The California Consumer Privacy Act (CCPA) and CIPA sit awkwardly next to each other, and the gap between them is exactly what's fueling the current wave of litigation.

Under the CCPA, collecting and processing personal information on a website is generally lawful without prior consent. Businesses just have to provide accessible notice about data handling and consumer rights, and offer an opt-out from the sale, sharing, or targeted-advertising use of that data. 

But CIPA works differently. It can require consent before collection or recording happens at all, particularly where a communication is deemed confidential. This is more in line with regulations like the EU’s General Data Protection Regulation (GDPR), which require prior consent for data collection and processing.

That gap matters most with tools like chat widgets. If a chat conversation is recorded, disclosure is required. Whether a business also needs affirmative consent and not just disclosure  before processing that recorded data is one of the open questions currently being litigated and debated in the California legislature. The outcome will affect anyone running a chatbot or live chat function on their site.

SB 690: Where CIPA Reform Stands in 2026

SB 690 is the bill everyone in this space has been watching, and it's worth being precise about where it actually stands, since coverage of the bill has been inconsistent.

Senator Anna Caballero introduced SB 690 in February 2025 to add a “commercial business purpose” exemption to CIPA. The idea being that tracking already regulated under the CCPA shouldn't also expose a business to CIPA liability. 

The bill passed the Senate unanimously (35–0) in June 2025, after an earlier provision that would have applied retroactively to pending lawsuits was stripped out in response to opposition from groups including the Electronic Frontier Foundation and the ACLU California Action.

From there, the bill stalled. It was referred to the Assembly's Public Safety and Privacy and Consumer Protection Committees after Senate passage, then converted to a two-year bill when the 2025 session closed without a hearing. It sat for roughly thirteen months before the Assembly Public Safety Committee finally took it up, passing it 9–0 on July 1, 2026, and re-referring it to the Privacy and Consumer Protection Committee for further consideration.

The legislature has now gone into summer recess, with the bill expected to be heard next by the Appropriations Committee in August 2026. California's deadline to pass bills this session is August 31, 2026, so even if SB 690 clears every remaining hurdle, it would not take effect before January 1, 2027.

Assuming SB 690 is signed into law — assuming it gets that far — the current litigation landscape holds, and there's no statutory safe harbor for businesses in the meantime.

Exceptions to CIPA

CIPA does carve out several categories of activity, though none of them are likely to apply to a typical commercial website:

  • Public utilities, including phone companies providing certain communications services
  • Communications systems used exclusively within a correctional facility
  • Conversations that aren't confidential, including those in public settings
  • Interactions where all parties have consented to recording
  • Law enforcement acting under a warrant or judicial approval
  • Emergency services recording to gather evidence of a crime
  • Hearing aids and similar assistive devices

What Rights Do Consumers Have Under CIPA?

CIPA gives California consumers four categories of rights that go further than what's available under most other state privacy laws.

Right to Notification

Businesses that record customer interactions, such as a support call, must clearly notify the individual before any substantive conversation happens, and give them a real opportunity to opt out or end the interaction.

CIPA operates on an “all-party consent” standard. Everyone involved in a private conversation has to agree before it's recorded or monitored. Consent can be express (a verbal or written agreement) or implied (continuing the interaction after being notified), but notification has to happen every time, even for returning customers.

Right to Privacy in Conversations

This right extends to private homes, workplaces, phone calls, text messages, direct messages, and any other setting where someone would reasonably expect privacy.

Unlike most privacy statutes, CIPA gives individuals the ability to sue directly, not just regulators. They can seek injunctive relief, statutory damages, or report a violation for possible criminal prosecution.

How to Reduce Your CIPA Compliance Risk

None of this is niche advice if your business already focuses on GDPR compliance, or even CCPA/CPRA compliance. CIPA best practices overlap heavily with what you're likely doing already. A few areas are worth double-checking specifically.

Work out which of your operations plausibly require consent under CIPA, and don't stop at chat widgets. Cookies, tracking pixels, session replay tools, and any script that captures a visitor's IP address, browsing behaviour, or interactions with the page fall squarely within the scope of what plaintiffs' attorneys have been arguing constitutes an unlawful pen register or trap and trace device. 

Until SB 690's commercial business purpose exemption is actually signed into law, that argument remains live, and courts have reached inconsistent conclusions on it.

Chat widgets are a common blind spot, but hardly the only one. If your site uses a chatbot or live chat function, provide a clear notice when it starts up, explain what might be recorded, and give visitors a genuine way to opt out. 

The same discipline should apply to cookies and trackers. A consent banner that merely informs rather than obtains a real, affirmative choice does little to help you here, since CIPA claims tend to hinge on whether consent was meaningfully given before the tool started collecting data, not simply disclosed after the fact. Session replay tools warrant particular care, given how directly they've featured in recent litigation.

Keep Your Privacy Policy Current

Your privacy policy should already spell out what personal data is collected, how it's used, and who has access to it. Update it any times there’s a notable change, such as in vendors, technologies in use on your website, business operations, or regulatory obligations. An automated consent management platform, such as Cookiebot™, helps keep disclosures aligned with what's actually running on your site by running regular scans.

Train Staff on What's Being Recorded

Anyone handling customer support or chat interactions should know what's monitored, why, and how to honor an opt-out request. Repeat this training regularly, especially when you add new tools.

A CMP does two things that matter for CIPA: it surfaces clear notice to visitors before tracking starts, and it records and signals their consent choices to the rest of your stack. Cookiebot handles this for websites specifically, which is the area where most CIPA claims currently originate.

Limit Access to Recordings and Logs

Restrict who on your team can access call recordings or chat logs to those who genuinely need it, support escalation or quality training, for example. Fewer people with access means less risk of unauthorized use.

Review Your Practices Regularly

Audit your tracking and recording setup periodically, particularly after adding new vendors or marketing tools. Only collect what you need, and follow clear retention limits so you're not holding data longer than necessary or using it beyond what visitors were told.

Who Enforces CIPA?

CIPA's enforcement is unusually broad. Both criminal and civil actions generally need to be brought within one year of discovering a violation, and several different bodies can pursue a claim:

  • California Attorney General
  • State agencies with relevant industry jurisdiction
  • County district attorneys
  • Other authorized agencies
  • Individual plaintiffs, through their own attorneys (the private right of action that has driven the bulk of recent litigation)

CIPA's Criminal Penalties

Prosecutors can bring CIPA violations as either misdemeanors or felonies. A misdemeanor conviction can carry fines up to USD 2,500 per violation and up to a year in jail. A felony conviction can extend prison sentences to three years, with fines up to USD 10,000 per violation.

CIPA's Civil Penalties

Civil exposure is where most website-related claims land, and it's significant:

  • Statutory damages up to USD 5,000 per violation
  • Three times actual damages, whichever is greater
  • Punitive damages for especially serious conduct
  • Injunctive relief to stop ongoing violations
  • Attorneys' fees and costs

Because damages can apply per violation, exposure adds up quickly on a website with meaningful traffic. A “violation” can arguably mean each individual site visit. That's a sharp contrast with the CCPA, which generally only creates a private right to sue in the event of a data breach. It's a large part of why plaintiffs' firms have gravitated toward CIPA for tracking-technology claims rather than the CCPA.

Why CIPA Litigation Isn't Slowing Down

CIPA is approaching 60 years old, and it shows no sign of fading into irrelevance. According to Fisher Phillips' Digital Wiretapping Litigation Map, as of June 25, 2026, over 5,100 digital wiretapping lawsuits had been filed across the U.S. since the 2022 court ruling that opened this litigation category, with California accounting for the large majority of filings.

Those figures don't include the demand letters and arbitration claims that never become public lawsuits, or the settlements businesses reach to avoid the cost and uncertainty of fighting a claim in court. 

Reputational risk compounds the financial exposure: plaintiffs' firms routinely frame these cases publicly as consumer privacy violations, which can invite copycat claims and erode customer trust regardless of how the underlying legal theory eventually holds up.

With SB 690 still working through the legislature and no statutory safe harbor in place, the practical calculus for most website owners hasn't changed: clear notice and documented consent remain the most reliable way to reduce exposure while the legal landscape sorts itself out.

Get Ahead of CIPA Risk

Whether or not SB 690 eventually narrows CIPA's reach, the underlying expectation of telling visitors what data you're collecting and for what purposes, and giving them a genuine choice, isn't going away. However, Cookiebot CMP supports both of those requirements, as well enabling auto-blocking of cookies and other data-collecting technologies on your website until consent is obtained.

Usercentrics does not provide legal advice. The content of this article is for educational purposes only. Businesses that have received a demand letter should engage qualified legal counsel promptly.

Frequently asked questions

Yes, potentially. CIPA exposure depends on where your website visitors are located, not where your business is headquartered. If your site interacts with California residents and runs cookies, a chat widget, or session replay tools, that's enough to fall within the theory plaintiffs' firms have been pursuing since 2022.

The CCPA generally treats data collection as lawful once businesses provide notice and an opt-out. CIPA can work the other way around, requiring consent before collection or recording starts, particularly for anything considered a confidential communication. Being aligned with CCPA does not automatically address CIPA exposure.

Not entirely, and not soon. Even if SB 690 is eventually signed into law, it would only exempt tracking already regulated under the CCPA for a "commercial business purpose," and it wouldn't take effect before January 1, 2027. Until then, the current litigation landscape holds.

Unlike most privacy statutes, where enforcement sits with regulators, CIPA gives individuals a private right to sue directly, alongside the California Attorney General, state agencies, and county district attorneys. That private right of action is a major reason CIPA litigation has grown as quickly as it has.

Civil penalties include statutory damages of up to USD 5,000 per violation, or three times actual damages if greater, along with potential punitive damages and attorneys' fees. Because damages can apply per violation, and each site visit can arguably count separately, exposure adds up quickly on a website with meaningful traffic.

No, not anymore. CIPA was written in 1967 with phone taps in mind, but plaintiffs' attorneys have argued since 2022 that its language is broad enough to cover website tools such as analytics scripts, chat widgets, and session replay software, framing them as unlawful interception or as "pen registers" and "trap and trace" devices.

Engage qualified legal counsel promptly rather than responding directly. This article is for educational purposes only, and Usercentrics does not provide legal advice — a demand letter is a legal matter that warrants proper representation, not a DIY response.