---------------------------
Title: California Invasion of Privacy Act: CIPA Requirements
URL: https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/
---------------------------

# California Invasion of Privacy Act: CIPA Requirements

CIPA is a 1967 California wiretapping law that is now being used to sue website owners over cookies, chatbots, and session replay tools deployed without prior user consent. This guide covers what the law covers and what triggers liability, who must comply, consumer rights, penalties, and the SB 690 reform bill moving through the legislature, plus practical steps website owners can take to reduce exposure.

## At a Glance

-

- **What it is:** CIPA is a 1967 California anti-wiretapping law now being applied to website cookies, chatbots, and session replay tools.
- **Who's exposed:** Any business interacting with California residents online, particularly those using tracking or recording technologies without clear consent.
- **The legal risk:** Unlike the CCPA, CIPA lets individuals sue directly, with statutory damages up to $5,000 per violation, and each site visit can arguably count separately.
- **Where it splits from CCPA:** CCPA generally allows data collection with an opt-out; CIPA can require consent before collection starts at all.
- **Reform in progress:** SB 690 would exempt CCPA-regulated tracking from CIPA, but no relief until at least 2027.
- **What actually helps:** Clear visitor notice, documented consent choices, and a consent management platform are the most direct ways to reduce exposure today.

If your website runs cookies, a chat widget, or session replay software, there's a decent chance it has quietly become a legal target. The California Invasion of Privacy Act (CIPA) began life in 1967 as a rule about tapping phone lines.

However, since 2022, plaintiffs' law firms have used it to file thousands of lawsuits and demand letters against ordinary websites, arguing that everyday tracking tools amount to unlawful wiretapping.

For businesses running a standard mix of analytics, chat, and marketing pixels, understanding what CIPA actually requires, where it diverges sharply from the CCPA, and why CCPA compliance won’t protect you from a CIPA demand letter, is now a practical necessity, not a legal curiosity.

## **What Is CIPA, and Why Does It Now Cover Websites?**

The [California Invasion of Privacy Act (CIPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=PEN&part=1.&title=15.&chapter=1.5) dates back to 1967, when the concern was phone taps and hidden recording devices, not cookies or chat widgets. The law protects the confidentiality of communications between California residents, requiring the consent of everyone involved before a conversation can be recorded or intercepted.

Nothing in that 1967 text mentions websites. But plaintiffs' attorneys have spent the past several years arguing that its language — “communication,” “interception,” “recording” — is broad enough to cover tools nearly every website runs today: analytics scripts, chat widgets, session replay software, and marketing pixels.

Courts have split on whether that argument holds up, but the sheer volume of lawsuits filed under this theory means the practical risk is real regardless of how the underlying legal question eventually gets resolved.

## **What CIPA Actually Prohibits**

CIPA was built around five goals:

1. Deterring unauthorized surveillance
2. Setting clear consent requirements
3. Creating accountability for violators
4. Protecting privacy rights
5. Adapting as technology changes

In practice, that translates into several specific statutory sections that keep coming up in website litigation:

- Section 631 (the “anti-wiretapping” rule): prohibits intercepting or recording any wired or electronic communication, video calls included, without consent from everyone involved.
- Section 632: prohibits recording confidential conversations — ones where participants reasonably expect privacy — again without all-party consent.
- Sections 632.5 and 632.6: extended the same rule to cellular (1985) and cordless (1992) phone calls.
- Section 632.01: added in 2017, criminalizes recording and disclosing confidential healthcare communications without consent.
- Section 637.2: gives individuals a private right to sue for damages, up to $5,000 or three times actual damages, whichever is greater.
- Section 638.51: bars installing or using a “pen register” or “trap and trace” device without consent or a court order. This is the section plaintiffs now argue covers cookies and other website trackers.

## Key CIPA Terms Website Owners Should Know

A handful of definitions in the statute do most of the work in modern CIPA claims, and they're worth understanding:

- **Confidential communication:** one made in circumstances where the parties reasonably expect it to stay private, not something said somewhere it could obviously be overheard or recorded.
- **Electronic communication:** any transfer of signs, signals, images, sounds, or data by wire, radio, or similar means, with a few carve-outs (wire communications, tone-only paging, tracking devices, and certain financial transfer data).
- **Pen register:** a device or process that records dialing, routing, or addressing information, but not the content of a communication.
- **Trap and trace device:** captures incoming signals that identify the source of a communication, again without capturing content. Plaintiffs argue website trackers fit this definition.
- **Tracking device:** an electronic or mechanical device that permits tracking the movement of a person or object.

## Does CIPA Apply to Your Website?

CIPA's reach is broad by design. It applies to individuals, employers, businesses, technology providers, and government entities, essentially anyone who intercepts, records, or monitors communications, or who builds and operates the equipment used to do so.

For a website owner, that means CIPA exposure isn't limited to obvious cases like recording customer support calls. If your site uses a chat widget, session replay tool, or third-party analytics script that captures visitor interactions, you're operating in the same territory that plaintiffs' firms have been targeting since 2022.

## CIPA vs. CCPA: Two Different Consent Standards

The [California Consumer Privacy Act (CCPA)](/en/what-is-ccpa/) and CIPA sit awkwardly next to each other, and the gap between them is exactly what's fueling the current wave of litigation.

Under the CCPA, collecting and processing personal information on a website is generally lawful without prior consent. Businesses just have to provide accessible notice about data handling and consumer rights, and offer an opt-out from the sale, sharing, or targeted-advertising use of that data.

But CIPA works differently. It can require consent before collection or recording happens at all, particularly where a communication is deemed confidential. This is more in line with regulations like the EU’s [General Data Protection Regulation (GDPR)](/en/gdpr/), which require prior consent for data collection and processing.

That gap matters most with tools like chat widgets. If a chat conversation is recorded, disclosure is required. Whether a business also needs affirmative consent and not just disclosure before processing that recorded data is one of the open questions currently being litigated and debated in the California legislature. The outcome will affect anyone running a chatbot or live chat function on their site.

## SB 690: Where CIPA Reform Stands in 2026

[SB 690](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB690) is the bill everyone in this space has been watching, and it's worth being precise about where it actually stands, since coverage of the bill has been inconsistent.

Senator Anna Caballero introduced SB 690 in February 2025 to add a “commercial business purpose” exemption to CIPA. The idea being that tracking already regulated under the CCPA shouldn't also expose a business to CIPA liability.

The bill passed the Senate unanimously (35–0) in June 2025, after an earlier provision that would have applied retroactively to pending lawsuits was stripped out in response to opposition from groups including the Electronic Frontier Foundation and the ACLU California Action.

From there, the bill stalled. It was referred to the Assembly's Public Safety and Privacy and Consumer Protection Committees after Senate passage, then converted to a two-year bill when the 2025 session closed without a hearing. It sat for roughly thirteen months before the Assembly Public Safety Committee finally took it up, passing it 9–0 on July 1, 2026, and re-referring it to the Privacy and Consumer Protection Committee for further consideration.

The legislature has now gone into summer recess, with the bill expected to be heard next by the Appropriations Committee in August 2026. California's deadline to pass bills this session is August 31, 2026, so even if SB 690 clears every remaining hurdle, it would not take effect before January 1, 2027.

Assuming SB 690 is signed into law — assuming it gets that far — the current litigation landscape holds, and there's no statutory safe harbor for businesses in the meantime.

## Exceptions to CIPA

CIPA does carve out several categories of activity, though none of them are likely to apply to a typical commercial website:

- Public utilities, including phone companies providing certain communications services
- Communications systems used exclusively within a correctional facility
- Conversations that aren't confidential, including those in public settings
- Interactions where all parties have consented to recording
- Law enforcement acting under a warrant or judicial approval
- Emergency services recording to gather evidence of a crime
- Hearing aids and similar assistive devices

## What Rights Do Consumers Have Under CIPA?

CIPA gives California consumers four categories of rights that go further than what's available under most other state privacy laws.

### Right to Notification

Businesses that record customer interactions, such as a support call, must clearly notify the individual before any substantive conversation happens, and give them a real opportunity to opt out or end the interaction.

### Right to Consent

CIPA operates on an “all-party consent” standard. Everyone involved in a private conversation has to agree before it's recorded or monitored. Consent can be express (a verbal or written agreement) or implied (continuing the interaction after being notified), but notification has to happen every time, even for returning customers.

### Right to Privacy in Conversations

This right extends to private homes, workplaces, phone calls, text messages, direct messages, and any other setting where someone would reasonably expect privacy.

### Right to Legal Remedies

Unlike most privacy statutes, CIPA gives individuals the ability to sue directly, not just regulators. They can seek injunctive relief, statutory damages, or report a violation for possible criminal prosecution.

## How to Reduce Your CIPA Compliance Risk

None of this is niche advice if your business already focuses on GDPR compliance, or even CCPA/CPRA compliance. CIPA best practices overlap heavily with what you're likely doing already. A few areas are worth double-checking specifically.

### Give Clear Notice and Real Consent Choices

Work out which of your operations plausibly require consent under CIPA, and don't stop at chat widgets. Cookies, tracking pixels, session replay tools, and any script that captures a visitor's IP address, browsing behaviour, or interactions with the page fall squarely within the scope of what plaintiffs' attorneys have been arguing constitutes an unlawful pen register or trap and trace device.

Until SB 690's commercial business purpose exemption is actually signed into law, that argument remains live, and courts have reached inconsistent conclusions on it.

Chat widgets are a common blind spot, but hardly the only one. If your site uses a chatbot or live chat function, provide a clear notice when it starts up, explain what might be recorded, and give visitors a genuine way to opt out.

The same discipline should apply to cookies and trackers. A consent banner that merely informs rather than obtains a real, affirmative choice does little to help you here, since CIPA claims tend to hinge on whether consent was meaningfully given before the tool started collecting data, not simply disclosed after the fact. Session replay tools warrant particular care, given how directly they've featured in recent litigation.

### Keep Your Privacy Policy Current

Your privacy policy should already spell out what personal data is collected, how it's used, and who has access to it. Update it any times there’s a notable change, such as in vendors, technologies in use on your website, business operations, or regulatory obligations. An automated consent management platform, such as [Cookiebot™](/en/cookie-consent-solution/), helps keep disclosures aligned with what's actually running on your site by running regular scans.

### Train Staff on What's Being Recorded

Anyone handling customer support or chat interactions should know what's monitored, why, and how to honor an opt-out request. Repeat this training regularly, especially when you add new tools.

### Use a Consent Management Platform (CMP)

A CMP does two things that matter for CIPA: it surfaces clear notice to visitors before tracking starts, and it records and signals their consent choices to the rest of your stack. Cookiebot handles this for websites specifically, which is the area where most CIPA claims currently originate.

### Limit Access to Recordings and Logs

Restrict who on your team can access call recordings or chat logs to those who genuinely need it, support escalation or quality training, for example. Fewer people with access means less risk of unauthorized use.

### Review Your Practices Regularly

Audit your tracking and recording setup periodically, particularly after adding new vendors or marketing tools. Only collect what you need, and follow clear retention limits so you're not holding data longer than necessary or using it beyond what visitors were told.

## Who Enforces CIPA?

CIPA's enforcement is unusually broad. Both criminal and civil actions generally need to be brought within one year of discovering a violation, and several different bodies can pursue a claim:

- California Attorney General
- State agencies with relevant industry jurisdiction
- County district attorneys
- Other authorized agencies
- Individual plaintiffs, through their own attorneys (the private right of action that has driven the bulk of recent litigation)

## CIPA's Criminal Penalties

Prosecutors can bring CIPA violations as either misdemeanors or felonies. A misdemeanor conviction can carry fines up to USD 2,500 per violation and up to a year in jail. A felony conviction can extend prison sentences to three years, with fines up to USD 10,000 per violation.

## CIPA's Civil Penalties

Civil exposure is where most website-related claims land, and it's significant:

- Statutory damages up to USD 5,000 per violation
- Three times actual damages, whichever is greater
- Punitive damages for especially serious conduct
- Injunctive relief to stop ongoing violations
- Attorneys' fees and costs

Because damages can apply per violation, exposure adds up quickly on a website with meaningful traffic. A “violation” can arguably mean each individual site visit. That's a sharp contrast with the CCPA, which generally only creates a private right to sue in the event of a data breach. It's a large part of why plaintiffs' firms have gravitated toward CIPA for tracking-technology claims rather than the CCPA.

## Why CIPA Litigation Isn't Slowing Down

CIPA is approaching 60 years old, and it shows no sign of fading into irrelevance. According to [Fisher Phillips' Digital Wiretapping Litigation Map](https://www.fisherphillips.com/en/resources-and-innovation/trackers-and-maps/wiretapping-litigation-map), as of June 25, 2026, over 5,100 digital wiretapping lawsuits had been filed across the U.S. since the 2022 court ruling that opened this litigation category, with California accounting for the large majority of filings.

Those figures don't include the [demand letters](/us/understand-and-respond-to-cipa-demand-letter/) and arbitration claims that never become public lawsuits, or the settlements businesses reach to avoid the cost and uncertainty of fighting a claim in court.

Reputational risk compounds the financial exposure: plaintiffs' firms routinely frame these cases publicly as consumer privacy violations, which can invite copycat claims and erode customer trust regardless of how the underlying legal theory eventually holds up.

With SB 690 still working through the legislature and no statutory safe harbor in place, the practical calculus for most website owners hasn't changed: clear notice and documented consent remain the most reliable way to reduce exposure while the legal landscape sorts itself out.

## Get Ahead of CIPA Risk

Whether or not SB 690 eventually narrows CIPA's reach, the underlying expectation of telling visitors what data you're collecting and for what purposes, and giving them a genuine choice, isn't going away. However, Cookiebot CMP supports both of those requirements, as well enabling auto-blocking of cookies and other data-collecting technologies on your website until consent is obtained.

*Usercentrics does not provide legal advice. The content of this article is for educational purposes only. Businesses that have received a demand letter should engage qualified legal counsel promptly.*

## Not sure which regulations apply to your business?

Use the Regulations Finder to see what applies based on where your visitors are located, and try the Interactive Demo Builder to see consent collection in action on a live site.

[Find My Regulations](https://www.cookiebot.com/en/regulations-finder/?step=1)

## Summary

CIPA is a 1967 California wiretapping law that is now being used to sue website owners over cookies, chatbots, and session replay tools deployed without prior user consent. This guide covers what the law covers and what triggers liability, who must comply, consumer rights, penalties, and the SB 690 reform bill moving through the legislature, plus practical steps website owners can take to reduce exposure.

---

## Footer

### Product
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)
- [Cookiebot vs CookieYes](https://www.cookiebot.com/us/cookiebot-best-cookieyes-alternative/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject Requests

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)