A wave of privacy litigation is washing over California businesses that never thought of themselves as "wiretappers": companies whose websites run chat widgets, session-replay tools, or advertising pixels. The vehicle is the California Invasion of Privacy Act (CIPA)—a 1967 eavesdropping statute now aimed at everyday web analytics—and the exposure is statutory damages of $5,000 per violation, which plaintiffs multiply across every visitor and page view. Most matters start not with a complaint but with a demand letter threatening a class action or mass arbitration.
This guide explains what CIPA prohibits, why website technologies trigger it, what a demand letter really means, the defenses that work, and the compliance steps that shrink the target on your back. (For the broader landscape, see our California privacy and AI compliance guide.)
What CIPA Prohibits
The Act (Pen. Code, § 630 et seq.) contains two provisions doing most of the work in web cases. Section 631 imposes liability on anyone who intercepts the contents of a communication in transit without consent—and, critically, on anyone who aids or permits a third party to do so. Section 632 prohibits recording confidential communications without the consent of all parties; companion provisions extend similar protection to phone calls involving cellular lines. The statute is a two-party-consent regime: one side's consent is not enough.
The private enforcement engine is Penal Code section 637.2: any person injured may sue for the greater of $5,000 per violation or three times actual damages—no actual damages required. Per-violation statutory damages, aggregated across web traffic, are what turn a chat widget into a seven-figure demand.
Why Ordinary Website Tools Trigger CIPA Claims
- Session-replay software that records keystrokes, mouse movements, and form entries as visitors type—alleged to be an interception of communication "contents" in transit.
- Chat widgets operated by third-party vendors—alleged to let an unauthorized third party eavesdrop on customer conversations, and in some suits to create unlawful recordings without disclosure.
- Tracking pixels and analytics that transmit user activity (including, in the health-adjacent cases, sensitive queries) to advertising platforms.
- Call recording without an "this call may be recorded" disclosure at the outset—the original CIPA fact pattern, still generating claims.
Courts are genuinely split on how far the statute stretches: decisions diverge on whether replay and pixel data are "contents," whether a vendor is a third-party eavesdropper or merely the operator's tool, and whether web-browsing interactions are "confidential" at all. That uncertainty is the business model—plaintiffs price settlements below the cost of finding out.
The Demand Letter Playbook—and How to Respond
The typical opening move is a letter from a claimant (often a serial tester) asserting they visited your site, were recorded without consent, and will file—unless you settle now. Treat it as litigation: preserve evidence (tag configurations, consent-banner versions, vendor contracts), do not fire off an admission-laden reply, and have counsel evaluate the actual technology stack against the current case law before responding. Options range from a defense-side refusal supported by consent and party-exception arguments to a negotiated walk-away; the right answer depends on what your site actually did and when. (Our team handles these disputes as part of our business litigation practice; for the parallel computer-intrusion statute, see our Penal Code § 502 guide.)
Defenses That Do the Heavy Lifting
- Consent. A properly implemented banner or notice obtaining consent before tracking fires defeats the claim at its core. Timing is everything—consent gathered after the tools start recording is the plaintiffs' favorite gap.
- The party exception. A business is a party to its own customer communications; the fight is over whether its vendor is a mere recording tool (no liability) or an independent eavesdropper that exploits the data (exposure).
- No "contents" intercepted. Metadata, page URLs, and mouse movements—as opposed to the substance of communications—support dismissal arguments in many courts.
- No interception "in transit," where data is captured after receipt rather than contemporaneously.
- Arbitration clauses and class waivers in site terms, which reshape the economics of mass claims.
Compliance: Shrinking the Target
- Inventory every third-party script—chat, replay, pixels, analytics—and what each actually captures and transmits.
- Gate tracking behind consent via a properly sequenced banner; do not load recording tools pre-consent.
- Disclose recording in chat interfaces and at the start of recorded calls.
- Update the privacy policy to name the technologies and data flows, consistent with CCPA/CPRA obligations.
- Contract with vendors for CIPA-aware configurations, data-use limits, and indemnity—see our guide to negotiating vendor contract protections.
- Audit quarterly. Marketing adds tags faster than legal removes them.
Frequently Asked Questions
Q: We received a CIPA demand letter over our website chat. Is it a scam?
A: Usually it is a real, monetized claim from a repeat filer—not a scam, but a business model. Ignoring it is risky; overpaying immediately is worse. Have counsel evaluate the technology facts and current case law before any response.
Q: What are the potential damages?
A: Section 637.2 authorizes the greater of $5,000 per violation or treble actual damages, with no proof of actual harm required—and plaintiffs argue each visit or session is a separate violation. Aggregation, not the single violation, creates the exposure.
Q: Does a cookie banner protect us?
A: Only if it is sequenced correctly—consent must be obtained before the tracking tools begin capturing data, and the disclosure must actually cover the technologies in use. A banner bolted on top of pre-firing scripts is the classic vulnerable configuration.
Q: Is it illegal to record customer service calls in California?
A: Recording without all-party consent is the core CIPA violation. The standard cure is a clear disclosure at the outset of every call, before substantive conversation begins.
Q: We are not based in California. Can we still be sued?
A: Yes—claims are routinely brought by California residents against out-of-state operators whose sites reach them here. If Californians use your website or call lines, CIPA is part of your risk map.
This article is provided for general informational purposes and is not legal advice.
Need help? Contact Kolmogorov Law, P.C. at (909) 235-6116 or visit kolmogorovlaw.com to schedule a consultation with our business litigation team in Irvine, California.
Comments
There are no comments for this post. Be the first and Add your Comment below.
Leave a Comment