Update, October 6, 2026: On September 30, 2026, the Governor signed SB 690 (Stats. 2026, ch. 976), which amends Penal Code section 637.2. Beginning January 1, 2027, a claim against a private business under section 638.51 (the pen register and trap-and-trace provision) that arises from a website, online application, or mobile application may be brought only by the Attorney General. The amendment applies retroactively to pending claims in actions filed within two years before that date. It does not change section 631 or section 632 claims, which remain privately enforceable. Details are in the SB 690 section below.
A wave of privacy litigation is washing over California businesses that never thought of themselves as wiretappers: companies whose websites run chat widgets, session-replay tools, or advertising pixels. The vehicle is the California Invasion of Privacy Act, a 1967 eavesdropping statute now aimed at everyday web analytics. The exposure is statutory damages of $5,000 per violation, which plaintiffs multiply across every visitor and page view. Most of these matters start not with a complaint but with a demand letter threatening a class action or mass arbitration.
This guide explains what CIPA prohibits, why website technologies trigger it, what a demand letter really means, the defenses that work, and the compliance steps that shrink the target on your back. For the broader picture, see our California privacy and AI compliance guide.
What CIPA prohibits
The Act (Pen. Code, § 630 et seq.) contains two provisions doing most of the work in web cases. Section 631 imposes liability on anyone who intercepts the contents of a communication in transit without consent, and on anyone who aids or permits a third party to do so. Section 632 prohibits recording confidential communications without the consent of all parties. Companion provisions extend similar protection to calls involving cellular lines. The statute is a two-party-consent regime. One side's consent is not enough.
The private enforcement engine is Penal Code section 637.2. Any person injured may sue for the greater of $5,000 per violation or three times actual damages. No actual damages are required. Per-violation statutory damages, aggregated across web traffic, are what turn a chat widget into a seven-figure demand.
Why ordinary website tools trigger CIPA claims
Session-replay software records keystrokes, mouse movements, and form entries as visitors type. Plaintiffs allege that is an interception of communication "contents" in transit.
Chat widgets operated by third-party vendors are alleged to let an unauthorized third party eavesdrop on customer conversations, and in some suits to create unlawful recordings without disclosure.
Tracking pixels and analytics transmit user activity to advertising platforms, including, in the health-adjacent cases, sensitive queries.
A newer theory treats tracking pixels, cookies, and similar scripts as a pen register or trap-and-trace device under Penal Code section 638.51, which bars installing such a device without a court order. Plaintiffs argue the script captures the visitor's IP address and routing data, and they seek the same $5,000 per violation under section 637.2. This is the theory SB 690 addresses.
Call recording without a "this call may be recorded" disclosure at the outset is the original CIPA fact pattern, and it still generates claims.
Courts are genuinely split on how far the statute stretches. Decisions diverge on whether replay and pixel data are "contents," whether a vendor is a third-party eavesdropper or merely the operator's tool, and whether web-browsing interactions are "confidential" at all. That uncertainty is the business model. Plaintiffs price settlements below the cost of finding out.
The demand letter, and how to respond
The typical opening move is a letter from a claimant, often a serial tester, asserting they visited your site, were recorded without consent, and will file unless you settle now. Treat it as litigation. Preserve evidence: tag configurations, consent-banner versions, vendor contracts. Do not fire off an admission-laden reply. Have counsel evaluate the actual technology stack against the current case law before responding. The options range from a defense-side refusal supported by consent and party-exception arguments to a negotiated walk-away. The right answer depends on what your site actually did, and when. We handle these disputes as part of our business litigation practice. For the parallel computer-intrusion statute, see our Penal Code § 502 guide.
Defenses that do the heavy lifting
Consent. A properly implemented banner or notice obtaining consent before tracking fires defeats the claim at its core. Timing is everything. Consent gathered after the tools start recording is the plaintiffs' favorite gap.
The party exception. A business is a party to its own customer communications. The fight is over whether its vendor is a mere recording tool (no liability) or an independent eavesdropper that exploits the data (exposure).
No "contents" intercepted. Metadata, page URLs, and mouse movements, as opposed to the substance of communications, support dismissal arguments in many courts.
No interception "in transit," where data is captured after receipt rather than contemporaneously.
Arbitration clauses and class waivers in site terms, which reshape the economics of mass claims.
Compliance: shrinking the target
Inventory every third-party script: chat, replay, pixels, analytics. Know what each actually captures and transmits.
Gate tracking behind consent with a properly sequenced banner. Do not load recording tools before consent.
Disclose recording in chat interfaces and at the start of recorded calls.
Update the privacy policy to name the technologies and data flows, consistent with CCPA and CPRA obligations.
Contract with vendors for CIPA-aware configurations, data-use limits, and indemnity. See our guide to negotiating vendor contract protections.
Audit quarterly. Marketing adds tags faster than legal removes them.
SB 690: what changed for pen register and trap-and-trace claims
The Legislature responded to the trap-and-trace wave with SB 690, which the Governor signed on September 30, 2026 (Stats. 2026, ch. 976). The bill adds subdivision (d) to Penal Code section 637.2. Under it, an action against a private actor for a section 638.51 violation that arises from conduct on a website, online application, or mobile application may be brought only by the Attorney General. As a non-urgency statute, the amendment takes effect on January 1, 2027.
Two features matter for businesses holding a demand letter today. First, the limitation reaches back: it applies to any pending section 638.51 claim in an action commenced within two years before the operative date. A trap-and-trace claim filed in 2025 or 2026 that is still pending on January 1, 2027 is covered by the new text, and we expect litigation over how courts apply that clause to cases already in motion. Second, the bill is narrow. It does not touch section 631 (interception of communications in transit) or section 632 (recording confidential communications), and it leaves the Attorney General free to sue under section 638.51. Expect demand letters to shift their emphasis to section 631 theories, where the consent and party-exception defenses described above remain the main battleground.
We will update this guide as courts begin applying the amendment. The chaptered text is on the Legislature's website.
Frequently asked questions
We received a CIPA demand letter over our website chat. Is it a scam?
Usually it is a real, monetized claim from a repeat filer. Not a scam, but a business model. Ignoring it is risky. Overpaying immediately is worse. Have counsel evaluate the technology facts and current case law before any response.
What are the potential damages?
Section 637.2 authorizes the greater of $5,000 per violation or treble actual damages, with no proof of actual harm required. Plaintiffs argue each visit or session is a separate violation. Aggregation, not the single violation, creates the exposure.
Does a cookie banner protect us?
Only if it is sequenced correctly. Consent must be obtained before the tracking tools begin capturing data, and the disclosure must actually cover the technologies in use. A banner bolted on top of scripts that fire first is the classic vulnerable configuration.
Is it illegal to record customer service calls in California?
Recording without all-party consent is the core CIPA violation. The standard cure is a clear disclosure at the outset of every call, before substantive conversation begins.
We are not based in California. Can we still be sued?
Yes. Claims are routinely brought by California residents against out-of-state operators whose sites reach them here. If Californians use your website or call lines, CIPA is part of your risk map.
Does SB 690 end website-tracking CIPA lawsuits?
No. It removes the private right of action for one theory: pen register and trap-and-trace claims under section 638.51 arising from websites and apps. That change starts January 1, 2027 and reaches pending claims in actions filed within the prior two years. Claims under sections 631 and 632 are unchanged, and the Attorney General can still enforce section 638.51. Consent sequencing and vendor configuration remain the defenses that matter.
This article is provided for general informational purposes and is not legal advice.
Need help? Contact Kolmogorov Law, P.C. at (909) 235-6116 or visit kolmogorovlaw.com to schedule a consultation with our business litigation team in Irvine, California.
Comments
There are no comments for this post. Be the first and Add your Comment below.
Leave a Comment