← All guidesGuide

CIPA's $5,000 Per Violation: How the Math Actually Works

The $5,000-per-violation figure in CIPA lawsuits sounds small until you see how 'per violation' gets counted. Here's the actual math, and why the real number is almost always smaller.

Published June 12, 2026·Last updated August 18, 2026

Every article about CIPA lawsuits mentions the same number: $5,000 per violation. It’s the statutory damages figure under Penal Code §637.2, and it’s the reason a wiretapping law from 1967 has become a live commercial risk for websites in 2026. But “$5,000 per violation” is doing a lot of work in that sentence, and most of the alarming headlines skip the part where “violation” gets defined.

Where the number comes from

Cal. Penal Code §637.2 allows a person who has been the subject of a CIPA violation to recover either their actual damages, or statutory damages of $5,000 per violation, whichever is greater, without having to prove they were harmed in some measurable way. That “without proving harm” part is what makes CIPA distinct from most consumer protection claims, and why plaintiffs’ firms can bring these suits even when a visitor never noticed anything was different about the site.

The part that actually determines your exposure: what counts as “a violation”

This is where the theoretical math and the practical math diverge. If “violation” meant one lawsuit, the number would just be $5,000. It doesn’t. Plaintiffs typically argue that each individual website visit where a tracker fired without consent is a separate violation, which is how our own CIPA risk checker arrives at a rough illustrative figure of monthly visitors × $5,000 as a theoretical ceiling.

Two things blunt that number sharply in practice:

  1. A single plaintiff’s suit is usually about their own visits, not your entire traffic base, unless it’s certified as a class action, and class certification in CIPA cases is contested and not guaranteed.
  2. Settlements are negotiated, not awarded at the statutory maximum. We haven’t seen a publicly reported CIPA settlement anywhere near “total visitors times $5,000.” Actual figures depend on case strength, how many named or class plaintiffs are involved, and litigation costs for both sides.
Our recommendation

Enzuzo

The visitor-count math is exactly what our CIPA risk checker illustrates, and exactly what Enzuzo's pre-consent tracker blocking is built to prevent from accumulating in the first place.

Try Enzuzo

So why does the theoretical ceiling matter at all

Two reasons. First, it’s the number plaintiffs’ demand letters cite, and it’s the anchor point for any settlement negotiation, a defense attorney needs to know the ceiling to evaluate the floor. Second, it scales with your traffic in a way most legal risk doesn’t: a site with 500 monthly California visitors and a site with 500,000 are not exposed to the same order of magnitude, even before you get into class dynamics. We go through what publicly known settlement patterns actually look like in our piece on 2026 CIPA settlement figures.

What this means for you, practically

Don’t anchor on the theoretical ceiling as a prediction of what a case would cost you, it isn’t one. Do treat it as a rough proxy for how seriously to take the underlying exposure: a high-traffic site running pre-consent trackers to California visitors has a meaningfully different risk profile than a low-traffic site doing the same thing, even though neither number tells you what a real case would settle for.

This is an educational illustration, not legal advice or a settlement prediction. Statutory damages calculations depend on facts a general article can’t account for. If you’re evaluating actual exposure, especially after receiving a demand letter, consult a California-licensed attorney.