CIPA Beyond California: Which Other States Have Wiretapping Laws
CIPA is California-specific, but the underlying legal structure, all-party consent wiretapping statutes with a private right of action, exists in other states too. Here's the landscape.
Everything else in this series has been about California specifically, because CIPA is a California statute and California is where this litigation wave started and is heaviest. But the underlying legal structure that makes CIPA usable against websites, an “all-party consent” wiretapping law with a private right of action and statutory damages, isn’t unique to California. If your traffic isn’t California-heavy, it’s worth knowing this isn’t purely a California question.
Why California became the epicenter
Two features of California’s specific statute made it the natural starting point for this litigation theory: it’s an all-party consent state (meaning every party to a communication must consent to it being recorded or intercepted, not just one party), and it provides for statutory damages without proof of actual harm. Many states are “one-party consent” states, where only one participant needs to consent, which generally defeats this theory outright, since the website operator itself is a party to the communication and has implicitly consented by operating the site.
Other all-party consent states worth knowing about
A handful of other states share the all-party consent structure that makes this kind of claim theoretically viable, including Florida, Illinois, Maryland, Pennsylvania, and Washington, among others. Each state’s specific statutory language, available damages, and case law maturity differ significantly from California’s, and litigation volume in these states has been much lower than in California to date. That’s not a guarantee it stays that way, plaintiffs’ firms actively look for jurisdictions with favorable statutory structures, and a state with the right combination of all-party consent and a private right of action is a plausible candidate for future litigation growth even without an established track record yet.
Usercentrics
If your traffic spans multiple states, the safer default is a platform like Usercentrics that gates trackers behind real consent everywhere, rather than one that depends on guessing which state's wiretapping statute might eventually get tested the way California's has.
Why “we don’t have much California traffic” isn’t the whole answer
Our own CIPA risk checker and most of this series focus on California specifically, because that’s where the case law is most developed and the risk is best understood today. But if your traffic is concentrated in one of the other all-party consent states listed above, treating your risk as zero because you’re not California-heavy would be premature, the underlying legal mechanism exists there too, even though it hasn’t been tested at the same scale.
The practical takeaway
The fix doesn’t change based on which state’s statute might eventually apply: consent-gating trackers so they don’t fire before a visitor makes a choice (see our piece on why this timing question is central) addresses the mechanical trigger for this entire category of claim, regardless of which state’s version of the underlying statute a future plaintiff might invoke.
This is an educational overview of general legal structures across states, not a comprehensive 50-state survey and not legal advice. Wiretapping statutes vary significantly by state. Consult a privacy attorney for guidance on your specific traffic footprint.