← All guidesGuide

What Is CIPA? The 1967 Wiretap Law Now Suing Websites

CIPA was written for phone taps, not pixels. Here's how a 1967 California wiretapping law became the legal theory behind thousands of website tracking lawsuits.

Published June 5, 2026·Last updated August 18, 2026

If you’ve heard “CIPA” mentioned in the same breath as cookie banners and website trackers, the name is doing some misdirection. The California Invasion of Privacy Act has nothing to do with cookies on its face. It was signed in 1967 to stop phone wiretapping and eavesdropping. Somewhere between then and now, plaintiffs’ firms found a way to point it at ordinary marketing pixels and chat widgets, and it’s now one of the most active sources of privacy litigation against websites in the country.

The law as written

CIPA’s core provisions relevant here are Penal Code §631 and §632.7:

  • §631 makes it illegal to willfully and without consent “tap” a communication line, or to read, learn the contents of, or use a communication in transit without the consent of all parties.
  • §632.7 covers similar ground for communications involving a cordless or cellular phone.

Neither section mentions websites, cookies, or pixels. They were written for a world of physical phone lines and recording devices.

How it got applied to websites

The theory plaintiffs’ attorneys use is that a website visit is a “communication,” and that third-party tracking tools, a chat widget, an ad pixel, a session-replay script, are functionally “listening in” on that communication and relaying it to another company, without the visitor’s consent. Under that reading, a tool like a live chat widget provided by a third-party vendor isn’t just collecting analytics; it’s an unauthorized second party on the line.

Courts have not settled on whether this reading is correct. Some judges have accepted it, letting cases proceed past early motions to dismiss. Others have rejected it, finding that a website’s own vendors, processing data the site itself chose to share with them, aren’t outside eavesdroppers in the sense the statute was written to cover. This split is exactly why CIPA claims are still being actively litigated rather than settled as a matter of law. If you want the honest state of play: it’s unresolved, and that uncertainty is part of what’s driving new filings.

Why this matters even if you’re not a tech company

Unlike most privacy law, CIPA claims are brought as private lawsuits, not government enforcement. There’s no regulator deciding whether to pursue you, any visitor (or, more realistically, any plaintiff’s firm working with a visitor) can file. And the statute provides for statutory damages, meaning a plaintiff doesn’t need to prove actual financial harm to seek compensation. We break down exactly how that damages math works in our companion piece on the $5,000-per-violation figure.

Our recommendation

Enzuzo

Enzuzo is the only tool in our comparison with an explicit CIPA posture, it flags trackers that fire before consent, which is the exact pattern behind most CIPA suits.

Try Enzuzo

What actually triggers a claim

In practice, the suits we’ve seen cluster around a specific pattern: a website runs a tracker (often a chat widget, session-replay tool, or ad pixel) that begins sending visitor data to a third party before the visitor has made any consent choice, sometimes before a banner has even rendered. We cover the specific tools involved in our breakdown of which trackers trigger CIPA lawsuits.

If you want a fast read on where your own site stands, our CIPA risk checker walks through the same factors, California traffic, tracker mix, and consent timing, that these cases turn on.

The bottom line

CIPA is old law being applied to new technology, in a legal environment where the answer to “is this actually illegal” genuinely depends on which courtroom you’re in. That ambiguity doesn’t make the risk disappear, filed lawsuits and demand letters are a real cost even when the underlying legal theory is contested. Understanding the mechanism is the first step to assessing whether your own setup looks like the pattern these cases target.

This is an educational overview, not legal advice. CIPA case law applying a 1967 wiretapping statute to website trackers is unsettled, courts have reached different conclusions on similar facts. If you’ve received a demand letter, consult a California-licensed attorney directly.