Guide

What Is the Florida Security of Communications Act (FSCA)?

Florida has its own two-party-consent wiretapping law, and like California's CIPA, it's increasingly being applied to website tracking technology. Here's what the FSCA actually says.

Published August 15, 2026·Last updated August 15, 2026

The Florida Security of Communications Act, codified at Florida Statutes Chapter 934, is the state’s wiretapping and electronic surveillance law. It predates the modern web by decades, like California’s CIPA, it was written for phone taps and bugged rooms, but plaintiffs’ firms have increasingly argued it applies just as directly to website tracking technology as it does to a literal wiretap.

The core prohibition

The FSCA makes it unlawful to intentionally intercept, or attempt to intercept, any wire, oral, or electronic communication without the consent of all parties to that communication. Florida is a two-party (or “all-party”) consent state, meaning every party to a communication has to consent to it being intercepted or recorded, not just one side. This is the same structural feature that makes California’s wiretapping law (part of CIPA) a source of website litigation risk, and it’s why Florida is increasingly discussed as a similar venue.

Why this reaches website tracking at all

The theory plaintiffs’ firms use is straightforward: when a website visitor’s keystrokes, mouse movements, form entries, or page interactions are captured in real time by a third-party script, session replay tools, some chat widgets, certain analytics configurations, that capture can be framed as “interception” of an “electronic communication” between the visitor and the website, with the third-party vendor as an unconsented-to second listener. Under a two-party consent framework, the website visitor’s consent alone (implied by using the site) isn’t enough, the theory goes, the visitor has to knowingly consent to the specific third party listening in too.

How this differs from CIPA structurally

The underlying legal theory is similar to CIPA’s Section 631 (wiretapping) claims, but the statutes aren’t identical, they have different specific provisions, different case law developing around them, and different penalty structures. A business that has addressed its CIPA exposure in California has not automatically addressed FSCA exposure in Florida, the two require separate review even though the underlying fact pattern, a third-party script capturing visitor interactions without clear consent, is often the same.

Our recommendation

Usercentrics

The practical fix for both CIPA and FSCA exposure is the same: get a real consent mechanism in front of any tool that captures visitor interactions before it fires. Usercentrics's Auto-Blocking feature blocks tracking scripts pre-consent by default, not just visually, which is the core mechanism these wiretapping-style claims target.

Try Usercentrics

Who this affects

Any business with a meaningful Florida visitor base and third-party tracking, chat, analytics, or session-recording tools on its site is a potential target, regardless of where the business itself is headquartered. As with CIPA, the statute doesn’t require the business to be Florida-based, it turns on where the website visitor is located when their interaction is captured.

The bottom line

The FSCA is Florida’s version of the same two-party-consent wiretapping framework that’s driven years of CIPA litigation in California, applied to the same category of website tracking tools. Businesses that have already reviewed their CIPA exposure have a head start on understanding the theory, but the FSCA is a distinct statute requiring its own review, not something automatically covered by California-focused compliance work.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.