CIPA risk checker
A growing wave of lawsuits uses California's decades-old wiretapping law against ordinary website trackers. Answer a few questions to see whether your setup matches the pattern plaintiffs' firms have been targeting.
The California Invasion of Privacy Act (CIPA) is a 1967 wiretapping law that plaintiffs' firms have repurposed to target websites over their tracking scripts. Under Cal. Penal Code §631/632.7, each violation can carry statutory damages of up to $5,000 , and unlike most privacy law, these are private lawsuits, not government fines.
A wave of suits since 2022 has targeted session-replay tools, chat widgets, and ad pixels that begin recording or sharing visitor data before consent is captured. In Camplisson v. Adidas (2025), a California court let CIPA claims over pre-consent tracking move forward, reinforcing the pattern these suits follow.
This tool estimates whether your setup matches that pattern. It does not predict litigation, and CIPA case law in this area is still unsettled, see the disclaimer below.
This is visitors × $5,000, the maximum statutory figure per violation under CIPA, not a prediction, not a likely settlement, and not what courts typically award. Real cases settle for a small fraction of the theoretical ceiling, or are dismissed outright.
Enzuzo
Enzuzo is the only tool we've reviewed with an explicit CIPA posture and a tracker crawler built to flag exactly this pattern, scripts firing before a consent decision is made.
Educational illustration only, not legal advice. Using this tool does not create an attorney-client relationship. CIPA case law applying a 1967 wiretapping statute to website trackers is unsettled, courts have reached different conclusions on similar facts. If you've received a demand letter or been named in a suit, consult a California-licensed attorney directly.