← All toolsFree tool

CIPA risk checker

A growing wave of lawsuits uses California's decades-old wiretapping law against ordinary website trackers. Answer a few questions to see whether your setup matches the pattern plaintiffs' firms have been targeting.

What is CIPA

The California Invasion of Privacy Act (CIPA) is a 1967 wiretapping law that plaintiffs' firms have repurposed to target websites over their tracking scripts. Under Cal. Penal Code §631/632.7, each violation can carry statutory damages of up to $5,000 , and unlike most privacy law, these are private lawsuits, not government fines.

A wave of suits since 2022 has targeted session-replay tools, chat widgets, and ad pixels that begin recording or sharing visitor data before consent is captured. In Camplisson v. Adidas (2025), a California court let CIPA claims over pre-consent tracking move forward, reinforcing the pattern these suits follow.

This tool estimates whether your setup matches that pattern. It does not predict litigation, and CIPA case law in this area is still unsettled, see the disclaimer below.

Q1: Do you have California visitors?
Q2: Which trackers do you run? (select all that apply)
Q3: When do these trackers fire, relative to consent?
Risk level

Flagged triggers

Educational illustration only, not legal advice. Using this tool does not create an attorney-client relationship. CIPA case law applying a 1967 wiretapping statute to website trackers is unsettled, courts have reached different conclusions on similar facts. If you've received a demand letter or been named in a suit, consult a California-licensed attorney directly.