If you run a business website, you have probably heard the term CIPA in the last year and CIPA compliance has quietly become something you are now expected to have an answer for. It is coming up in vendor calls, in emails from your marketing team and in nervous conversations between managing partners and their IT people. The reason is simple. Thousands of ordinary businesses are receiving legal demand letters that accuse their websites of illegal wiretapping, and most of them are running the exact same tools everyone else runs.
This guide explains what the California Invasion of Privacy Act actually is, why CIPA compliance has become a real risk for website owners far outside California, and what you can do to reduce your exposure. It is written for decision-makers, not lawyers. StateWP is not a law firm, and nothing here is legal advice. The law in this area is unsettled and changing, and how it applies to any specific website depends on facts we cannot assess for you. Talk to qualified counsel before acting on anything here. Our job is to make sure the website you depend on is maintained in a way that reduces risk, and that starts with understanding the problem clearly.
What Is the California Invasion of Privacy Act (CIPA)?
The California Invasion of Privacy Act, or CIPA, is a state wiretapping law codified in California Penal Code sections 630 through 638. The act was enacted in 1967, long before the modern web existed. Its original purpose was to stop people from secretly recording or eavesdropping on private telephone calls. California is an all-party consent state, which means every person in a conversation has to agree before it can be recorded. CIPA made that requirement law and attached real penalties to breaking it.
For decades, CIPA was about phones. That has changed. Plaintiffs’ attorneys have reframed the statute to argue that common website technology intercepts electronic communications without consent, in the same way a wiretap intercepts a phone call. Under this theory, when your website loads a tracking pixel or a chat tool that shares visitor activity with a third party, it is capturing communications without consent. The data collected in the background becomes the basis for the claim.
Three sections of the law drive most website cases. Section 631 covers wiretapping and the interception of communications in transit. Section 632 covers recording a confidential communication, which most often applies to live chat and support widgets. Section 638.51 covers pen registers and trap-and-trace devices, the tools that historically captured the numbers dialed on a phone. Attorneys now argue that tracking scripts function as digital pen registers. The financial exposure is what makes this serious. Plaintiffs’ attorneys point to statutory damages they calculate at $5,000 per violation under the wiretapping provisions, and $2,500 per violation under the pen register provision, and argue no actual harm needs to be shown. Multiply that by every affected visitor and the numbers become large very quickly.
One quick clarification, because the acronym causes real confusion. This article is about the California Invasion of Privacy Act. It is not the Children’s Internet Protection Act, the federal law that requires internet filters in schools and libraries that receive discounts for internet access through the E-rate program to limit access by minors to inappropriate content. Both are called CIPA, but only the California Invasion of Privacy Act is driving the website lawsuits and the CIPA compliance work this article covers. They are completely different laws with completely different purposes.
Why Is CIPA Suddenly a Major Concern for Website Owners?
The short answer is that a small number of law firms found a profitable playbook, and they are running it at scale. Over the past two years, plaintiffs’ attorneys have filed thousands of CIPA claims and sent an even larger volume of demand letters. Individual senders have become well known in the space for issuing these notices in bulk. It is now common for a business to receive a CIPA complaint letter with little warning, over technology it never thought twice about installing.
The claims target technology that is everywhere. Google Analytics, the Meta Pixel, session replay software, chat widgets, and heatmaps all send visitor activity to outside vendors. The legal argument is that this sharing of personal data happens without meaningful consent, and therefore violates the ban on intercepting communications without consent. Because these tools are standard on almost every commercial website, the pool of potential targets is effectively unlimited.
The legal landscape is also genuinely unsettled, which sustains the pressure rather than resolving it. Courts have split. In June 2026 a federal court approved a multimillion-dollar class settlement against a major publisher, while other California courts have dismissed nearly identical claims outright, some finding that the pen register provisions apply only to telephones and not to website software. That uncertainty is exactly why demand letters keep coming. When the outcome of any single case is hard to predict, a settlement offer becomes the path of least resistance, and plaintiffs’ firms know it.
Does CIPA Apply to Your Business?
The most common misconception is that CIPA is a California problem for California companies. It is not. The law protects California residents, and plaintiffs have argued it reaches any business whose website is accessed by people in California. For most organizations that operate online, that is hard to rule out. If a California resident can visit your site and interact with it, plaintiffs’ firms have treated that as enough to bring a claim, regardless of where your offices are.
Size is not the shield people assume it is either. These claims are not reserved for large consumer brands. Professional service firms, including law firms, financial and accounting practices, insurance agencies, healthcare organizations, and non-profits, have all received letters. If your website uses analytics or advertising tools, hosts a chat feature, or runs booking and contact forms that quietly collect user information, you have the same profile as the businesses being targeted. Ironically, the firms most exposed are often the ones with the most sophisticated marketing stacks, because more tracking means more alleged violations.
The honest position is that very few businesses can rule this out. The right question is not whether CIPA could theoretically apply to you. It is how much unmanaged tracking is running on your site right now, and whether any of it collects and shares visitor data without proper consent. Most owners have never been shown that inventory, which is the first gap worth closing.
Which Website Technologies Can Trigger CIPA Claims?
CIPA claims tend to cluster around a predictable set of tools. Any technology that captures visitor behavior and shares it with a third party, or records an interaction that a visitor would consider private, is a potential trigger.
Common culprits include:
- Advertising and analytics pixels, such as the Meta Pixel, Google Analytics, and TikTok and other ad-network tags, which send visitor activity to outside platforms and are the technologies most often argued to function as unauthorized pen registers.
- Session replay tools, which record mouse movement, clicks, scrolling, and keystrokes so the site owner can replay a visitor’s session as if watching over their shoulder.
- Live chat and chatbot widgets, where the transcript of a conversation may be captured or shared with a vendor. Plaintiffs argue this is the modern equivalent of recording a confidential communication or eavesdropping on private chat rooms.
- Heatmaps and behavioral tracking scripts, which log and analyze how visitors move through a page.
- Third-party embeds and tag managers, which can load additional trackers you never see, creating unauthorized access to visitor data and quiet, unauthorized disclosure to vendors you never vetted.
The pattern is consistent. The risk is not the tool itself. It is running the tool without clear disclosure and consent, so that data is collected and shared before the visitor ever agrees to it.
CIPA vs. CCPA vs. GDPR: Why They Are Not the Same Thing
Business owners often assume that if they have addressed one privacy law, they have addressed them all. They have not. CIPA, the CCPA, and the GDPR are three different laws with different origins, different mechanics, and different consequences. Treating them as interchangeable is how compliance gaps form.
CIPA is a criminal wiretapping statute from 1967 that plaintiffs’ firms have reframed and are now using as a civil weapon. Its power comes from the private right of action and fixed statutory damages, which let an individual sue over interception of electronic communications without having to prove they were harmed. The CCPA, California’s consumer privacy law, is a modern regulation focused on giving residents rights over their personal information, including the right to know what is collected and to opt out of its sale. The GDPR is the European Union’s comprehensive data protection regulation, built on the principle that businesses need a lawful basis and clear consent before they process personal data.
| Dimension | CIPA (California Invasion of Privacy Act) | CCPA / CPRA | GDPR |
|---|---|---|---|
| Origin | 1967 California wiretapping law | 2018 California consumer privacy law | 2018 EU data protection regulation |
| Core purpose | Prevent interception, recording, and eavesdropping on communications without consent | Give California consumers control over their personal data | Protect personal data of individuals in the EU |
| Who it protects | People in California | California residents | People in the EU and EEA |
| Consent model | All-party consent before interception | Notice and right to opt out | Lawful basis, often opt-in consent |
| Who can enforce it | Individuals, through private lawsuits | Individuals (for certain breaches) and the state | Data protection regulators |
| Typical penalty | $5,000 per violation, or $2,500 under the pen register provision | Up to $7,500 per intentional violation | Up to 4% of global annual revenue |
The practical takeaway is that a cookie banner built for the CCPA or the GDPR does not automatically protect you from CIPA. CIPA is about whether tracking fired before consent was captured, which is a technical implementation question, not just a policy question.
What Happens If You Get a CIPA Demand Letter
A CIPA demand letter is designed to pressure you into a quick settlement. It typically names your website, identifies the specific tracking technology it claims you are using without consent, cites the relevant sections of the invasion of privacy act, and calculates a potential exposure figure by multiplying the statutory damages by an estimated number of affected visitors. That number is usually alarming by design. Many letters also raise the possibility of a class action to make the stakes feel larger.
The instinct to ignore the letter is understandable and dangerous. These are not idle threats. The senders file real lawsuits, and courts in some jurisdictions have allowed these claims to proceed. Ignoring a letter can turn a negotiable demand into formal litigation, which is far more expensive and disruptive, especially for a professional service firm whose reputation depends on discretion.
The right response is measured, not panicked. Do not admit liability or make representations on your own. Preserve the letter and loop in qualified legal counsel promptly, because deadlines in these letters are often short. At the same time, get a clear technical picture of what your website is actually running, because your lawyer will need to know exactly which tools are firing, when they fire relative to consent, and what data is collected. That technical inventory is where a specialized website partner becomes valuable.
The CIPA Compliance Checklist for Your Website
You cannot eliminate the risk of receiving a demand letter, but you can make your website a far less attractive and far more manageable target. Practical CIPA compliance overlaps heavily with good website governance, which is exactly the work most sites have been neglecting. Use the CIPA compliance checklist below as a practical starting point, and confirm the specifics with your legal counsel.
- Inventory every tracking technology on your site. You cannot manage what you have not mapped. Identify every pixel, analytics tag, session replay script, chat widget, and third-party embed, including anything loading quietly through a tag manager.
- Block trackers until consent is given. Configure your consent management platform so that non-essential scripts do not fire before a visitor agrees. This is the single most important technical step, because CIPA claims turn on whether data was collected before consent.
- Use a real consent banner, not a decorative one. Many banners display a notice but load trackers anyway. Make sure yours actually controls script behavior.
- Review your live chat and session replay settings. Disable keystroke and input capture on sensitive fields, and disclose recording clearly so a conversation is not later characterized as an unauthorized recording of a confidential communication.
- Publish a clear, current privacy policy that accurately describes what personal information you collect, how it is used, and which third parties receive it.
- Vet your vendors and third-party scripts. Understand what each tool does with the data collected, and remove anything you cannot justify.
- Keep the platform patched and secure. Unauthorized access and outdated software create separate liability. On WordPress specifically, unmaintained plugins are a common source of hidden trackers and vulnerabilities.
- Document your compliance decisions. A clear record of what you run and why demonstrates good faith and helps counsel respond quickly if a letter arrives.
- Re-audit on a schedule. Marketing teams add tools constantly. A site that was clean six months ago may not be today.
Will SB 690 Fix the CIPA Problem?
There is legislative movement, but no relief you can rely on yet, and it does not change your CIPA compliance obligations today. California Senate Bill 690, sponsored by Senator Anna Caballero, is an effort to curb the wave of CIPA website litigation. After stalling in 2025, an amended version advanced through the Assembly’s Privacy and Consumer Protection Committee on July 1, 2026. The current version is narrower than the original. Rather than overhauling CIPA, it focuses on eliminating the private right of action under the pen register and trap-and-trace provision, the theory behind a large share of recent website claims, and it is drafted to apply retroactively to claims filed within the prior two years.
The bill is not law. It still has to pass floor votes in both chambers before the August 31, 2026 deadline, and if it passes and is signed, it would not take effect until later in the year. Lawmakers have also signaled that the language may change again before then. Until a final bill is signed and in force, the litigation risk is unchanged, and the demand letters are still going out. The responsible move is to keep following current compliance practices and treat any future relief as a bonus, not a plan.
How StateWP Helps Reduce CIPA Compliance Risks
Most CIPA compliance exposure is not a legal problem first. It is a website management problem that becomes a legal problem. Trackers get added and never removed. Consent tools get installed but never configured correctly. Nobody owns the question of what is actually running on the site. StateWP exists to close exactly that gap. We secure and maintain mission-critical WordPress websites for professional service firms, and that includes knowing precisely what your site loads, when it loads, and what data it shares.
We help by giving you a complete inventory of the tracking technologies on your site, checking whether your consent tools block scripts before a visitor agrees, keeping your platform patched against the unauthorized access that creates separate liability, and maintaining the ongoing governance that keeps your tracking documented and under control as your marketing stack changes. We are not your law firm, and we do not replace legal counsel. We are the partner who makes sure the technical foundation your counsel and your business depend on is sound, documented, and under control.
Request a Free Website Assessment Today
CIPA risk hides in the parts of your website nobody is watching. The fastest way to understand your exposure is to see exactly what your site is running today. A StateWP assessment gives you that clarity, along with a clear picture of the security, performance, and maintenance gaps that put your site at risk.
If your firm depends on its website, do not wait for a demand letter to find out what is on it. Request your free assessment or book a call. We will help you see what is there, understand what it means, and take the next step with confidence.