CIPA complaints claim that tracking tools on your website violate California’s wiretapping and electronic-tracking laws. Now we’re seeing a similar story play out: California plaintiffs’ lawyers are taking advantage of a gray area in the law to make legal claims against website owners.
Summary:
- California Invasion of Privacy Act (CIPA) is a 1967 California wiretapping law now aimed at pixels, session replay, chat widgets, and analytics
- It provides a private right of action for injured persons, with statutory damages of $5,000 per violation
- It’s less expensive to settle and many defendants are doing just that
- The practical defense is preventing non-essential third-party tracking from firing before valid consent, then verifying that behavior on the live website
We offer services — including manual testing and accessible consent banner installation — to ensure that non-essential tracking stays blocked until a visitor gives valid consent.
This is extremely important. Many plugins, widgets, and apps claim they work for CIPA compliance, but they don’t actually prevent tracking (and most website owners wouldn’t know if they did or did not).
Installing a consent plugin does not mean your website is actually blocking tracking. The only way to know is to test what fires on the live website before and after the visitor makes a consent choice.
If you use tracking technologies such as Google Analytics, Meta Pixel, session replay, chat tools, or advertising pixels, you need to know exactly when they fire—and make sure non-essential third-party tracking does not fire before valid consent.
Let’s take a look at the situation.
What’s Happening
The California Invasion of Privacy Act sits at Penal Code Sections 630 through 638. Two provisions drive the wave.
Section 631 prohibits wiretapping. In the Ninth Circuit’s unpublished decision in Javier v. Assurance IQ, the court applied Section 631(a) to internet communications and held that consent obtained after the alleged interception was too late.
Section 638.51, a pen register provision added in 2015, says “a person may not install or use a pen register or a trap and trace device without first obtaining a court order.” Plaintiffs argue that trackers collecting IP addresses are modern pen registers.
Section 637.2 provides the private right of action, allowing an injured person to recover the greater of $5,000 per violation or three times actual damages, while expressly providing that actual damages are not required to bring the action.
Old statute, new theory, statutory damages. That combination built an industry.
A July 2026 California Assembly committee analysis calls the pen register statute “a poster child for abusive lawsuits,” says plaintiffs’ attorneys have “exploited the statute at scale,” and notes that hasty settlements encourage vexatious litigants to continue “blasting out demand letters.”
Current Legislative Climate
California is trying to rein it in. Senate Bill 690, as amended, would eliminate private CIPA pen register claims arising from websites and apps, leaving those claims to the California Attorney General, with a retroactive bar reaching pending claims filed within the prior two years.
As of this writing it is not law. Even if it passes, it leaves the Section 631 wiretapping provision intact, so CIPA claims over session replay, chat, and pixels continue.
The courts may move first. In Variety Media v. Superior Court, the California Court of Appeal is considering whether the pen register statute reaches ordinary website tracking at all, with oral argument scheduled for August 25, 2026. The case could produce the first California appellate authority on the issue.
However Variety Media and SB 690 land, they address the pen register theory only. Section 631 wiretapping claims, and the underlying question of whether your website tracks people without consent, remain.
Big companies are paying to end these cases. A federal court approved a $3.85 million class settlement against the Los Angeles Times in June 2026 over three website trackers, without any admission of liability. The parties settled to avoid the uncertainty and expense of continued litigation.
What You Need to Do
Take the gray area away before anyone looks for it.
Inventory every tracking technology your website loads. Block non-essential third-party tracking until the visitor gives prior consent.
Verify on the live website that nothing fires early, because an installed consent app is not verification.
And make the consent mechanism accessible: if a visitor cannot operate the banner or understand the choices with a keyboard or screen reader, proving valid consent becomes considerably harder.
If the third-party trackers behind these claims never fire before valid consent, you eliminate the factual basis for the most common Section 631 website-tracking theory and substantially reduce the exposure these demand letters target.
How Accessible.org Helps With CIPA
We do the work. Not an app you install and hope for the best, and not a knowledge base that answers your question with a link.
Here’s what that looks like:
- We inventory every tracking technology firing on your live website: pixels, session replay, chat widgets, analytics, and the scripts a developer added years ago that nobody remembers
- We implement blocked-by-default consent, so nothing non-essential fires before a visitor says yes
- We fix the interference problems that break consent flows, like newsletter popups and embedded apps that steal focus or fire on their own timers
- We make the banner itself accessible, so focus lands on it when it appears, returns to a logical place when it closes, and every visitor can operate it with a keyboard or screen reader
- We verify the finished implementation on your live website, because the demand letters are based on what actually fires, not what your settings page says
When you have a question, you get an answer and a fix, not a link to an article and a chatbot.
We use a standardized approach with room to customize inside it. That’s deliberate. Doing this one proven way keeps the quality consistent and the price within reach. A straightforward website gets a straightforward engagement, and complicated setups are priced for what they actually require.
And we only do it the right way. If you want a banner that looks compliant but keeps trackers firing, that’s not a service we offer.
Accessible.org helps clients with both accessibility and privacy risk. Contact us to discuss how our services can help.