CIPA Compliance

The California Invasion of Privacy Act (CIPA) is a 1967 wiretap statute now applied to website tracking, with statutory damages of $5,000 per violation and no requirement to prove actual harm. If your site tracks visitors through pixels, session replay, or chat widgets before obtaining consent, you are a potential target for a demand letter, and compliance means blocking that tracking until California visitors agree.

CIPA is one piece of website privacy compliance, and it is the piece most likely to arrive as a legal threat rather than a regulator inquiry.

CIPA website claims at a glance
Key Point What It Means for You
Private right of action Individuals can sue directly, with statutory damages of $5,000 per violation and no proof of harm required.
What triggers claims Session replay, chat widgets, and advertising pixels that capture visitor data before consent.
Why timing matters Consent must come before tracking fires. A privacy policy accepted afterward does not cure it.
The defensive posture Opt-in blocking for California visitors, plus preserved evidence that the blocking works.
Reform status Legislation may narrow some claim types. Wiretapping and recording claims are expected to remain.

Why does a 1967 wiretap law apply to websites?

CIPA was written to stop phone line interception. Its language prohibits reading or learning the contents of a communication in transit without the consent of all parties. Plaintiff attorneys argue that modern tracking does exactly that: a session replay script intercepts what a visitor types, a chat widget transmits a conversation to a third-party vendor, and an advertising pixel reads browsing behavior as it happens.

Courts have split on many of these theories, and outcomes vary by claim type and by judge. That uncertainty has not slowed the filings. The economics resemble ADA website litigation: statutory damages plus low-cost technical scanning of thousands of websites makes mass demand letters viable, whether or not any individual claim would win at trial.

What tracking technologies trigger CIPA claims?

Session replay

Session replay tools record scrolling, mouse movement, clicks, and keystrokes, then reconstruct the visit. Claims allege this is interception of the visitor’s communication with the site. Replay scripts that capture form fields before submission draw particular attention.

Chat widgets

Third-party chat tools transmit conversations to an outside vendor’s servers. Claims allege the vendor is an unauthorized third party listening in. Widgets that route or analyze transcripts through additional providers compound the theory.

Advertising and analytics pixels

Pixels such as the Meta Pixel send page views, identifiers, and events to advertising platforms. Claims allege interception and, under a separate CIPA section, unauthorized collection of routing information. Pixels firing on page load, before any consent interface appears, are the recurring fact pattern.

What is a CIPA demand letter?

Most CIPA matters begin as a letter, not a lawsuit. The typical sequence:

  1. A law firm tests your site, or scans it at scale, and observes tracking that fires before consent
  2. A letter arrives identifying the statute, describing the observed tracking, and asserting claims on behalf of a visitor
  3. The letter demands a settlement and sets a deadline, with litigation as the stated alternative
  4. What happens next turns on the technical facts: what actually fired, when it fired, and whether valid consent preceded it

Ignoring the letter is the one clearly wrong response. Whether to contest, negotiate, or remediate first depends on what your site was actually doing, which is a question of evidence, not opinion. Sites that can produce dated verification testing are in a categorically different negotiating position than sites that can only say a cookie banner was installed.

What are the essentials for reducing CIPA exposure?

  • Serve California visitors an opt-in experience: non-essential tracking blocked until they agree
  • Cover the technologies claims actually target: session replay, chat, and pixels, not just cookies
  • Confirm consent comes first in time, including during the moments before your consent tool loads
  • Name every tracking tool accurately in your privacy policy
  • Conduct verification testing that rejection and non-consent genuinely stop tracking
  • Preserve the evidence: recordings, network captures, dates, and the configuration tested

The consent interface itself is covered in depth on our cookie banner page, and it matters here for a specific reason: an installed banner that does not actually block tracking is the exact fact pattern demand letters describe.

Is CIPA reform coming?

California lawmakers have moved to narrow some website CIPA claims, and pending legislation would limit private lawsuits under certain sections of the statute. Two things are worth knowing. Reform proposals have not covered every claim type, so wiretapping and recording theories are expected to survive. And any change operates on a schedule, not retroactively erasing exposure the moment it passes. Until reform is final and effective, the practical posture is unchanged: block first, verify, and keep evidence.

What does accessibility have to do with CIPA?

Your defense to a CIPA claim is consent: the visitor agreed before tracking began. That defense is only as strong as the interface that collected the agreement. A consent banner that a screen reader never announces, or that a keyboard user cannot reach, did not collect anything from that visitor. For those sessions, the consent defense may not exist at all.

There is also a second exposure running in parallel. An inaccessible banner is a WCAG conformance failure on your most-seen interface, and ADA website claims are driven by the same demand-letter economics as CIPA. A banner that conforms to WCAG 2.1 AA and WCAG 2.2 AA closes both doors at once. Correct implementation and accessible implementation are the same project.

CIPA claims also increasingly travel alongside California’s consumer privacy statute, which works on an opt-out model. That side of California law is covered on our CCPA page.

How do the app and services address CIPA risk?

The app

Our consent app, available for Shopify, WordPress, and as a general script for all other sites, serves California visitors an opt-in experience and blocks non-essential tracking, including replay, chat, and pixel scripts, until they choose. It distinguishes scripts actually prevented from loading from scripts that merely received a denied signal, and it logs consent state so a record exists for every choice. The banner itself conforms to WCAG 2.1 AA and WCAG 2.2 AA, keyboard navigable and screen reader supported, so the consent it collects holds up.

The services

We implement the setup on your site, then conduct manual verification testing built around the CIPA fact pattern: what loads before any interaction, what loads after rejection, and what a California visitor’s session actually transmits, covering replay, chat, and pixels rather than cookies alone. The testing is recorded, dated, and preserved with the exact configuration tested, so if a letter ever arrives, you respond with evidence instead of hope. We also provide privacy policy language that accurately documents your tracking and your consent practices, plus guidance for keeping the setup compliant as your site changes.

Frequently asked questions

Can I be liable under CIPA if I never sold any data?

Yes, in theory. CIPA claims are about interception and collection, not sale. Tracking that captures visitor data before consent is the alleged violation, regardless of what happens to the data afterward.

Does a cookie banner protect me from CIPA claims?

Only if it actually blocks tracking before consent, and only for visitors who could operate it. Demand letters routinely target sites with banners installed, because the tracking fired anyway. Verification is what turns a banner into protection.

What should I do first if I receive a demand letter?

Do not ignore it, and establish the technical facts before responding. What fired, when, and under what consent state determines every option you have. Speak with counsel, and get your site tested and documented.

Does CIPA apply if my company is not in California?

Claims are brought over California visitors, not California businesses. If Californians use your site and tracking fires before consent, the theory reaches you regardless of where you operate.

Where to start

  1. Inventory the session replay, chat, and pixel tracking on your site
  2. Implement opt-in blocking for California visitors, verified to fire before any tracking
  3. Confirm the consent banner conforms to WCAG 2.1 AA as rendered on your site
  4. Conduct and record verification testing of the reject and non-consent paths
  5. Preserve the evidence, and retest whenever your site or tags change

Sign up for Accessibility Tracker

New platform has real AI. Tracking and fixing accessibility issues is now much easier.

Kris Rivenburgh, Founder of Accessible.org holding his new Published Book.

Kris Rivenburgh

I've helped thousands of people around the world with accessibility and compliance. You can learn everything in 1 hour with my book (on Amazon).