To be CIPA compliant, website owners must prevent non-essential third parties from receiving visitor data before valid consent.
To ensure this is the case, it’s essential verify that the consent controls and tracking restrictions are working correctly. We highly recommend you maintain evidence of this verification with screenshots, screen recordings, and any third-party documentation.
Website-tracking law and its interpretation under the California Invasion of Privacy Act (CIPA) remain unsettled. The reality is that no banner or configuration can provide 100% certainty against a lawsuit or demand letter.
This is why website owners must pay attention to detail and take manual steps to ensure they are not sued.
| Step | What to do | What this involves |
|---|---|---|
| 1. Test the website | Observe what the live website does before consent | Test important pages, forms, chat, videos, checkout, and other interactions from a California location |
| 2. Identify the trackers | Find every technology that collects or transmits visitor information | Document the vendor, information collected, purpose, trigger, installation location, and whether it is essential |
| 3. Block non-essential tracking | Stop non-essential third-party trackers from operating before consent | Connect each tracker to the consent system and confirm that rejection keeps it blocked |
| 4. Make consent accessible | Make sure every visitor can understand and operate the consent banner | Manually test keyboard access, screen readers, focus, contrast, zoom, mobile use, and every consent control |
| 5. Verify the implementation | Re-test the live website under every consent choice | Confirm that tracking remains off before consent and after rejection, begins only after acceptance, and stops after withdrawal |
| 6. Preserve evidence and monitor | Document the results and repeat the testing as the website changes | Save dated screenshots, screen recordings, and test results, then re-test after website changes |
What is CIPA Compliance?
the California Invasion of Privacy Act (CIPA is a California wiretapping statute that plaintiffs’ lawyers are now apply to website tracking.
What are Courts Saying About CIPA Lawsuits?
Under Section 631, plaintiffs argue that session replay tools, chat widgets, pixels, and similar technologies allow third parties to intercept visitor communications while they are being transmitted.
In the Ninth Circuit’s unpublished, nonprecedential decision in Javier v. Assurance IQ, the court concluded that consent obtained after the alleged interception was too late.
Under this theory, consent needs to come before the interception.
In another unpublished decision, Mikulsky v. Bloomingdale’s, the Ninth Circuit addressed session replay technology and concluded that allegations involving the real-time capture of website communications without consent were sufficient to state a Section 631 claim.
Under Section 638.51, plaintiffs argue that software collecting IP addresses and other routing, addressing, or signaling information functions as a modern pen register or trap-and-trace device.
Courts are divided over whether standard website-tracking technology fits the statute and which statutory exceptions apply.
Whether a website operator or tracking vendor qualifies for that exception is currently disputed and appellate review is underway.
Until a clear rule becomes established, it’s best practice not to allow trackers to collect visitor information before the visitor has consented to tracking.
With this in mind, here is a step-by-step guide on how to follow best practices for CIPA compliance.
Step 1: Test the Live Website
Start with what the website does before a visitor makes a consent choice.
Open the website in a private browsing window. Clear any existing cookies and stored consent preferences.
Use the browser’s network tools to record the requests made when each important page loads.
Do not accept or reject tracking yet. The purpose of this first test is to determine what happens before consent.
Test more than the homepage. Include important pages and screens in the key flows:
- Product and service pages
- Landing pages
- Blog posts
- Contact and lead-generation forms
- Account registration and login
- Shopping carts and checkout
- Embedded videos
- Chat and support tools
Repeat the test while clicking, scrolling, searching, playing videos, opening chat, entering forms, and beginning checkout.
Some trackers activate only after a specific interaction or delay.
Step 2: Identify Every Tracker
Document every technology that collects or transmits visitor information.
For each tracker, identify:
- The company receiving the information
- The information being collected
- The business purpose
- The page or interaction that activates it
- Whether it operates before consent
- Whether it continues after rejection
- Where it is installed
- Whether it is essential to operating or securing the website
Common examples include analytics, advertising pixels, session replay, chat widgets, embedded video, newsletter tools, heatmaps, customer-support software, and social-media integrations.
Also inspect tag-manager containers, plugins, applications, theme files, header and footer code, and scripts added directly to the website.
Review server-side integrations as well. Browser testing may not reveal everything that happens after information reaches your server.
Step 3: Block Non-Essential Tracking Until Prior Consent
Non-essential third-party tracking should be off by default.
No request containing visitor information should be sent to those third parties before the visitor consents.
Connect every non-essential tracker to the appropriate consent category. Do not rely on the presence of a banner alone.
A consent application may display the visitor’s choices while tracking code embedded elsewhere continues to operate.
This is why every tracker identified during testing must be connected to the consent state.
If the visitor rejects tracking, non-essential trackers should remain blocked.
If the visitor accepts a tracking category, the connected technologies may begin operating after that choice.
Functionality genuinely required to operate or secure the website may remain active.
But verify exactly what each service collects and where it sends that information. Calling a tracker “necessary” does not make it legally harmless.
Consent should involve a clear, affirmative choice based on understandable information about the tracking purposes.
The website should:
- Honor rejection as well as acceptance
- Avoid preselected non-essential categories
- Remember the visitor’s consent state
- Allow the visitor to change or withdraw the decision
- Keep a record of the banner and configuration versions used
Watch delayed triggers.
Newsletter popups, chat widgets, embedded applications, and marketing tools may transmit data according to their own timers.
Step 4: Make the Consent Banner Accessible
Every visitor must be able to understand and operate the consent mechanism.
Manually test the banner using only a keyboard. Every control must be reachable and operable.
Test it with a screen reader. Accept, reject, close, and preference controls must have clear names and communicate their current state.
If the banner operates as a modal dialog, keyboard focus should move into it and remain within it while it is open.
When the dialog closes, focus should move to an appropriate location.
If the banner is non-modal, it must be announced and operable without unexpectedly stealing focus.
It must not obscure the element currently receiving keyboard focus.
Also test:
- Visible keyboard focus
- Text and control contrast
- Browser zoom
- Text spacing
- Mobile screen sizes
- Touch-target size
- Screen orientation
- Error messages and instructions
Delayed popups must not interrupt the consent process.
An inaccessible banner can prevent a visitor from making an informed and effective choice. It also creates separate accessibility exposure.
If the banner is being used as evidence of consent, it needs to work for people using assistive technology.
Step 5: Verify the Implementation
After implementation, repeat the testing on the live website.
Do not rely on what the consent platform’s settings page says should happen. Verify what actually happens.
Test each consent state separately:
- Make no choice and confirm that non-essential tracking remains blocked
- Reject tracking and confirm that it remains blocked
- Accept tracking and confirm that it begins only after acceptance
- Withdraw consent and confirm that future non-essential tracking stops
- Return to the website and confirm that the saved consent state is honored
Repeat these tests across important pages, browsers, and mobile devices.
If the website uses regional targeting, test from a California IP address or use the consent platform’s regional testing tools.
The California configuration may not appear when testing from another location.
Step 6: Preserve Evidence and Keep Monitoring
Preserve dated evidence showing how the website behaved during testing.
Screenshots and screen recordings are recommended. Network logs and exported test results provide additional technical evidence.
The records should identify:
- The date of the test
- The location used for testing
- The browser and device
- The pages and interactions reviewed
- The consent state being tested
- The network activity observed
- The banner and configuration versions
- Problems found and corrected
A website that was properly configured in January is not automatically properly configured in June.
Every new application, plugin, theme update, embedded service, marketing campaign, or tag-manager change can introduce a tracker.
Re-test whenever tracking technology changes. Also perform scheduled checks of the live website.
Update the tracker inventory whenever a technology is added, removed, or reconfigured.
Follow Best Practices
No configuration makes litigation impossible given the uncertain legal landscape.
However, you can greatly reduce your risk of being sued by following the steps above and documenting your efforts.
Accessible.org provides manual services to ensure you not only follow CIPA best practices, but also ensure all implementation is WCAG conformant. Contact us for a CIPA audit and corrective privacy tracking services.