July 31st, 2026
Your Website Tracking Technology Might Violate The California Invasion of Privacy Act
If your business has a website and does not require visitors to “opt-in” to cookies and other tracking technology, you may receive a letter from someone in California threatening to file a lawsuit under the California Invasion of Privacy Act (CIPA); yes, even against Tri-State area businesses.
CIPA was first enacted almost 60 years ago to safeguard California residents’ confidential conversations and personal information from being intercepted and recorded without consent. It first banned wiretapping, eavesdropping, or recording private communications, as well as the use of pen register or tap and trace devices that capture dialing, routing, addressing, or signaling information. However, with the evolution of the Internet and cookies or other tracking technologies, California residents have taken to the courts, applying CIPA’s “pen register” and “tap and trace devices” to a wide variety of tracking technologies used in most modern websites. Thus, the current theory pursued by California residents is that when they visit a website and tracking technology captures information from that visit, CIPA applies to the California-facing communication, regardless of where the business is physically located or the market it serves. Because of CIPA’s broad application, businesses of all sizes have been sued or threatened with litigation in California, including those in the Tri-State area.
Since nearly every modern business operates a website, understanding how California courts are currently interpreting CIPA is one of many considerations in effective privacy risk management.
Ignoring any criminal remedies, and at a minimum, individuals may recover the greater of $5,000 per violation or three times the actual damages, punitive damages, treble damages, and attorneys’ fees and costs.
California courts have found that a California resident need not allege any actual damages (usually a requirement to initiate a lawsuit) to bring a CIPA claim—the unauthorized invasion of privacy is, in itself, a sufficient injury. And at least for now, those courts have allowed most of these claims to proceed past the initial dismissal stage, even though businesses have tried (and sometimes lost) the argument that “pen register” and “tap and trace devices” referred to information gleaned from telephone numbers, not internet communications on websites.
While businesses are starting to gain some traction and obtain favorable rulings, California courts remain divided on the scope and application of CIPA, and ultimately, appellate guidance or legislative action likely will be necessary before the CIPA claims calm.
So, what can you do? Be proactive and review your website and/or consult with your website designer to determine if website visitors must “opt-in” and consent to tracking technologies, session replays, chat boxes, and other technologies prior to data collection; maintain accurate privacy policies; review CIPA’s text; and monitor the legislative interpretation of CIPA that may clarify exemptions for basic business tools.