CIPA & Website Tracking Litigation: A Working Resource for E‑Commerce Businesses

Last updated: July 19, 2026. This is a living resource — we update it as the case law and legislation move. Check the date above for currency.

The short version

The California Invasion of Privacy Act (CIPA) — a 1960s wiretapping statute — has become the engine behind a wave of class actions and demand letters aimed at ordinary website technology: chat widgets, session‑replay tools, advertising pixels, and analytics software. If your site uses Meta Pixel, a live‑chat vendor, session recording, or third‑party trackers, you are in the target zone.

As of mid‑2026 the law is genuinely unsettled and moving in more than one direction at once. California state trial courts have started reining in the most aggressive theory (pen register / trap‑and‑trace), federal courts are tightening standing and class certification, yet plaintiffs are still extracting real settlements. A pending bill, SB 690, could reshape the whole landscape. Below is our read on where things stand and what it means operationally. We keep this page current because our clients ask these questions weekly.

What CIPA actually is, and why e‑commerce is the target

CIPA is California's two‑party‑consent wiretap law. Three provisions drive most website litigation:

Section 631 — the classic anti‑wiretapping provision. Plaintiffs argue that when a third‑party vendor (a chat provider, a session‑replay tool, an ad tech pixel) receives visitor data in real time, it is an unlawful "interception" of a communication. This is the theory behind most chatbot and session‑replay suits.

Section 632.7 — targets recording of communications involving cellular or cordless phones; it surfaces in call‑recording and some mobile contexts.

Sections 638.50–638.51 — the pen register / trap‑and‑trace ("PR/TT") provisions. This is the newer and more aggressive theory: plaintiffs contend that software capturing a visitor's IP address, device data, or routing information is an unlawful "pen register." Because CIPA carries statutory damages of $5,000 per violation and a private right of action, even a modest website can face enormous theoretical exposure — which is precisely why the plaintiffs' bar has leaned in.

The practical pattern is familiar: a demand letter arrives citing CIPA and a laundry list of the trackers detected on your site, followed by a settlement demand pitched below the cost of defense.

Where the law stands in mid‑2026

The single most important thing to understand is that there is no settled answer right now — there is a split, and it runs along a state‑court / federal‑court line as well as within the Ninth Circuit itself.

California state trial courts are narrowing the pen‑register theory. In Blalock v. EquipmentShare.com, an Orange County court sustained a demurrer without leave to amend, holding that CIPA's pen register/trap‑and‑trace provisions are limited to telephones and do not reach ordinary web analytics — rejecting the expansive reading that had fueled the PR/TT wave. A Los Angeles County court reached a similar result in the NetScout Systems matter, dismissing a §638.51 claim with prejudice on the ground that the statute applies to telephone communications, not website software. For e‑commerce defendants sued in California state court, these are useful demurrer authorities.

Federal courts are mixed — skeptical on some fronts, still open on others. In Stroble v. Laird Superfood, a federal court in the Central District of California dismissed a §631 claim because the plaintiff could not plead a concrete privacy injury — the intercepted information was ordinary browsing data, not private or sensitive material. In the In re Meta Pixel Tax Filing Cases litigation, a Northern District of California court denied class certification, with the one‑year limitations period and individualized data questions defeating the predominance required for a class. Both decisions give defendants real tools: a standing attack on the front end and a class‑certification attack on the back end.

But exposure is still live. In Mirmalek v. Los Angeles Times Communications, a federal court granted final approval to a $3.85 million class settlement built on the §638.51 pen‑register theory tied to third‑party advertising trackers. So even as some courts narrow the theory, others continue to let it reach settlement value. Treating CIPA claims as harmless would be a mistake.

The appellate backdrop. The Ninth Circuit has its own unresolved tension between decisions that are more defense‑friendly on §631 chat claims and decisions that have revived §631 session‑replay theories. Until that is squarely resolved, outcomes will continue to vary by courtroom and by the specific technology at issue.

Legislative watch: SB 690

The biggest potential change is not in the courts. California SB 690 would narrow the pen register/trap‑and‑trace provisions and, critically, curtail the private right of action that makes these cases economically attractive to file. It advanced out of Assembly committee in July 2026. If it passes in a form that strips the private right of action for these web‑tracking theories, it would substantially deflate the current litigation wave. We are tracking it closely and will update this page as it moves.

What this means for your business

None of this is legal advice for your specific situation, but the practical throughline is consistent:

Re‑audit what is actually running on your site. Most demand letters begin with an automated scan of your trackers. Know what you have — chat tools, session replay, pixels, analytics SDKs — and why.

Get consent architecture right. A properly implemented consent banner and disclosure, calibrated to the tools you run, is one of the strongest defenses and the cheapest to put in place before a claim arrives.

Look hard at your vendor contracts. Whether a third‑party tool is acting as your service provider or as an independent recipient of data can be dispositive under the §631 "party exception." The contract language matters.

Consider arbitration and consent design. Well‑drafted terms of use with arbitration and class‑action‑waiver provisions can change the economics of a claim significantly.

Do not overpay a demand letter — but do not ignore it either. Given the growing body of dismissals, many CIPA demands are more negotiable than they present. But federal pixel exposure remains real, and the right response depends on the technology, the forum, and your posture.

If you have received a CIPA demand letter

Do not respond substantively or make representations about your technology before counsel reviews it. Preserve the relevant records. Identify the specific trackers and the vendor relationships behind them. Then assess the claim against the current state of the law in the likely forum — which, as the cases above show, can point in very different directions depending on where and how the claim is brought.

Frequently asked questions about CIPA

Is a website pixel or session‑replay tool illegal under CIPA?
Not inherently. Liability turns on the specific technology, how data flows to third parties, what consent you obtained, and — increasingly — whether the plaintiff can show a concrete privacy injury. Courts in 2026 are reaching different answers on similar facts.

What is the "pen register" theory?
It is the argument that software capturing a visitor's IP address, device, or routing data is an unlawful pen register or trap‑and‑trace device under CIPA §§638.50–638.51. California state courts have recently pushed back on stretching a telephone‑era statute to cover website analytics, but the theory is not dead, especially in federal court.

How much is a CIPA claim worth?
CIPA authorizes statutory damages of $5,000 per violation, which is what makes class exposure large on paper. Real‑world value depends heavily on class certification, standing, and forum — all of which are contested right now.

Does this only affect California companies?
No. CIPA can reach businesses whose sites are used by California residents. Given California’s size—nearly everyone is implicated. Comparable two‑party‑consent wiretap statutes in states such as Pennsylvania, Florida, Washington, and Illinois, plus federal wiretap and video‑privacy theories, raise parallel risk nationally.

Will SB 690 make this go away?
Possibly for the pen‑register theory, if it passes and strips the private right of action. It is not law yet. We are watching it.

About this resource

I represent e‑commerce and technology businesses facing CIPA and web‑tracking privacy exposure — from proactive consent and vendor‑contract audits to responding to demand letters and defending class claims. We maintain this page as a practical, regularly updated reference because the law here changes faster than most published commentary keeps up with. If you have a question about your own site or a letter you have received, contact me, Jonathan L.A. Phillips, jphillips@bhslaw.com

This article is attorney advertising and general information, not legal advice, and does not create an attorney‑client relationship. Case descriptions reflect our reading of developments as of the update date and should be confirmed against primary sources before relying on them. Prior results do not guarantee a similar outcome.

Next
Next

Texts Are Not "Calls": A Big Win for SMS Marketers (With Fine Print)