CIPA & Website Tracking Litigation: A Working Resource for E‑Commerce Businesses
Last updated: July 27, 2026. This is a living resource — we update it as the case law and legislation move. Check the date above for currency.
The short version
The California Invasion of Privacy Act (CIPA) — a 1960s wiretapping statute — has become the engine behind a wave of class actions and demand letters aimed at ordinary website technology: chat widgets, session‑replay tools, advertising pixels, and analytics software. If your site uses Meta Pixel, a live‑chat vendor, session recording, or third‑party trackers, you are in the target zone.
As of mid‑2026 the law is genuinely unsettled and moving in more than one direction at once. California state trial courts have started reining in the most aggressive theory (pen register / trap‑and‑trace), federal courts are tightening standing and class certification, and — new this month — courts have begun pushing back directly on the serial plaintiffs who drive much of this litigation. Yet plaintiffs are still extracting real settlements, and the bill that could reset the whole landscape, SB 690, has stalled. Below is our read on where things stand and what it means operationally. We keep this page current because our clients ask these questions weekly.
What CIPA actually is, and why e‑commerce is the target
CIPA is California's two‑party‑consent wiretap law. Three provisions drive most website litigation:
Section 631 — the classic anti‑wiretapping provision. Plaintiffs argue that when a third‑party vendor (a chat provider, a session‑replay tool, an ad tech pixel) receives visitor data in real time, it is an unlawful "interception" of a communication. This is the theory behind most chatbot and session‑replay suits.
Section 632.7 — targets recording of communications involving cellular or cordless phones; it surfaces in call‑recording and some mobile contexts.
Sections 638.50–638.51 — the pen register / trap‑and‑trace ("PR/TT") provisions. This is the newer and more aggressive theory: plaintiffs contend that software capturing a visitor's IP address, device data, or routing information is an unlawful "pen register." Because CIPA carries statutory damages of $5,000 per violation and a private right of action, even a modest website can face enormous theoretical exposure — which is precisely why the plaintiffs' bar has leaned in.
The practical pattern is familiar: a demand letter arrives citing CIPA and a laundry list of the trackers detected on your site, followed by a settlement demand pitched below the cost of defense.
Where the law stands in mid‑2026
The single most important thing to understand is that there is no settled answer right now — there is a split, and it runs along a state‑court / federal‑court line as well as within the Ninth Circuit itself.
California state trial courts are narrowing the pen‑register theory. In Blalock v. EquipmentShare.com, an Orange County court sustained a demurrer without leave to amend, holding that CIPA's pen register/trap‑and‑trace provisions are limited to telephones and do not reach ordinary web analytics — rejecting the expansive reading that had fueled the PR/TT wave. A Los Angeles County court reached a similar result in Blaker v. NetScout Systems, dismissing a §638.51 claim with prejudice on the ground that the statute applies to telephone communications, not website software. For e‑commerce defendants sued in California state court, these are useful demurrer authorities.
Federal courts are mixed — skeptical on some fronts, still open on others. In Schallert v. Laird Superfood, a federal court in the Central District of California dismissed a §631 claim because the plaintiff could not plead a concrete privacy injury — the intercepted information was ordinary browsing data, not private or sensitive material. In the In re Meta Pixel Tax Filing Cases litigation, a Northern District of California court denied class certification, with the one‑year limitations period and individualized data questions defeating the predominance required for a class. And in In re Meta Android Privacy Litigation (N.D. Cal., May 2026), the court dismissed a §638.51 pen‑register claim as too conclusory — the plaintiffs alleged the Meta Pixel captured IP addresses but never explained how or when. Read the fine print on that last one, though: the same court said IP‑address capture can fall within the pen‑register statute if a plaintiff pleads it with specificity, so it is a win on how the complaint was written, not a ruling that pixels are safe. Together these decisions give defendants real tools: a standing attack on the front end, a pleading‑specificity attack in the middle, and a class‑certification attack on the back end.
Courts are starting to push back on the serial filers themselves. This is the most notable development of the past few weeks. On July 20, 2026, a federal judge in the Central District of California declared a prolific CIPA plaintiff a vexatious litigant in Vivek Shah v. Crain Communications, entering a pre‑filing order that requires him to obtain the court's permission before filing any new CIPA or digital‑privacy suit in that district. The court built the order on a record of at least 29 filings since 2021 — including seven nearly identical CIPA complaints in the preceding seven months — that the plaintiff routinely dropped the moment a defendant moved to dismiss, a pattern the court found was designed "to harass defendants into coercive settlements." The order is narrow (it does not reach other courts or dismiss pending cases), but it is a roadmap: a defendant willing to compile a repeat filer's full litigation history can hand a court exactly what it needs, and in California state court a prior vexatious‑litigant finding on similar facts is an independent ground to seek the same relief.
And some businesses are no longer waiting to be sued. In Lofty, Inc. v. Shah (C.D. Cal., filed July 8, 2026), a company that received a CIPA demand letter went to federal court first, asking for a declaration that its ordinary website analytics are lawful and that the plaintiff lacks standing. There is no ruling yet, and it is not the right move in every case, but filing first lets a company choose the timing, forum, and framing of the fight instead of ceding all three to whoever mailed the letter. It is now a live option worth discussing with counsel.
But exposure is still live. In Mirmalek v. Los Angeles Times Communications, a federal court granted final approval to a $3.85 million class settlement built on the §638.51 pen‑register theory tied to third‑party advertising trackers. So even as some courts narrow the theory and rein in repeat filers, others continue to let these cases reach settlement value. Treating CIPA claims as harmless would be a mistake.
The appellate backdrop. The Ninth Circuit has its own unresolved tension between decisions that are more defense‑friendly on §631 chat claims and decisions that have revived §631 session‑replay theories. Until that is squarely resolved, outcomes will continue to vary by courtroom and by the specific technology at issue.
Legislative watch: SB 690
The biggest potential change is not in the courts. California SB 690 would narrow the pen register/trap‑and‑trace provisions and, critically, curtail the private right of action that makes these cases economically attractive to file — shifting enforcement of the web‑tracking theory to the Attorney General. It cleared the Assembly Privacy and Consumer Protection Committee on July 1, 2026, but it has since stalled: it was re‑referred to the Assembly Appropriations Committee and has not reached a floor vote. Both chambers must pass it by the end of August 2026 or it dies for the session. As one defense firm put it, "CIPA liability remains at least through 2026." And even if SB 690 passes, it would touch only the pen‑register theory — the separate Section 631 wiretap claims would be untouched. We are tracking it closely and will update this page as it moves.
What this means for your business
None of this is legal advice for your specific situation, but the practical throughline is consistent:
Re‑audit what is actually running on your site. Most demand letters begin with an automated scan of your trackers. Know what you have — chat tools, session replay, pixels, analytics SDKs — and why.
Get consent architecture right. A properly implemented consent banner and disclosure, calibrated to the tools you run, is one of the strongest defenses and the cheapest to put in place before a claim arrives.
Look hard at your vendor contracts. Whether a third‑party tool is acting as your service provider or as an independent recipient of data can be dispositive under the §631 "party exception." The contract language matters.
Consider arbitration and consent design. Well‑drafted terms of use with arbitration and class‑action‑waiver provisions can change the economics of a claim significantly.
Know your options if a repeat filer targets you. If the letter comes from a prolific plaintiff, their own litigation history may be a defense — and in the right case, filing first for a declaratory judgment can put you on the front foot.
Do not overpay a demand letter — but do not ignore it either. Given the growing body of dismissals, many CIPA demands are more negotiable than they present. But federal pixel exposure remains real, and the right response depends on the technology, the forum, and your posture.
If you have received a CIPA demand letter
Do not respond substantively or make representations about your technology before counsel reviews it. Preserve the relevant records. Identify the specific trackers and the vendor relationships behind them. If the sender is a serial filer, pull their litigation history — it increasingly matters. Then assess the claim against the current state of the law in the likely forum — which, as the cases above show, can point in very different directions depending on where and how the claim is brought.
Frequently asked questions about CIPA
Is a website pixel or session‑replay tool illegal under CIPA? Not inherently. Liability turns on the specific technology, how data flows to third parties, what consent you obtained, and — increasingly — whether the plaintiff can show a concrete privacy injury. Courts in 2026 are reaching different answers on similar facts.
What is the "pen register" theory? It is the argument that software capturing a visitor's IP address, device, or routing data is an unlawful pen register or trap‑and‑trace device under CIPA §§638.50–638.51. California state courts have recently pushed back on stretching a telephone‑era statute to cover website analytics, but the theory is not dead, especially in federal court — and at least one federal court has said IP‑address capture can qualify if it is pleaded with enough specificity.
How much is a CIPA claim worth? CIPA authorizes statutory damages of $5,000 per violation, which is what makes class exposure large on paper. Real‑world value depends heavily on class certification, standing, and forum — all of which are contested right now.
A serial plaintiff keeps filing these suits. Can anything be done? Sometimes, yes. In July 2026 a federal court declared a prolific CIPA plaintiff a vexatious litigant and required him to get permission before filing new privacy suits in that district. It takes work — a defendant has to compile the plaintiff's full filing history — but courts will act on a documented pattern of file‑and‑dismiss litigation, and the findings can carry over to other courts.
Does this only affect California companies? No. CIPA can reach businesses whose sites are used by California residents. Given California's size — nearly everyone is implicated. Comparable two‑party‑consent wiretap statutes in states such as Pennsylvania, Florida, Washington, and Illinois, plus federal wiretap and video‑privacy theories, raise parallel risk nationally.
Will SB 690 make this go away? Possibly for the pen‑register theory, if it passes and strips the private right of action. But it has stalled in the Assembly and is not law yet, and it would not touch the Section 631 wiretap theory. We are watching it.
About this resource
I represent e‑commerce and technology businesses facing CIPA and web‑tracking privacy exposure — from proactive consent and vendor‑contract audits to responding to demand letters and defending class claims. We maintain this page as a practical, regularly updated reference because the law here changes faster than most published commentary keeps up with. If you have a question about your own site or a letter you have received, contact me, Jonathan L.A. Phillips, jphillips@bhslaw.com
This article is attorney advertising and general information, not legal advice, and does not create an attorney‑client relationship. Case descriptions reflect our reading of developments as of the update date and should be confirmed against primary sources before relying on them. Prior results do not guarantee a similar outcome.###
Prior Versions:
Last updated: July 19, 2026. This is a living resource — we update it as the case law and legislation move. Check the date above for currency.
The short version
The California Invasion of Privacy Act (CIPA) — a 1960s wiretapping statute — has become the engine behind a wave of class actions and demand letters aimed at ordinary website technology: chat widgets, session‑replay tools, advertising pixels, and analytics software. If your site uses Meta Pixel, a live‑chat vendor, session recording, or third‑party trackers, you are in the target zone.
As of mid‑2026 the law is genuinely unsettled and moving in more than one direction at once. California state trial courts have started reining in the most aggressive theory (pen register / trap‑and‑trace), federal courts are tightening standing and class certification, yet plaintiffs are still extracting real settlements. A pending bill, SB 690, could reshape the whole landscape. Below is our read on where things stand and what it means operationally. We keep this page current because our clients ask these questions weekly.
What CIPA actually is, and why e‑commerce is the target
CIPA is California's two‑party‑consent wiretap law. Three provisions drive most website litigation:
Section 631 — the classic anti‑wiretapping provision. Plaintiffs argue that when a third‑party vendor (a chat provider, a session‑replay tool, an ad tech pixel) receives visitor data in real time, it is an unlawful "interception" of a communication. This is the theory behind most chatbot and session‑replay suits.
Section 632.7 — targets recording of communications involving cellular or cordless phones; it surfaces in call‑recording and some mobile contexts.
Sections 638.50–638.51 — the pen register / trap‑and‑trace ("PR/TT") provisions. This is the newer and more aggressive theory: plaintiffs contend that software capturing a visitor's IP address, device data, or routing information is an unlawful "pen register." Because CIPA carries statutory damages of $5,000 per violation and a private right of action, even a modest website can face enormous theoretical exposure — which is precisely why the plaintiffs' bar has leaned in.
The practical pattern is familiar: a demand letter arrives citing CIPA and a laundry list of the trackers detected on your site, followed by a settlement demand pitched below the cost of defense.
Where the law stands in mid‑2026
The single most important thing to understand is that there is no settled answer right now — there is a split, and it runs along a state‑court / federal‑court line as well as within the Ninth Circuit itself.
California state trial courts are narrowing the pen‑register theory. In Blalock v. EquipmentShare.com, an Orange County court sustained a demurrer without leave to amend, holding that CIPA's pen register/trap‑and‑trace provisions are limited to telephones and do not reach ordinary web analytics — rejecting the expansive reading that had fueled the PR/TT wave. A Los Angeles County court reached a similar result in the NetScout Systems matter, dismissing a §638.51 claim with prejudice on the ground that the statute applies to telephone communications, not website software. For e‑commerce defendants sued in California state court, these are useful demurrer authorities.
Federal courts are mixed — skeptical on some fronts, still open on others. In Stroble v. Laird Superfood, a federal court in the Central District of California dismissed a §631 claim because the plaintiff could not plead a concrete privacy injury — the intercepted information was ordinary browsing data, not private or sensitive material. In the In re Meta Pixel Tax Filing Cases litigation, a Northern District of California court denied class certification, with the one‑year limitations period and individualized data questions defeating the predominance required for a class. Both decisions give defendants real tools: a standing attack on the front end and a class‑certification attack on the back end.
But exposure is still live. In Mirmalek v. Los Angeles Times Communications, a federal court granted final approval to a $3.85 million class settlement built on the §638.51 pen‑register theory tied to third‑party advertising trackers. So even as some courts narrow the theory, others continue to let it reach settlement value. Treating CIPA claims as harmless would be a mistake.
The appellate backdrop. The Ninth Circuit has its own unresolved tension between decisions that are more defense‑friendly on §631 chat claims and decisions that have revived §631 session‑replay theories. Until that is squarely resolved, outcomes will continue to vary by courtroom and by the specific technology at issue.
Legislative watch: SB 690
The biggest potential change is not in the courts. California SB 690 would narrow the pen register/trap‑and‑trace provisions and, critically, curtail the private right of action that makes these cases economically attractive to file. It advanced out of Assembly committee in July 2026. If it passes in a form that strips the private right of action for these web‑tracking theories, it would substantially deflate the current litigation wave. We are tracking it closely and will update this page as it moves.
What this means for your business
None of this is legal advice for your specific situation, but the practical throughline is consistent:
Re‑audit what is actually running on your site. Most demand letters begin with an automated scan of your trackers. Know what you have — chat tools, session replay, pixels, analytics SDKs — and why.
Get consent architecture right. A properly implemented consent banner and disclosure, calibrated to the tools you run, is one of the strongest defenses and the cheapest to put in place before a claim arrives.
Look hard at your vendor contracts. Whether a third‑party tool is acting as your service provider or as an independent recipient of data can be dispositive under the §631 "party exception." The contract language matters.
Consider arbitration and consent design. Well‑drafted terms of use with arbitration and class‑action‑waiver provisions can change the economics of a claim significantly.
Do not overpay a demand letter — but do not ignore it either. Given the growing body of dismissals, many CIPA demands are more negotiable than they present. But federal pixel exposure remains real, and the right response depends on the technology, the forum, and your posture.
If you have received a CIPA demand letter
Do not respond substantively or make representations about your technology before counsel reviews it. Preserve the relevant records. Identify the specific trackers and the vendor relationships behind them. Then assess the claim against the current state of the law in the likely forum — which, as the cases above show, can point in very different directions depending on where and how the claim is brought.
Frequently asked questions about CIPA
Is a website pixel or session‑replay tool illegal under CIPA?
Not inherently. Liability turns on the specific technology, how data flows to third parties, what consent you obtained, and — increasingly — whether the plaintiff can show a concrete privacy injury. Courts in 2026 are reaching different answers on similar facts.
What is the "pen register" theory?
It is the argument that software capturing a visitor's IP address, device, or routing data is an unlawful pen register or trap‑and‑trace device under CIPA §§638.50–638.51. California state courts have recently pushed back on stretching a telephone‑era statute to cover website analytics, but the theory is not dead, especially in federal court.
How much is a CIPA claim worth?
CIPA authorizes statutory damages of $5,000 per violation, which is what makes class exposure large on paper. Real‑world value depends heavily on class certification, standing, and forum — all of which are contested right now.
Does this only affect California companies?
No. CIPA can reach businesses whose sites are used by California residents. Given California’s size—nearly everyone is implicated. Comparable two‑party‑consent wiretap statutes in states such as Pennsylvania, Florida, Washington, and Illinois, plus federal wiretap and video‑privacy theories, raise parallel risk nationally.
Will SB 690 make this go away?
Possibly for the pen‑register theory, if it passes and strips the private right of action. It is not law yet. We are watching it.
About this resource
I represent e‑commerce and technology businesses facing CIPA and web‑tracking privacy exposure — from proactive consent and vendor‑contract audits to responding to demand letters and defending class claims. We maintain this page as a practical, regularly updated reference because the law here changes faster than most published commentary keeps up with. If you have a question about your own site or a letter you have received, contact me, Jonathan L.A. Phillips, jphillips@bhslaw.com
This article is attorney advertising and general information, not legal advice, and does not create an attorney‑client relationship. Case descriptions reflect our reading of developments as of the update date and should be confirmed against primary sources before relying on them. Prior results do not guarantee a similar outcome.