The CIPA Lawsuit Tracker
ON THIS PAGE
California's Invasion of Privacy Act (CIPA) is an old wiretapping law that requires consent to record or intercept confidential communications. While originally enacted to stop landline wiretapping, courts now apply it broadly to modern digital communications, including website cookies, tracking pixels, session replay software, and chat widgets.
The Digital Wiretapping Litigation Map maintained by the law firm Fisher Phillips tracks the surge of lawsuits filed under CIPA. It monitors class actions and demand letters involving digital tracking technologies.
Read this blog to learn more about CIPA website tracking, CIPA compliance, and recent tracking pixel lawsuits.
What Is CIPA: a Short Overview
The California Invasion of Privacy Act (CIPA) was enacted in 1967. It was originally intended to prevent wiretapping and the unauthorized recording of conversations, particularly over the phone. In 2026, the Act is being used for digital communication means.
The law mandates all-party consent, which means everyone involved in a communication must consent before it can be intercepted or recorded.
In recent years, CIPA has been used for digital wiretapping. Plaintiffs frequently file CIPA lawsuits alleging that third-party analytics or marketing tools, such as website cookies, tracking pixels, session replay tools, or chat transcripts, intercept their website interactions without clear user consent.
CIPA is stricter than federal laws: It doesn't focus on categories of personal data. Under CIPA, the act of capturing the interaction itself, not the type of data collected, often triggers potential liability. These are much higher requirements.
Note that the law has extraterritorial reach: even if your company has headquarters outside of California, CIPA applies if you do business with or record individuals located in California.
Legal notice: This article provides general information and is not legal advice. CIPA litigation is evolving, and businesses should consult qualified legal counsel about their specific websites and recent tracking practices.
The CIPA Lawsuit Tracker: What Website Owners Need to Know
For website owners, the key lesson is simple: installing a valid Cookie Banner is not enough. The banner, tracking scripts, consent settings, privacy disclosures, and technical implementation must work as a unified consent management system.
CIPA is not specifically a cookie law. It’s an old wiretapping law that has been since 1967. However, plaintiffs and courts are now applying CIPA to modern digital communications.
In recent years, website tracking has become a major source of privacy litigation in California. Technologies that businesses routinely use for analytics, advertising, customer support, and conversion optimization are being challenged under the Act.
California Penal Code Section 631 prohibits tapping, unauthorized connection, and reading or learning the contents of communications while they are in transit without the consent of all parties.
Consent obtained only after tracking technologies have already recorded a visitor’s interactions may not be valid.
The Act originally refers to communications passing over a wire, line, or cable or being sent from or received in California. Courts have interpreted Section 631 as potentially applying to internet communications, even though the law was written decades before modern websites existed.
The CIPA lawsuit tracker provides a comprehensive view of digital privacy litigation issues filed across all fifty U.S. states.
CIPA Section 638.51 regulates pen registers and trap-and-trace devices.
Plaintiffs have argued that software collecting IP addresses, device identifiers, routing data, URLs, and similar information can qualify as pen devices that are not allowed to be used without all-party consent.
CIPA is a powerful tool for class-action lawsuits because it contains a private right of action. Website users who believe that their privacy rights are violated can sue for:
- $5,000 per violation; or
- Three times their actual damage, whichever is greater.
This makes CIPA claims attractive for proposed class actions involving large numbers of website visitors.
Why CIPA Lawsuits Are Increasing
CIPA website litigation is increasing because of widely used third-party tracking technologies, legal strategy, weak consent implementation, and unsettled case law.
In 2026, websites increasingly rely on modern analytics and tracking tools, such as cookies, tracking pixels, session replay software, and chat widgets. Plaintiffs argue that these technologies directly violate CIPA.
Weak consent mechanism implementation could also lead to CIPA lawsuits.
1. Widespread use of third-party tracking technologies
A modern website may load dozens of third-party tools, used for analytics, marketing, attribution, profiling, or advertising, including ad-tracking pixels, analytics software, embedded videos, heatmaps, live chat, A/B testing tools, payment integrations, lead-generation forms, and session replay.
Each integration may collect user Personal Information, including:
- IP addresses;
- Browser/device identifiers;
- URLs and referring pages;
- Mouse movements, clicks, and scrolling behavior;
- Information entered into forms;
- Account or advertising identifiers;
- Chat messages and customer-support interactions;
- Shopping, browsing, or appointment activity.
The main concern when using third-party tracking technologies and CIPA website tracking is that third-party scripts may collect or transmit information before the visitor has been properly informed or given a meaningful choice.
For example, session replay lawsuits make up a significant amount of CIPA lawsuits.
Not sure if your website uses cookies and tracks users without obtaining Cookie Consent? Scan your website for free and see what cookies, including Third-Party Cookies, your website uses:
2. Plaintiffs are applying older laws to modern tracking
California's Invasion of Privacy Act is an old wiretapping law, enacted to stop landline wiretapping. Nevertheless, courts have recognized that some of its provisions can apply to modern digital communications.
This has encouraged plaintiffs to treat common website technologies as pen registers. Pen-register claims have expanded the focus from the contents of communication to addressing, routing, and identification information.
3. The case law is unsettled
California state and federal courts have taken different approaches to CIPA’s pen register provisions. State trial courts have increasingly ruled that website tracking technologies fall outside these restrictions, while federal courts in California have generally reached the opposite conclusion.
Since no California appellate court has yet settled the issue, federal judges are not required to follow state trial court decisions. As a result, the legal landscape remains divided, and case outcomes are hard to predict.
4. Weak consent implementation
A Cookie Banner is not equal to the right consent implementation. The banner, tracking scripts, consent settings, privacy disclosures, and technical implementation must work together as a unified consent management system.
One common issue is that tracking can begin before the visitor sees or accepts a banner.
A website may display a privacy notice and ask for a Cookie Consent while third-party scripts are already running in the background and collecting user information. This is a direct violation of data privacy laws.
Tracking scripts must actually be blocked before users give consent.
Another CIPA compliance issue arises when consent and privacy disclosures become inconsistent.
Businesses frequently update their marketing technologies without updating their privacy notices on the banner or privacy policies.
For example, a marketing team might add a new pixel through Google Tag Manager without updating the cookie declaration table.
In other cases, the Privacy Policy may mention “analytics partners” without disclosing these partners and without identifying what data is collected and for what reasons.
CIPA cases increasingly examine actual website behavior and whether it corresponds to the Privacy Policy.
To comply with CIPA, review all third-party tags, pixels, analytics tools, tag managers, booking tools, chat widgets, and marketing platforms to confirm whether any of them load before consent.
Use CookieScript Consent Management Platform (CMP) for consent management and compliance with CIPA.
CookieScript can help in several practical ways:
- Cookie and tracker scanning
CookieScript can scan the website to identify cookies, trackers, scripts, and third-party services that may be present on the site. This helps to know which vendors are active and what categories they belong to. - Prior blocking of non-essential scripts
CookieScript automatically blocks all Third-Party Cookies and scripts. This can help prevent analytics, marketing, advertising, and profiling tools from running before the visitor gives consent or makes the required privacy choice. - Geo-targeting
The geo-targeting feature allows websites to detect the user location. Based on the corresponding jurisdiction, the correct cookie banner could be displayed. - California-specific banner setup
For California visitors, CookieScript can be configured to display a region-specific privacy banner, including options such as “Do Not Sell or Share” where applicable. This helps separate California privacy requirements from EU-style GDPR consent flows. - Global Privacy Control support
CookieScript supports GPC signals, which are especially relevant for California privacy compliance. When a visitor has GPC enabled, the banner can respect that opt-out signal according to the configured settings. - Consent and opt-out records
CookieScript can record user consent choices. This can be useful for internal audits or legal review, helping to demonstrate what cookie options were shown to visitors and what choice the visitor made. - Better disclosure and vendor transparency
CookieScript can help maintain a Cookie Policy and vendor/category information so visitors can better understand which technologies are used and for what purpose.
In 2025, CookieScript received its fourth consecutive badge in a row as the leader on G2, a peer review site, and became the best CMP on the market for a whole year!
CIPA Lawsuit Tracker: Recent Cases
The Digital Wiretapping Litigation Map maintained by the law firm Fisher Phillips provides a comprehensive view of digital privacy litigation matters filed across all U.S. states under CIPA. It monitors class actions and demand letters involving digital tracking technologies, such as cookies, pixels, and beacons, embedded in websites, apps, or marketing emails.
As of end of July 2026, there are 3.968 cases in California, followed by Florida (811 cases) and Illinois (108 cases).
The most targeted industry is retail (1817 cases), followed by technology (542 cases) and professional and technical services (447 cases).
The CIPA litigation landscape is not uniform. The cases are different. Outcomes depend on the technology, information collected, timing of consent, nature of the third party, sensitivity of Personal Information, allegations of harm, and the court hearing the case. There are many tracking pixel lawsuits, but session replay lawsuits are becoming more common as well.
The following developments illustrate the most prominent recent cases and the technologies in use.
1. Mirmalek v. Los Angeles Times Communications LLC (June 2026)
A federal court granted final approval to a $3.85 million class action settlement targeting the LA Times over third-party trackers, such as TripleLift, GumGum, and Audiencerate, that allegedly captured user interactions and metadata under CIPA’s pen register claims (§ 638.51).
Technology used: Pixel-tracking.
Why it’s important: It demonstrates that pen register claims for targeting routing data, IP addresses, and device metadata rather than direct message content carry severe multi-million-dollar class action exposure for mainstream publishers and digital platforms.
2. Javier v. Assurance IQ (2019)
Javier v. Assurance IQ is a landmark digital privacy case that fundamentally reshaped how businesses handle user consent under the CIPA.
In 2019, Florentino Javier visited Assurance IQ’s website to get an online life insurance quote. The website utilized third-party session-replay software (provided by ActiveProspect) that secretly recorded his keystrokes, mouse clicks, and personal data entry in real time from the moment he landed on the page. At the very end of the questionnaire, Javier clicked a button to "View My Quote," which was paired with a notice stating that clicking the button constituted agreement to the site’s Privacy Policy, containing disclosure of the tracking.
Javier filed a class action complaint against Assurance and ActiveProspect, alleging that recording his actions before he agreed to the Privacy Policy violated Section 631(a) of the CIPA.
Technology used: Form and session recording.
Why it’s important: The Ninth Circuit's 2022 ruling acted as the primary catalyst for thousands of CIPA class action lawsuits targeting website operators using session-replay tools, tracking pixels, and chat widgets. It established the rule that website consent mechanisms must block trackers before any data collection or recording starts.
3. Popa v. Microsoft (2025)
Ashley Popa visited a pet supply website that used Microsoft’s Clarity session-replay software. The tool recorded her mouse movements, clicks, and navigation. She filed a class action alleging that capturing her digital interactions without explicit consent violated wiretap laws and common-law privacy rights.
The court ruled that tracking routine website interactions is not highly offensive and bears no close historical analog to traditional common-law privacy torts like intrusion upon seclusion.
Technology used: Session replay.
Why it’s important: Based on this case, federal courts routinely throw out class actions targeting website pixels, chat tools, and cookies if the plaintiffs fail to prove that genuinely sensitive, embarrassing, or private information was intercepted. Federal courts argue that a technical data transfer alone is not enough to win the court. Session replay lawsuits are becoming more common.
4. Conner v. Toyota Motor Corp. (2026)
A class action filed against Toyota alleging that the automaker continued to deploy tracking technology and fingerprinting tools on visitors to Toyota.com even after users explicitly declined cookies on the Cookie Consent banner.
Technology used: Moving beyond standard social media pixels, Toyota used advanced behavioral tracking and device fingerprinting.
Why it’s important: This case highlights the evolution of a broken banner and post-opt-out tracking litigation. The case targets advanced behavioral tracking and device fingerprinting used when traditional cookies are rejected, dragging major non-tech enterprises, such as automotive brands, directly into the CIPA investigations.
5. Fregosa v. Mashable (2025)
Dawn Fregosa filed a class action lawsuit against digital publisher Mashable under the CIPA (§ 638.51). The lawsuit alleged that Mashable embedded commonly used third-party tracking software, provided by Microsoft, Wunderkind, and PubMatic, that automatically captured and transmitted visitors' IP addresses and device identifiers for advertising profiling without prior consent.
The court found that website tracking software could plausibly qualify as a pen register at the pleading stage. U.S. District Judge Charles R. Breyer denied Mashable's motion to dismiss, ruling that CIPA's prohibition on unapproved pen registers extends to software that record routing, addressing, or signaling information in digital communications.
Technology used: Trackers collecting IP addresses and metadata.
Why it’s important: The court ruled out that pen registers can broadly extend to software and web trackers that record routing, addressing, or signaling information in electronic communications.
6. Shah v. Crain Communications, Inc. / Shah v. Talentbridge, Inc. (July 2026)
Federal courts also took action against frequent pro se litigant Vivek Shah, who had filed dozens of substantially similar CIPA complaints. In July 2026, Judge R. Gary Klausner officially declared Shah a vexatious litigant, entering a pre-filing order to block him from filing further CIPA suits without court permission.
Why it’s important: This case represents a critical pushback against serial CIPA filings and mass shakedown demand letters. Courts are increasingly recognizing that some plaintiffs' lawyers and pro se actors are exploiting CIPA's statutory damages for coercive settlements rather than genuine grievance redress. This trend may give companies stronger grounds to challenge repetitive and potentially bad-faith lawsuits.
How to Reduce Your CIPA Compliance Risk
There is no single action that eliminates the possibility of a lawsuit. However, website owners can substantially improve their position by combining legal review with technical controls.
1. Conduct a tracking-tool audit
Identify all user tracking technologies operating across your website, including tools added directly, through a tag manager, through plugins, or through embedded content.
Look for:
- browser cookies;
- tracking pixels;
- analytics tags;
- session replay;
- heatmaps;
- chat and chatbot tools;
- form analytics;
- call-tracking tools;
- embedded videos;
- social media widgets;
- advertising tags;
- fingerprinting technologies;
- software development kits;
- server-side tracking and conversion APIs.
- Document each tool, what data it collects and why, who receives the data, the pages where it is installed, and when it activates.
CookieScript Cookie Scanner can detect cookies and website trackers, including third-party scripts. Monthly scanning automatically scans your website for cookies and scripts and updates your cookie declaration table on the Privacy Policy.
2. Block non-essential scripts before consent
Non-essential scripts must not load until users agree to them.
Advertising, behavioral analytics, and similar third-party scripts should be blocked before visitors see the cookie banner and give their choice.
CookieScript CMP automatically scans, categorizes, and blocks third-party scripts until the visitor accepts the relevant cookie category.
3. Review high-risk pages separately
Control stricter pages involving health, finance, accounts, payments, employment, education, or other sensitive interactions.
Consider disabling unnecessary third-party tracking entirely on:
- login and registration pages;
- customer portals;
- checkout flows;
- appointment forms;
- support chats;
- password-reset pages;
- application or eligibility forms.
Masking fields may reduce risk, but website owners should test how masking works in practice and what other information remains visible through URLs, event names, or custom parameters.
4. Obtain prior consent
Obtain consent before the relevant tracking occurs.
Provide the cookie notice that explains the categories of technology involved and give users a genuine opportunity to accept or reject them. Provide granular consent options, so that users can accept just specific categories of cookies and trackers.
5. Align the Privacy Policy with actual website behavior
Create a transparent and clear Privacy Policy.
Avoid relying exclusively on vague statements such as “By continuing to browse, you agree to our use of cookies.” List clearly all tracking tools, what data they collect, for what reasons, how long the data is retained, who receives the data, and the actual date of the Policy.
Do not copy disclosures from another website because in most cases they do not match your technical configuration.
Regularly update your Privacy Policy. Your marketing team may add new tracking tools for tracking, advertising, retargeting, or analytics purposes. Make sure each time the tool is added to your website, it appears on your Privacy Policy as well.
6. Record user consent
Record user consent for proof of compliance. Consent records could demonstrate what user selected and which banner configuration was presented.
CookieScript can record users’ consent choices and allow to download consent logs for internal and external audits.
7. Test the banner regularly
It is a common problem of a broken banner. The banner could be presented on the website, users make choices regarding cookies, but the consent signal doesn’t reach a website or third parties.
Sometimes, a consent banner can stop working after a website redesign, tag-manager update, plugin installation, or marketing campaign launch.
When testing the banner, test whether:
- no tracking scripts load before consent;
- rejected scripts remain blocked;
- only selected categories of cookies fire;
- consent withdrawal works;
- new scripts are correctly categorized;
- mobile and desktop behavior match;
- geolocation rules work as intended.
Use browser developer tools and network-request testing for your banner testing.
8. Set rules for implementing new technologies
Marketing and development teams should work together with your privacy or legal team. New tracking tools could only be deployed after privacy review.
Create an approval process covering the vendor, data fields, purpose, page placement, retention, third-party use, contract terms, and consent category.
How CookieScript Can Support Your CIPA Compliance
CIPA compliance involves more than displaying a popup. Website owners need to implement technical control over script activation and the propagation of user choices to third-party vendors.
CookieScript can support CIPA compliance through:
- cookie and script scanning;
- categorization of tracking technologies;
- automatic third-party script blocking;
- respecting Global Privacy Control signals;
- geo-targeting and providing the right cookie banner;
- cookie banner customization;
- customizable consent choices;
- consent recording and downloadable logs;
- updated cookie declarations.
CookieScript CMP delivers the right balance of compliance, affordability, and ease of use. You’ll get a fully compliant consent management tool for as little as €8 per month/ per domain for basic features or for €19 per month/ per domain for full CIPA compliance.
CIPA Lawsuit Tracker FAQs
Does CIPA apply to every website?
CIPA has extraterritorial reach, meaning that even if your company has headquarters outside of California. Thus, if you do business with or record individuals located in California, CIPA applies to your website. Use CookieScript CMP for consent management to avoid CIPA lawsuits.
Are tracking pixels illegal under CIPA?
A tracking pixel is not automatically illegal merely because it is installed on a website. Risk depends on whether it activates before or after user consent, what data it collects, where it operates, and who receives the data. Recent courts have nevertheless allowed some claims alleging that pixels and related software function as pen registers to proceed at the pleading stage. Use CookieScript CMP to avoid CIPA tracking pixel lawsuits.
Is implied consent sufficient for CIPA compliance?
It depends on the claim and circumstances, but relying solely on implied consent creates significant risk. The Ninth Circuit’s Javier decision concluded that Section 631 requires prior, explicit cookie consent. Use CookieScript CMP to collect valid consent and avoid CIPA tracking pixel lawsuits.
Does a cookie banner prevent CIPA lawsuits?
Not necessarily. The banner, tracking scripts, consent settings, privacy disclosures, and technical implementation must work as a unified consent management system, respecting user choices. A banner that loads after tracking has started, does not block scripts, or provides inaccurate information is not a valid banner.
How to reach CIPA compliance?
To reach CIPA compliance, businesses should conduct a tracking-tool audit, block non-essential scripts before consent, review high-risk pages, obtain prior consent, record user consent, align the privacy policy with actual website behavior, test the banner regularly, and set rules for implementing new technologies. Use CookieScript CMP, one of the best CMPs, for consent management and CIPA compliance.