Table of Contents [TOC]

{tocindex article="current"}

Privacy laws

Menu

  • Pricing
  • Features
    • Regulation compliance
    • GDPR (EU)
    • CCPA (California)
    • PIPEDA (Canada)
    • LGPD (Brasil)
    • KVKK (Turkey)
    • POPIA (South Africa)
    • The basics
    • 42 languages
    • User consents recording
    • Third-party cookie blocking
    • Geo targeting
    • Cookie Banner
    • Google Consent Mode v2
    • Automation
    • Automatic monthly scans
    • Automatic script blocking
    • Advanced reporting
    • Cookie Banner sharing
    • IAB TCF 2.3 integration
    • Google-certified CMP
  • Resources
    • Cookie Scanner
    • Privacy Policy Generator
    • System status
    • Roadmap
    • Changelog
  • Blog
    • Guides
    • News
    • GDPR & CCPA
    • Privacy laws
    • Compare
    • Knowledge base
  • Support
    • Help Center
    • Integrations
    • Contact us
    • Feature request
  • For partners
    • Agencies
    • Affiliates
  • separator
  • Language switcher
    • Profile
    • Billing
    • My plan
  • Sign in
  • Try now
 
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Compare
  • Knowledge base
Details
20 July 2026

Ranking the Worst Tracking Pixels Under CIPA

ON THIS PAGE

  • What Makes a Tracking Pixel Risky Under CIPA?
  • The Ranking: Worst Tracking Pixels and Tracking Setups Under CIPA Risk
    • 1. Any Third-Party Tracking Technology on Sensitive Pages
    • 2. Ad Pixels With Identity or Matching Features
    • 3. Session Replay and Heatmap Tools
    • 4. Chat Widgets and Lead-Generation Forms
    • 5. Tag Manager Containers That Nobody Audits
    • 6. Retargeting Pixels on Cart, Checkout, or Account Pages
    • 7. Embedded Video, Social Media, and Third-Party Widgets
    • 8. Basic Analytics on Public, Low-Sensitivity Pages
  • Why the Pixel Name Is Not Enough
  • What Website Owners Should Audit First
    • What Is Running?
    • Where Does It Run?
    • What Is Transmitted?
    • What Controls It?
  • How CookieScript Can Help Reduce Tracking Pixel Blind Spots
  • The Riskiest Pixel Is the One You Have Not Audited
  • Frequently Asked Questions

A conversion pixel added for a short campaign may still be firing months later across checkout, appointment, login, account, or lead-intake pages. In such cases, the risk is not about the vendor name but what the pixel collects, where it fires, who it sends the data to, and whether the site visitors are adequately notified and given a choice.

This article provides a ranking of the worst offenders of tracking in light of California Invasion of Privacy Act (CIPA) and identifies the key areas that need to be audited first by any website owner.

What Makes a Tracking Pixel Risky Under CIPA?

CIPA, the California law regarding the privacy of communications and wiretapping, is often cited in claims involving website tracking. Website-tracking claims often invoke Section 631, which refers to learning the “contents or meaning” of a communication “while the same is in transit.”

In plain language, the dispute may turn on whether a tool received meaningful information while a visitor interacted with the site—not simply whether a cookie existed. Sections 638.50 and 638.51 support separate pen-register or trap-and-trace theories involving routing, addressing, or signaling data. Section 632 is more likely to matter when a confidential communication, such as a chat, is allegedly recorded.

The risk hinges on what technology collects, whether identifiers are attached, what the page discloses, who receives the data, when collection starts, and whether there is notice or choice. For example, the URL, searches, clicks, form activities, and page titles are sensitive health, financial, employment, benefits, legal, or account-related information.

Every case is not treated alike. In the unpublished, nonprecedential Javier v. Assurance IQ decision, the Ninth Circuit held narrowly that consent given after collection began did not address the alleged earlier interception.

A tracking pixel is a tiny piece of code that transmits visit, event, conversion, or user-related information to another system.

The Ranking: Worst Tracking Pixels and Tracking Setups Under CIPA Risk

Note that this does not provide a legal opinion. No tracker is per se illegal simply because it appears on this list.

1. Any Third-Party Tracking Technology on Sensitive Pages

This goes back to the issue of context. You look at each pixel, widget, recorder, SDK, analytics tag, or embed and ask yourself: does this run on pages with sensitive healthcare content or interactions, such as articles about health, symptom searches, or other consumer medication or treatment information?

Does it run on pages related to booking appointments, financial accounts, legal intake forms, employment and benefits-related information, disability forms, or other logged-in content?

The purpose of the visit may be inferred from a URL, article title, search query, event name, or button label. LinkedIn, for instance, provides clear guidance that there is a meaningful difference between a generic pharmacy homepage and pages about consumer medication, financial accounts, or medical appointments.

2. Ad Pixels With Identity or Matching Features

Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, Google Ads conversion tags, Microsoft UET, and similar tools offer different combinations of event tracking, conversion measurement, audience building, and identity matching.

Depending on the platform and the particular implementation, this might include hashed emails or phone numbers, names, addresses, URLs, customer IDs, and conversion events.

Hashing does not put a transmission out of scope. It is merely a change in the form of the data, but it does not change the fact that data has been sent to be matched for measurement, attribution, or audience creation.

3. Session Replay and Heatmap Tools

Depending on the product and how it is configured, session replay can reproduce mouse movements and clicks, scrolling, page changes, input activity, form behavior, and even content viewed. While some products suppress typed values by default, that has to be checked on a live site.

For example, Hotjar suppresses keystroke data by default but allows administrators to permit certain fields, subject to restrictions that keep specified sensitive fields suppressed.

While Popa v. Microsoft did not involve CIPA but rather the Pennsylvania wiretap statute, its federal standing analysis is relevant to CIPA cases filed in Ninth Circuit federal courts.

The court found no concrete injury where the plaintiff failed to identify any embarrassing, invasive, or otherwise private information gathered from session replay on a pet-supply website. Sensitivity, invasiveness, and the kind of harm alleged all matter.

4. Chat Widgets and Lead-Generation Forms

Customer-service chat, AI chatbots, intake widgets, newsletter forms, quote tools, CRM forms, and appointment schedulers may combine written messages and contact details with page context, campaign data, and health, financial, employment, or legal interests.

Whether a provider of such software is a third party or merely a tool of the site operator varies by jurisdiction and may depend on the technical means by which the software is provided, whether the software is used by the software provider for their purposes, when the software provider receives the communications, and consent issues.

Section 632 may be implicated where the confidential contents of a chat are intentionally recorded without the consent of all parties.

5. Tag Manager Containers That Nobody Audits

Google Tag Manager and other similar systems are deployment systems and are not, on their own, unlawful trackers. Unmanaged containers with stale campaign tags, duplicate analytics, old agency scripts, affiliate pixels, custom HTML, wide-reaching site triggers, or tags that fired regardless of the consent setting create risk.

A direct integration may be removed while an older version keeps firing on checkout and account pages. Check publishing permissions, container versions, triggers, ownership, and preview results to find out which tags fire and what data they handle.

6. Retargeting Pixels on Cart, Checkout, or Account Pages

Depending on the events configured, retargeting may reveal products viewed, cart contents, purchase value, subscription level, abandoned checkout activity, renewal status, login state, or repeat-purchase behavior.

Retargeting is not necessarily unlawful, but risks increase when detailed events are connected with cookies, advertising IDs, hashed identifiers, customer IDs, or sensitive product categories.

This can sometimes happen accidentally—for example, where form values, URL parameters, names, addresses, phone numbers, and email addresses are all inadvertently transmitted. Microsoft’s dynamic remarketing documentation, for example, describes matching visitors with products they viewed, considered, or purchased.

7. Embedded Video, Social Media, and Third-Party Widgets

Video players, social feeds, share buttons, maps, review widgets, calendars, schedulers, recommendation tools, and third-party forms often reach out to third-party domains, set identifiers, or transmit URLs and interaction data. They should therefore be included in audits, even if no one calls them pixels.

Separately, associating identifying information with video materials or services may raise issues under the Video Privacy Protection Act, or VPPA.

8. Basic Analytics on Public, Low-Sensitivity Pages

Simple analytics on a generic homepage or public blog post is an entirely different risk profile from analytics that include full URLs, internal searches, user IDs, advertising signals, form events, or logged-in user behavior.

Although Popa did not interpret CIPA, it implies that, from the standpoint of federal standing, simple browsing of non-sensitive pages will be treated differently than the use of tracking software on pages containing medical, financial, or other sensitive private information. Basic analytics ranks lower, but it still belongs in the website inventory.

CIPA Section 637.2 allows persons injured by a violation of this chapter to recover the greater of $5,000 per violation or three times actual damages. Injunctive relief is also available. There is no requirement to allege actual damages in bringing a claim; however, a plaintiff filing in federal court must plead an injury in fact to satisfy the standing requirement.

Why the Pixel Name Is Not Enough

Two websites can use the same tracking vendor and still create very different data flows. The practical difference may depend on whether:

  • Automatic collection and matching features are enabled.
  • Sensitive pages, form data, or full URLs are included.
  • Tags fire before or after the visitor makes a choice.
  • Browser-side and server-side implementations send duplicate versions of the same event because deduplication is not configured correctly.

The configuration matters more than the vendor name alone.

Server-side tracking is not an automatic risk reducer. It may give a website more control over what is transmitted, but the server can still send identifiers, lead details, purchases, account activity, or sensitive signals when configured poorly.

Google Consent Mode v2 changes how supported Google tags behave based on consent states. It does not obtain or store the visitor’s consent choice, decide which legal rules apply, or independently establish that a website’s tracking setup is compliant.

What Website Owners Should Audit First

An audit of tracking has to provide answers to these four pragmatic questions to be really helpful:

What Is Running?

Your inventory needs to cover more than just the obvious ad pixels:

  • Direct scripts, plugins, and tag-manager containers.
  • Analytics, advertising, and session-replay tools.
  • Chat widgets, embedded services, and CRM forms.
  • Browser-side APIs, server-side tags, and conversion APIs.

Where Does It Run?

Prioritize the pages where user activity could reveal sensitive information about the visitor, such as:

  • Healthcare, appointments, loans, insurance, and legal intake.
  • Internal searches, checkout, login, and account areas.
  • Employment, benefits, contact, and lead-generation forms.

What Is Transmitted?

For each network request, watch the transmitted values, including the URL, page title, search term, event parameters, button text, and form values. Look for the transmission of email addresses, phone numbers, hashed identifiers, IP addresses, cookie or device IDs, and customer or account IDs.

What Controls It?

Check banner categories, acceptance and rejection options, opt-out controls, regional rules, consent records, tag manager checks, and server-side controls. Where the business is subject to the CCPA and sells or shares Personal Information, qualifying opt-out preference signals, including the Global Privacy Control, must be honored.

Separate legal issues are raised by the CCPA, as amended by the CPRA, and the CIPA. Therefore, the sale-or-sharing opt-out control will not automatically defeat a CIPA claim.

!

How CookieScript Can Help Reduce Tracking Pixel Blind Spots

CookieScript can support the audit and control process by connecting common tracking problems with practical tools:

  • Use the Cookie Scanner to identify cookies, pixels, analytics tools, advertising tags, embeds, and third-party scripts detected during a scan. Dynamic scripts, logged-in pages, conditional tags, and unusual triggers may still require manual testing.
  • Automatic monthly scans help catch changes after plugins, campaign tags, ecommerce tools, embeds, or scripts are added or updated.
  • Selected non-essential scripts can be held back with automatic script blocking when the feature is installed and configured correctly.
  • Third-party cookie blocking can restrict designated third-party tracking until the relevant visitor choice is received.
  • With granular Cookie Banner choices, tools can be separated into necessary, analytics, functionality, and targeting categories based on the site’s actual setup.
  • Different Cookie Banner experiences can be shown by region through geo targeting, although the business must still decide which legal approach applies.
  • Consent recording retains visitor selections and the cookie banner configuration under which they were made.
  • Teams can use Advanced Reporting to review cookie banner accept, reject, and ignore rates, see which categories visitors choose, and identify consent-behavior patterns.
  • The Privacy Policy Generator and Cookie Policy Generator can support disclosures, but the final policies still need to reflect the website’s real data practices.
  • For websites using Google tags, Google Consent Mode v2 can connect consent choices to supported Google-tag behavior.
  • Websites using programmatic advertising or an IAB-based ad stack may also use IAB TCF 2.3 to communicate consent choices to participating ad-tech vendors. It is not required for every website and does not independently address CIPA risk or establish compliance.

CookieScript is a Consent Management Platform trusted by businesses in markets wordwide. In 2025, it earned a G2 Leader badge for the fourth year in a row, highlighting continued positive recognition from users.

The Riskiest Pixel Is the One You Have Not Audited

The pixel most likely to cause trouble is not necessarily the one with the biggest brand name. More often, it is an old tag that nobody remembers adding. It may be collecting more than expected, firing on sensitive pages, or sending identifiable information to a third party without the website team realizing it.

Start by finding out what is actually running. Check which pages each tag appears on, what it sends, how it is configured, and what the vendor can do with the data. Remove anything that no longer serves a clear purpose and fix the tags that are firing in the wrong places.

Then do the review again whenever the site changes. A new campaign, plugin, redesign, or agency can quietly introduce new tracking. Sensitive pages and regulated industries should also receive legal review.

 

Register for free Show pricing plans

 

Frequently Asked Questions

What Is CIPA?

CIPA stands for the California Invasion of Privacy Act. It is a California communications privacy and wiretapping law written before websites used tracking pixels, session replay, or chat software. Courts have reached different conclusions when applying it to these tools. CookieScript’s Cookie Scanner provides a practical starting point for reviewing what a site uses.

Does CIPA Apply to Tracking Pixels?

It may, depending on what happened. CIPA tracking-pixel lawsuits have involved advertising tags, chat tools, and session replay, but an allegation is not proof of a violation. The data collected, timing, recipients, consent, and technical setup all matter. A Cookie Scanner can help establish the underlying facts.

What Tracking Pixels Are Riskiest Under CIPA?

Look first at tags running on health, finance, legal, employment, checkout, and account pages. Search terms, form activity, identity matching, and third-party access can raise the risk further. No tracker is automatically illegal. CookieScript’s monthly scans are useful for catching tags added later through a plugin or campaign.

Is Meta Pixel Illegal Under CIPA?

No. A useful Meta Pixel CIPA review asks what the pixel sends and where it fires. A basic conversion event on a public page is not the same as identified activity from an appointment or account page. CookieScript can place selected marketing tags behind an appropriate cookie banner category and automatic script blocking.

Are Google Analytics and Google Ads Tags Risky Under CIPA?

Configuration makes the difference. Compare basic traffic counts on a public homepage with a setup sending full URLs, form events, user IDs, enhanced-conversion data, or logged-in activity. For sites using Google tags, Google Consent Mode v2 can adjust supported tag behavior after receiving consent states. It does not make the site compliant by itself.

Do Cookie Banners Prevent CIPA Lawsuits?

Not automatically. A banner shown after a pixel has already fired may do little to address that earlier transmission. The wording and choices matter, but so do the technical results. CookieScript combines granular cookie banner choices with script blocking and consent recording. Those settings still need to match the tags on the live website.

What Should I Do If Pixels Run on Sensitive Pages?

Pause anything that does not need to be there. Then inspect the network requests, URLs, event parameters, identifiers, and server-side transmissions.
During that review, CookieScript’s automatic script blocking and third-party cookie blocking can keep selected tools from running. Higher-risk implementations should also receive legal review.

How Often Should I Audit Tracking Pixels?

Monthly scanning is a sensible baseline, but do not wait for the next scheduled scan after a major change. Check immediately after launching a campaign, installing a plugin, publishing tag-manager changes, replacing a CMP, redesigning forms, or adding server-side tracking.

 
  • About CookieScript
  • Terms of Service
  • Privacy Policy
  • Pricing
  • Resources
  • Cookie Scanner
  • Privacy Policy Generator
  • System status
  • Sitemap
  • Changelog
  • Alternatives
  • CookieBot
  • Termly
  • OneTrust
  • Iubenda
  • Cookie Information
  • CookieFirst
  • Illow
  • Blog
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Knowledge base
  • Support
  • Help center
  • Contact us
  • Integrations
  • Request a feature
  • Roadmap
  • For Partners
  • For agencies
  • For Affiliates

Copyright ©2026 CookieScript


main version