California's CIPA Wiretapping Lawsuit Wave Explained
An explainer on why chat widgets, pixels, and tracking tools are fueling a wave of CIPA wiretapping lawsuits against ordinary business websites.
An explainer on why chat widgets, pixels, and tracking tools are fueling a wave of CIPA wiretapping lawsuits against ordinary business websites.
A wiretapping law written for telephone lines in 1967 now underpins thousands of lawsuits over chat widgets, tracking pixels, and cookie banners. Here's what's driving the CIPA lawsuit wave, and how to find out where your website stands.
A growing wave of lawsuits is testing whether everyday website technologies, including chat widgets, tracking pixels, and session-replay tools, violate California's 1967 wiretapping law.
More than 4,300 digital wiretapping lawsuits have been filed nationwide since a pivotal 2022 court ruling, according to Fisher Phillips’ Digital Wiretapping Litigation Map, with businesses ranging from retailers and car dealerships to insurers and hospitality companies facing claims.
The issue often comes down to something deceptively simple: when website tracking begins, and whether a visitor's consent choice actually controls it.
The California Legislature passed CIPA in 1967, decades before the modern internet, and it makes it illegal to intentionally intercept or record the contents of a communication without the consent of everyone involved, according to a legal history published by law firm Constangy, Brooks, Smith & Prophete. Unlike most privacy statutes, it lets a private citizen sue directly rather than waiting on a regulator, with statutory damages of $5,000 per violation, or three times actual damages, and no requirement to prove real-world harm, according to law firm Spencer Fane.
The modern wave accelerated after the Ninth Circuit's 2022 decision in Javier v. Assurance IQ, which held that consent for session-replay tracking must be obtained before the recording begins, not after. The ruling helped fuel claims involving third-party technologies embedded on business websites.
A handful of technologies show up again and again in these claims:
CIPA plaintiffs argue that some of these transmissions amount to unlawful interception or collection of routing information.
Three patterns commonly appear in these claims, the first identified in an April 2026 alert from law firm Loeb & Loeb as “the millisecond problem”:
1. Tracking starts before consent
Scripts load before the visitor can choose.
2. Tracking continues after “decline”
The banner records the choice, but the underlying tracking technology doesn't respond to it.
3. There is no consent mechanism
Tracking begins without presenting the visitor with a relevant choice.
One pending lawsuit against Toyota Motor Corporation, for example, alleges that tracking continued even after a visitor repeatedly selected “decline,” the second pattern above. As one legal alert put it, a cookie banner is a policy statement, not a guarantee that every connected tool is actually listening to a visitor's choice.

Cyber insurer Coalition found that privacy-related insurance claims it received roughly doubled in the first half of 2026 compared with 2025, and that nearly 75% of those web-privacy claims specifically cited CIPA, according to the insurer’s midyear claims analysis. Settlements have run into the millions: the Los Angeles Times agreed to pay $3.85 million in 2026 over third-party ad trackers, without admitting wrongdoing, and Forbes Media agreed to pay $10 million the same year to resolve similar claims.
These lawsuits aren't limited to large technology companies. Retail and e-commerce businesses represent the largest industry group in Fisher Phillips’ litigation tracker, while law firms have also reported claims involving auto dealerships, insurers, hospitality businesses, healthcare providers and media companies.
The common thread isn't industry or company size. It's the use of third-party website technologies that collect or transmit visitor data.
No. Courts remain divided over how CIPA applies to modern website tracking technologies. In one 10-day stretch in April 2026, four different California courts issued rulings on nearly identical tracking claims and reached different conclusions.
Lawmakers have also taken notice: Senate Bill 690 would narrow one specific category of CIPA claim, but even if it passes, it would leave CIPA's core wiretapping provisions, the ones underlying cases like the suit against Toyota, fully intact. In other words, even a successful reform effort wouldn't eliminate this exposure.
None of this means every business running a chat widget or an ad pixel is facing an imminent lawsuit. It does mean a cookie banner is only as accurate as the technical work behind it. Before assuming your site is covered, it's worth checking:
For most businesses, that's as much a technical audit question as a legal one, and it typically requires input from whoever manages the website's code, not just whoever wrote the privacy policy.
Yes. CIPA claims have been brought against businesses located anywhere in the country as long as their website has visitors located in California. Company size, industry, and headquarters location haven't offered meaningful protection in this wave of litigation.
Plaintiffs argue that pixels from providers like Meta, TikTok and LinkedIn, along with analytics scripts, can violate CIPA if they collect and transmit visitor identifiers before consent is given. Courts are still divided on how far this theory extends, and no ruling has established that pixels are always illegal under CIPA.
Only if it's implemented correctly. A cookie banner can prevent CIPA exposure, but only when it's technically connected to every tracking tool running on the site, so a visitor's choice actually stops data collection.
Several lawsuits allege the opposite happened: tracking tools kept running, or kept transmitting data, even after a visitor selected 'decline,' because the banner's setting was never wired to the scripts actually collecting the data. In those cases, the banner displayed the right choice; it just didn't control anything.
The legal theory driving many CIPA lawsuits is that certain tracking technologies require a visitor's consent before they begin collecting data, not after. That principle traces back to the 2022 Javier v. Assurance IQ ruling. Whether it applies to a specific technology on a specific website is still being litigated case by case.
Start by identifying which third-party scripts, pixels, and chat tools are running on your site, when they begin collecting data, and whether declining consent actually stops them. Clym's free Scanner can help identify what's currently running on your website.