ConsentPixel – Privacy · Verified

CIPA & Legal Risk

CIPA & Legal Risk: The Website Wiretapping Wave

CIPA turned a 1967 wiretapping law into 2026’s most active website-litigation risk — and the trigger is almost always the same: a tracker that fired before the visitor agreed to it.

The California Invasion of Privacy Act (CIPA) is a decades-old anti-wiretapping statute that plaintiffs’ firms have re-aimed at ordinary websites. The theory is simple and unforgiving: when a session-replay script, ad pixel, or chat widget intercepts a visitor’s activity before they consent, that interception can be an unlawful wiretap. Because CIPA carries a private right of action and statutory damages of $5,000 per violation under Cal. Penal Code §637.2, the risk is real for businesses of every size — and it follows the California resident, not your office.

This category tracks that litigation wave as it develops: what triggers a claim, which tools plaintiff firms scan for, how demand letters work, and what actually reduces exposure. The through-line across every piece is prevention — making sure nothing fires before consent, and being able to prove it.

CIPA's Expanding Frontier: From Phone Taps to Pixels to AI
CIPA & Legal Risk

CIPA’s Expanding Frontier: From Phone Taps to Pixels to AI

In August 2026, a federal court let a wiretapping case proceed against an AI notetaker that sat in on Zoom calls. The statute it was decided under? A California law written in 1967 for telephone eavesdropping. That’s not a stretch — it’s the pattern. The same consent theory has marched from phone taps, to website pixels, to AI tools, and each jump makes the last one look settled.

CIPA’s Expanding Frontier: From Phone Taps to Pixels to AI Read Post »

The Split Sharpens — And the Pixel Theory Goes National
CIPA & Legal Risk

CIPA Case Watch: The Split Sharpens — September 2026

Last cycle was about verdicts. This one is about division. A California federal court let some tracking claims against Wayfair proceed while tossing others in the same order; a $3.85M settlement won final approval — then drew an appeal; and the pen-register theory keeps winning for defendants in one courtroom while §631 wiretapping claims survive in the next.

CIPA Case Watch: The Split Sharpens — September 2026 Read Post »

Meta Pixel on Hospital Websites: The #1 Healthcare Privacy Risk
CIPA & Legal Risk

Meta Pixel on Hospital Websites: The #1 Healthcare Privacy Risk

Of every privacy mistake a healthcare organisation can make online, one has produced more lawsuits, more settlements, and more patient-notification letters than any other: a small snippet of Meta’s advertising code, quietly running on the website — sometimes inside the patient portal itself. It was never installed maliciously. It was added to measure ad campaigns, the way it is on millions of ordinary sites. But on a hospital site, what it transmits is different, and the law treats it differently. Here’s exactly how the Meta Pixel became healthcare’s most expensive line of JavaScript — and what the 2026 picture really looks like.

Meta Pixel on Hospital Websites: The #1 Healthcare Privacy Risk Read Post »

When the Regulator Runs the Scan: Australia's Tracking-Pixel Ruling
CIPA & Legal Risk

Australia’s Tracking-Pixel Ruling: What the OAIC Found

For three years, the tracking-pixel story was a lawsuit story — plaintiff firms in California scanning websites, sending demand letters, collecting settlements. In June 2026, Australia’s privacy regulator did something different: it ran the scan itself, and formally found two health providers had breached the Privacy Act by loading tracking pixels without consent. A cookie banner, it held, was not enough. Here is exactly what the OAIC decided, and why it turns the pixel problem from a private-litigation risk into a regulatory one — worldwide.

Australia’s Tracking-Pixel Ruling: What the OAIC Found Read Post »

Will Insurance Cover a CIPA Lawsuit? Inside the FullStory Coverage Fight
CIPA & Legal Risk

Will Insurance Cover a CIPA Lawsuit? The FullStory Fight

Everyone warns you about getting sued for website tracking. Almost no one asks the more expensive question: will your insurance actually pay for it? A new case involving session-replay vendor FullStory suggests the answer is increasingly “not without a fight” — and it reveals a whole layer of the tracking-litigation economy that most compliance guides ignore.

Will Insurance Cover a CIPA Lawsuit? The FullStory Fight Read Post »

Decline Means Decline: When Your Opt-Out Doesn't Stop Tracking
CIPA & Legal Risk

Decline Means Decline: When Your Opt-Out Doesn’t Stop Tracking

A cookie banner makes a promise. When a visitor clicks “Decline,” tracking is supposed to stop. Two 2026 lawsuits — against Toyota and the NFL — allege it didn’t, and a wave of CCPA enforcement now punishes the same gap. Here’s why a decline button that doesn’t actually stop trackers has become one of the clearest privacy risks a website can carry, and how to close it.

Decline Means Decline: When Your Opt-Out Doesn’t Stop Tracking Read Post »

What a "Vexatious Litigant" Designation Actually Means
CIPA & Legal Risk

What a “Vexatious Litigant” Designation Actually Means for CIPA

In July 2026, a federal court declared one of the most prolific individual CIPA filers a vexatious litigant and restricted his future lawsuits. Headlines framed it as a turning point. It is meaningful — but its practical effect is narrow, and reading it as “the CIPA demand-letter wave is over” would be a costly mistake. Here’s exactly what the designation does, what it doesn’t, and what it changes for a business that receives a demand letter.

What a “Vexatious Litigant” Designation Actually Means for CIPA Read Post »

SB 690 Explained: What California's CIPA Reform Bill Actually Does Now
CIPA & Legal Risk

SB 690 Explained: What California’s CIPA Reform Bill Does

SB 690 was supposed to be the bill that ended the CIPA lawsuit wave. Then, in July 2026, it was gutted and rewritten — and what’s left is far narrower than the headlines suggest. If you’ve heard “California is fixing CIPA” and assumed your exposure is about to disappear, this is the reality check: here’s what the amended bill actually does, what it pointedly leaves untouched, and why it changes much less than you’d hope.

SB 690 Explained: What California’s CIPA Reform Bill Does Read Post »

The Year Theory Became Verdicts — And a New Frontier Opened
CIPA & Legal Risk

CIPA Case Watch: The Year Theory Became Verdicts (August 2026)

Last cycle, the story was a spreading defense against the pen register theory. This cycle, the ground shifted the other way — hard. A jury handed down the first major CIPA verdict in the statute’s history, a $59.5M settlement landed alongside it, patient-portal settlements kept stacking up, and a brand-new theory emerged: suing companies for tracking people after they opted out. Meanwhile the “reform” headlines — SB 690 and a serial filer restricted — sound like relief but change little. Here’s the Good, the Bad, and the Ugly.

CIPA Case Watch: The Year Theory Became Verdicts (August 2026) Read Post »

Privacy policy vs cookie policy vs cookie declaration: which do you actually need?
CIPA & Legal Risk

Privacy Policy vs Cookie Policy vs Cookie Declaration: Which Do You Need?

These terms get used interchangeably, and they’re not interchangeable. There are actually four things hiding in this question — a privacy policy, a cookie policy, a cookie declaration, and cookie consent — and they do genuinely different jobs. Here’s each one in plain language, whether you need all of them, and how they connect.

Privacy Policy vs Cookie Policy vs Cookie Declaration: Which Do You Need? Read Post »

Your Client Got a CIPA Demand Letter. Here's the Agency Playbook.
CIPA & Legal Risk

Your Client Got a CIPA Demand Letter. Here’s the Agency Playbook.

When a demand letter lands on your client’s desk, they forward it to you — because it’s about the website you built and the tags you manage. Here’s how to steer them through it, what to actually do on the site and the CMP, how the “just ignore it” path really plays out, and how to protect your client and your agency at the same time.

Your Client Got a CIPA Demand Letter. Here’s the Agency Playbook. Read Post »

CCPA Compliant, but Still Got a CIPA Letter? You're Not as Covered as You Think
CIPA & Legal Risk

CCPA Compliant, but Still Got a CIPA Letter? You’re Not as Covered as You Think

You built the cookie banner. You added the “Do Not Sell or Share” link. You’re CCPA compliant — so how did a CIPA demand letter still land on your desk? The uncomfortable answer: CCPA compliance and CIPA compliance are two different things, and the gap between them is exactly where the 2026 wave of website lawsuits lives. Here’s the gap, in plain English, and how to close it.

CCPA Compliant, but Still Got a CIPA Letter? You’re Not as Covered as You Think Read Post »

CIPA Explained: The Law Behind the Lawsuits
CIPA & Legal Risk

CIPA Explained: The Law Behind the Website Lawsuits (2026)

How did a California wiretapping statute written in 1967 — decades before the web existed — become the engine behind thousands of website tracking lawsuits? This is the story of the California Invasion of Privacy Act: the two court rulings that opened the floodgates, the “pen register” theory driving today’s demand letters, and why, in 2026, your everyday analytics and ad pixels put your site in the crosshairs.

CIPA Explained: The Law Behind the Website Lawsuits (2026) Read Post »

GDPR vs CIPA: One Configuration Handles Both
CIPA & Legal Risk

GDPR vs CIPA: One Configuration Handles Both

If you run websites for both European and American audiences, you’ve probably wondered whether you need two different consent setups — one for GDPR, one for California’s CIPA. The reassuring answer: a single, correctly built prior-consent configuration can satisfy both. Here’s how the two laws actually differ, where they converge, and the one setup that covers you on both sides of the Atlantic.

GDPR vs CIPA: One Configuration Handles Both Read Post »

The Pen-Register Defense Is Turning — What the Shift Means for Your Website
CIPA & Legal Risk

CIPA Case Watch: The Pen-Register Defense Is Turning — What It Means for Your Website (July 2026)

Something changed this cycle. For two years, the CIPA §638.51 “pen register” theory was the plaintiff bar’s most reliable weapon against websites. Now a line of defense rulings — led by Rodriguez v. Ink America — is spreading, holding that CIPA can’t criminalise what the CCPA already regulates. But federal courts still disagree. Here’s the shift, the split, and what both mean for your site.

CIPA Case Watch: The Pen-Register Defense Is Turning — What It Means for Your Website (July 2026) Read Post »

CIPA Section 631 Explained: The Four Clauses, the Case Law, and What They Mean for Every Website
CIPA & Legal Risk

CIPA Section 631 Explained: The Four Clauses, the Case Law, and What They Mean for Every Website

California Penal Code Section 631 is a 1967 anti-wiretapping statute that became, in 2022, the most-litigated digital privacy law in the United States. This article explains precisely how it works — the four operative clauses, the aiding-and-abetting theory that reaches website operators, the defenses that have succeeded and failed, and what the 2026 case law means for agencies managing multiple client sites and for CIPA-practicing counsel.

CIPA Section 631 Explained: The Four Clauses, the Case Law, and What They Mean for Every Website Read Post »

Scroll to Top