CIPA Section 631 Explained: The Four Clauses, the Case Law, and What They Mean for Every Website
California Penal Code Section 631 is a 1967 anti-wiretapping statute that became, in 2022, the most-litigated digital privacy law in the United States. This article explains precisely how it works — the four operative clauses, the aiding-and-abetting theory that reaches website operators, the defenses that have succeeded and failed, and what the 2026 case law means for agencies managing multiple client sites and for CIPA-practicing counsel.
In this article
- The statutory text, precisely
- The four operative clauses, broken down
- Why the fourth clause is the operative theory for websites
- The party exception: what it means and when it fails
- The in-transit requirement: the 2025 battleground
- The consent requirement: prior, not retroactive
- The full penalty stack
- 2025–2026 case law map
- Available defenses, ranked by reliability
- For agencies: a per-client Section 631 risk audit
- Why technical evidence decides these cases
- Frequently asked questions
This is not a general overview of the California Invasion of Privacy Act. It is a precise statutory analysis of Section 631 specifically — the provision that drives the vast majority of website tracking litigation — written for two audiences who need more depth than general-audience compliance articles provide: lawyers advising defendants in CIPA litigation or structuring consent frameworks to prevent it, and digital agencies that manage multiple client websites and carry non-trivial exposure for the tracking configurations they deploy on those sites.
One unambiguous statement at the outset: this article is informational and not legal advice. CIPA outcomes are intensely fact-specific, the case law is genuinely unsettled and evolving, and the only reliable guidance for a specific client situation comes from qualified counsel who has reviewed the actual facts. What this article is intended to do is give both audiences the statutory and doctrinal foundation that makes those conversations more productive.
The statutory text, precisely
California Penal Code § 631(a) reads, in the portions most relevant to website tracking litigation:
"Any person who, by means of any machine, instrument, or contrivance, or in any other manner, intentionally taps, or makes any unauthorized connection, whether physically, electrically, acoustically, inductively, or otherwise, with any telegraph or telephone wire, line, cable, or instrument, including the wire, line, cable, or instrument of any internal telephonic communication system, or who willfully and without the consent of all parties to the communication, or in any unauthorized manner, reads, or attempts to read, or to learn the contents or meaning of any message, report, or communication while the same is in transit or passing over any wire, line, or cable, or is being sent from, or received at any place within this state; or who uses, or attempts to use, in any manner, or for any purpose, or to communicate to others, any information so obtained, or who aids, agrees with, employs, or conspires with any person or persons to unlawfully do, or permit, or cause to be done any of the acts or things mentioned above in this section..." Cal. Penal Code § 631(a) (emphasis on the four operative clauses)
Three observations before unpacking the clauses. First, the statute was enacted in 1967 to address telephone wiretapping. Second, the Ninth Circuit's landmark 2022 ruling in Javier v. Assurance IQ, LLC held that § 631 applies to internet communications — the decision that ignited the current wave. Third, the phrase "or in any other manner" in the opening — which replaced earlier language limiting the clause to physical line connections — has been used to argue the statute is intentionally broad. Courts have divided sharply on how broad.
The four operative clauses, broken down
Section 631(a) contains four distinct prohibitions. Plaintiffs' counsel typically pleads all four, but their practical importance for website tracking cases is highly uneven.
The wiretapping / unauthorized connection clause
Prohibits intentionally tapping or making an unauthorized connection with a telegraph or telephone wire, line, or cable — including internal telephonic communication systems. Courts have read this as potentially covering unauthorized connections to systems that function like telephone infrastructure.
Practical relevance for websites: Low to none. Multiple courts — including the Ninth Circuit in Gutierrez v. Converse, Inc. (July 2025) — have held that this clause applies only to telephonic communications, not internet communications. A website deploying a pixel is not tapping a telephone line. Plaintiffs rarely carry § 631 claims on this clause alone in modern web-tracking litigation.
Low relevance for web trackingThe contents-in-transit clause
Prohibits willfully and without all-party consent reading, or attempting to read, or learning the contents or meaning of any message, report, or communication while the same is in transit. The phrase "in transit" is the critical limitation.
Practical relevance: High — and the most actively litigated. This is the clause where the "in transit" requirement generates the most significant defense wins (Torres, Gutierrez, Ramos) and the plaintiff victories (Javier, Mikulsky). Whether session replay software or a pixel "reads" data while it is "in transit" — or only after storage and reassembly — is the central question of 2025–2026 litigation.
High — primary litigation battlegroundThe use / communication clause
Prohibits using, attempting to use, or communicating to others any information obtained through Clause 1 or Clause 2 violations. It is a derivative clause — liability requires an underlying Clause 1 or 2 violation. If the primary interception claim fails, this clause fails with it.
Practical relevance: Moderate. In cases where Clause 2 survives, Clause 3 typically survives with it — adding an independent basis for damages when a vendor receives and uses the intercepted data. It is rarely the sole surviving theory.
Moderate — derivative of Clause 2The aiding-and-abetting clause
Prohibits aiding, agreeing with, employing, or conspiring with any person to unlawfully perform any of the above acts. This is the clause that reaches website operators — even though the party exception prevents direct liability under Clauses 1–3.
Why it matters: Courts have generally held that a website cannot directly "wiretap" its own visitors, since it is itself a party to the communication. The viable theory for plaintiffs is therefore that the website operator aided and abetted a third-party vendor (analytics provider, session replay tool, advertising pixel) that itself intercepted the communication. Clause 4 requires both knowledge of the conduct that will violate the statute and a purpose of aiding the third party.
Primary theory — requires technical evidence of third-party receiptWhy the fourth clause is the operative theory for websites
The structural logic is worth spelling out precisely because it determines what evidence actually decides these cases. Under California law, one party to a communication cannot "wiretap" it — you cannot eavesdrop on a conversation you are participating in. Every court to have considered the question has accepted this reasoning: a website is a party to the interaction with its own visitor, so the website operator cannot directly violate Clauses 1–3 of § 631(a) by collecting visitor data through its own infrastructure.
The plaintiff's path to the website operator therefore runs through Clause 4 — the aiding-and-abetting theory. The plaintiff must plausibly allege that: (a) a third-party vendor received a copy of the communication in real time; (b) that vendor "read" or "attempted to read" the contents in transit; and (c) the website operator aided, agreed with, employed, or conspired with that vendor in achieving this. Critically, the Ninth Circuit in Mikulsky v. Bloomingdale's held this requires both knowledge and purpose: the website operator must have known the vendor would intercept and must have intended to assist it.
This framing has two significant practical implications. First, it means that characterising the vendor relationship — as independent interceptor vs. mere agent of the website operator — is the most important strategic decision in any CIPA § 631 defense. Second, it means the technical configuration of the vendor contract and data flows is central evidence. Whether FullStory had rights to use data independently, whether Hotjar's contract made it an agent of the site or an independent third party, whether the analytics vendor received a real-time copy or only post-transmission data — these technical and contractual facts determine the outcome more than the legal theories do.
The aiding-and-abetting theory means vendor contracts are discovery targets from day one. Preserving the defendant's tag manager configuration, the vendor's data processing agreement, and the technical architecture showing what the vendor received and when are critical for establishing whether the party exception extends to the vendor (as mere agent) or whether the vendor acted as an independent interceptor. This technical evidence is rarely collected as a matter of course — and often disposed of before litigation hold is issued.
The party exception: what it means and when it fails
The party exception is the single most important structural defense in § 631 litigation. Its logic is simple: a party to a communication cannot wiretap it. CIPA's text does not state the exception explicitly, but it has been read into the statute by California courts for decades. The digital-tracking wave has forced courts to decide how far the exception extends — specifically, whether a third-party vendor receiving data from a website qualifies as an "extension" of the website (and therefore protected) or as an independent interceptor (and therefore exposed).
Two lines of authority have emerged on this question:
The agent/tool theory (protective): If a third-party technology provider does not have the right to make independent use of the communications it receives — if it operates exclusively as a tool for the website operator — it falls under the umbrella of the party exception. Several courts have embraced this reasoning, finding that a vendor acting as a pure processor, without independent data rights, is effectively an extension of the party to the communication. Thomas v. Papa John's International, Inc. (Ninth Circuit, affirmed 2025) is the clearest expression of this theory: the court dismissed the § 631 claim because Papa John's, as a party, could not eavesdrop on its own conversation. Critically, the plaintiff in Thomas had not pleaded the aiding-and-abetting theory against the vendor specifically — a pleading gap noted by the Ninth Circuit as leaving that avenue open.
The independent use theory (exposed): If the vendor has the right to use the received data for its own purposes — analytics, product improvement, benchmarking, training AI models — it is an independent third party, not a mere agent of the website. Several courts have adopted this reasoning, finding that the party exception does not extend to vendors who extract value from the data independently. The Microsoft Clarity situation illustrates the practical significance: Clarity uses received data for Microsoft's own benchmarking and AI products, which plaintiffs have argued is independent use that removes Clarity from the party exception.
Whether a vendor is an "agent" or an "independent interceptor" is not decided by the vendor's marketing materials. It is decided by the vendor's data processing agreement, its terms of service, and its actual data practices. DPAs that restrict vendor use of data exclusively to service provision to the client support the agent theory. Vendor agreements that permit independent data use for the vendor's own purposes undermine it. Reviewing vendor contracts through this lens is one of the most practical steps a CIPA-aware practitioner can recommend to a business client.
The in-transit requirement: the 2025 battleground
If the party exception is the structural defense, the "in transit" requirement is the substantive one. Section 631(a) Clause 2 prohibits reading the contents of a communication "while the same is in transit or passing over any wire, line, or cable." Whether the data captured by session replay tools, pixels, and analytics scripts is read while "in transit" — or only after storage, reassembly, and decoding — has become the most actively litigated question in CIPA § 631 jurisprudence.
The defendant-favorable interpretation, which generated the most significant defense wins of 2025, holds that "in transit" means contemporaneous with transmission — the millisecond the data is moving over the wire, not after it arrives, is stored, and is later processed. Under this reading, a session replay tool that records user interactions and reassembles them into a playback video is not capturing data "in transit" — it is reconstructing data that was already received and stored.
Torres v. Prudential Financial (N.D. Cal., April 2025) is the landmark expression of this theory. The court granted summary judgment for the defendant, ruling that session replay software does not violate § 631 because the captured data only becomes readable after it has been stored and reassembled — not while it is in transit. Gutierrez v. Converse, Inc. (Ninth Circuit, July 2025) affirmed summary judgment against a § 631 Clause 2 claim on similar grounds. Ramos v. Gap, Inc. (N.D. Cal., July 2025) dismissed a § 631 claim involving third-party email marketing pixels, holding that the data collected — email open rates and content click rates — constituted general information "about" a communication rather than its "contents."
The plaintiff-favorable interpretation, which kept claims alive in Mikulsky v. Bloomingdale's and Javier v. Assurance IQ, holds that real-time capture — keystrokes transmitted to a third-party server as they are entered — constitutes interception "in transit." The Ninth Circuit in Mikulsky reversed the district court's dismissal, finding the complaint adequately pleaded that session replay code captured "the contents or meaning" of communications in real time without consent — distinguishing this from merely collecting metadata about communications.
The consent requirement: prior, not retroactive
The consent defense to § 631 has a precise and frequently misunderstood requirement: consent must be prior to the interception, not post-hoc. This was the operative holding of Javier v. Assurance IQ, LLC (Ninth Circuit, 2022) — the decision that opened the current litigation wave. In Javier, the user completed a form on Assurance IQ's website and was then directed to a privacy policy disclosing third-party data collection by ActiveProspect. The Ninth Circuit held that consent provided after data had already been captured could not retroactively cure the lack of prior consent.
The practical implication is stark: a privacy policy disclosure in a website footer, a cookie banner that appears while scripts are already loading, a terms-of-service link in a confirmation email — none of these establish the "prior consent" that § 631 requires. Every demand letter since Javier cites its holding in its opening paragraphs, and for good reason: it means that most pre-2022 privacy compliance programs — which were designed around disclosure, not technical enforcement — provide no § 631 defense.
What courts have found does establish consent:
- A functional consent mechanism that blocked non-essential scripts before any choice was made, coupled with a clear disclosure of what categories of data would be shared with which categories of third parties if the user accepted
- Affirmative acceptance of terms that explicitly disclosed real-time data sharing with named vendors — where the user accepted before any data was transmitted
- In some court decisions, continued use of a website after clear, prominent notice of tracking practices — though this "implied consent" theory has received much more skepticism from courts than affirmative opt-in
What courts have consistently held does not establish consent:
- A privacy policy describing data practices, however detailed, when the user is not required to review or accept it before data is captured
- A banner that loads after the tracked scripts have already begun executing
- Disclosure of tracking in fine print, footer links, or buried terms
- Retroactive disclosure — informing users after data has already been collected that it was shared
In Garcia v. AEG (May 2026), the defendant had a consent banner — but third-party cookies fired the moment the user landed, before the banner even rendered. The court let the CIPA § 631 aiding-and-abetting claim survive. This is the most dangerous pattern in modern web deployments: the existence of a banner is being used by plaintiffs as evidence that the operator knew consent was expected, compounding rather than mitigating the exposure when the technical configuration fails to enforce it.
The full penalty stack
Section 631 carries both criminal and civil consequences, and they stack in ways that create asymmetric pressure in litigation.
Civil penalties under § 637.2
Any person whose communication has been intercepted in violation of CIPA may recover the greater of: $5,000 per violation, or three times the amount of actual damages. No proof of harm is required for the $5,000 statutory floor — an unconsented interception is its own violation. In class action contexts, each California-resident visit during the class period is a potential class member and a potential per-violation calculation. The math at scale is enormous: a mid-sized eCommerce site with 50,000 California visits per month running an unconsented pixel for 24 months represents a theoretical exposure of $1.2 billion on a raw per-violation calculation. Courts have not applied that math, but it explains the settlement leverage that plaintiff counsel wield.
Criminal penalties
Section 631 is a "wobbler" — prosecutors may charge it as either a misdemeanor or a felony. A first offense misdemeanor carries up to one year in county jail and a fine of up to $2,500. A first offense felony carries up to three years in state prison. A second offense under CIPA (any provision from § 631 through § 636) carries fines up to $10,000 per violation. Criminal prosecution of website operators for tracking-related CIPA violations is rare, but the wobbler classification gives prosecutors discretion that defense counsel should not underestimate in high-profile cases.
Injunctive relief and attorneys' fees
§ 637.2 also authorizes injunctive relief and the recovery of reasonable attorneys' fees by a prevailing plaintiff. The attorneys' fees provision is part of what makes class actions economically viable for plaintiff firms even at low per-class-member settlement values — plaintiff counsel typically negotiates a percentage of the class fund as fees, making even modest settlements worth pursuing at scale.
2025–2026 case law map
| Case | Court · Date | Outcome | Key holding |
|---|---|---|---|
| Javier v. Assurance IQ, LLC | 9th Cir. · May 2022 | Plaintiff | § 631 applies to internet communications; consent must be prior, not retroactive. The watershed ruling — every demand letter cites it. |
| Greenley v. Kochava Inc. | S.D. Cal. · 2023 | Plaintiff | Surreptitiously embedded software fits the pen-register definition under §§ 638.50–51 when it identifies consumers and correlates data through fingerprinting. Most aggressive pen-register precedent cited in 2026 demand letters. |
| Mikulsky v. Bloomingdale's LLC | 9th Cir. · June 2025 | Plaintiff | Reversed district court dismissal. Complaint adequately pleaded that Bloomingdale's aided and abetted a session replay vendor to capture "contents" of communications in real time. Masking text fields was not sufficient when the pleading alleged real-time interception. |
| Torres v. Prudential Financial | N.D. Cal. · Apr. 2025 | Defense | Summary judgment for defendant. Session replay software does not violate § 631 because data only becomes readable after storage and reassembly — not while in transit. Strongest single defense victory of 2025. |
| Thomas v. Papa John's Int'l | 9th Cir. · 2025 | Defense | Affirmed dismissal. Papa John's as a party to the communication cannot eavesdrop on its own conversation (party exception). Plaintiff failed to plead the aiding-and-abetting theory against the vendor — a noted gap. |
| Gutierrez v. Converse Inc. | 9th Cir. · Jul. 2025 | Defense | Affirmed summary judgment against § 631(a) Clause 1 claim. Clause 1 applies to telephonic communications, not internet communications. Clause 2 claim failed: data not accessed in transit. |
| Ramos v. Gap, Inc. | N.D. Cal. · Jul. 2025 | Defense | Dismissed. Defendant retailer is a "party to the communication" and cannot be liable under § 631(a) for wiretapping. Email marketing pixel data (open rates, click rates) is information "about" communications, not "contents." |
| Garcia v. AEG | Cal. Ct. · May 2026 | Plaintiff | CIPA pen-register claim survived MTD. Consent banner present but cookies fired before it rendered. Court noted banner's existence suggests operator knew consent was expected. |
| Sisti v. Bosley, Inc. | Cal. Ct. · Apr. 2026 | Defense | Dismissed with prejudice. Site required affirmative acceptance before any tracking began. Consent was genuinely prior. Clearest example of the consent-first defense working on the merits. |
| Ortiz v. Foris Dax (Crypto.com) | Fed. · May 2026 | Plaintiff | Comprehensive analysis finding CIPA pen-register provision applies to internet tracking. Pen-register theory distinguished from § 631 wiretapping — broader and harder to dismiss. |
| R.C. et al. v. Sussex Publishers | N.D. Cal. · Jun. 2025 | Plaintiff | Plaintiff plausibly alleged § 631 claim for aiding and abetting third-party vendor to collect information without knowledge and consent. |
Available defenses, ranked by reliability
1. Prior consent — most reliable
A properly configured consent mechanism that blocks non-essential scripts before any visitor interaction — with verifiable, timestamped records proving that no third-party data was transmitted before consent — is the most reliable defense and the one that has generated clean dismissals. Sisti v. Bosley (April 2026) is the clearest recent example: the site required affirmative acceptance before any tracking began, and all CIPA claims were dismissed with prejudice. This is the only defense that is entirely within the website operator's technical control.
2. Party exception with agent characterization — reliable but fact-dependent
Characterizing the third-party vendor as a "mere agent" of the website operator — not an independent data user — can extend the party exception to the vendor. This requires vendor contracts that restrict data use exclusively to service provision and actual technical and operational evidence that the vendor's data practices are consistent with agent status. Thomas v. Papa John's shows this defense succeeding; Mikulsky shows it failing when the pleading adequately alleges real-time interception.
3. Post-transmission / not-in-transit — strong but vulnerable to specific technologies
Torres and Gutierrez have generated significant traction for the argument that data only becomes "readable" after storage and reassembly. This defense is strongest for analytics platforms that aggregate data in batches, and weakest for session replay tools that transmit keystrokes in real time to a third-party server — exactly the pattern Mikulsky found adequately pleaded. Counsel must assess whether the specific technology at issue is closer to batch analytics or real-time keystroke capture.
4. Clause 1 telephony limitation — reliable for that clause only
Several courts, including the Ninth Circuit in Gutierrez, have held that Clause 1 applies only to telephonic communications. This provides a clean defense to Clause 1 claims but does nothing for Clause 2 or Clause 4 — plaintiffs will simply drop Clause 1 and proceed on the others.
5. Arbitration clauses and class-action waivers — structural, not substantive
Enforceable arbitration agreements shift exposure significantly by converting putative class actions into individual arbitrations. They do not eliminate substantive liability — a $5,000 individual arbitration claim is still a valid claim — but they remove the class-action multiplier that makes mass demand-letter campaigns economically viable. Their enforceability turns on whether the plaintiff clearly assented to terms before data was captured, and plaintiffs challenge formation vigorously.
6. Content vs. metadata / IP-address-only — available but narrowing
Arguments that the challenged data is "metadata" or "routing information" rather than "contents" of a communication have succeeded in some cases (Ramos) but are increasingly vulnerable. Courts that have allowed Clause 2 claims through have often done so precisely because the plaintiffs alleged more than IP addresses — typing content, form values, and interaction data that more clearly qualifies as "contents."
For agencies: a per-client Section 631 risk audit
Agencies managing multiple client websites carry a specific, non-obvious exposure: they are often the entity that deploys the tracking configuration on a client site, and aiding-and-abetting liability under Clause 4 of § 631(a) can attach to the party who configures the system, not only to the party whose name appears on the website. An agency that installs a session replay tool on a client site, wires it to fire before consent is verified, and does not disclose that configuration to the client is potentially in the chain of liability. The following checklist represents the minimum § 631-aware audit for each client engagement.
Per-Client Section 631 Risk Audit Checklist
For agencies managing multiple client websites. Informational — not legal advice. Recommend qualified privacy counsel for high-risk clients.
Why technical evidence decides these cases
Read across the case law and one theme is consistent: cases are decided by technical facts, not legal theories. Which specific tool fired. When it fired relative to consent. What data it transmitted. Whether that data was "contents" or "metadata." Whether the vendor contract permitted independent use. Whether the consent mechanism genuinely blocked the tool or merely displayed a banner alongside it.
This creates a specific practical implication that legal practitioners and agency professionals increasingly recognize: the technical configuration of a client's consent architecture — not the language of its privacy policy — determines both liability exposure and the availability of defenses. A consent mechanism that technically blocks every third-party script before a user interaction, maintains verifiable timestamps of that blocking, and produces an exportable log showing that no data was transmitted to a specific vendor during a specific session is a fundamentally different legal position than a mechanism that displays a banner while the same data transmissions happen in the background.
For practitioners advising clients on pre-litigation risk reduction, the ask is not to change the legal strategy — it is to change the technical configuration. And for agencies managing multiple client sites, the risk-reduction question is the same: not "what does our privacy policy say" but "what actually fired before consent, for which vendor, on which page, on which date."
This is where a purpose-built consent enforcement platform, rather than a generic cookie banner, becomes relevant. A platform designed specifically around pre-consent enforcement — that blocks scripts genuinely before any visitor interaction, maintains page-scoped timestamps, and produces exportable records that hold up in a technical audit — creates an evidentiary position that generic disclosure-oriented tools do not. That configuration is what generated the clean dismissal in Sisti v. Bosley. It is what sets the factual record that determines whether a § 631 Clause 4 defense succeeds or fails.
ConsentPixel is built specifically around the technical configuration that § 631 defense requires: non-essential scripts are blocked before any visitor interaction, consent decisions are logged with page-level timestamps, and those records are exportable for use in regulatory or litigation contexts. We mention this not as a sales pitch but as the honest answer to the question practitioners and agencies are increasingly asking: what does compliant technical architecture actually look like? The short answer is: the same architecture that generated the clean § 631 dismissal in Bosley.
The bottom line
California Penal Code Section 631 is a statute whose operative reach for website operators runs almost entirely through its fourth clause — the aiding-and-abetting prohibition that reaches any website operator who deploys a third-party tool that receives communications in real time. The party exception insulates the website from direct liability but does not insulate the vendor if it uses data independently; the in-transit requirement is the most actively litigated substantive question; and the consent defense requires technical enforcement, not disclosure. The 2026 case law is genuinely split, with both significant defense wins (Torres, Gutierrez, Ramos, Bosley) and plaintiff victories (Mikulsky, Garcia, Ortiz). The decisive factor across every defense win on the merits: consent that was demonstrably prior, technically enforced, and evidentially documented. For agencies managing multiple client sites, the per-client configuration audit in this article is the minimum due-diligence framework. For CIPA-practicing counsel, the vendor contract, the DPA, and the technical configuration log are the evidence that will determine outcomes more than the legal theories will. This article is informational and not legal advice — specific situations require specific counsel.
See what actually fires before consent on your client sites
ConsentPixel — Privacy · Verified scans any site and shows exactly which third-party scripts fire before consent — the technical question that decides § 631 claims. Free scan, no card required.
Scan a site freeFrequently asked questions
What exactly does CIPA Section 631 prohibit?
Section 631(a) of the California Penal Code prohibits four categories of conduct: (1) intentionally tapping or making an unauthorized connection with a telegraph or telephone wire; (2) willfully reading or attempting to read the contents or meaning of any communication while in transit, without all-party consent; (3) using or communicating information obtained through either of the above; and (4) aiding, agreeing with, employing, or conspiring with any person to commit any of the above. The fourth clause — aiding and abetting — is the operative theory for website tracking claims, because the party exception prevents a website from being directly liable under clauses 1–3 for intercepting its own communications with visitors.
Why can't a website be directly liable under Section 631 for its own tracking?
The party exception holds that a party to a communication cannot "wiretap" it — you cannot eavesdrop on a conversation you are part of. Courts have consistently applied this to website operators: a website is itself a party to the interaction with its visitor, so it cannot directly violate clauses 1–3 of § 631(a). The viable theory for plaintiffs is therefore the aiding-and-abetting clause (4), arguing the website deployed a third-party vendor that received the communication and itself "intercepted" it. The viability of that theory turns on whether the vendor is an independent interceptor or merely an agent of the website.
What does "in transit" mean under Section 631?
"In transit" is the most actively litigated phrase in § 631 jurisprudence. The defendant-favorable interpretation — which generated defense wins in Torres v. Prudential (2025) and Gutierrez v. Converse (2025) — holds that data must be read while actively passing over a wire, not after storage, reassembly, and processing. Session replay software that reassembles data post-transmission does not read it "in transit." The plaintiff-favorable interpretation — upheld in Mikulsky v. Bloomingdale's (2025) — holds that real-time capture of keystrokes and interactions as they occur constitutes interception in transit. Whether a specific technology is closer to batch analytics or real-time keystroke capture is the decisive factual question.
What constitutes valid consent under Section 631 for a website?
The Ninth Circuit's 2022 ruling in Javier v. Assurance IQ established that consent must be prior to the interception — not retroactive or concurrent. A privacy policy disclosure, however detailed, does not satisfy the consent requirement if the user is not required to accept it before data is captured. A cookie banner that appears after tracking scripts have already loaded does not establish prior consent. What courts have found adequate: a consent mechanism that technically prevents any third-party data transmission before the user makes an affirmative choice, with clear disclosure of what data will be shared with which categories of third parties. This is not the "banner is present" standard — it is the "banner actually prevented the transmission" standard.
What are the damages under CIPA Section 631?
California Penal Code § 637.2 authorizes civil recovery of the greater of $5,000 per violation or three times actual damages — with no proof of harm required for the $5,000 statutory floor. Each unconsented interception is its own violation. In class action contexts where every California-resident visit during the class period is a potential class member, the aggregate theoretical exposure can reach enormous figures, which is what creates the demand-letter leverage that plaintiff firms deploy. Criminal penalties under § 631 itself run up to $2,500 per violation and one year in county jail as a misdemeanor, or up to three years in state prison as a felony. Second-offense CIPA violations carry fines up to $10,000 per violation.
Are agencies liable for CIPA violations on client websites they manage?
Potentially yes. The aiding-and-abetting clause under § 631(a) can reach any party who knowingly assists in the interception. An agency that configures and deploys tracking tools on a client site — particularly if the deployment includes session replay tools or pixels that fire before consent — may be in the chain of Clause 4 liability alongside the website operator. The agency's exposure depends on the facts: what it deployed, whether it knew the tools fired before consent, and what its contract with the client says about responsibility for privacy compliance. Agencies that proactively audit and document consent-gate configurations for each client, and disclose those configurations to clients, are in a materially stronger position than those that treat tracking deployment as a purely technical exercise. This is informational, not legal advice.