Invasion of Privacy in California: CIPA Litigation & Statute — Deep Reference
A working reference to invasion of privacy in California: what each section of the California Invasion of Privacy Act actually says, how the $5,000-per-violation math works, the one-year clock that governs every claim, and how the same conduct is treated in Texas, Indiana, Louisiana, New Jersey, and Michigan.
On this page
What "invasion of privacy in California" actually means legally
When people search for invasion of privacy in California, they're usually looking for one specific thing: the California Invasion of Privacy Act (CIPA), codified at California Penal Code §§ 630–638. It's worth being precise, because two different bodies of law hide behind that phrase.
Common-law privacy torts — intrusion upon seclusion, public disclosure of private facts, false light, misappropriation — are judge-made claims requiring proof of harm. They're what most states mean by "invasion of privacy."
CIPA is different. It's a criminal statute, enacted in 1967, that also carries a private right of action with fixed statutory damages and no requirement to prove harm. That combination is why California invasion of privacy laws generate litigation no other state's do. The legislature's stated purpose, right there in §630, was protecting Californians' privacy against new eavesdropping devices and techniques. It was written for phone taps. It is now aimed at your marketing tags.
The three facts that explain everything else
- Private right of action (§637.2) — any individual can sue. No regulator required.
- $5,000 per violation, or 3× actual damages, with no proof of harm needed.
- It applies to any site a Californian can visit — your business needn't be in California.
The Invasion of Privacy Act, section by section
Most coverage treats CIPA as one undifferentiated thing. In litigation it isn't — the section pleaded determines the theory, the defenses, and often the outcome.
| Section | What it prohibits | Role in website cases |
|---|---|---|
| §631 | Wiretapping — reading or attempting to read the contents of a communication in transit without all-party consent | The classic theory. Requires interception in transit — a real defense point. |
| §632 | Recording confidential communications without all-party consent | Mostly calls & chat; "confidential" is a limiting element |
| §638.51 | Installing or using a pen register or trap-and-trace device without a court order | The 2024–26 growth theory. Captures routing/addressing data — IPs, URLs, identifiers. |
| §637.2 | — (remedy provision) | The engine. Creates the private right of action and the $5,000 figure. |
| §632.7 | Interception of cellular/cordless calls, all-party consent, no malice required | Call-recording claims |
The strategic shift worth understanding: §631 requires "contents" of a communication, which invites arguments about whether a pixel captures content or mere metadata. §638.51 doesn't — a pen register is defined by capturing "dialing, routing, addressing, or signaling information," excluding contents. Plaintiffs moved to the pen-register theory precisely because it sidesteps the hardest element of the wiretap theory.
How CIPA statutory damages actually work
CIPA statutory damages come from §637.2, and the mechanics matter more than the headline number.
- The greater of $5,000 per violation or three times actual damages. Not a cap — a floor.
- No proof of actual harm is required. A plaintiff who lost nothing can still claim the statutory figure.
- Injunctive relief and fees are also available under the same section.
- "Per violation" was clarified effective January 1, 2017, and at least one federal court treated that as a clarification rather than an amendment — meaning it can reach conduct predating 2017.
The reason this drives an entire litigation industry is the multiplication. In a class action where every California visitor during the class period is a member, the arithmetic escalates immediately: a site with 10,000 California visitors over a one-year class period carries $50 million in theoretical statutory exposure before any settlement discount. Nobody expects that number to be awarded. It doesn't need to be — it only needs to be credible enough to make settling cheaper than litigating.
Criminal penalties exist too (§631/§632 first violations carry fines up to $2,500 and up to a year in county jail; repeat offenses up to $10,000), but prosecution of website operators is rare in practice. Enforcement runs almost entirely through §637.2 and private plaintiffs.
The statute is abstract. Your tag list isn't.
Every theory on this page starts with one factual question: did a third-party tracker transmit before the visitor consented? Scan your site free to see which trackers fire before consent — in about 10 seconds. It's the same check a plaintiff firm runs before drafting a demand letter.
Scan your site free →No account needed · results in ~10 seconds
The CIPA statute of limitations: one year
The CIPA statute of limitations is one year, applied through California's Code of Civil Procedure §340(a) and confirmed by the Ninth Circuit in NEI Contracting & Engineering, Inc. v. Hanson Aggregates Pacific Southwest, Inc., 926 F.3d 528 (9th Cir. 2019). A claim filed after the year has run is time-barred.
This short clock has consequences most summaries miss:
- Equitable tolling is a live argument. Because covert interception is by nature hard to discover, plaintiffs argue the clock shouldn't start until discovery. Courts have entertained this.
- It shapes class definitions. Class periods are typically drawn to the limitations window, and stretching a class beyond it creates tolling gaps — which is exactly how Meta defeated class certification in the Pixel tax-filing litigation: plaintiffs broadened the class at certification, class members outside the original definition had untimely claims, and individualised tolling questions destroyed predominance.
- It means reform won't end filings quickly. California's SB 690 would create a "commercial business purpose" exemption, but the retroactivity provision was removed in May 2025 — so even if enacted, suits could keep landing for a full year after it takes effect, with relief realistically no earlier than 2027.
- It does not make old tracking safe. The clock runs from the violation, and every page load is arguably its own violation. A tracker still firing today generates fresh claims today.
How CIPA litigation became a wave
CIPA was a quiet statute for over fifty years, handling phone-recording disputes. The turn came with Javier v. Assurance IQ (9th Cir. 2022), which held that consent under §631 must be obtained before tracking begins — agreeing to a privacy policy after the fact isn't valid consent.
That single holding rewired the economics. Every site running the Meta Pixel, TikTok pixel, Google tags, or session-replay tools without a genuine consent gate became a candidate. The scale since is well documented: Fisher Phillips counted 1,641 digital wiretapping lawsuits filed across 28 states since June 2022, with 1,361 in California — 83% of all claims.
Where courts actually split
Anyone telling you CIPA litigation outcomes are settled is selling something. Courts applying a 1967 statute to technology its drafters couldn't imagine have reached openly inconsistent conclusions — sometimes on near-identical facts.
- Pen-register theory accepted: in Camplisson v. Adidas America (S.D. Cal., Nov. 18, 2025), the court declined to dismiss claims that TikTok and Bing pixels were unlawful pen registers, finding IP addresses, unique identifiers, and fingerprinting material — and that a privacy policy buried in the footer, without affirmative opt-in, wasn't valid consent.
- Pen-register theory rejected: other courts have dismissed the same theory outright — see our Rounds v. DDI breakdown.
- Standing as the battleground: in Popa v. Microsoft, 153 F.4th 784 (9th Cir. 2025), the court rejected standing where the plaintiff didn't identify "embarrassing, invasive, or otherwise private" information captured by session replay. Sensitivity of the data has become the dividing line.
- Real-time interception as a defense: Torres v. Prudential gave defendants their strongest §631 precedent, reasoning that session-replay data becomes readable only after storage and reassembly — not while in transit.
For the current state of play across every known case, see the CIPA Lawsuit Tracker, which we update monthly.
Invasion of privacy laws in other states
If you're asking about Texas invasion of privacy laws, Indiana, Louisiana, New Jersey, or Michigan, the honest answer is that none of them replicate CIPA's economics — and understanding why tells you where your real risk is.
| State | Wiretap statute | Consent standard | Website-tracking risk profile |
|---|---|---|---|
| California | Penal Code §§630–638 (CIPA) | All-party | Severe — $5,000/violation + private right of action |
| Texas | Tex. Penal Code §16.02 | One-party | Low for wiretap theory — the site is a party. Exposure runs through the TDPSA instead. |
| Indiana | Ind. Code §35-33.5 (+ privacy torts) | One-party | Low — "invasion of privacy" in Indiana usually means the tort or a criminal offense, not web tracking |
| Louisiana | La. Rev. Stat. §15:1303 | One-party | Low — plus the LDPA arrives Jan 1, 2027 |
| New Jersey | NJ Wiretapping & Electronic Surveillance Control Act | One-party | Low for wiretap; NJDPA governs data practices |
| Michigan | MCL §750.539c | Nominally all-party* | Limited — Sullivan v. Gray read the statute to reach only third-party intercepts, not participants |
*Michigan is the interesting case: the statute reads as all-party, but Sullivan v. Gray, 117 Mich. App. 476 (1982), interpreted "eavesdropping" to require a third party — a participant may record. Michigan is frequently listed as all-party without that caveat.
The pattern is consistent. In one-party consent states, the website is itself a party to the visitor's communication, so its own consent satisfies the statute — which is why the wiretap theory largely fails there. California's all-party rule removes that defense entirely. Add a fixed $5,000 figure and no harm requirement, and you have the only jurisdiction where mass filings are economically rational.
The trap: this doesn't mean a Texas or Michigan business is safe. CIPA applies to any website a California resident can visit, regardless of where the business sits. Your exposure follows your visitors, not your headquarters. Separately, comprehensive state privacy laws — Texas's TDPSA, Indiana's, New Jersey's, and Louisiana's LDPA (effective January 1, 2027) — impose their own disclosure and opt-out duties, on a different track from wiretap law. A consent setup adequate under one framework can be inadequate under the other.
"A concept intended to anticipate, build, and manage privacy"
That phrase describes Privacy by Design — the principle that privacy should be anticipated and engineered into a system from the outset, rather than bolted on after a problem appears. It's embedded in GDPR Article 25 ("data protection by design and by default"), and it's the conceptual opposite of how most sites arrive at CIPA exposure.
The connection isn't decorative. Nearly every CIPA claim traces to the same architectural decision: tags were installed first, and consent was considered later — usually as a banner layered on top of tracking that was already running. Privacy by Design inverts the order, and inverting the order is what removes the claim.
The only defense that reliably works
Across every split, every theory, and every section, one principle survives: informed, affirmative, prior consent is a complete defense. CIPA does not reach conduct the visitor agreed to. A business with a genuine opt-in framework has little difficulty with these claims.
What fails is the near-miss. A banner that appears while tags are already transmitting doesn't cure anything — practitioners call it the "millisecond problem," and it's precisely the pattern Javier targets. A privacy policy in the footer isn't consent, as Camplisson confirmed. An opt-out model means the interception already happened before the opt-out rendered.
Which makes the remedy technical rather than legal. ConsentPixel — Privacy · Verified blocks third-party trackers at the browser level until the visitor affirmatively consents, and logs each decision with a timestamp — so the interception the statute prohibits never occurs, and you can prove it. For the full remediation walkthrough, see our complete CIPA compliance guide.
✅ Key takeaways
- CIPA is Cal. Penal Code §§630–638. §631 (wiretap) and §638.51 (pen register) supply the theories; §637.2 supplies the money.
- $5,000 per violation or 3× actual damages, whichever is greater, with no proof of harm required.
- The statute of limitations is one year — which shapes class definitions, tolling fights, and why reform won't stop filings quickly.
- 83% of digital wiretap suits are Californian because it's the only state combining all-party consent, a private right of action, and fixed statutory damages.
- One-party states (TX, IN, LA, NJ, and effectively MI) defeat the wiretap theory — but CIPA still reaches you if Californians can load your site.
- Prior, affirmative consent is a complete defense. Everything else is argument.
Frequently asked questions
What is invasion of privacy in California?
What is the CIPA statute of limitations?
How much are CIPA statutory damages?
Do Texas, Indiana, Louisiana, New Jersey or Michigan have laws like CIPA?
If my business isn't in California, am I exposed to CIPA?
The bottom line
The California Invasion of Privacy Act is a 1967 wiretapping statute whose modern power comes from three features working together: a private right of action, $5,000 per violation without proof of harm, and an all-party consent rule that removes the defense every one-party state gives you. The one-year limitations clock shapes how claims are packaged, but it doesn't make yesterday's tracking safe — every page load is arguably a fresh violation.
Courts remain split on almost every contested element. They are not split on consent. Prior, affirmative, informed consent defeats the claim — which turns a legal question into an engineering one: does anything transmit before your visitor chooses?
See which trackers fire before consent on your site
Scan free in about 10 seconds to see exactly what transmits before your visitors choose — the single factual question underneath every CIPA theory on this page. Then close the gap with ConsentPixel: block non-essential trackers until consent, log every decision, one pixel for CIPA, CCPA, and GDPR.
Scan your site free →No account needed · then a 14-day free trial, no credit card, from $8.99/mo