ConsentPixel – Privacy · Verified

⚖️ CIPA & Legal Risk

Invasion of Privacy in California: CIPA Litigation & Statute — Deep Reference

A working reference to invasion of privacy in California: what each section of the California Invasion of Privacy Act actually says, how the $5,000-per-violation math works, the one-year clock that governs every claim, and how the same conduct is treated in Texas, Indiana, Louisiana, New Jersey, and Michigan.

ConsentPixel Team Published July 2026 13 min read Statute reference
1 year
CIPA's statute of limitations — the clock that shapes every claim
$5,000
Statutory damages per violation, or 3× actual damages — whichever is greater
83%
Of US digital wiretapping suits filed in California alone

What "invasion of privacy in California" actually means legally

When people search for invasion of privacy in California, they're usually looking for one specific thing: the California Invasion of Privacy Act (CIPA), codified at California Penal Code §§ 630–638. It's worth being precise, because two different bodies of law hide behind that phrase.

Common-law privacy torts — intrusion upon seclusion, public disclosure of private facts, false light, misappropriation — are judge-made claims requiring proof of harm. They're what most states mean by "invasion of privacy."

CIPA is different. It's a criminal statute, enacted in 1967, that also carries a private right of action with fixed statutory damages and no requirement to prove harm. That combination is why California invasion of privacy laws generate litigation no other state's do. The legislature's stated purpose, right there in §630, was protecting Californians' privacy against new eavesdropping devices and techniques. It was written for phone taps. It is now aimed at your marketing tags.

The three facts that explain everything else

  • Private right of action (§637.2) — any individual can sue. No regulator required.
  • $5,000 per violation, or 3× actual damages, with no proof of harm needed.
  • It applies to any site a Californian can visit — your business needn't be in California.

The Invasion of Privacy Act, section by section

Most coverage treats CIPA as one undifferentiated thing. In litigation it isn't — the section pleaded determines the theory, the defenses, and often the outcome.

SectionWhat it prohibitsRole in website cases
§631Wiretapping — reading or attempting to read the contents of a communication in transit without all-party consentThe classic theory. Requires interception in transit — a real defense point.
§632Recording confidential communications without all-party consentMostly calls & chat; "confidential" is a limiting element
§638.51Installing or using a pen register or trap-and-trace device without a court orderThe 2024–26 growth theory. Captures routing/addressing data — IPs, URLs, identifiers.
§637.2— (remedy provision)The engine. Creates the private right of action and the $5,000 figure.
§632.7Interception of cellular/cordless calls, all-party consent, no malice requiredCall-recording claims

The strategic shift worth understanding: §631 requires "contents" of a communication, which invites arguments about whether a pixel captures content or mere metadata. §638.51 doesn't — a pen register is defined by capturing "dialing, routing, addressing, or signaling information," excluding contents. Plaintiffs moved to the pen-register theory precisely because it sidesteps the hardest element of the wiretap theory.

How CIPA statutory damages actually work

CIPA statutory damages come from §637.2, and the mechanics matter more than the headline number.

  • The greater of $5,000 per violation or three times actual damages. Not a cap — a floor.
  • No proof of actual harm is required. A plaintiff who lost nothing can still claim the statutory figure.
  • Injunctive relief and fees are also available under the same section.
  • "Per violation" was clarified effective January 1, 2017, and at least one federal court treated that as a clarification rather than an amendment — meaning it can reach conduct predating 2017.

The reason this drives an entire litigation industry is the multiplication. In a class action where every California visitor during the class period is a member, the arithmetic escalates immediately: a site with 10,000 California visitors over a one-year class period carries $50 million in theoretical statutory exposure before any settlement discount. Nobody expects that number to be awarded. It doesn't need to be — it only needs to be credible enough to make settling cheaper than litigating.

Criminal penalties exist too (§631/§632 first violations carry fines up to $2,500 and up to a year in county jail; repeat offenses up to $10,000), but prosecution of website operators is rare in practice. Enforcement runs almost entirely through §637.2 and private plaintiffs.

The statute is abstract. Your tag list isn't.

Every theory on this page starts with one factual question: did a third-party tracker transmit before the visitor consented? Scan your site free to see which trackers fire before consent — in about 10 seconds. It's the same check a plaintiff firm runs before drafting a demand letter.

Scan your site free →

No account needed · results in ~10 seconds

The CIPA statute of limitations: one year

The CIPA statute of limitations is one year, applied through California's Code of Civil Procedure §340(a) and confirmed by the Ninth Circuit in NEI Contracting & Engineering, Inc. v. Hanson Aggregates Pacific Southwest, Inc., 926 F.3d 528 (9th Cir. 2019). A claim filed after the year has run is time-barred.

This short clock has consequences most summaries miss:

  • Equitable tolling is a live argument. Because covert interception is by nature hard to discover, plaintiffs argue the clock shouldn't start until discovery. Courts have entertained this.
  • It shapes class definitions. Class periods are typically drawn to the limitations window, and stretching a class beyond it creates tolling gaps — which is exactly how Meta defeated class certification in the Pixel tax-filing litigation: plaintiffs broadened the class at certification, class members outside the original definition had untimely claims, and individualised tolling questions destroyed predominance.
  • It means reform won't end filings quickly. California's SB 690 would create a "commercial business purpose" exemption, but the retroactivity provision was removed in May 2025 — so even if enacted, suits could keep landing for a full year after it takes effect, with relief realistically no earlier than 2027.
  • It does not make old tracking safe. The clock runs from the violation, and every page load is arguably its own violation. A tracker still firing today generates fresh claims today.

How CIPA litigation became a wave

CIPA was a quiet statute for over fifty years, handling phone-recording disputes. The turn came with Javier v. Assurance IQ (9th Cir. 2022), which held that consent under §631 must be obtained before tracking begins — agreeing to a privacy policy after the fact isn't valid consent.

That single holding rewired the economics. Every site running the Meta Pixel, TikTok pixel, Google tags, or session-replay tools without a genuine consent gate became a candidate. The scale since is well documented: Fisher Phillips counted 1,641 digital wiretapping lawsuits filed across 28 states since June 2022, with 1,361 in California — 83% of all claims.

Why 83% of these suits are filed in California It's not that other states allow tracking — it's that suing there doesn't pay CALIFORNIA (CIPA) ✓ All-party consent required ✓ Private right of action (§637.2) ✓ $5,000 fixed, per violation ✓ No proof of harm needed = 1,361 suits since June 2022 the whole combination is the problem TX · IN · LA · NJ · MI ✗ One-party consent (mostly) ~ Civil remedies vary ✗ No $5,000-per-visit engine ~ Harm usually matters = the other 17%, across 27 states the site owner consents — that's enough Your site is visible in all 50 states. You are judged by the strictest one your visitors live in.
The consent standard is the whole story. In one-party states the website's own consent satisfies the statute. In California it doesn't — the visitor's consent is required too.

Where courts actually split

Anyone telling you CIPA litigation outcomes are settled is selling something. Courts applying a 1967 statute to technology its drafters couldn't imagine have reached openly inconsistent conclusions — sometimes on near-identical facts.

  • Pen-register theory accepted: in Camplisson v. Adidas America (S.D. Cal., Nov. 18, 2025), the court declined to dismiss claims that TikTok and Bing pixels were unlawful pen registers, finding IP addresses, unique identifiers, and fingerprinting material — and that a privacy policy buried in the footer, without affirmative opt-in, wasn't valid consent.
  • Pen-register theory rejected: other courts have dismissed the same theory outright — see our Rounds v. DDI breakdown.
  • Standing as the battleground: in Popa v. Microsoft, 153 F.4th 784 (9th Cir. 2025), the court rejected standing where the plaintiff didn't identify "embarrassing, invasive, or otherwise private" information captured by session replay. Sensitivity of the data has become the dividing line.
  • Real-time interception as a defense: Torres v. Prudential gave defendants their strongest §631 precedent, reasoning that session-replay data becomes readable only after storage and reassembly — not while in transit.

For the current state of play across every known case, see the CIPA Lawsuit Tracker, which we update monthly.

Invasion of privacy laws in other states

If you're asking about Texas invasion of privacy laws, Indiana, Louisiana, New Jersey, or Michigan, the honest answer is that none of them replicate CIPA's economics — and understanding why tells you where your real risk is.

StateWiretap statuteConsent standardWebsite-tracking risk profile
CaliforniaPenal Code §§630–638 (CIPA)All-partySevere — $5,000/violation + private right of action
TexasTex. Penal Code §16.02One-partyLow for wiretap theory — the site is a party. Exposure runs through the TDPSA instead.
IndianaInd. Code §35-33.5 (+ privacy torts)One-partyLow — "invasion of privacy" in Indiana usually means the tort or a criminal offense, not web tracking
LouisianaLa. Rev. Stat. §15:1303One-partyLow — plus the LDPA arrives Jan 1, 2027
New JerseyNJ Wiretapping & Electronic Surveillance Control ActOne-partyLow for wiretap; NJDPA governs data practices
MichiganMCL §750.539cNominally all-party*Limited — Sullivan v. Gray read the statute to reach only third-party intercepts, not participants

*Michigan is the interesting case: the statute reads as all-party, but Sullivan v. Gray, 117 Mich. App. 476 (1982), interpreted "eavesdropping" to require a third party — a participant may record. Michigan is frequently listed as all-party without that caveat.

The pattern is consistent. In one-party consent states, the website is itself a party to the visitor's communication, so its own consent satisfies the statute — which is why the wiretap theory largely fails there. California's all-party rule removes that defense entirely. Add a fixed $5,000 figure and no harm requirement, and you have the only jurisdiction where mass filings are economically rational.

The trap: this doesn't mean a Texas or Michigan business is safe. CIPA applies to any website a California resident can visit, regardless of where the business sits. Your exposure follows your visitors, not your headquarters. Separately, comprehensive state privacy laws — Texas's TDPSA, Indiana's, New Jersey's, and Louisiana's LDPA (effective January 1, 2027) — impose their own disclosure and opt-out duties, on a different track from wiretap law. A consent setup adequate under one framework can be inadequate under the other.

"A concept intended to anticipate, build, and manage privacy"

That phrase describes Privacy by Design — the principle that privacy should be anticipated and engineered into a system from the outset, rather than bolted on after a problem appears. It's embedded in GDPR Article 25 ("data protection by design and by default"), and it's the conceptual opposite of how most sites arrive at CIPA exposure.

The connection isn't decorative. Nearly every CIPA claim traces to the same architectural decision: tags were installed first, and consent was considered later — usually as a banner layered on top of tracking that was already running. Privacy by Design inverts the order, and inverting the order is what removes the claim.

The only defense that reliably works

Across every split, every theory, and every section, one principle survives: informed, affirmative, prior consent is a complete defense. CIPA does not reach conduct the visitor agreed to. A business with a genuine opt-in framework has little difficulty with these claims.

What fails is the near-miss. A banner that appears while tags are already transmitting doesn't cure anything — practitioners call it the "millisecond problem," and it's precisely the pattern Javier targets. A privacy policy in the footer isn't consent, as Camplisson confirmed. An opt-out model means the interception already happened before the opt-out rendered.

The distinction that trips people up: being CCPA-compliant does not make you CIPA-compliant. CCPA asks whether you disclosed your tracking and offered an opt-out. CIPA asks whether you intercepted the communication in the first place. A fully CCPA-compliant site and a CIPA-exposed site can be the same site.

Which makes the remedy technical rather than legal. ConsentPixel — Privacy · Verified blocks third-party trackers at the browser level until the visitor affirmatively consents, and logs each decision with a timestamp — so the interception the statute prohibits never occurs, and you can prove it. For the full remediation walkthrough, see our complete CIPA compliance guide.

✅ Key takeaways

  • CIPA is Cal. Penal Code §§630–638. §631 (wiretap) and §638.51 (pen register) supply the theories; §637.2 supplies the money.
  • $5,000 per violation or 3× actual damages, whichever is greater, with no proof of harm required.
  • The statute of limitations is one year — which shapes class definitions, tolling fights, and why reform won't stop filings quickly.
  • 83% of digital wiretap suits are Californian because it's the only state combining all-party consent, a private right of action, and fixed statutory damages.
  • One-party states (TX, IN, LA, NJ, and effectively MI) defeat the wiretap theory — but CIPA still reaches you if Californians can load your site.
  • Prior, affirmative consent is a complete defense. Everything else is argument.

Frequently asked questions

What is invasion of privacy in California?
Legally it usually means the California Invasion of Privacy Act (CIPA), California Penal Code §§630–638, enacted in 1967. It's a criminal statute that also creates a private right of action under §637.2, allowing individuals to sue for statutory damages without proving harm. That's distinct from common-law privacy torts like intrusion upon seclusion, which require proof of harm. CIPA now drives most US website-tracking litigation.
What is the CIPA statute of limitations?
One year. Courts apply California Code of Civil Procedure §340(a) to CIPA claims, confirmed by the Ninth Circuit in NEI Contracting & Engineering v. Hanson Aggregates Pacific Southwest, 926 F.3d 528 (9th Cir. 2019). Claims filed after a year are time-barred, though plaintiffs may argue equitable tolling where the interception was not reasonably discoverable. The one-year window also shapes class periods and was central to Meta defeating class certification in the Pixel tax-filing litigation.
How much are CIPA statutory damages?
Under §637.2, a plaintiff can recover the greater of $5,000 per violation or three times actual damages, plus injunctive relief and potentially fees. No proof of actual harm is required. The figure is a floor, not a cap. In class actions the multiplication is what drives settlements: a site with 10,000 California visitors over a one-year class period faces roughly $50 million in theoretical statutory exposure before any discount. Criminal penalties also exist but prosecution of website operators is rare.
Do Texas, Indiana, Louisiana, New Jersey or Michigan have laws like CIPA?
Not with the same economics. Texas (Penal Code §16.02), Indiana, Louisiana (Rev. Stat. §15:1303) and New Jersey are one-party consent states, so a website is itself a party to the visitor's communication and its own consent satisfies the statute — which largely defeats the wiretap theory. Michigan's statute reads as all-party, but Sullivan v. Gray interpreted it to reach only third-party intercepts. None combine all-party consent with a fixed $5,000-per-violation private right of action, which is why 83% of digital wiretapping suits are filed in California.
If my business isn't in California, am I exposed to CIPA?
Yes, potentially. CIPA applies to any website California residents can visit, regardless of where your business is located — exposure follows your visitors, not your headquarters. Separately, comprehensive state privacy laws such as Texas's TDPSA, Indiana's, New Jersey's NJDPA and Louisiana's LDPA (effective January 1, 2027) impose their own disclosure and opt-out obligations on a different legal track. This is general information, not legal advice; consult a qualified attorney about your situation.

The bottom line

The California Invasion of Privacy Act is a 1967 wiretapping statute whose modern power comes from three features working together: a private right of action, $5,000 per violation without proof of harm, and an all-party consent rule that removes the defense every one-party state gives you. The one-year limitations clock shapes how claims are packaged, but it doesn't make yesterday's tracking safe — every page load is arguably a fresh violation.

Courts remain split on almost every contested element. They are not split on consent. Prior, affirmative, informed consent defeats the claim — which turns a legal question into an engineering one: does anything transmit before your visitor chooses?

See which trackers fire before consent on your site

Scan free in about 10 seconds to see exactly what transmits before your visitors choose — the single factual question underneath every CIPA theory on this page. Then close the gap with ConsentPixel: block non-essential trackers until consent, log every decision, one pixel for CIPA, CCPA, and GDPR.

Scan your site free →

No account needed · then a 14-day free trial, no credit card, from $8.99/mo

CP

ConsentPixel Team

Privacy & Website Compliance

ConsentPixel — Privacy · Verified helps website owners and agencies control exactly which trackers fire, and when — covering CIPA, CCPA, and GDPR from a single pixel. We maintain the CIPA Lawsuit Tracker and read the filings so you don't have to. This article is educational and not legal advice; statutes and case law change, and outcomes are notoriously inconsistent. Consult a qualified attorney about your specific situation.

Scroll to Top