Will Insurance Cover a CIPA Lawsuit? Inside the FullStory Coverage Fight
Everyone warns you about getting sued for website tracking. Almost no one asks the more expensive question: will your insurance actually pay for it? A new case involving session-replay vendor FullStory suggests the answer is increasingly "not without a fight" — and it reveals a whole layer of the tracking-litigation economy that most compliance guides ignore.
On August 4, 2026, Evanston Insurance Company asked a California federal court to declare it owes no coverage to FullStory — the vendor behind widely used "Session Replay" software — for a claimed $5 million under an excess cyber policy, against defense costs FullStory says exceed $10 million. When even a well-funded technology vendor ends up fighting its own insurer over a tracking-litigation bill, it's a warning about how these claims get paid — or don't.
The takeaway for any business running session replay, pixels, or chat tools: a CIPA lawsuit and a covered CIPA lawsuit are two very different things. This is general information, not legal or insurance advice.
What this guide covers
There's a hidden layer to the website-tracking litigation wave that rarely makes it into compliance checklists: the fight over who pays. Getting a demand letter is one problem. Discovering your cyber policy won't respond to it is a second, larger one — and it's playing out right now in a case that pits a session-replay vendor against its own insurer.
The FullStory coverage case, decoded
Here's what the filing says. According to reporting on the complaint, Evanston Insurance Company filed a declaratory judgment action on August 4, 2026 in a California federal court, asking the court to find it owes no coverage to FullStory under an excess "follow form" cyber policy — the kind that sits above a primary insurer and largely mirrors its terms.
The complaint reportedly brings six declaratory causes of action, arguing in the alternative that FullStory: must prove exhaustion of the underlying policy limit; has no coverage for lawsuits that don't name FullStory or for client "claims"; gave late or insufficient notice; can't be reimbursed for voluntary payments; breached its duty to cooperate; and may be barred by a "Prior Knowledge Exclusion."
These are allegations in a pending coverage dispute — nothing has been decided, and FullStory has its own position to present. But the shape of the fight is the point: it's a menu of the exact arguments insurers use to avoid paying tracking-litigation bills.
Whatever the outcome, the case is a rare public look at how an excess cyber tower is supposed to work — and how quickly it can turn adversarial when a large, novel litigation bill lands. FullStory isn't a fly-by-night operator; it's an established analytics vendor. If it is in a coverage fight over session-replay defense costs, a mid-market business using the same category of tool should not assume its own policy will quietly respond.
Why this is a genuinely new kind of story
Most writing about CIPA — including plenty of ours — focuses on the litigation itself: the wiretapping theory, the $5,000-per-violation statutory damages under California Penal Code §637.2, the demand letters. That's the first layer of the tracking-litigation economy. The FullStory case exposes a second layer that gets almost no coverage: the insurance fight that determines whether any of those costs actually land on you or on a carrier.
And it's not isolated. Insurers have been moving on this for over a year:
- Cyber carriers are adding specific exclusions for web-tracking and wiretapping-style claims, insurance attorneys report.
- Carriers including large, well-known insurers have themselves filed coverage suits to avoid paying for underlying tracking cases.
- Since 2022, roughly 4,000 online-privacy claims tied to digital tracking have been filed nationwide, per an analysis cited by law firm Constangy — enough volume to make carriers rethink their exposure.
In other words, the FullStory dispute isn't a one-off. It's the most visible example of a market-wide shift: as tracking claims scaled, insurers started building the door that lets them decline them.
The three exclusions that deny CIPA claims
Here's the part that should reshape how you think about your policy. Even a cyber policy that looks like it covers privacy can deny a CIPA claim on any one of three common exclusions. Insurance counsel consistently name the same three — and any single one can produce a full denial.
The eavesdropping / wiretapping exclusion
Bars claims arising from unauthorized interception, monitoring, or recording of communications. Because CIPA is a wiretapping statute, a claim built on session replay, live chat, or call recording is likely to trigger this exclusion immediately.
The intentional-acts exclusion
Excludes losses from deliberate conduct. Carriers argue that deploying tracking technology on purpose — even routine analytics — is an intentional act, not a fortuitous "occurrence" the policy was meant to cover.
The statutory-violation exclusion
Excludes liability arising from violations of specific statutes — often listing wiretap and privacy laws by name. A CIPA claim can fall squarely inside it, regardless of how strong the rest of the policy's privacy language looks.
The trap is that "privacy liability" coverage in a cyber policy is not the same as coverage for a CIPA wiretapping claim. The labels look alike; the outcomes diverge. A policy can advertise privacy protection on its declarations page and still deny a session-replay claim through one of these carve-outs.
The "silent cyber" trap
Even when your policy doesn't contain an explicit tracking exclusion, you may not be safe — because of the opposite problem: silence. Most cyber policies were written for data breaches, not wiretapping. When a policy is "silent" on CIPA — neither clearly granting nor clearly excluding it — you don't get a clean coverage grant. You get a disputed coverage situation at claim time, exactly when you can least afford one.
Affirmative coverage
The policy expressly covers privacy-statute claims — often conditioned on you maintaining privacy controls. The cleanest outcome, and increasingly what careful buyers negotiate for.
"Silent" policy
Neither grants nor excludes CIPA claims. Reads like coverage until a claim hits — then becomes a fight over interpretation, notice, and exclusions. The most common and most dangerous state.
Explicit exclusion
The policy names web-tracking or wiretapping claims and excludes them outright. No ambiguity — and no coverage. Increasingly common as carriers tighten wording.
Industry commentary describes insurers taking exactly these three approaches to the CIPA surge: adding exclusions, staying silent, or offering affirmative coverage tied to compliance requirements. Which one your policy took is the difference between a covered claim and a self-funded one — and most buyers have never checked.
See what's actually firing before consent on your site
The cleanest way to stay out of a coverage fight is to not generate the claim in the first place. Scan your site free to see which trackers — including session-replay tools — fire before a visitor consents, and whether any keep running after they opt out. About 10 seconds, no account.
Why this matters for your business, not just FullStory
It's tempting to read the FullStory case as a vendor problem. It isn't. The same dynamics reach any business running the tools plaintiffs target — and the exposure runs in both directions:
- You can be sued directly. Website operators, not just vendors, are the primary CIPA and wiretapping defendants. The statutory-damages math ($5,000 per violation under §637.2, or federal Wiretap Act damages of the greater of $100/day or $10,000) scales fast across a class.
- Vendor exposure flows back to you. When a vendor like FullStory is named — as it reportedly is in a federal Wiretap Act class action involving JetBlue — the underlying business is usually a defendant too, and contractual indemnities can pull you into the vendor's fight.
- Your coverage may be thinner than the vendor's. FullStory has a cyber tower and the resources to litigate coverage. A mid-market business with a single "silent" cyber policy has far less cushion if a carrier declines.
You can track the underlying litigation wave in our CIPA lawsuit tracker, and read the mechanics of the wiretapping theory on our CIPA regulation hub. The coverage layer sits on top of all of it.
Three questions to ask your broker this week
You don't need to be an insurance expert to close the biggest gaps. Bring these three questions to your broker or carrier — the answers tell you almost everything about your real exposure. (This is general information; your broker and counsel should advise on your specific policy.)
- "Does our policy respond to claims alleging violations of privacy laws — not just breaches of our own privacy policy?" This is the distinction brokers say matters most. Coverage for "your privacy policy" is not coverage for a CIPA statutory claim.
- "Do we have an eavesdropping/wiretapping, intentional-acts, or statutory-violation exclusion — and does any of them name CIPA or web tracking?" Ask them to point to the exact endorsement language, not summarize it.
- "If we switched carriers, is our retro date continuous?" Switching without retro-date continuity can leave prior-act CIPA exposure uncovered — a claim about last year's tracking can fall into a gap between policies.
The control that keeps you out of the coverage fight
Here's the throughline. Every path above — denial by exclusion, a "silent" policy dispute, a retro-date gap — only matters if a claim exists in the first place. The most reliable way to protect yourself isn't a better policy after the fact; it's not generating the claim: don't let trackers fire before consent.
The CIPA theory depends on session-replay tools and pixels capturing a visitor's activity before they've agreed. A consent layer that genuinely blocks those trackers until the right consent state removes the underlying conduct the lawsuits are built on. It's also increasingly what affirmative cyber coverage requires — carriers offering real CIPA coverage often condition it on maintaining privacy controls, so prevention can both reduce your risk and improve your insurability.
This is the core of the prevention-first, CIPA-first approach behind ConsentPixel — Privacy · Verified: from a single pixel, it blocks third-party trackers — including session replay — at the browser level until a visitor consents, honors opt-out and Global Privacy Control signals, and logs each decision as evidence. The goal isn't to help you win a coverage fight; it's to keep you out of one. It's not legal or insurance advice, and not a substitute for proper counsel and a well-negotiated policy.
Weigh the numbers. A prevention-first consent layer costs a few dollars a month per site. A contested CIPA claim can mean statutory damages, a defense bill in the six or seven figures, and — as the FullStory case shows — a second fight with your own insurer over who pays it. The cheapest tracker setup is a false economy if it invites the one claim your policy won't cover. (We break down the tooling economics in our CMP pricing comparison.)
Key takeaways
- A CIPA lawsuit and a covered CIPA lawsuit are different things. The FullStory coverage fight shows even a well-resourced vendor can end up battling its own insurer over a $10M+ defense bill.
- Three exclusions can deny a CIPA claim — eavesdropping/wiretapping, intentional-acts, and statutory-violation — even on a policy that advertises "privacy" coverage.
- "Silent" cyber policies are the common trap — written for breaches, not wiretapping, they turn into disputes at claim time rather than clean coverage.
- This reaches operators, not just vendors — you can be a direct defendant and get pulled into a vendor's fight through indemnities.
- Ask three broker questions: Does it cover privacy laws? Any wiretap/statutory exclusions? Is our retro date continuous?
- Prevention avoids the fight entirely — blocking trackers before consent removes the conduct the claims are built on, and often improves insurability.
The bottom line
The tracking-litigation economy has grown a second story. The first was the wave of lawsuits; the second is the fight over who pays for them — and as the FullStory case shows, insurers are increasingly willing to say "not us." For a business relying on a cyber policy it has never stress-tested against a wiretapping claim, that's a gap hiding in plain sight.
You can close it from two directions: negotiate coverage that actually names privacy-law claims, and — more durably — stop generating the claims in the first place by making sure trackers don't fire before consent. The second is cheaper, faster, and entirely in your control.
Start by seeing what's actually running on your own site today.
See if your site is generating the claim your insurer won't cover
Scan your site free to see every third-party tracker — including session-replay tools — that fires before consent, and whether any keep running after opt-out. Then close the gap with a single prevention-first pixel that blocks trackers, honors GPC, and logs the proof.
Scan your site free →ConsentPixel — Privacy · Verified helps website owners and agencies reduce exposure to CIPA, CCPA, GDPR, and US state privacy laws from a single pixel — blocking trackers until the right consent state, honoring opt-out and GPC signals, and logging each decision as evidence. This article is general educational information, not legal or insurance advice, and does not describe or recommend any specific insurance policy. Litigation details reflect allegations in pending or reported matters as of August 2026 and may change. ConsentPixel is not a law firm or an insurance advisor.
Frequently asked questions
Does cyber insurance cover CIPA lawsuits?
Not automatically. Most cyber policies were designed for data breaches, not wiretapping-style privacy claims, so a CIPA lawsuit may fall outside what the policy actually covers. Carriers commonly rely on three exclusions to deny these claims — an eavesdropping/wiretapping exclusion, an intentional-acts exclusion, and a statutory-violation exclusion — any of which can produce a full denial even when the policy appears to include privacy liability coverage. Some policies are "silent" on CIPA, neither granting nor excluding it, which creates a disputed coverage situation at claim time. Whether you're covered depends entirely on your specific policy wording; review it with your broker and counsel. This is general information, not insurance advice.
What is the FullStory insurance case about?
According to reporting on the complaint, Evanston Insurance Company filed a declaratory judgment action on August 4, 2026 in a California federal court, asking the court to find it owes no coverage to FullStory — the vendor behind widely used session-replay software — under an excess cyber policy. FullStory reportedly demanded $5 million under that excess policy and says its defense costs across session-replay litigation exceed $10 million. The insurer's complaint reportedly raises six declaratory causes of action, including arguments about exhaustion of underlying limits, late notice, voluntary payments, a duty to cooperate, and a "Prior Knowledge Exclusion." These are allegations in a pending dispute; nothing has been decided.
Why would an insurer refuse to pay a session-replay defense bill?
Because session-replay claims are usually built on wiretapping statutes like California's CIPA, and cyber policies often contain an eavesdropping or wiretapping exclusion that bars claims arising from unauthorized interception, monitoring, or recording of communications. Insurers may also invoke an intentional-acts exclusion — arguing that deploying tracking technology was deliberate rather than a fortuitous loss — or a statutory-violation exclusion that lists privacy or wiretap laws by name. On top of those, insurers can dispute notice timing, exhaustion of underlying limits, and cooperation. The FullStory coverage case reportedly raises several of these arguments at once, which is why it's such a clear illustration of the exposure.
Can my business be sued for CIPA even if we only use a third-party tool?
Yes. Website operators — not just the software vendors — are the primary defendants in CIPA and wiretapping cases, because the operator is the party that deployed the tracking tool on its site. Plaintiffs often name both the operator and the vendor. Even where a vendor is named directly, as FullStory reportedly is in a federal Wiretap Act class action involving JetBlue, the underlying business is typically a defendant too, and contractual indemnities can pull the operator into the vendor's dispute. Statutory damages are significant: $5,000 per violation under California Penal Code §637.2, or under the federal Wiretap Act the greater of $100 per day or $10,000. This is general information, not legal advice.
What questions should I ask my insurance broker about CIPA?
Three questions cover most of the exposure. First: does our policy respond to claims alleging violations of privacy laws, not just breaches of our own privacy policy? Coverage for your privacy policy is not the same as coverage for a CIPA statutory claim. Second: do we have an eavesdropping/wiretapping, intentional-acts, or statutory-violation exclusion, and does any of them name CIPA or web tracking? Ask to see the exact endorsement language. Third: if we switched carriers, is our retro date continuous? Switching without retro-date continuity can leave prior-act CIPA exposure uncovered. Your broker and counsel should advise on your specific policy.
How can I reduce my CIPA exposure in the first place?
The CIPA theory depends on session-replay tools and tracking pixels capturing a visitor's activity before they've consented. The most reliable way to reduce exposure is to prevent that: deploy a consent layer that genuinely blocks non-essential third-party trackers — including session replay — until a visitor consents, honors opt-out and Global Privacy Control signals, and keeps timestamped records of each decision. This removes the underlying conduct the lawsuits are built on, and because some insurers now condition affirmative CIPA coverage on maintaining privacy controls, it can also improve your insurability. Confirm what actually fires on your site before and after consent, since a banner that only displays a notice without blocking trackers doesn't close the gap. This is general information, not legal advice.