Skip to Main Content
Publications
Publications | December 5, 2025
2 minute read

A Word of Caution: Wiretap Lawsuits Continue to Plague Website Owners

Over the last several years, plaintiffs’ attorneys and other individuals have used antiquated wiretapping laws, including California’s 1967 wiretapping act, to allege that businesses with websites utilizing third parties and tracking technologies (such as a cookies and Google-powered search functionality) are “eavesdropping” in violation of such laws. While this interpretation is dubious, the annoyance and cost of a potential lawsuit often result in settlements being paid to these claimants.

California Invasion of Privacy Act (CIPA)

The California Invasion of Privacy Act (CIPA) is a 1967 law which prohibits “eavesdropping on private communications” and forbids the use of “pen registers” or other devices capturing these communications. A violation allows a plaintiff to seek the greater of $5,000 or three times the actual damages. CIPA applies to individuals and entities doing business in California or targeting California residents — meaning if your website reaches California consumers, you could be subject to a claim.

Current Practice

Plaintiffs’ attorneys and enterprising individuals have seized on this opportunity to go after companies using pixels, session replay and chat widgets on their websites, arguing that if third parties provide these technologies, then they are intercepting “private communications” in violation of CIPA. The company is then threatened with a lawsuit, alleging the company’s practices result in the wrongful interception of the website user’s information in violation of CIPA, unless the company agrees to a settlement. Companies are generally paying out, determining that the payment will be less burdensome and expensive than fighting it out in court.

Change on the Horizon

These cases are still being litigated, and courts in California remain divided as to whether these actions do, in fact, constitute illegal wiretapping. There is also significant pressure on the legislature to amend the CIPA to make it clear it does not encompass web-based data collection for commercial purposes, but thus far, it has not taken action.

Minimize Your Risk

There are steps you can take now to mitigate your risk of a CIPA claim.

1) Audit Your Website. Regularly review the technologies used on your website to understand your risks, with a specific focus on third-party cookies and other tracking technologies.

2) Update Your Privacy Policy. Confirm your website privacy policy is up to date and accurately reflects your current practices.

3) Ensure Appropriate Notice. CIPA requires that consumers are given notice before their data is collected and provided an opportunity to consent to such data being collected. Implementing a pop-up (often called a cookie banner) to alert visitors that you are utilizing third-party tracking technologies is strongly recommended. Additionally, adding language to search functionalities and chat features clarifying that the functionality is provided by a third party can help satisfy the notice requirements.

We’re here to help.

If you have any questions about how these principles may impact your company, please reach out to Nate Steed, Kelly Hollingsworth, Sam Poortenga, Brian Wassom or your Warner attorney.