CIPA and Your Website: Why Pre-Consent Trackers Are the New Wiretap Lawsuit
By Lukasz Czechura · August 12, 2026 · 9 min read
Executive summary. A wiretapping statute written in 1967, decades before the web existed, has become one of the most active sources of privacy litigation in the United States. Under the California Invasion of Privacy Act (CIPA), plaintiffs are suing ordinary businesses over the analytics and advertising trackers running on their websites - the same pixels, tags, and chat widgets that marketing teams install without a second thought. The mechanics are unforgiving: statutory damages of $5,000 per violation, argued on a per-visitor basis, turn a routine tracking script into a balance-sheet risk. Most organizations have no idea what their own site does before a visitor consents. This article explains why CIPA is serious, what the law actually says, and how Inttelio measures your true exposure.
A wiretap law, repurposed for the modern web
CIPA was designed to stop people from tapping phone lines and secretly recording conversations. Its language, however, is broad, and the plaintiffs’ bar has spent the last few years fitting that language onto website technology. Two provisions now dominate the litigation.
- Section 631 - the anti-wiretapping clause. This is used against session-replay tools that record a visitor’s clicks, scrolling, and form entries, and against third-party pixels such as advertising and analytics tags. The theory: the tracker is an unauthorized third party “eavesdropping” on the communication between the visitor and the website, in real time, without consent.
- Section 638.51 - the pen register and trap-and-trace clause. This newer and fast-growing theory targets scripts that capture a visitor’s IP address, device, and browser signals. Plaintiffs argue that a tracking tag which routes those identifiers to a third party is, in effect, an unlawful “pen register” installed without the court order the statute requires.
Neither theory requires the plaintiff to prove any real harm. That is the crux of the problem.
Why the numbers make this so dangerous
CIPA carries statutory damages of $5,000 per violation, or three times actual damages, whichever is greater, plus injunctive relief. Plaintiffs contend that each visitor - or even each tracked interaction - is a separate violation. Do the arithmetic on a modest amount of traffic and the theoretical exposure climbs into the tens or hundreds of millions of dollars. No actual data breach is needed. No misuse of the data is needed. The mere act of transmitting a visitor’s information to a third party before consent is the alleged violation.
That structure is catnip for class actions and, increasingly, for a demand-letter industry. A law firm sends a letter asserting CIPA violations and offers to settle for a five or six-figure sum, well below the cost of litigating. Many companies pay simply to make it disappear, which funds the next round of letters. This is no longer a theoretical risk for large enterprises; small and mid-sized businesses with a Meta Pixel, Google Analytics, or a chat widget are receiving these letters every week.
The uncomfortable truth: most sites track before they ask
The single fact that decides most of these cases is timing. Did the tracker transmit the visitor’s data before they made a consent choice? In the assessments Inttelio runs, the answer is far too often yes, and the site’s owners are genuinely surprised to learn it. A few patterns recur:
- Banners that gate nothing. A cookie banner appears, but analytics, advertising, and identity tags have already fired on page load. The banner records a preference after the fact - the transmission the lawsuits target has already happened.
- Implied “by using this site you agree” notices. A notice that treats mere presence on the page as consent does not meet the prior, express, opt-in standard these claims demand.
- No banner at all. Plenty of sites - including some that advertise their compliance credentials - run a full analytics and remarketing stack with no consent mechanism whatsoever.
- Silent identity resolution. Behind the visible pixels, real-time-bidding identity syncs and B2B de-anonymization vendors quietly match the visitor across the ad ecosystem, sending unique identifiers to third parties the business has never heard of.
A screenshot of a tidy cookie banner tells you nothing about whether any of this is happening. Only watching the site behave, in a real browser, does.
Why generic scanners miss it
Off-the-shelf cookie scanners give a false sense of security for two technical reasons. First, many enterprise sites sit behind bot protection that starves an automated scanner of the very requests it is supposed to measure, producing a clean-looking report that is simply wrong. Second, a growing number of sites defer their tracking tags until the visitor interacts - a scroll or a click - so a scanner that never touches the page sees nothing, while a real person triggers the full tracker load a second later. An assessment that does not use a real, interacting browser will under-report the exact behavior that creates liability.
How Inttelio analyzes your real consent behavior
Inttelio approaches this the way a plaintiff’s expert would, but on your side and before a letter arrives. We capture your site exactly as a real visitor’s browser experiences it, and we document what actually happens around the consent choice. A typical engagement produces:
- A pre-consent tracker inventory. Every analytics, advertising, and identity tracker that transmits before any consent choice, with the specific network requests and cookies as evidence.
- A before-and-after comparison. What fires on load, what unblocks after an explicit accept, and whether a rejection is actually honored - captured with real interaction so interaction-delayed tags are not missed.
- A CIPA risk rating per finding. Each tracker mapped to the active theories under sections 631 and 638.51, with a plain-language explanation of why it matters and how strong the exposure is.
- A prioritized remediation plan. Concrete fixes - a true consent gate with denied defaults, a “reject” option as easy as “accept,” honoring Global Privacy Control, and blocking the highest-risk identity syncs first - so the report ends with action, not just alarm.
We can run this as a one-time assessment or on a recurring schedule, because tag managers change and a marketing team can reintroduce a risky pixel long after the original fix. The goal is simple: you should know what your website does before a plaintiff’s firm tells you.
What good looks like
A defensible consent posture is not complicated in principle. Every non-essential tracker stays blocked until the visitor makes an explicit, affirmative choice. Refusing is as easy as accepting. Browser-level signals such as Global Privacy Control are honored automatically. The consent decision is recorded, and nothing about the visitor is transmitted to a third party until it is made. Sites that get this right exist, and they are dramatically harder to sue. The distance between them and a site that fires everything on load is a few engineering decisions - and knowing which ones to make starts with an accurate picture of the current behavior.
The bottom line
CIPA turned a wiretap statute into a per-visitor liability meter, and the plaintiffs’ bar has industrialized it. The businesses most at risk are not the ones with the most sophisticated tracking; they are the ones who have never measured what their own site does before consent. That measurement is the starting point, and it is exactly what Inttelio provides. If you are not certain what fires on your homepage the instant it loads, that uncertainty is the risk - and it is one we can resolve quickly.
This article is for general information and is not legal advice. CIPA theories and their application evolve; consult qualified counsel about your specific circumstances.
Frequently asked questions
What is CIPA?
The California Invasion of Privacy Act (Penal Code section 630 and following) is a 1960s anti-wiretapping law. Plaintiffs now apply two of its provisions to website tracking: section 631, the anti-wiretapping clause, is used against session-replay tools and third-party pixels that read a visitor’s activity; and section 638.51, the pen register and trap-and-trace clause, is used against scripts that capture a visitor’s IP address and device signals before consent.
How much are CIPA damages?
CIPA allows statutory damages of $5,000 per violation, or three times actual damages, plus injunctive relief. Because plaintiffs argue a violation occurs per visitor or per interaction, exposure scales with traffic. A site with tens of thousands of monthly visitors can face a theoretical exposure in the tens or hundreds of millions, which is exactly why demand letters and class actions have surged.
Who is actually enforcing CIPA?
The current wave is driven mainly by the plaintiffs’ bar, through pre-litigation demand letters and class-action complaints, not primarily by a state agency. Separately, the California Privacy Protection Agency enforces the CCPA and its rules on cookies and opt-outs. A single non-compliant consent banner can create exposure under both.
Does having a cookie banner make us compliant?
Not by itself. In our assessments we routinely find banners that block nothing: analytics, advertising, and identity trackers fire on page load, before the visitor clicks anything. A banner that records a preference after the tracking has already happened does not cure the pre-consent transmission that the lawsuits target.
How can we tell if our site has a problem?
It requires observing the site the way a real visitor’s browser does: capturing exactly which trackers transmit before any consent choice, which cookies are set, and where the data goes. Inttelio performs this analysis with a real browser, produces a tracker inventory with a pre and post-consent comparison, and rates each finding against the active CIPA theories.
Need help with this?
Inttelio helps businesses in Chicago and nationwide get secure and audit-ready. Let’s talk.
Book a free consultation