CIPA Website Compliance Checklist: Stop Pre-Consent Trackers Before the Demand Letter
By Lukasz Czechura · September 14, 2026 · 8 min read
Executive summary. A 1960s wiretapping law - the California Invasion of Privacy Act (CIPA) - has become the basis for a flood of website-tracking lawsuits. The trigger is almost always the same: trackers that fire before the visitor consents. Because CIPA carries $5,000-per-violation statutory damages with no need to prove harm, plaintiff firms scan sites at industrial scale and send demand letters daily. This is a practical CIPA compliance checklist for websites - and the good news is the fix is concrete. (For the legal background, see our companion piece, CIPA and Your Website.)
Why an old wiretap law is suing modern websites
CIPA was written to stop phone wiretapping. Plaintiffs now apply it to the web on two main theories:
- Interception (section 631). Third-party scripts - analytics, ad pixels, session-replay, chat widgets - allegedly “intercept” a visitor’s communications with your site and send them to a vendor.
- Pen register / trap-and-trace (sections 638.50-638.51). Tracking tools allegedly capture routing and identifier data (like IP addresses and device signals) without authorization.
Because it is a wiretap statute, no actual harm is required - just the fact pattern and a California visitor. That is what makes it so dangerous, and why the target is not sophisticated spyware but ordinary marketing technology almost every site runs.
The CIPA website compliance checklist
Work these in order. The goal is simple: nothing non-essential transmits before an affirmative opt-in.
- 1. Inventory every third-party tracker. List every pixel, analytics tag, session-replay script, chat widget, and ad tag - including anything injected through a tag manager. You cannot gate what you have not found.
- 2. Classify essential vs. non-essential. Strictly-necessary functionality can load; analytics, advertising, session-replay, and social pixels are non-essential and must wait for consent.
- 3. Block non-essential trackers by default. Default to off. Non-essential tags should not load until the visitor opts in - not merely be “disclosed” while they fire anyway.
- 4. Make the consent banner actually gate scripts. This is where most sites fail: the banner is present, but the pixels still fire on page load behind it. The banner has to control the tags, not just display a notice.
- 5. Log consent defensibly. Keep a verifiable, timestamped record of when and how each visitor consented. Without that log you cannot show a court the tracking was authorized.
- 6. Verify from the outside, repeatedly. Test the site the way a plaintiff’s scanner does - observe what fires before consent. Re-test on a schedule, because a single new tag can silently reintroduce pre-consent tracking.
The mistake that keeps sites exposed
Nearly every site we look at has a consent banner - and still fires trackers before the visitor clicks anything. A banner that only displays a notice while the Meta pixel, analytics, and session-replay load on page load is exactly the fact pattern the lawsuits are built on. Consent has to gate the scripts, and the only way to know it does is to watch the site’s real behavior, not the banner’s configuration screen.
How Inttelio helps
We analyze your site the way the plaintiff’s tooling does: loading it and recording exactly which third-party trackers fire before and after consent - so you see your real pre-consent exposure instead of trusting that the banner works. Then we help you close it: fix the consent gate, block pre-consent tags, and stand up defensible consent logging. It is the difference between hoping you are compliant and having evidence you are.
Do not wait for the demand letter. Request a consent and tracking review, or read the background in CIPA and Your Website.
Frequently asked questions
What is CIPA and why does it apply to websites?
CIPA is the California Invasion of Privacy Act, a 1960s anti-wiretapping law. Plaintiffs now argue that common website tracking - pixels, session-replay, and chat widgets that capture and transmit visitor activity to third parties - is an illegal "interception" of communications under section 631, or unlawful collection of routing data under the pen register / trap-and-trace provisions (sections 638.50-638.51). Because it is a wiretap statute, it carries statutory damages with no requirement to prove actual harm.
How much can a CIPA violation cost?
CIPA allows statutory damages of $5,000 per violation - and plaintiffs frame each affected visitor or each interception as a separate violation, so exposure scales with traffic. Because no actual harm has to be shown, plaintiff firms scan sites at scale and send demand letters and class actions daily. The practical result is a settlement-driven enforcement wave aimed at ordinary marketing technology.
What actually triggers a CIPA claim?
The recurring pattern is trackers that fire before the visitor consents: analytics, advertising pixels (for example a Meta or ad-network pixel), session-replay scripts, and chat widgets that load and start transmitting on page load. If third-party tracking runs before an affirmative opt-in - especially for California visitors - you have the fact pattern these suits are built on. Trackers that only load after consent are far lower risk.
How do I make my website CIPA-compliant?
Block all non-essential trackers by default and only load them after a clear, affirmative opt-in; make sure your consent banner actually gates the scripts rather than just displaying a notice; keep a verifiable, timestamped log of each visitor's consent; and re-check regularly, because a tag added through a tag manager can quietly reintroduce a pre-consent tracker. The checklist in this article walks through each step.
How does Inttelio help with CIPA and consent?
Inttelio analyzes your site the way a plaintiff's scanner does - loading it and observing exactly which third-party trackers fire before and after consent, so you can see your real pre-consent exposure rather than trusting that the banner works. We pair that evidence with practical remediation: fixing the consent gate, blocking pre-consent tags, and standing up defensible consent logging.
Need help with this?
Inttelio helps businesses in Chicago and nationwide get secure and audit-ready. Let’s talk.
Book a free consultation