A decades-old California statute is driving a sharp rise in privacy litigation against companies using common website tracking technologies across the United States.
The California Invasion of Privacy Act, known as CIPA, was originally enacted in 1967 as a penal code designed to protect the privacy rights of California residents from unlawful surveillance.
Plaintiffs’ attorneys are now using CIPA to sue companies nationwide for deploying tracking technologies on their websites without obtaining proper cookie consent from users.
Under the statute, parties may not intercept or record private communications without the consent of all parties involved, a standard that plaintiffs argue online tools routinely violate.
Chatbots, session replay scripts, and analytics tools are among the technologies being cited as unlawful interception mechanisms in an increasing number of demands and lawsuits.
CIPA also prohibits the use of pen register or trap and trace devices without a court order, and plaintiffs frequently allege that standard analytics and fraud prevention tools fall into that category.
One notable serial litigant, Vivek Shah, is estimated to have single-handedly sent thousands of demand letters to companies across all sectors alleging CIPA violations.
In a development offering some relief to businesses, Shah was declared a vexatious litigant in the Central District of California by Judge R. Gary Klausner, meaning he must now obtain court permission before filing new CIPA claims.
Judges also have discretion to require that Shah post a bond for costs early in a lawsuit, protecting defendants who prevail but cannot recover attorneys’ fees from him.
On the legislative front, the California Assembly Privacy and Consumer Protection Committee advanced Senate Bill 690, which would prevent private litigants from suing under Section 638.1 of CIPA relating to pen register and trap and trace prohibitions.
However, the bill would not extend protection to other commonly cited CIPA sections, including Section 631, which prohibits the intentional interception or reading of communications in transit.
A critical tension exists between CIPA and newer comprehensive privacy laws, as CIPA generally requires opt-in consent while laws like the California Consumer Privacy Act require only an opt-out mechanism.
This means businesses that are fully compliant with opt-out requirements under modern privacy frameworks can still face CIPA litigation and significant legal exposure.
Companies that receive demand letters are strongly advised to promptly consult knowledgeable legal counsel, as the appropriate response varies significantly depending on the demanding party’s litigation history.
Businesses should also retain records of what website tracking tools they are running, what data those tools collect, and the purpose for which that data is used.
Privacy policies should be updated yearly and reviewed every time a change is made to a website, with compliance revisited as a matter of routine practice.

