TL;DR:
Some recent CIPA demand letters argue that tracking tools running before a visitor consents violate a 1967 California wiretapping law. Two different sections of that law are actually in play:
-One about tools that capture communication content.
-The other is about tools that send routing data like IP addresses.
CCPA’s opt-out model doesn’t defend against either.
The practical fix is timing: block non-essential tools until a visitor actively agrees, and keep proof you did.
If you run a WordPress site with visitors in California, “CCPA” is probably the law you already know. It lets you track visitors by default and give them a way to opt out later. Recent court activity suggests CIPA may apply too.
This week alone, we’ve seen a rise in WPConsent support conversations mentioning demand letters that cite a different law entirely: the California Invasion of Privacy Act (CIPA), written in 1967 to stop phone wiretapping.
Plaintiff attorneys are now applying it to websites, arguing that a tracking script running before a visitor makes a choice is the digital version of listening in on a call.
This isn’t settled law.
Courts disagree with each other, and a bill working through the California legislature right now, covered in more detail below, could change part of the picture before the year is out.
Here’s what’s actually happening, what it means for a WordPress site, and where WPConsent does and doesn’t help.
Key Takeaways
- CIPA demand letters are private lawsuits, not a new law or a government enforcement action.
- These claims actually run under two different CIPA provisions, not one theory, and they target different tools.
- CCPA’s opt-out model doesn’t defend against either theory. The claim is about when tracking starts, not whether you offer an opt-out later.
- Courts are genuinely split. Recent rulings go both ways, roughly evenly, depending on the court and the theory.
- A bill moving through the legislature (SB 690) would narrow only one of the two theories, not the whole risk.
- The practical fix: block non-essential tools until consent, and keep proof you did.
To help you quickly navigate this article, use the table of content below to skip to any section you want.
- What's the Difference Between CCPA and CIPA?
- What Question Are Courts Asking About CIPA Claims?
- Why Is CIPA Litigation Surging Right Now?
- What CIPA Actually Targets on Your Site, and Why?
- Where Do Courts Currently Stand on CIPA Claims?
- What Happens If a CIPA Claim Succeeds?
- Why Does a Consent Management Platform Matter Here?
- A Word of Caution Before You Switch California to Opt-In
- What Should You Check on Your WordPress Site? (CIPA Compliance Checklist)
- What Should You Do Before a CIPA Demand Letter Arrives?
- What Should You Do If You Receive a CIPA Demand Letter?
- Where WPConsent Fits in CIPA Compliance
- FAQs: CIPA Demand Letters in California: What They Mean for Your WordPress Site
- Fix the Timing on Your WordPress Site: Block Before Consent, Not After
What’s the Difference Between CCPA and CIPA?
Under CCPA, you’re allowed to collect data by default.
Your job is disclosure: tell visitors what you’re collecting and give them a link to opt out, usually “Do Not Sell or Share My Personal Information.” That’s the model most WordPress cookie plugins were built around.
CIPA claims sidestep that model entirely.
The argument isn’t about disclosure; it’s about interception.
According to this theory, an opt-out link that appears after a script already fired doesn’t undo the interception that already happened.
| CCPA / CPRA | CIPA (Wiretapping Theory) | |
|---|---|---|
| What kind of law | Consumer privacy statute | 1967 criminal wiretapping statute, applied to websites through litigation |
| Default state | Tracking allowed, disclosure required | Tracking itself is the alleged violation |
| What satisfies it | An opt-out link and accurate disclosure | Nothing runs until the visitor opts in |
| Who enforces it | California Attorney General, plus a narrow private right of action for data breaches | Private lawsuits, filed directly by individuals |
| Damages | Tied to actual harm in most cases | $5,000 per violation, no harm required |
| Legal status | Settled, established since 2020 | Contested, courts split |
Two different laws, two different questions.
A site can be doing everything CCPA asks and may still be a target under this theory, because CCPA was not built to answer the timing question CIPA claims are raising.
If your visitors aren’t only in California, the rules shift again outside the US. This guide covers what changes under GDPR, which takes a stricter opt-in approach across the board.
What Question Are Courts Asking About CIPA Claims?
Strip away the legal terminology and nearly every one of these cases comes back to one question: did a third party receive a visitor’s data before that visitor had a chance to choose?
If the timing was right, the claim usually fails. If it wasn’t, the tool becomes a target, regardless of what your privacy policy may say about it.
These claims don’t all come from the same part of CIPA, and knowing which one applies changes what you’re actually defending against.
Which Part of CIPA Are They Actually Using?
CIPA is a long statute, and website claims pull from two different sections that ask different things.
Section 631(a):
- The wiretapping and eavesdropping provision requires that someone read or learn the “contents” of a communication without consent from everyone involved.
- This is the section behind Javier v. Assurance IQ and Mikulsky v. Bloomingdale’s, both about session replay software that recorded what a visitor actually typed and clicked.
- Chat widgets and forms that capture what someone writes fall into this category too.
Section 638.51:
- The pen register and trap-and-trace provision is about routing information, not content: things like IP addresses and device identifiers.
- This is the section behind the wave of cases against tracking pixels and analytics beacons, including Sanchez v. Cars.com and Aviles v. LiveRamp.

The distinction matters because courts have treated the two very differently.
California state courts have been dismissing 638.51 pen-register claims against ordinary analytics tools fairly consistently. The 631(a) wiretapping claims, the ones behind session replay and chat capture, are more genuinely split.
Why Is CIPA Litigation Surging Right Now?
CIPA allows statutory damages of $5,000 per violation without the plaintiff having to prove actual harm.
That structure applies to class actions as well as individual claims. So the per-visitor number can multiply across everyone tracked the same way on a high-traffic site.

Filings tied to one nationwide serial-plaintiff campaign have grown from roughly 600 to more than 4,000 since it began.
Courts are still deciding whether the underlying legal theories hold up. And outcomes go both ways depending on the court and which section of CIPA a claim relies on, as the case table below shows.
What CIPA Actually Targets on Your Site, and Why?
The letters aren’t random.
They name specific, common tools, and which theory applies depends on what the tool actually does: move routing data, or capture content.
| Tracking Technology | CIPA Theory Used | Why It’s Targeted |
|---|---|---|
| Meta/Facebook Pixel | Section 638.51 (pen register) | Sends a visitor identifier to a third party before consent |
| Google Analytics / Ads conversion tags | Section 638.51 (pen register) | Same routing-data argument, high visibility because of how common it is |
| TikTok Pixel / LinkedIn Insight Tag | Section 638.51 (pen register) | Newer plaintiff targets, same underlying theory |
| Session replay / heatmap tools | Section 631(a) (wiretapping) | Records what a visitor actually did and typed, closest to “contents” of a communication |
| Chat widgets | Section 631(a) (wiretapping) | Can capture the text of a conversation before a visitor has consented |
| Search bars and forms | Section 631(a) (wiretapping) | Send typed input to a third-party service before the visitor submits anything |
None of these tools are unusual. Most WordPress sites run at least one from each column. For the common ones, we’ve written individual walkthroughs:
Where Do Courts Currently Stand on CIPA Claims?
Outcomes are genuinely mixed across recent rulings:
| Case | Court | Date | Theory | Outcome |
|---|---|---|---|---|
| Javier v. Assurance IQ | 9th Circuit | 2022 | 631(a) | Claim revived, retroactive consent rejected |
| Mikulsky v. Bloomingdale’s | 9th Circuit | Jun 2025 | 631(a) | Claim revived, session replay allegation sufficient |
| Gutierrez v. Converse | 9th Circuit | Jul 2025 | 631(a) | Mixed, court noted the statute hasn’t been updated for modern tech |
| Heerde v. Learfield Communications | C.D. Cal. | Jul 2024 | 631(a) | Survived motion to dismiss |
| Jurdi v. MSC Cruises | Cal. Superior Ct. | Sep 2024 | 638.51-adjacent | Survived motion to dismiss |
| Sanchez v. Cars.com | Cal. Superior Ct. | Jan 2025 | 638.51 | Dismissed |
| Aviles v. LiveRamp | Cal. Superior Ct. | Jan 2025 | 638.51 | Dismissed |
| Blaker v. Netscout Systems | L.A. Superior Ct. | May 2026 | 638.51 | Dismissed with prejudice |
A few rulings put the split in plain language.
- In Sanchez v. Cars.com, the court called routine tracking “a basic function of accessing the internet.”
- In Aviles v. LiveRamp, the court found the plaintiff “has not alleged anything above and beyond how the internet normally works.”
- In Blaker v. Netscout Systems, the court concluded plainly that the pen register statute “applies to telephonic communications and not to software on a commercial website.”
On the other side, in Gutierrez v. Converse, the Ninth Circuit noted that “California has failed to update § 631(a) to account for advances in technology since 1967.”
California state courts are increasingly skeptical of the pen-register theory. The wiretapping theory under 631(a) remains unsettled at the federal appellate level.
What Happens If a CIPA Claim Succeeds?
Statutory damages under CIPA run $5,000 per violation, or three times actual damages, whichever is greater.
And a plaintiff doesn’t have to prove real harm to collect.
On a high-traffic site, that math turns into class-action exposure fast. If a court certifies a class of visitors who were tracked the same way, the per-visitor number multiplies across everyone in it.
A federal judge approved a $3.85 million class settlement against the Los Angeles Times in June 2026 over tracking practices similar to what’s described above.
Not every case reaches that size, and as it stands, most demand letters never turn into a filed lawsuit at all.
Why Does a Consent Management Platform Matter Here?
A consent management platform, or CMP, is software that controls consent timing.
It holds tracking scripts back until a visitor makes a choice, then only releases the ones that the visitor agreed to.
That’s different from a cookie notice, which displays a message while everything underneath keeps running regardless.
A CMP alone doesn’t win a lawsuit and doesn’t guarantee compliance with anything.
What it does is address the timing question most of these rulings turn on: whether something ran before consent. Get that right, and these claims have a lot less to work with, regardless of which section a plaintiff’s firm reaches for.
A Word of Caution Before You Switch California to Opt-In
Opt-in, blocking every non-essential tool until a visitor actively clicks accept, is the strongest answer to the all-party-consent theory behind CIPA.
But it’s stricter than CCPA actually requires.
In practice, it sharply reduces the tracking data you collect, because some visitors never click accept.
If your advertising and analytics tools sit behind consent and few people consent, those tools rarely fire. In plain terms, opt-in reduces most of your California tracking.
That’s a tradeoff to weigh before making the change.
What You Can Do
The way most sites split the difference is geographic: apply opt-in specifically to the visitors where the exposure is real, typically California, and leave your setup as-is everywhere else.
That contains the tracking-data cost to the traffic where it actually matters, instead of taking the hit sitewide. Check out this article on how to set up location-based cookie consent if you want to see what that looks like in practice.
That covers what the law, the lawsuits, and the demand letters are actually about. Here’s what you can actually do about it, starting with your own site.
What Should You Check on Your WordPress Site? (CIPA Compliance Checklist)
Here’s how to check where you stand with CIPA.
Open your site in a private browser window, as if you were a first-time visitor from California, and check the following before you click accept on anything.
-
💡 WPConsent Tip: The Cookie Inspector does this for you automatically. It walks your site as a fresh visitor, tracks every cookie in real time, and flags anything that loaded before consent as a violation, no DevTools required. Find it under WPConsent » Scanner » Inspector.
-
💡 WPConsent Tip: WPConsent can generate a fresh cookie policy page for you directly from your scan results, one click from the dashboard, instead of you comparing text by hand.
The image below is a simple checklist of what we just discussed above. Since it is an image, you can download it and walk through it at your convenience.

None of this requires guessing. It’s a fifteen-minute audit with tools already built into your browser, done from a clean session so you’re seeing what a real first-time visitor sees, not a cached version of your own site.
What Should You Do Before a CIPA Demand Letter Arrives?
Waiting until a letter arrives is the expensive way to do this. A few things are worth having in place now, before a deadline forces the decision.
WPConsent can help with everything on both checklists above, blocking scripts by default, generating your policy, and logging consent. If you want to see how it actually holds up, we put it through a full review.
What Should You Do If You Receive a CIPA Demand Letter?
A demand letter follows a predictable pattern, and knowing what it is (and isn’t) shapes how you respond.
- Expect a named tracker and a deadline. Most letters cite CIPA’s statutory damages and ask for a response or settlement within a set window, often 30 days.
- Recognize it as a private demand, not a government notice. It comes from a law firm representing an individual, sent before any lawsuit is filed.
- Don’t treat it as proof you broke the law. These claims rely on a legal theory still being argued in court, as the case table above shows.
- Don’t panic-settle because of the deadline. A number and a short window don’t make the underlying claim automatically valid.
⚠ This isn’t legal advice, and it isn’t a substitute for a licensed attorney who can look at your specific site and your specific letter.
That said, don’t ignore it either.
Preserve the letter and anything that came with it.
Actually check whether the tracker named in the letter was present on your site, and whether it fired before or after consent.
If you use WPConsent, check whether the Self-Hosted Consent Log was already running at the time. It gives you a timestamped record to check against.

Use the same theory it’s filed under (631(a) or 638.51) to know what to look for. Then talk to a lawyer who knows this area before you respond.
Check out this article on how to view and manage your consent logs.
Where WPConsent Fits in CIPA Compliance
We’re not going to tell you a cookie consent plugin makes a lawsuit go away. It doesn’t.
What WPConsent actually does is fix the timing. That’s the one mechanism every ruling in this article turns on. Check out the table below to learn more.
| Litigation Question | WPConsent Feature | What It Does | Plan |
|---|---|---|---|
| Are my scripts blocking automatically until a visitor consents? | Automatic Script Blocking | Non-essential scripts stay off until a visitor accepts, then run | Free |
| Do I actually know what’s running on my site? | Cookie Scanner | Scans the full site and lists every script it finds | Free |
| Does Google’s own tracking respect a visitor’s decision too? | Google Consent Mode v2 | Google tags get a “denied” signal by default until a visitor consents | Free |
| Can I apply stricter opt-in to California visitors without changing everyone else’s experience? | Geolocation Display Rules | Shows a stricter banner to visitors from a chosen region, leaves the rest untouched | Pro |
| If a letter names my site, do I have proof of what a visitor agreed to and when? | Consent Log | Keeps a searchable, timestamped record of every consent decision | Pro |
The first three rows are in the WPConsent free version, installed on 100,000+ WordPress sites.
Geolocation Display Rules and the Consent Log are part of WPConsent Pro, and they’re the two pieces that turn “we think we were fine” into a documented answer if a letter ever names your site.
That’s it. We’ve covered what CIPA is, what it targets, and what to do about it. If you still have questions, check out the commonly asked questions below.
FAQs: CIPA Demand Letters in California: What They Mean for Your WordPress Site
Is CIPA a new law?
No. The California Invasion of Privacy Act dates to 1967 and was written for phone wiretapping. Plaintiff attorneys are applying two of its sections, 631(a) and 638.51, to website tracking through legal theories that are still being tested in court, not through a new statute passed for this purpose.
Are all CIPA website claims the same theory?
No, and that’s a common misconception. Section 631(a) claims are about tools that capture communication content, like session replay and chat widgets. Section 638.51 claims are about tools that send routing data like IP addresses, mainly tracking pixels and analytics. California state courts have been dismissing 638.51 claims fairly consistently. The 631(a) claims are more genuinely unsettled.
Does CCPA compliance protect me from a CIPA claim?
Not on its own. CCPA’s opt-out model assumes tracking can start before a visitor makes a choice, which is exactly what both CIPA theories target. The laws ask different questions.
Does this only apply to businesses based in California?
No. The relevant factor is usually where your website visitors are located, not where your business is registered. A site based anywhere can be named if it has California visitors and runs trackers the way these claims describe.
Is a cookie banner alone enough?
Only if it actually blocks non-essential scripts until a visitor accepts. A banner that displays a choice while trackers run underneath it in the background doesn’t change the timing issue these claims are built on.
What is SB 690, and does it fix this?
SB 690 is a California bill that would narrow CIPA’s pen register provision, Section 638.51, by removing the private right of action for those specific claims. An amendment on July 1, 2026 scaled it back further, and as of this writing it still hasn’t cleared the legislature, needing to pass the Assembly floor and return to the Senate before an August 31, 2026 deadline. Even if it passes, it wouldn’t touch Section 631(a) wiretapping claims, the theory behind Javier and Mikulsky and the one closer to a “you need opt-in” argument. Don’t assume passing SB 690 would end this risk.
What should I do first if I get a demand letter?
Don’t ignore it, and don’t reply or settle immediately either. Preserve the letter and check whether the tracker it names was actually present on your site, and whether it fired before or after a visitor consented. Then bring it to a lawyer with CIPA experience before you respond. What you find in that first check often changes what your lawyer recommends.
Fix the Timing on Your WordPress Site: Block Before Consent, Not After
As mentioned, the fix is timing.
Nothing should fire before a visitor has actually made a choice, and you should be able to prove that if anyone ever asks.
Install WPConsent and the scanner lists what’s running on your site. The banner starts blocking non-essential scripts by default once it’s active.
See how to install WPConsent for more details.

If California traffic is a meaningful share of your visitors, or a letter has already landed, the Geolocation Display Rules and Consent Log in WPConsent Pro are built for exactly this situation.
Get WPConsent for free →
See WPConsent pricing →
Additional Resources
These three guides go deeper on the pieces this article covers at a summary level.
- Beginner’s Guide to WordPress and CCPA Compliance: the opt-out model this article contrasts against, explained in full.
- Cookie Consent WordPress Requirements by Country: if your visitors aren’t only in California, here’s what changes elsewhere.
- What Is Cookie Consent? A Beginner’s Guide: the fundamentals this article builds on, if you’re starting from zero.
