TL;DR:
CIPA demand letters argue that tracking tools running before a visitor consents violate a 1967 California wiretapping law.
Two different sections of that law are actually in play:
-One about tools that capture communication content.
-Another about tools that send routing data like IP addresses.
Plaintiffs argue CCPA’s opt-out model doesn’t defend against either. The practical fix is timing: block non-essential tools until a visitor actively agrees, and keep a timestamped record of the consent you collect.
If you run a WordPress site with visitors in California, “CCPA” is probably the law you already know.
It generally works on an opt-out model. Businesses it covers can collect data with proper notice, as long as they honor opt-out requests. Recent court activity suggests CIPA applies too.
This week alone, we’ve seen a rise in WPConsent support conversations mentioning demand letters that cite a different law entirely: the California Invasion of Privacy Act (CIPA), written in 1967 to stop phone wiretapping.
Plaintiff attorneys are now applying it to websites, arguing that a tracking script running before a visitor makes a choice is the digital version of listening in on a call.
This isn’t settled law.
Courts disagree with each other, and a bill working through the California legislature right now, covered in more detail below, could change part of the picture before the year is out.
Here’s what’s actually happening, what it means for a WordPress site, and where WPConsent does and doesn’t help.
Key Takeaways
- CIPA demand letters are pre-litigation demands from private law firms, not government enforcement actions or court judgments.
- These claims actually run under two different CIPA provisions, not one theory, and they target different tools.
- Plaintiffs argue CCPA’s opt-out model doesn’t defend against either theory: the claim is about when tracking starts, not whether you offer an opt-out later.
- Courts are genuinely split. Recent rulings go both ways, roughly evenly, depending on the court and the theory.
- A bill moving through the legislature (SB 690) would narrow only one of the two theories, not the whole risk.
- The practical fix: block non-essential tools until consent, and keep a record of the consent you collect.
What’s the Difference Between CCPA and CIPA?
Under CCPA, the model is opt-out.
Businesses it covers can collect data as long as they give proper notice and honor opt-out requests, usually through a “Do Not Sell or Share My Personal Information” link.
That’s the model most WordPress cookie plugins were built around.
💡 Note: Not every small site is covered by CCPA, which has revenue and data-volume thresholds. CIPA has none, which is part of why smaller site owners get these letters.
CIPA claims sidestep that model entirely.
The argument isn’t about disclosure; it’s about interception. An opt-out link that appears after a script already fired doesn’t undo the interception that already happened, according to this theory.
| CCPA / CPRA | CIPA (Wiretapping Theory) | |
|---|---|---|
| What kind of law | Consumer privacy statute | 1967 criminal wiretapping statute, applied to websites through litigation |
| Default state | Opt-out model, notice required | Tracking itself is the alleged violation |
| What satisfies it | An opt-out link and accurate disclosure | Nothing runs until the visitor opts in |
| Who enforces it | California Attorney General, plus a limited right for individuals to sue over data breaches | Private lawsuits, filed directly by individuals |
| Damages | Tied to actual harm in most cases | $5,000 per violation, no harm required |
| Legal status | Settled, established since 2020 | Contested, courts split |
Two different laws, two different questions.
A site can be doing everything CCPA asks and still be a target under this theory, because CCPA was never built to answer the timing question CIPA claims are raising.
If your visitors aren’t only in California, the rules shift again outside the US. This guide covers what changes under GDPR, which takes a stricter opt-in approach across the board.
What Question Are Courts Asking About CIPA Claims?
Strip away the legal terminology and nearly every one of these cases comes back to one question: did a third party receive a visitor’s data before that visitor had a chance to choose.
If the timing was right, the claim usually fails. If it wasn’t, the tool becomes a target, regardless of what your privacy policy says about it.
These claims don’t all come from the same part of CIPA, and knowing which one applies changes what you’re actually defending against.
Which Part of CIPA Are They Actually Using?
CIPA is a long statute, and website claims pull from two different sections that ask different things.
Section 631(a):
- The wiretapping and eavesdropping provision requires that someone read or learn the “contents” of a communication without consent from everyone involved.
- This is the section behind Javier v. Assurance IQ and Mikulsky v. Bloomingdale’s, both about session replay software that recorded what a visitor actually typed and clicked.
- Chat widgets and forms that capture what someone writes fall into this category too.
Section 638.51:
- The pen register and trap-and-trace provision is about routing information, not content: things like IP addresses and device identifiers.
- This is the section behind the wave of cases against tracking pixels and analytics beacons, including Sanchez v. Cars.com and Aviles v. LiveRamp.

The distinction matters because courts have treated the two very differently.
California state courts have been dismissing 638.51 pen-register claims against ordinary analytics tools fairly consistently. The 631(a) wiretapping claims, the ones behind session replay and chat capture, are more genuinely split.
Why Is CIPA Litigation Surging Right Now?
CIPA lets a plaintiff claim a set $5,000 per violation without having to prove they were actually harmed.
That structure applies to class actions as well as individual claims, so the per-visitor number can multiply across everyone tracked the same way on a high-traffic site.

Filings tied to one nationwide serial-plaintiff campaign have grown from roughly 600 to more than 4,000 since it began.
Courts are still deciding whether the underlying legal theories hold up.
And outcomes go both ways depending on the court and which section of CIPA a claim relies on, as the case table below shows.
What CIPA Actually Targets on Your Site, and Why?
The letters aren’t random.
They name specific, common tools, and which theory applies depends on what the tool actually does: move routing data, or capture content.
| Tracking Technology | CIPA Theory Used | Why It’s Targeted |
|---|---|---|
| Meta/Facebook Pixel | Section 638.51 (pen register) | Sends a visitor identifier to a third party before consent |
| Google Analytics / Ads conversion tags | Section 638.51 (pen register) | Same routing-data argument, high visibility because of how common it is |
| TikTok Pixel / LinkedIn Insight Tag | Section 638.51 (pen register) | Newer plaintiff targets, same underlying theory |
| Session replay / heatmap tools | Section 631(a) (wiretapping) | Records what a visitor actually did and typed, closest to “contents” of a communication |
| Chat widgets | Section 631(a) (wiretapping) | Can capture the text of a conversation before a visitor has consented |
| Search bars and forms | Section 631(a) (wiretapping) | Send typed input to a third-party service before the visitor submits anything |
None of these tools are unusual. Most WordPress sites run at least one from each column.
For the common ones, we’ve written individual walkthroughs:
Where Do Courts Currently Stand on CIPA Claims?
Outcomes are genuinely mixed across recent rulings:
| Case | Court | Date | Theory | Outcome |
|---|---|---|---|---|
| Javier v. Assurance IQ | 9th Circuit | 2022 | 631(a) | Claim revived; after-the-fact consent rejected |
| Mikulsky v. Bloomingdale’s | 9th Circuit | Jun 2025 | 631(a) | Claim revived, session replay allegation sufficient |
| Gutierrez v. Converse | 9th Circuit | Jul 2025 | 631(a) | Defense won without a trial; one judge doubted CIPA reaches the internet |
| Heerde v. Learfield Communications | C.D. Cal. | Jul 2024 | 631(a) | Allowed to proceed |
| Jurdi v. MSC Cruises | Cal. Superior Ct. | Sep 2024 | 638.51-adjacent | Allowed to proceed |
| Sanchez v. Cars.com | Cal. Superior Ct. | Jan 2025 | 638.51 | Dismissed |
| Aviles v. LiveRamp | Cal. Superior Ct. | Jan 2025 | 638.51 | Dismissed |
| Blaker v. Netscout Systems | L.A. Superior Ct. | May 2026 | 638.51 | Dismissed for good |
A few rulings put the split in plain language.
- In Sanchez v. Cars.com, the court called routine tracking “a basic function of accessing the internet.”
- In Aviles v. LiveRamp, the court found the plaintiff “has not alleged anything above and beyond how the internet normally works.”
- In Blaker v. Netscout Systems, the court concluded plainly that the pen register statute “applies to telephonic communications and not to software on a commercial website.”
The genuine counterweight sits on the wiretapping side.
The Ninth Circuit let session-replay claims proceed in Mikulsky v. Bloomingdale’s and Javier v. Assurance IQ, which is why 631(a) is the theory still considered unsettled at the federal appellate level.
Even there, the wiretapping cases don’t all favor plaintiffs.
In Gutierrez v. Converse, the Ninth Circuit affirmed summary judgment for the defense, and a concurring judge questioned whether CIPA’s wiretapping clause reaches the internet at all.
That judge put it bluntly: “California has failed to update § 631(a) to account for advances in technology since 1967.”
Even a defense win, in other words, flagged how poorly the 1967 law fits the modern web. Meanwhile, California state courts stay increasingly skeptical of the pen-register theory.
What Happens If a CIPA Claim Succeeds?
Statutory damages under CIPA run $5,000 per violation, or three times actual damages, whichever is greater, and a plaintiff doesn’t have to prove real harm to collect.
On a high-traffic site, that math turns into class-action exposure fast.
If a court lets those visitors sue as a single group, the per-visitor number multiplies across everyone in it.
A federal judge approved a $3.85 million class settlement against the Los Angeles Times in June 2026 over tracking practices similar to what’s described above.
Not every case reaches that size, and most demand letters never turn into a filed lawsuit at all.
Why Does a Consent Management Platform Matter Here?
A consent management platform, or CMP, is the piece of software that actually controls timing.
It holds tracking scripts back until a visitor makes a choice, then only releases the ones that the visitor agreed to.
That’s different from a cookie notice, which just displays a message while everything underneath keeps running regardless.
A CMP alone doesn’t win a lawsuit and doesn’t guarantee compliance with anything.
What it does is address the timing question most of these rulings turn on: whether something ran before consent.
Get that right, and these claims have a lot less to work with, regardless of which section a plaintiff’s firm reaches for.
A Word of Caution Before You Switch California to Opt-In
Opt-in, blocking every non-essential tool until a visitor actively clicks accept, is the strongest answer to CIPA’s core argument: that a visitor has to agree before anything captures their activity.
But it’s stricter than CCPA actually requires, and in practice it sharply reduces the tracking data you collect, because most visitors never click accept.
If your advertising and analytics tools sit behind consent and few people consent, those tools rarely fire.
In plain terms, opt-in reduces most of your California tracking. That’s a tradeoff to weigh before making the change.
The way most sites split the difference is geographic: apply opt-in specifically to the visitors where the exposure is real, typically California, and leave your setup as-is everywhere else.
That contains the tracking-data cost to the traffic where it actually matters, instead of taking the hit sitewide. Check out this article on how to set up location-based cookie consent for the practical steps.
That covers what the law, the lawsuits, and the demand letters are actually about. Here’s what you can actually do about it, starting with your own site.
What Should You Check on Your WordPress Site?
WordPress Audit Checklist: Checking Your Script TimingHere’s how to check where you stand. Open your site in a private browser window, as if you were a first-time visitor from California, and check the following before you click accept on anything.
-
💡 WPConsent Tip: The Cookie Inspector does this for you automatically. It walks your site as a fresh visitor, tracks every cookie in real time, and flags anything that loaded before consent as a violation, no DevTools required. Find it under WPConsent » Scanner » Inspector.
-
💡 WPConsent Tip: WPConsent can generate a fresh cookie policy page for you directly from your scan results, one click from the dashboard, instead of you comparing text by hand.
The image below is a simple checklist of what we just discussed above. Since it is an image, you can download it and walk through it at your convenience.

None of this requires guessing.
It’s a fifteen-minute audit with tools already built into your browser, done from a clean session so you’re seeing what a real first-time visitor sees, not a cached version of your own site.
What Should You Do Before a CIPA Demand Letter Arrives?
Waiting until a letter arrives is the expensive way to do this. A few things are worth having in place now, before a deadline forces the decision.
WPConsent can help with everything on both checklists above, blocking scripts by default, generating your policy, and logging consent.
If you want to see how it actually holds up, we put it through a full review.
What Should You Do If You Receive a CIPA Demand Letter?
A demand letter follows a predictable pattern, and knowing what it is (and isn’t) shapes how you respond.
- Expect a named tracker and a deadline. Most letters cite CIPA’s statutory damages and ask for a response or settlement within a set window, often 30 days.
- Recognize it as a private demand, not a government notice. It comes from a law firm representing an individual, sent before any lawsuit is filed.
- Don’t treat it as proof you broke the law. These claims rely on a legal theory still being argued in court, as the case table above shows.
- Don’t panic-settle because of the deadline. A number and a short window don’t make the underlying claim automatically valid.
⚠ This isn’t legal advice, and it isn’t a substitute for a licensed attorney who can look at your specific site and your specific letter.
That said, don’t ignore it either.
Preserve everything, not just the letter.
Keep a record of your current site configuration, the trackers running, and your logs before you change anything, because the state of your site when the letter arrived is what matters.
Then take it to a lawyer who knows this specific area of privacy law, and let them direct the fact-finding. This includes whether the tracker named was actually on your site and when it fired relative to consent.
If you use WPConsent, the Consent Log gives your attorney timestamped records of when consent was recorded on your site, one piece of the timeline they’ll need.

Where WPConsent Fits
We’re not going to tell you a cookie consent plugin makes a lawsuit go away. It doesn’t.
What WPConsent actually does is fix the timing. That’s the one mechanism every ruling in this article turns on.
| Litigation Question | WPConsent Feature | What It Does | Plan |
|---|---|---|---|
| Are my scripts blocking automatically until a visitor consents? | Automatic Script Blocking | Non-essential scripts stay off until a visitor accepts, then run | Free |
| Do I actually know what’s running on my site? | Cookie Scanner | Scans the full site and lists every script it finds | Free |
| Does Google’s own tracking respect a visitor’s decision too? | Google Consent Mode v2 | Google tags get a “denied” signal by default until a visitor consents | Free |
| Can I apply stricter opt-in to California visitors without changing everyone else’s experience? | Geolocation Display Rules | Shows a stricter banner to visitors from a chosen region, leaves the rest untouched | Pro |
| If a letter names my site, do I have a record of what a visitor agreed to and when? | Consent Log | Keeps a searchable, timestamped record of every consent decision | Pro |
The first three rows are in the WPConsent free version, installed on 100,000+ WordPress sites.
Geolocation Display Rules and the Consent Log are on WPConsent Pro, and they’re the two pieces that turn “we think we were fine” into a documented answer if a letter ever names your site.
That’s it. We’ve covered what CIPA is, what it targets, and what to do about it. A few specific questions are still worth answering directly.
Frequently Asked Questions
Is CIPA a new law?
No. The California Invasion of Privacy Act dates to 1967 and was written for phone wiretapping. Plaintiff attorneys are applying two of its sections, 631(a) and 638.51, to website tracking through legal theories that are still being tested in court, not through a new statute passed for this purpose.
Are all CIPA website claims the same theory?
No, and that’s a common misconception. Section 631(a) claims are about tools that capture communication content, like session replay and chat widgets. Section 638.51 claims are about tools that send routing data like IP addresses, mainly tracking pixels and analytics. California state courts have been dismissing 638.51 claims fairly consistently. The 631(a) claims are more genuinely unsettled.
Does CCPA compliance protect me from a CIPA claim?
Not according to the plaintiffs bringing these claims. Their argument is that CCPA’s opt-out model assumes tracking can start before a visitor makes a choice, which is exactly what both CIPA theories target.
Does this only apply to businesses based in California?
No. The relevant factor is usually where your website visitors are located, not where your business is registered. A site based anywhere can be named if it has California visitors and runs trackers the way these claims describe.
Is a cookie banner alone enough?
Only if it actually blocks non-essential scripts until a visitor accepts. A banner that displays a choice while trackers run underneath it in the background doesn’t change the timing issue these claims are built on.
What is SB 690, and does it fix this?
SB 690 is a California bill that would narrow CIPA’s pen register and trap-and-trace provisions, Sections 638.50 and 638.51, by removing the ability for individuals to sue over those claims and leaving enforcement to the state Attorney General. A July 2, 2026 amendment scaled it back to just those provisions. As currently drafted it would take effect January 1, 2027 and apply retroactively to qualifying pen-register claims filed on or after January 1, 2025, but it isn’t law yet and still has to clear the Assembly. It wouldn’t touch the Section 631(a) wiretapping claims behind Javier and Mikulsky, the theory closer to a “you need opt-in” argument. So the pen-register versus wiretapping distinction matters for your own letter: a demand resting on the pen-register theory could be affected by SB 690, while a wiretapping demand would not be. That is one of the things a lawyer weighs. Don’t assume passing SB 690 would end this risk.
What should I do first if I get a demand letter?
Don’t ignore it, and don’t reply or settle immediately either. Preserve everything first: the letter, your current site configuration, and your logs, before you change anything. Then bring it to a lawyer with CIPA experience and let them direct the fact-finding, including whether the tracker named was actually on your site and when it fired relative to consent.
Fix the Timing on Your WordPress Site: Block Before Consent, Not After
The fix here starts with timing.
Nothing should fire before a visitor has actually made a choice, and you should be able to prove that if anyone ever asks.
Install WPConsent and the scanner lists what’s running on your site. The banner starts blocking non-essential scripts by default once it’s active.
If California traffic is a meaningful share of your visitors, or a letter has already landed, the Geolocation Display Rules and Consent Log in WPConsent Pro are built for exactly this situation.

Get WPConsent for free →
See WPConsent pricing →
Additional Resources
These three guides go deeper on the pieces this article covers at a summary level.
- Beginner’s Guide to WordPress and CCPA Compliance: the opt-out model this article contrasts against, explained in full.
- Cookie Consent WordPress Requirements by Country: if your visitors aren’t only in California, here’s what changes elsewhere.
- What Is Cookie Consent? A Beginner’s Guide: the fundamentals this article builds on, if you’re starting from zero.
Disclaimer: This article is provided for informational and educational purposes only and does not constitute legal advice. No tool, WPConsent included, can by itself guarantee compliance or prevent a lawsuit; proper configuration and legal review of your specific site both matter. Privacy laws and court interpretations change rapidly. If you have received a legal demand letter or have questions regarding your site’s specific legal obligations, please consult with a licensed attorney.
