California Invasion of Privacy Act (CIPA): Rules and Website Risks

The California Invasion of Privacy Act, codified at California Penal Code Sections 630 through 638.55, makes it a crime to record or eavesdrop on someone’s private communications in California without the consent of every party to the conversation.1California Legislative Information. California Penal Code Chapter 1.5 Invasion of Privacy It also gives anyone whose communications were captured the right to sue for $5,000 per violation without proving any actual harm, which is why the statute now drives some of the most active privacy litigation in the country.2California Legislative Information. California Penal Code 637.2 The law dates to 1967 and was written for phone wiretapping, but courts today apply it to website analytics, session replay tools, and chatbots.

All-Party Consent Is the Core Rule

California is an all-party consent state. Under Section 632, every person involved in a confidential communication has to agree before anyone can record it.3California Legislative Information. California Penal Code Section 632 That is stricter than federal wiretap law and stricter than the roughly three-quarters of states that require only one party’s consent. When a call crosses state lines between a one-party state and California, the stricter California standard generally controls.

The consent requirement only applies to communications that qualify as “confidential.” Section 632(c) defines a confidential communication as one carried on in circumstances where any party reasonably expects the conversation is limited to the people in it.1California Legislative Information. California Penal Code Chapter 1.5 Invasion of Privacy The statute explicitly excludes conversations at public gatherings, open government proceedings, and any situation where the participants could reasonably expect to be overheard. A phone call between two people at home is almost always confidential. A shouted exchange across a park is not.

Consent does not have to be written or formal. If someone is told the call is being recorded and keeps talking, most courts treat that as implied consent, which is why businesses play “this call may be recorded” announcements. The disclosure has to happen before any substantive conversation begins.

What Each Section of the Statute Covers

CIPA is not a single prohibition. Different sections target different surveillance methods, and the distinctions matter.

Section 631: Wiretapping

Section 631 prohibits making an unauthorized connection to a phone line, cable, or other communication instrument to intercept or learn the contents of a message. It also covers using information obtained from an illegal wiretap and helping someone else carry one out.1California Legislative Information. California Penal Code Chapter 1.5 Invasion of Privacy This is the section most often cited in modern website-tracking lawsuits, where plaintiffs argue that third-party analytics tools function as unauthorized taps on the communication between a user and a site.

Section 632: Recording Confidential Communications

Section 632 makes it illegal to use any recording or amplifying device to capture a confidential communication without every party’s consent.3California Legislative Information. California Penal Code Section 632 It reaches in-person conversations as well as phone and electronic exchanges. Because of the “confidential” requirement, it only applies when the parties reasonably expected privacy.

Section 632.7: Cell and Cordless Phone Calls

Section 632.7 works differently. It prohibits recording any communication involving a cellular or cordless phone without all parties’ consent, and it does not require the communication to be confidential. Any call carried over a cellular or cordless connection is protected regardless of the setting. Plaintiffs sometimes rely on this section precisely because it eliminates the confidentiality element.

Sections 638.50–638.52: Pen Registers and Trap-and-Trace

These sections regulate devices that capture dialing, routing, addressing, or signaling information rather than the content of a communication. A pen register records outgoing information; a trap-and-trace device records incoming data. Plaintiffs in website cases increasingly argue that tracking software collecting IP addresses functions as a pen register, though courts are split on whether that reading fits the statute.

Exceptions to Consent

Two carve-outs matter in practice.

Section 633 exempts authorized law enforcement officers acting with proper judicial approval, typically a warrant. Police and other state agencies can lawfully intercept communications during investigations when they follow that process.

Section 633.5 lets one party to a confidential communication record it without the other party’s consent when the recording is made to gather evidence of specific serious crimes: extortion, kidnapping, bribery, any felony involving violence against a person (including human trafficking), domestic violence, and the harassment threats described in Section 653m.4California Legislative Information. California Penal Code 633.5 Recordings made under this exception are admissible in court. This matters most for domestic violence victims and others documenting ongoing criminal conduct.

Civil Damages

Section 637.2 lets anyone injured by a CIPA violation sue. The damages structure is what makes this statute a plaintiff’s-attorney magnet.

A successful plaintiff recovers whichever is greater: $5,000 per violation or three times any actual damages.2California Legislative Information. California Penal Code 637.2 The statute explicitly says a plaintiff does not need to prove any actual harm to collect the $5,000 minimum. That single feature drives class action litigation, because a tracking tool that violates CIPA on a site with a million monthly California visitors produces enormous theoretical exposure even when no visitor lost a dollar.

Section 637.2(b) also allows plaintiffs to seek a court order forcing the violator to stop the illegal conduct, and they can combine that request with a damages claim in the same lawsuit.2California Legislative Information. California Penal Code 637.2 For businesses, an injunction is often more disruptive than the money award because it may require rebuilding analytics infrastructure on a court-imposed timeline.

Civil CIPA claims must be filed within one year. The applicable deadline falls under California Code of Civil Procedure Section 340(a), which sets a one-year limit for actions based on a statutory penalty.5California Legislative Information. California Code of Civil Procedure 340 The clock generally starts when the plaintiff discovers the violation, not when it happened.

Criminal Penalties

Violations of Sections 631 and 632 are wobblers. Prosecutors can charge them as either a misdemeanor or a felony depending on the circumstances.

A first-time violation carries a fine of up to $2,500 per violation, up to one year in county jail, or imprisonment in state prison, or both the fine and imprisonment.3California Legislative Information. California Penal Code Section 632 When charged as a felony with state prison time, the sentence can reach up to three years. The same structure applies to wiretapping under Section 631.

Anyone previously convicted under Sections 631, 632, 632.5, 632.6, 632.7, or 636 faces steeper consequences on a subsequent violation. The fine rises to $10,000 per violation, with the same jail and prison options.3California Legislative Information. California Penal Code Section 632 Criminal prosecution is relatively rare next to civil litigation, but the possibility is real.

How CIPA Now Applies to Websites

The most aggressive growth in CIPA cases involves website technologies that did not exist when the statute was written. Courts have not settled on clean answers, and the law here is genuinely in motion.

Session Replay Tools

Session replay software records a visitor’s interactions with a site, capturing keystrokes, mouse movements, clicks, and pages viewed. Plaintiffs argue these tools function as wiretaps under Section 631 because a third-party vendor intercepts the communication between user and website in real time. Courts have gone both ways. Some have dismissed these claims for lack of concrete harm, holding that browsing activity and an IP address are not personally identifiable information. Others have let similar cases proceed.

Third-Party Tracking Pixels

When a site embeds a pixel from a company like Meta or Google, data about the visitor travels to that third party. Plaintiffs frame this as a three-party wiretap: the user communicates with the site, and the analytics company secretly listens in. Viability turns on whether the tool merely processes data for the website (acting as its agent) or independently collects and uses the data. Some courts have held that a vendor’s technical capability to access user data is enough to create liability under Section 631, even without evidence the vendor exploited it.

IP Addresses as Pen Registers

Whether collecting a visitor’s IP address violates the pen register provisions is unsettled. Multiple California state courts have dismissed these claims, reasoning that IP addresses are addressing information voluntarily provided when someone visits a site, not the kind of outgoing call data pen registers were designed to capture. One court has held that CIPA’s legislative history points to telephone-tracking technology rather than internet communications. Federal courts and some state courts have gone the other way, finding that trackers collecting IP addresses qualify as pen registers because they capture addressing information that reveals location details like city and zip code. Until an appellate court resolves the split, this remains uncertain.

Chatbots and Live Chat

Chat features that capture text as the user types it, rather than waiting for a “send” click, raise a separate problem. Plaintiffs argue that recording keystrokes in real time is interception of a communication in transit. The risk is highest when the tool transmits partially typed text to a third-party provider before the user intentionally submits it.

Staying Compliant

The practical fix depends on whether you record phone calls, run a consumer website, or both.

For phone recording, play a clear disclosure at the very start of every call, before any substantive conversation begins. A standard notice like “This call may be recorded for quality assurance purposes” works. The disclosure has to happen on inbound and outbound calls alike. If the other party stays on the line, that is implied consent. If they hang up, you cannot record.

For websites, the legal landscape is still forming, but the minimum is a consent mechanism that loads before any tracking scripts. The safest approach mirrors what European privacy law requires: a banner that blocks all third-party tracking until the visitor actively clicks “accept,” gives equal visual prominence to “accept” and “decline,” does not track visitors who decline, and provides enough information about the tools in use for the visitor to make an informed choice. Pre-checked consent boxes and buried opt-outs are unlikely to hold up. The banner should also let visitors withdraw consent later, because continued tracking after withdrawal can be argued as a fresh violation.

Because many lawsuits target both the website operator and the third-party analytics provider, it helps to know exactly what each embedded tool collects, when the collection starts relative to consent, and whether the vendor uses the data for its own purposes. A vendor that intercepts user data before consent is granted creates liability for the operator regardless of intent.