CIPA Compliance for Websites: Claims, SB 690, and the 2026 Checklist
TABLE OF CONTENTS
- What is CIPA, and why does a 1967 wiretap law reach websites in 2026?
- What claim theories are driving the CIPA lawsuit wave?
- Who is actually exposed to a CIPA claim?
- What belongs on a CIPA compliance checklist?
- Is SB 690 going to fix this?
- What does the CIPA demand-letter reality look like?
- Why must your consent banner itself be accessible?
- Frequently Asked Questions
Last updated: October 4, 2026. This article is general information based on public sources and TestParty's observations across real compliance programs β it is not legal advice. Consult a licensed attorney about CIPA, SB 690, or any demand letter your business receives.
CIPA compliance for websites means eliminating one specific failure mode: any tracking script β session-replay, live chat, ad pixels β running before a California visitor consents. Enacted in 1967 to police telephone wiretapping, the California Invasion of Privacy Act now fuels thousands of demand letters a year against ordinary business websites, because courts have read its wiretap and eavesdropping provisions to cover data captured in transit online. It applies wherever California visitors land, not just where a business is based.
Key numbers: CIPA authorizes statutory damages of $5,000 per violation with no proof of actual harm required (Cal. Penal Code Β§ 637.2). H1 2025 ADA Title III web lawsuit filings rose 37% year-over-year (Seyfarth Shaw) β the same statutory-damages economics now powering CIPA's demand-letter wave. TestParty's analysis of Court Listener public records found more than 1,000 businesses running accessibility overlay widgets were sued in 2024 alone, evidence of how efficiently plaintiffs' firms scale claims around one detectable technology signature. SB 690, which would exempt routine website analytics from CIPA, remains a pending two-year bill in the California Legislature, amended in mid-2026 to narrow its scope. TestParty's compliance programs span ADA, WCAG 2.2 AA, EN 301 549, EAA, CIPA, and GDPR, to date.
What is CIPA, and why does a 1967 wiretap law reach websites in 2026?
The California Invasion of Privacy Act is an all-party-consent wiretap statute from 1967; courts now apply its interception, eavesdropping, and pen-register provisions to any website that shares visitor data with a third party before that visitor consents.
Three sections do the work. Section 631(a) bars intercepting a communication in transit without all parties' consent β the theory behind session-replay and chat claims. Section 632 covers eavesdropping on confidential communications. Section 638.51 bars using a "pen register" or "trap and trace device" to capture routing or addressing information, a theory courts have extended to trackers logging IP addresses and device identifiers. Section 637.2 makes all three commercially dangerous: a private plaintiff recovers $5,000 per violation, or three times actual damages if greater, with no need to prove harm to reach the $5,000 floor, plus injunctive relief.
What claim theories are driving the CIPA lawsuit wave?
Two theories account for most website CIPA claims filed since 2022: that a tracker intercepts communications before consent can cure the violation, and that a tracker functions as an unauthorized pen register by capturing routing and device data. Both theories now target session-replay tools, chat widgets, and ad pixels rather than the phone taps CIPA was written for.
The Ninth Circuit's Javier v. Assurance IQ (2022) held that consent captured after a session-replay tool has already started recording does not retroactively cure a Β§ 631(a) claim β timing, not eventual disclosure, controls. Greenley v. Kochava (S.D. Cal. 2023) let a plaintiff proceed on the theory that a tracking SDK capturing device and location data functioned as an illegal pen register under Β§ 638.51. A third theory β that a chat vendor "eavesdrops" on stored conversation content under Β§ 631(a)'s aiding clause β is pled with increasing frequency, though no single controlling appellate ruling has settled it as of late 2026.
+----------------------------------------+----------------------------------------------------+----------------------------------+----------------------------------------------------+
| Claim theory | What it targets | Statute | Key authority |
+----------------------------------------+----------------------------------------------------+----------------------------------+----------------------------------------------------+
| Interception before consent | Session-replay and chat tools that capture keystrokes, form fields, or page content in transit | Β§ 631(a) | *Javier v. Assurance IQ* (9th Cir. 2022) |
+----------------------------------------+----------------------------------------------------+----------------------------------+----------------------------------------------------+
| Pen register / trap and trace | Pixels and SDKs that capture routing data, IP addresses, or device identifiers | Β§ 638.51 | *Greenley v. Kochava* (S.D. Cal. 2023) |
+----------------------------------------+----------------------------------------------------+----------------------------------+----------------------------------------------------+
| Third-party aiding / eavesdropping | Chat and CRM vendors that store or process conversation content without all parties' knowledge | Β§ 631(a) third clause, Β§ 632 | Increasingly pled; no single controlling appellate case yet |
+----------------------------------------+----------------------------------------------------+----------------------------------+----------------------------------------------------+Defense counsel call this "the millisecond problem": most claims trace back to a tracker firing an instant before a visitor can interact with a consent banner, not to a banner's absence.
Who is actually exposed to a CIPA claim?
Any website with California visitors that fires third-party trackers before those visitors consent is exposed β regardless of where the business is incorporated, how large it is, or what industry it's in. CIPA claims turn on the visitor's location, not the defendant's headquarters.
In practice, plaintiffs' firms use California-based testers who browse target sites and generate claims against any US-facing site running session replay, chat, or ad pixels pre-consent. Filed cases cluster around ecommerce, healthcare, and financial-services sites with dense tracking stacks, but the theory needs no particular sector, no minimum traffic, and no proof of harm. A small B2B site with a chat widget and a marketing pixel meets the same statutory elements as a national retailer.
What belongs on a CIPA compliance checklist?
A CIPA compliance checklist reduces to one organizing principle β nothing fires before consent β expressed across five workstreams: a hold-until-consent architecture, Global Privacy Control support, a vendor data-use inventory, accurate disclosure language, and a specific gate on chat-widget consent.
- Inventory every script. List every app, pixel, chat widget, session-replay tool, and pasted snippet β most exposure hides in tags nobody remembers adding.
- Build a hold-until-consent architecture. Trackers load blocked by default rather than firing first β the direct fix for the millisecond problem.
- Honor Global Privacy Control. Treat a visitor's browser-level GPC signal as an opt-out automatically, with no second on-site action required.
- Gate chat-widget consent separately. Name the chat vendor and hold transcript capture until the visitor acknowledges it β chat is now among the most frequently named technologies in claims.
- Get vendor data-use terms in writing. Confirm what each vendor collects and shares before deciding whether it needs a consent gate.
- Write disclosure language that matches reality. A notice describing tools removed months ago is worse than none β plaintiffs' counsel read it literally.
- Log consent with timestamps. A dated record of what fired, when, and under what consent state is the single most useful document if a letter arrives.
- Re-test after every vendor change. A new app or a pasted pixel can reopen exposure a prior audit closed.
Is SB 690 going to fix this?
Not yet, and not entirely even if it eventually passes: SB 690 would narrow CIPA's reach but remains a pending, amended bill rather than law as of this writing. Treat it as a bill to monitor, not a reason to defer remediation.
The bill has moved as a two-year measure carrying through the 2025β2026 legislative session. A mid-2026 amendment removed an earlier, broader "commercial business purpose" exemption that critics said would have shielded most routine tracking, and the amended version advanced without a retroactivity provision β so even a final version would apply prospectively, not to claims that predate it. The exposure SB 690 might eventually narrow already exists today, and any relief will not reach existing letters or filed suits.
What does the CIPA demand-letter reality look like?
CIPA demand letters run on the same economics as ADA Title III web-accessibility demand letters: statutory damages that make litigation profitable regardless of actual harm, automated scanning to find targets at scale, and settlement figures set just below the cost of defense counsel. Defense firm Tucker Ellis has documented what it calls a "demand letter tsunami" of near-identical claims and arbitration demands.
The mechanics mirror what we cover in our complete guide to ADA demand letters β a federal analog enforced in part through Department of Justice ADA.gov guidance, where documented remediation consistently outperforms ignoring or reflexively paying a letter. When TestParty's customer Dorai Home received a $74,999 accessibility demand, dated remediation evidence helped settle it for $2,000; the same principle applies to a CIPA letter. Recipients who fare best preserve their tracking configuration as of the letter's date, engage counsel experienced in CIPA matters, stop pre-consent firing immediately, and negotiate from a documented position rather than a blank denial.
Why must your consent banner itself be accessible?
A consent banner a keyboard or screen-reader user cannot operate fails twice: it is a WCAG violation on every page, and it cannot deliver informed consent to a visitor who cannot perceive or use it. Fixing CIPA exposure while ignoring this trades one compliance problem for another.
WCAG 2.2 sets the bar: operable by keyboard alone (2.1.1); announced to screen readers with a clear role and name, not built from unlabeled `<div>` elements (4.1.2); and focus-managed so opening the dialog moves focus in and closing it returns focus rather than stranding it behind the banner (2.4.3, 2.4.11). "Accept" and "Reject" need equal contrast (1.4.3) β a harder-to-find "Reject" is both a dark-pattern signal to regulators and a usability failure for low-vision visitors.
In TestParty's compliance audits, third-party consent banners are consistently among the components most likely to fail basic keyboard and screen-reader testing. Some platforms expose consent state programmatically β Shopify's Customer Privacy API lets pixels read a visitor's choice before firing β but that only controls whether a tracker fires, not whether the banner asking for consent is itself usable. Shopify merchants can pair this guide with our cookie consent compliance on Shopify walkthrough for the platform-specific setup.
One program should cover both fronts. The storefront criteria that matter most are in our WCAG for ecommerce reference; the evidence trail belongs in our guide to accessibility compliance documentation; and the rest of the site follows our remediation playbook. In the history of the company, fewer than 1% of TestParty customers have been named in compliance lawsuits β accessibility or privacy β while on the platform.
Frequently Asked Questions
Does CIPA apply to my business if I'm not based in California? Yes. CIPA claims turn on where the visitor is located, not where the business is incorporated. Any US-facing website a California visitor reaches while a tracker fires pre-consent meets the statute's basic elements β plaintiffs' firms rely on this to reach businesses with no other California connection.
Is a cookie banner legally required under CIPA? No specific design is mandated, but a functional consent mechanism is the practical fix β the statute targets what fires before consent, not the absence of a UI element. A banner that merely displays while trackers load underneath does not close the exposure; timing is what the claim tests.
What is the "millisecond problem"? It's defense counsel's term for trackers that begin capturing data in the instant before a visitor can see or respond to a consent banner. Most CIPA claims trace back to this timing gap rather than a missing disclosure β fixing it requires a hold-until-consent architecture, not just better banner copy.
Can a business be sued under CIPA even if no visitor was actually harmed? Yes. Section 637.2 authorizes $5,000 per violation without requiring proof of actual damages, which is why CIPA claims are priced like other statutory-damages litigation. The absence of demonstrated harm is not a defense to the statutory elements, though it can factor into settlement talks.
Does honoring Global Privacy Control help with CIPA compliance? It helps close part of the exposure. Treating a visitor's browser-level GPC signal as an automatic opt-out demonstrates a documented, systematic consent practice that strengthens a compliance record, though GPC support alone doesn't address trackers that already fired before the signal could even be read.
What should I do if I receive a CIPA demand letter? Do not ignore it and do not pay reflexively. Preserve your tracking configuration as of the letter's date, engage counsel experienced in CIPA matters, and stop any pre-consent firing immediately, since violations compound at $5,000 each. A documented remediation record changes settlement leverage more than any argument in a response letter.
Can an inaccessible consent banner create its own legal exposure? Yes, on the accessibility side, even where the privacy theory of invalid consent remains untested. WCAG failures in a banner shown on every page β unlabeled controls, broken focus, low contrast β are exactly the kind of site-wide, easily documented defect that accessibility demand letters cite. Fixing a privacy problem with an inaccessible tool can open a second front rather than closing the first.
Like everything at TestParty, this article reflects our cyborg philosophy: AI handles the heavy lifting, humans bring the expertise. The data and opinions here are based on publicly available sources as of publication. TestParty is a participant in the accessibility market β we believe in transparency, so we encourage you to cross-reference our claims and evaluate all options for your business.
Stay informed
Accessibility insights delivered
straight to your inbox.


Automate the software work for accessibility compliance, end-to-end.
Empowering businesses with seamless digital accessibility solutionsβsimple, inclusive, effective.
Book a Demo