California Invasion of Privacy Act: A 2026 Business Compliance Guide

The California Invasion of Privacy Act—commonly known as CIPA—was enacted in 1967, decades before websites, tracking pixels, artificial intelligence chatbots, and session-replay software became ordinary business tools. Nevertheless, plaintiffs increasingly rely on this California privacy law to challenge how businesses record telephone calls and collect information through websites and mobile applications.

These lawsuits are not limited to large technology companies or businesses physically located in California. A small or midsized business operating elsewhere may face a CIPA claim if it records communications involving California residents or deploys technology that allegedly intercepts communications from California website visitors.

Because CIPA authorizes statutory damages of $5,000 per violation under specified circumstances, businesses should evaluate their call-recording systems, analytics software, chat tools, and other monitoring technologies before deployment.

What Does the California Invasion of Privacy Act Prohibit?

CIPA is codified at California Penal Code sections 630 through 638.55. Several provisions are particularly relevant to businesses.

Penal Code section 631 prohibits specified forms of unauthorized wiretapping, interception, use, and disclosure of communications. It also contains an aiding provision that may impose liability on a business that assists another person in committing an underlying violation.

Penal Code section 632 generally prohibits intentionally recording or eavesdropping on a confidential communication without the consent of all parties. Under Flanagan v. Flanagan (2002) 27 Cal.4th 766, the relevant question is whether a participant had an objectively reasonable expectation that the communication was not being overheard or recorded—not whether the participant expected its contents would never be disclosed later.

Penal Code section 632.7 addresses communications involving cellular or cordless telephones. In Smith v. LoanMe, Inc. (2021) 11 Cal.5th 183, the California Supreme Court held that section 632.7 may apply when a participant to the call makes the recording; it is not limited to recordings made by outside eavesdroppers.

Penal Code sections 638.50 and 638.51 regulate pen registers and trap-and-trace devices, subject to enumerated exceptions. Plaintiffs have attempted to apply these older statutory concepts to technologies that collect internet protocol addresses, device identifiers, routing information, and other website data. Courts have not reached a uniform conclusion about whether ordinary online tracking technologies fall within these provisions.

Unlike the California Consumer Privacy Act, CIPA does not contain general revenue or data-processing thresholds. A company may therefore face potential CIPA exposure even if it does not qualify as a regulated “business” under the CCPA.

Why Are Businesses Outside California Potentially at Risk?

A company does not necessarily avoid CIPA because its headquarters, employees, or recording equipment are located outside California.

In Kearney v. Salomon Smith Barney, Inc. (2006) 39 Cal.4th 95, the California Supreme Court permitted California law to govern future interstate calls between California clients and a Georgia office that recorded the calls. The court emphasized California’s interest in protecting its residents and explained that an out-of-state business could comply by informing California participants at the outset that the call was being recorded.

CIPA does not, however, automatically govern every nationwide website or every communication involving a California resident. Personal jurisdiction, choice of law, the participants’ locations, the location and nature of the alleged interception, and the defendant’s California contacts remain fact-specific issues.

Which Business Technologies May Generate CIPA Claims?

Modern CIPA lawsuits frequently concern ordinary commercial technologies, including:

  • Customer-service and sales-call recording systems;
  • Website chat features and AI-powered chatbots;
  • Contact, lead-generation, and quotation forms;
  • Session-replay software that reconstructs website activity;
  • Analytics platforms, cookies, pixels, and advertising tags;
  • Search bars that transmit user-entered terms to third parties;
  • Software that records clicks, keystrokes, scrolling, or mouse movements; and
  • Employee-monitoring and productivity applications.

The use of one of these technologies does not, by itself, establish a CIPA violation. The analysis may depend on what the technology collects, whether it captures communication contents or only addressing information, when acquisition occurs, whether a third-party vendor can access or independently use the information, and whether legally sufficient consent was obtained.

A vendor that merely processes information as an extension of the website operator may present different issues than a vendor that allegedly uses the information for its own advertising, analytics, profiling, or commercial purposes. The distinction frequently depends on both the contractual terms and the technology’s actual operation.

Consent Must Be Timely and Legally Sufficient

Consent is one of the most important issues in CIPA litigation. In the unpublished and nonprecedential decision Javier v. Assurance IQ, LLC (9th Cir. May 31, 2022, No. 21-16351) 2022 WL 1744107, the Ninth Circuit predicted that the California Supreme Court would interpret section 631 to require prior consent. The court concluded that the plaintiff had plausibly alleged a claim because the challenged website recording allegedly occurred before he assented to the privacy policy.

Accordingly, a privacy-policy link presented after tracking begins may not authorize earlier collection. A disclosure buried in lengthy terms may also create disputes over whether the user received reasonably conspicuous notice and manifested consent.

Where the applicable legal analysis calls for consent, potentially sensitive technologies should remain inactive until appropriate notice and consent are obtained. Businesses should preserve timestamps, consent status, disclosure language, policy versions, and other evidence showing what the user saw before collection occurred.

Call-recording disclosures should likewise be provided at the outset and before the substantive conversation is recorded. Businesses should not assume that a CCPA-compliant opt-out process necessarily satisfies a consent requirement asserted under CIPA because the statutes regulate different conduct and provide different remedies.

What Damages and Remedies Are Available Under CIPA?

California Penal Code section 637.2 authorizes a person injured by a CIPA violation to seek the greater of:

  1. $5,000 per violation; or
  2. Three times the plaintiff’s actual damages.

Section 637.2 states that actual damages are not a prerequisite to an action and also authorizes injunctive relief. The section does not itself establish a general automatic award of attorney fees to every prevailing plaintiff.

This statutory-damages framework can create substantial aggregate exposure when a claim concerns numerous calls or website sessions. However, what constitutes a separate “violation” may be disputed. In federal court, a plaintiff must also establish constitutional standing under Article III; a statutory violation without a sufficiently concrete injury may not always be enough.

Certain CIPA provisions additionally carry criminal penalties, although civil demands and lawsuits are the more common concern for businesses.

Courts remain divided over whether particular pixels, cookies, session-replay products, or similar website tools qualify as wiretaps, pen registers, or trap-and-trace devices. No definitive California appellate decision has resolved every aspect of CIPA’s application to modern website tracking.

What Is the Status of Senate Bill 690?

As of August 1, 2026, Senate Bill 690 remains pending and has not become law.

Under the bill’s current language, a civil action under Penal Code section 637.2 against a private actor for a section 638.51 violation arising from conduct on a website, online application, or mobile application could be brought only by the California Attorney General. The proposal also contains a limited retroactivity provision for certain pending claims commenced within two years before the legislation’s operative date. Even if enacted in its present form, SB 690 would not eliminate potential claims under other CIPA provisions, including sections 631, 632, or 632.7. Businesses should therefore not delay compliance measures in anticipation of legislative relief.

Practical CIPA Compliance Steps for Businesses

Businesses can reduce their litigation risk by taking several proactive measures:

  1. Inventory recording and tracking technologies. Identify every call recorder, chatbot, pixel, analytics tool, advertising tag, session-replay program, and third-party script.
  2. Map the data flow. Determine what each technology collects, when it activates, where information is transmitted, how long it is retained, and whether a vendor uses it independently.
  3. Review consent timing. Where consent is legally required, prevent the relevant technology from activating before adequate notice and consent.
  4. Protect sensitive fields. Mask or suppress passwords, payment information, medical details, free-text entries, search terms, and other sensitive inputs.
  5. Evaluate vendors. Review the vendor agreement, privacy documentation, data-retention practices, and actual technical configuration.
  6. Maintain consent evidence. Preserve timestamps, disclosure versions, user selections, and technical logs showing the consent process.
  7. Test regularly. Website tags, consent tools, and vendor settings can change. Periodic technical and legal audits can identify configuration drift or unintended collection.
  8. Coordinate internal teams. Marketing, information technology, product-development, customer-service, and legal personnel should review new tracking or recording technologies before deployment.

Responding to a CIPA Demand or Lawsuit

A business receiving a CIPA demand should promptly preserve relevant website versions, tag-manager containers, deployment records, consent logs, vendor agreements, call recordings, and technical settings. It should also evaluate insurance-notice obligations and avoid making factual admissions before counsel has investigated the allegations.

Potential defenses may involve consent, the absence of interception while a communication was in transit, the vendor’s status as a service provider rather than an independent eavesdropper, standing, personal jurisdiction, choice of law, the statute of limitations, and the nature of the information allegedly collected. CIPA remains a rapidly developing area of internet and privacy law. Businesses should not assume that ordinary commercial technology is automatically lawful—or automatically unlawful—without examining how the technology actually operates.

Our law firm provides legal counsel regarding internet law, data privacy, cybersecurity, website compliance, artificial intelligence, and technology-related disputes. Businesses concerned about CIPA compliance or a threatened privacy claim should consult qualified counsel regarding their specific technologies and practices. This article is provided for informational purposes only and does not constitute legal advice.

Contact Information