{ Banner }

Intellectual Property & Technology Blog

The Wiretap Law That Ate California's Websites

How a 1967 Telephone Statute Became a $5,000-a-Click Litigation Machine, and Why Sacramento’s Fix Only Solves Part of the Problem

On January 27 and 28, 2025, two California Superior Court judges ruled on the same legal theory a day apart and reached opposite conclusions. In Sanchez v. Cars.com, Inc. and Aviles v. LiveRamp, Inc., both courts held that California’s pen register and trap-and-trace statute, written for telephone lines, does not reach a website’s collection of a visitor’s IP address and device identifiers. Other courts, on nearly identical facts, have let the same claims proceed. Nearly sixty years after the California Invasion of Privacy Act (“CIPA”) was enacted to police telephone wiretapping, businesses still cannot get a consistent answer to whether their Google Analytics installation is a crime.

That uncertainty has been profitable for one corner of the plaintiffs’ bar. More than 4,300 “digital wiretapping” suits have been filed under CIPA since 2022, roughly 3,300 of them in California. Any business with a California-facing website is now a plausible target.

CIPA, enacted in 1967 as Penal Code sections 630 through 638, was built for a two-party-consent world: no one may wiretap or eavesdrop on a phone call without everyone’s consent. Section 638.50(b) defines a “pen register” broadly as any “device or process” that records “dialing, routing, addressing, or signaling information.” Section 638.51(a) bars installing or using one without a court order. Section 637.2(a)(1) lets a private plaintiff recover $5,000 per violation, with no injury required.

Plaintiffs’ firms have mapped that language onto ordinary web analytics. Google Analytics, the Meta Pixel, Microsoft Clarity, ad tags, session-replay scripts, and chat widgets all cause a browser to transmit an IP address and device identifiers to a third party the instant a page loads, before the visitor touches a cookie banner. Plaintiffs argue that makes each tool a pen register, and every visit a separate $5,000 violation. A mid-traffic website can face six-figure exposure over tools nearly every commercial site runs by default, and a demand letter priced below the cost of initiating a defense highly encourages defendants to settle, regardless of merit. That is the business model.

Senate Bill 690 was billed as the fix. As introduced by Senator Anna Caballero, it would have added a “commercial business purpose” exemption across Sections 631, 632, 632.7, 637.2, and 638.50, tied to the CCPA. It passed the Senate 35-0.

It has since been gutted. Facing opposition from privacy advocates and the plaintiffs’ bar, the Legislature stripped the broad exemption. The version amended July 2, 2026 does one narrow thing: it eliminates the private right of action under Section 638.51 for pen register claims arising from website, app, or mobile conduct, shifting enforcement to the Attorney General alone, with retroactivity reaching pending claims filed within two years of the bill’s operative date.

That helps with the pen register demand letters. It does nothing for Sections 631 and 632, the wiretapping and eavesdropping provisions that generate the majority of website tracking suits and remain untouched. SB 690, as it now stands, closes one door and leaves the main one open.

Businesses should stop treating every CIPA demand letter as a foregone settlement. The pen register theory is genuinely contested, several courts have rejected it, and if SB 690 passes, pending Section 638.51 claims could lose their private right of action retroactively. But Sections 631 and 632 survive regardless. We recommend auditing which trackers fire on page load versus after opt-in, and rebuilding consent banners so analytics and advertising tools wait for an affirmative opt-in before they run. Sacramento may close one loophole. It has not closed the website.

Categories: Data Privacy
  • Marcus  Burnside
    Senior Counsel

    Marcus Burnside advises technology companies, private equity-backed businesses, and foreign clients on intellectual property strategy, AI governance, and data privacy. His practice sits at the intersection of three areas most ...