Skip to main content

    Website Tracking & Surveillance

    Protecting Californians from unlawful website tracking and corporate surveillance under the California Invasion of Privacy Act.

    When a website deploys tracking pixels — Meta Pixel, Google Analytics, TikTok Pixel, session replay tools — without proper consent, it violates the California Invasion of Privacy Act (CIPA). CIPA provides $5,000 per violation in statutory damages plus discretionary attorney fees, making it one of the most powerful privacy enforcement tools in the nation.

    Available through our Los Angeles office for California residents.

    What Constitutes a Violation

    CIPA prohibits the interception and recording of communications without all-party consent. In the digital context, this means:

    • Websites that deploy tracking pixels before obtaining user consent
    • Session replay tools that record keystrokes, mouse movements, and form inputs
    • Third-party analytics that intercept communications between you and the website
    • Chat widgets that record conversations without disclosure
    • Fingerprinting technologies that identify users without consent

    CIPA Statutory Framework

    CIPA consists of several sections addressing different forms of surveillance. Section 631 prohibits wiretapping, Section 632 prohibits recording confidential communications, Section 632.7 addresses cellular and cordless phone interceptions, and Section 638.51 prohibits pen register and trap-and-trace operations. Each section provides independent causes of action with $5,000 statutory damages.

    Your Rights

    If you are a California resident or visited a website while in California and that website tracked your activity without your explicit consent, you may have a CIPA claim. Contact us — we will analyze the website's tracking technologies and determine whether a violation occurred.

    Need Legal Help?

    Call or email our firm to discuss your situation.