Is Your Website Compliant? How Common Website Tools Are Triggering Wiretapping Claims

June 24, 2026

Is Your Website Creating Legal Exposure?

If your business has a website, it likely runs third-party tools like analytics platforms, advertising pixels, chat widgets, or software that records how visitors interact with a page. When those tools transmit user data to outside vendors without adequate user consent, that transmission can constitute an illegal interception of electronic communications under state and federal wiretapping laws—even if the tools are being used for entirely routine purposes.

Plaintiffs’ law firms have developed a systematic approach to identifying these practices and sending demand letters at scale. One estimate puts the number of companies that resolved a CIPA lawsuit between 2022 and 2025 at approximately 7,500—a figure that has grown every year and is almost certainly undercounted, since most cases resolve through private arbitration with no public record. These claims are not limited to any particular industry, and a company does not need to be based in California to receive one.

The Two Laws Primarily Driving These Claims

California’s Invasion of Privacy Act (“CIPA”) requires that website users consent to data collection before it begins—not buried in a privacy policy after the fact. When a third party—like an analytics vendor or advertising platform—receives user data from a website without that prior consent, a claim can arise. CIPA applies to any business whose website can be accessed by California residents, regardless of where the business is located or how large it is—there is no revenue threshold or size exemption, and geofencing or IP blocking does not eliminate exposure.

The statute provides for damages of up to $5,000 per violation, a figure that compounds rapidly in a class action. Kaiser Permanente agreed in January 2026 to pay $46 million—one of the largest healthcare privacy settlements on record—over allegations that its websites and apps transmitted sensitive patient data to advertising vendors without opt-in consent, affecting up to 13.4 million individuals. Aspen Dental settled a similar CIPA class action in 2025 for $18.5 million, with claims centered on session replay software and advertising pixels intercepting appointment requests and health-related form submissions in real time.

The federal Electronic Communications Privacy Act (“ECPA”) or Wiretap Act also prohibits the intentional interception of electronic communication. In the website context, “interception” means the capture and transmission of user data to a third party as it occurs. Federal law, unlike California and some other state laws, usually requires only one party’s consent—but exceptions apply, and an estimated half of all CIPA lawsuits include an ECPA claim alongside it.

The ECPA carries a minimum penalty of $10,000 per plaintiff, plus the possibility of punitive damages and attorney’s fees—higher per-plaintiff exposure than CIPA, which is why plaintiffs’ attorneys frequently plead both together. Unlike CIPA, ECPA claims can be filed in any federal court in any state. In 2025, streaming service Fubo paid $3.4 million to settle ECPA, CIPA, and related video privacy claims arising from its use of the Meta Pixel and Google Analytics to share viewers’ identities and watch history with advertising partners.

What You Can Do—And How We Can Help

Understand what is on your website. Identify every third-party tool collecting or transmitting user data and confirm your disclosures accurately reflect those practices. Session replay tools, advertising pixels, third-party chat widgets, and appointment or contact forms that feed data to marketing platforms are among the highest-risk categories and are frequently cited in demand letters.

Make consent meaningful and specific. Consent must be obtained before data collection begins, from a disclosure that clearly identifies which third parties will receive user data and why. Vague or after-the-fact disclosures have not held up. Note that having a consent banner is not the same as verifying that it works: a recurring pattern in settled cases is that tracking technologies were firing before consent was collected, or that advertising cookies were miscategorized and therefore not properly blocked when users opted out. Consent management platforms manage user preferences—they do not independently audit what is transmitting data behind the scenes.

Review your vendor agreements. Contracts with analytics and marketing technology vendors should restrict how they are permitted to use the data they receive. Many standard agreements do not.

Act before a demand arrives. Businesses that have reviewed their practices and updated their disclosures are in a significantly stronger position than those responding to a demand letter for the first time.

Osborn Maledon advises businesses on website compliance, privacy policy drafting, and vendor contract review, and represents clients in legal disputes. If you have questions about your exposure or would like a compliance review, please contact: