TL;DR: CIPA, a California wiretapping law passed in 1967, is being used in a fast-growing wave of lawsuits against websites that track visitors without proper consent. Your site may be vulnerable even if it’s compliant with the newer – and better known – CCPA law. The fixes are concrete: a handful of changes to how your brand handles consent and tracking can meaningfully reduce your exposure.
What is CIPA, and why are ecommerce brands suddenly hearing about it?
CIPA, the California Invasion of Privacy Act, is a state wiretapping law California passed in 1967, making it unlawful to intercept or record a confidential communication without every party’s consent. It was written decades before websites existed, aimed at things like phone taps and hidden microphones, not cookies or chat widgets.
In 2022, a California court ruled that CIPA could also apply to modern website tracking tools. Chat widgets, session replay software, analytics platforms, and ad pixels can all be treated as “recording a communication” under CIPA if they capture a visitor’s activity before that visitor has consented.
Most US ecommerce brands think of the California Consumer Privacy Act (CCPA) as their main privacy compliance concern. CIPA is a separate, and in some ways sharper, legal risk. A claim can be filed directly by an individual visitor, who doesn’t have to prove real harm to collect.
We’ve seen this shift firsthand. In the past several months, our Analytics team has fielded CIPA-related questions from nearly a dozen clients looking to understand when and where digital marketing tracking fires on their sites.
What’s driving the surge in CIPA lawsuits
CIPA lawsuits have been rising since the court ruling in 2022. But there’s a practical reason the volume has surged more recently. Artificial Intelligence tools make it easy for an opportunistic law firm to scan hundreds of small and mid-sized ecommerce sites at once and find the ones that aren’t gating their tags according to the little-known CIPA rule and 2022 court ruling. A gap that went unnoticed for years can now get flagged in minutes.
In August 2026, California passed a bill that prevents individuals and trial lawyers from suing for this type of claim and moves CIPA enforcement solely to the California Attorney General. However, the law is awaiting the governor’s signature and won’t go into effect until 2027. In the meantime, you can reduce your risk of a lawsuit by auditing your pixels and confirming that they are set up in compliance.
The compliance basics most ecommerce sites are missing
A few of the most common mistakes we see:
- No Google Consent Mode setup. Without it, your site has no reliable record of whether a given visitor opted in or out before tracking started.
- One banner for every visitor. California has specific requirements, so most compliant setups use a separate consent flow for California visitors versus the rest of the US.
- No opt-out path outside the banner. Even sites without a full banner need a way for visitors to opt out, typically through the cookie policy page.
- Missing state-specific requirements. Some states go further. Utah, for example, requires a mandatory process for handling data deletion requests.
- No visible, classified cookie policy. Visitors should be able to see which cookies are marketing, statistics, or preference categories, not just that cookies exist.
- An incomplete data deletion process. A real request needs to reach every system holding a visitor’s data, not just Google Analytics. That includes backend sales systems and CRM records.
How to check if your site is at risk
Two checks catch most of what we see in practice:
- Audit what fires before consent versus after. Load a page in a clean or incognito browser and watch the network requests before clicking “accept.” Anything sending user-identifying data to third-party platforms at that point is a problem. User-identifying data can go beyond conventional PII (Personally Identifiable Information) to include character identifiers (IDs) such as those used for GA4, CRM, and Personalization tooling.
- Look for tags outside your consent-gated setup. This includes stray tags a developer may have added directly to the site outside Google Tag Manager, and tags hosted by a platform itself. Shopify, for example, can fire its own tags in ways that may not sync with your consent management platform unless explicitly configured
What to do if you find gaps in your tracking setup
If any of this sounds familiar, here’s a fix list to take to your web and development teams:
- Set up Google Consent Mode with a California-specific banner and flow.
- Add opt-out functionality to your cookie policy page, even if you already have a banner.
- Publish a classified cookie policy link reference in your site footer.
- Build a real data deletion process that reaches every system holding visitor data, not just your analytics.
- Audit and re-gate any tags firing outside your consent management platform, including platform-hosted ones like Shopify’s.
- Ensure your Consent Management Platform has auto-block turned on to remove any vulnerable third-party tracking that has not been configured in the above steps.
For a small or newly built site, setting up Google Consent Mode and a brand-new Consent banner on your site with a tool like Cookiebot can take less than a day. Larger, more established sites with more tracking sources involved will take longer.
Frequently asked questions
Does CIPA only apply to California-based businesses?
No. CIPA applies based on where your website visitors are located, not where your brand is headquartered. Any ecommerce brand with California visitors, which is nearly every online store, has some exposure.
How much can a CIPA lawsuit actually cost?
Statutory damages run $5,000 per violation, or three times actual damages, whichever is greater. Since damages don’t require proof of real harm, and a single visit can count as a violation, costs can add up quickly across multiple claims.
Does having a cookie banner protect my brand?
Only if it’s actually stopping tracking tools from firing before a visitor consents. Many sites have a banner that displays correctly but doesn’t gate the tags behind it, which is exactly the gap most CIPA claims target.
Is there a law that will protect businesses from these lawsuits?
Not yet. California Senate Bill 690 would prevent individuals and law firms from suing under CIPA for website tracking, but it still must be signed and will take effect in 2027 at the earliest. No statutory protection exists today.
Need expert support?
If you’re not sure whether your site’s tracking setup would hold up to a CIPA audit, ROI Revolution’s Analytics team can review your consent setup, spot what’s firing before opt-in, and help you close the gaps before they become a legal problem. Reach out to get started.
Sources
- Privacy Rights Clearinghouse: California Invasion of Privacy Act (CIPA)
- Cookiebot: Close the CIPA Claim Consent Gap




