Building windows

When One Statute Closes, Another Opens: How CIPA Plaintiffs Are Shifting to the Wiretap Act, VPPA, and Florida’s FSCA

For three years, the California Invasion of Privacy Act has been the engine driving website-tracking litigation. If your company’s website runs Google Analytics, a Meta or TikTok pixel, a session-replay tool, or a live chat widget, you might have received a lawsuit or demand letter alleging these ordinary web tools amount to illegal “wiretapping” or “spyware.” A handful of plaintiffs’ firms have built practices using this theory, including Pacific Trial Attorneys, Maning Law APC, Tauler Smith LLP, Potter Handy LLP, and Victims Advocacy Group PLLC.

What is changing in 2026 is not the technology or the business conduct being targeted. It is the statute plaintiffs are citing. As CIPA’s most popular theory gets narrowed by both the courts and the California Legislature, the same firms are increasingly pairing or replacing their CIPA counts with claims under the federal Electronic Communications Privacy Act (the Wiretap Act), the Video Privacy Protection Act, and out-of-state wiretap laws led by Florida’s Security of Communications Act. The allegations look nearly identical. Only the citations have moved.

First, a Quick Refresher on CIPA

CIPA is a 1967 criminal statute, enacted to stop people from tapping telephone lines, that carries a private right of action. Two provisions do nearly all the work in website cases. Penal Code § 631(a)—the wiretap theory—prohibits reading or attempting to read the contents of a communication in transit without the consent of all parties. Because California is an all-party consent state, plaintiffs argue that what a visitor types into a search bar, chat window, or web form is protected content, and that a third-party script capturing it is an unlawful interception. Penal Code § 638.51—the pen register theory—prohibits using a “pen register” or “trap and trace device” without consent, and plaintiffs argue that an analytics tag or advertising pixel is the digital equivalent because it captures the visitor’s IP address and device details.

The pen register theory became the growth engine because it is easier to plead: the plaintiff need not allege that anyone read the contents of anything. Under Penal Code § 637.2, a plaintiff can recover the greater of $5,000 per violation or three times actual damages, with no actual damages required. Multiply $5,000 across every visit or every data transmission and a demand letter can credibly threaten exposure that dwarfs the cost of settling. That math is why the filings exploded, and it is also why two developments this year matter so much.

Why CIPA Is Being Narrowed: Variety Media and SB 690

Two things happened in the same week of late August 2026, and together they have plaintiffs’ firms looking for backup theories.

The tentative ruling in Variety Media, LLC v. Superior Court. On Aug. 21, 2026, the California Court of Appeal (Second Appellate District, Division Three) issued a tentative ruling in the first case squarely presenting whether the pen register statute reaches ordinary website trackers. The panel tentatively rejected the argument that § 638.51 is limited to telephone surveillance, but held that the plaintiff’s specific theory failed because a pen register captures metadata identifying the destination of an outgoing communication, while a visitor’s IP address identifies its source. For plaintiffs, that is a warning: the IP-address theory underpinning a large share of pen register complaints may not survive as pleaded.

SB 690. On Aug. 28, 2026, the California Legislature passed SB 690, which amends Penal Code § 637.2 to provide that an action for a § 638.51 violation “alleged to arise from conduct occurring on an internet website, online application, or mobile application” may be brought only by the Attorney General. The limitation applies retroactively to pending claim in an action commenced within two years before the bill’s operative date. The bill sits on Governor Newsom’s desk; he has until Sept. 30, 2026 to sign or veto, and if he does neither it becomes law automatically, operative Jan. 1, 2027.

Read together, the message is clear but bounded: the pen register avenue that generated thousands of demand letters is being closed to private plaintiffs, and the leading IP-address theory is on shaky ground. But note that SB 690 leaves §§ 631 and 632 untouched, so the wiretap theory survives. And nothing in Variety Media or SB 690 reaches any statute other than CIPA. That is precisely the gap plaintiffs’ firms are now moving into.

The Pivot to Alternative Statutes

Faced with a narrowing CIPA pen register theory, plaintiffs are reframing the same underlying allegation (e.g., “your website shared my data with third parties without my consent”) as a violation of other statutes. Three vehicles are carrying most of that weight.

1. The Electronic Communications Privacy Act (ECPA) – AKA the Federal Wiretap Act

The federal ECPA, 18 U.S.C. § 2510 et seq., prohibits the interception of electronic communications. Ordinarily it has a built-in obstacle for website cases: the “party exception,” which allows a party to a communication to intercept it. A website operator is usually a party to the communication with its own visitor, so the claim would seem to fail at the threshold.

Plaintiffs get around this using the statute’s “crime-tort” exception, which withdraws the party exception where the interception is undertaken “for the purpose of committing any criminal or tortious act.” The argument is that even if the business is a party, the interception is still actionable because it was done in furtherance of an independently tortious privacy violation. The predicate wrong plaintiffs most often name is the common-law tort of intrusion upon seclusion, on the theory that capturing and de-anonymizing a visitor’s browsing activity into an advertising profile is a highly offensive intrusion; others plead a privacy-policy misrepresentation, a violation of another privacy statute, or in the health context, a HIPAA violation as the predicate.

Courts must determine how demanding to make the intent requirement: some let these claims through where the interception plausibly served a tortious purpose, while others dismiss unless the plaintiff shows the interception aimed at a separate, downstream wrong rather than the ordinary commercial goal of selling advertising. The theory is generating motion-to-dismiss splits across federal courts, but it does something valuable for plaintiffs: it gives them a federal hook that does not depend on CIPA at all, is not limited to California visitors, and is untouched by SB 690. ECPA carries its own statutory damages (under 18 U.S.C. § 2520(c)(2), the greater of actual damages plus the violator’s profits, or statutory damages of $100 a day for each day of violation or $10,000, whichever is greater), and a surviving ECPA count can keep an entire case alive after the wiretap theory fails under state law.

2. The Video Privacy Protection Act (VPPA)

The VPPA, 18 U.S.C. § 2710, is a 1988 statute enacted after a newspaper published a Supreme Court nominee’s video-rental history. It bars a “video tape service provider” from knowingly disclosing a consumer’s personally identifiable information, including video-viewing history, without consent, and it carries actual damages but not less than liquidated damages of $2,500, plus possible punitive damages and attorney’s fees. Plaintiffs have repurposed it for the pixel era: the theory is that a Meta Pixel or similar tag on a page containing video transmits both the video the visitor watched and an identifier (often a Facebook ID) to a third party, which is an unlawful disclosure.

The VPPA is attractive to the plaintiffs’ bar for the same structural reasons the Wiretap Act is: it is federal, it turns on U.S. visitors rather than a company’s location, and it is entirely outside the reach of CIPA reform. The open question dividing the courts is who counts as a “consumer.” The Sixth Circuit read the term narrowly in Salazar v. Paramount Global, holding that subscribing to a free newsletter does not make someone a consumer of a provider’s video services, while the Second Circuit read it broadly. On January 26, 2026, the U.S. Supreme Court granted certiorari in Salazar to resolve the split. A broad ruling would open the door to a wave of VPPA class actions against any publisher that offers both a newsletter and video; a narrow one would sharply limit the theory. Either way, plaintiffs are filing now and pricing that uncertainty into their settlement demands.

3. Florida’s Security of Communications Act (FSCA) and Other State Wiretap Laws

Florida’s Security of Communications Act, Fla. Stat. § 934.01 et seq., is a two-party consent wiretap statute that, like CIPA, was rarely aimed at websites until recently. That changed when a federal court in the Middle District of Florida declined to dismiss an FSCA pixel-tracking claim, reasoning that the trackers captured substantive information rather than mere routing metadata. Within months, the same demand-letter playbook that produced thousands of California CIPA claims was running in Florida. FSCA even contains its own pen register and trap-and-trace provision (§ 934.31), a discrete exposure that CIPA reform does nothing to address. The statutory damages differ, providing for actual damages but not less than liquidated damages of $100 a day for each day of violation or $1,000, whichever is higher, plus punitive damages and fees under § 934.10, but the structure is familiar.

Florida is the leading example, not the only one. Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA) and the wiretap statutes of other all-party or two-party consent states are being pressed on the same facts. The practical effect is a multistate campaign: what began as a California-specific CIPA problem is now a portfolio of parallel claims that a business with an ordinary AdTech stack can face regardless of where it is based, so long as it has visitors in the right states.

What This Means for Businesses

The most important takeaway is a defensive one: do not assume that Variety Media and SB 690 make website-tracking exposure go away. They narrow one CIPA theory in one state. They do nothing to the federal Wiretap Act, the VPPA, FSCA, or the wiretap laws of other states, and the same firms driving CIPA filings are already citing those statutes. A compliance program built solely around “CIPA pen register risk” is aimed at a target that is moving.

And as always: do not ignore a filed lawsuit or demand letter, and do not reflexively pay to settle. There are evidence preservation requirements that apply in either scenario. So consult legal counsel before making privacy related changes to the website. These claims vary widely in strength, several of the underlying legal theories are actively splitting the courts, and the leverage in a given matter often turns on which firm sent the letter and which statute they had to reach for once CIPA ran out.

This area of law is moving quickly, and the status of the litigation and legislation described above is current as of September 20, 2026. Stay tuned for more.

For help with CIPA, ECPA, VPPA, or FSCA or website privacy compliance, contact Stuart K. Tubis, Esq. at stubis@jeffer.com or 415-984-9622.