This is the property of the Daily Journal Corporation and fully protected by copyright. It is made available only to Daily Journal subscribers for personal or collaborative purposes and may not be distributed, reproduced, modified, stored or transferred without written permission. Please click "Reprint" to order presentation-ready copies to distribute to clients or use in commercial marketing materials or for permission to post on a website. and copyright (showing year of publication) at the bottom.

self-study / Privacy Law

Sep. 25, 2026

CIPA meets the modern web: California's data-tracking disputes and the path forward

David S. Cunningham III

Judge (ret.), neutral
JAMS

New York University School of Law, 1980

See more...

Your preferences are tracked everywhere you go online. Data-tracking disputes raise a difficult question: How much privacy should exist in a marketplace built on IP address recognition, metadata validation, analytics and advertising technology? California courts are now confronting that question as they decide whether common data-tracking tools are a component of ordinary digital commerce or unlawful surveillance.

The trial courts are split on whether CIPA, a statute enacted to combat wiretapping and eavesdropping, can be applied to ordinary website technologies that collect or transmit user data. California Invasion of Privacy Act, (CIPA) Cal. Penal Code §§ 630-638.55. Plaintiffs argue that cookies, pixels, analytics code, chat widgets, session-replay tools and advertising technology can function like modern forms of interception when they capture a user's activity or route it to third parties without meaningful consent. Defendants respond that these tools are part of routine digital commerce and that CIPA was never intended to regulate the ordinary collection of IP addresses, device information, URLs, clicks or other web metadata. The disagreement is especially difficult because many cases do not involve a traditional data breach, hacker, stolen database or direct financial loss. Instead, the alleged injury is that a website or vendor observed, recorded, duplicated, or shared user activity or content in a way that plaintiffs say CIPA prohibits.

The stakes are high for businesses that depend on IP address recognition, metadata validation, personalization, fraud prevention and audience measurement. Courts must decide when analytics becomes surveillance, especially when data reveals sensitive information, identifies users or flows to third parties. They must also decide where the individual injury occurs, if it occurs at all. Because these cases turn on complex data flows and unsettled law, structured alternative dispute resolution (ADR) can help parties balance legitimate data analysis against privacy interests that deserve protection while narrowing issues before litigation costs escalate.

The statutory mismatch

CIPA was not drafted for the internet. It targeted clandestine access to telephone calls and confidential conversations, but two provisions now drive data-tracking litigation. Section 631(a) addresses interception or eavesdropping on communications in transit. Plaintiffs invoke it when they allege that pixels, analytics scripts or embedded third-party tools captured a user's website activity in real time, including search terms, form entries, button clicks, URLs and health- or finance-related information.

Plaintiffs also rely on the pen-register and trap-and-trace provisions in section 638.50 (a)-(c), which regulate the capture of dialing, routing, addressing or signaling information. They argue that IP addresses, device identifiers, HTTP headers and related routing data play the same role online as telephonic communications. Defendants respond that those provisions were aimed at telephone surveillance, not routine web analytics, and that modern privacy statutes such as the California Consumer Privacy Act of 2018 (CCPA) are better suited to commercial data practices. (See Cal. Civ. Code §§ 1798.100-1798.199.100.)

However, courts are divided over whether common data-tracking tools should be treated as unlawful interception or routine analytics. Some allow claims to proceed when plaintiffs plausibly allege the real-time duplication of third-party communications, the disclosure of content rather than the transmission of data or the capture of routing information, such as IP addresses, device identifiers and HTTP headers that may qualify as dialing, routing, addressing or signaling information. See Shah v. Fandom, Inc., 754 F. Supp.3d 924 (N.D. Cal. 2024); Garcia v. Anschutz Entertainment Group, Inc. (C.D. Cal. May 5, 2026, F.Supp.3d, 2026 WL 1278912). Others dismiss claims where users consented through clicking banners or disclosures, the website operator was a party to the communication or the alleged collection looked like ordinary analytics rather than interception. That divide makes the pending Variety Media appeal especially important because it may clarify how far CIPA reaches into routine website operations. (Variety Media, LLC v. Superior Court, Court of Appeal Case No. B350578 (Second Appellate District, Division Three).)

Why the Variety Media appeal matters

The pending Variety Media appeal has become a focal point in California privacy litigation because it squarely presents the question of whether CIPA's pen-register provisions apply to routine website technologies that collect IP addresses and other device metadata. Amicus briefs from business and media organizations argue that the answer should be no. They contend that publishers and other online businesses depend on analytics, ad measurement, audience development, fraud prevention and metadata validation to operate in a digital marketplace. If CIPA reaches every common tool that records IP addresses or similar metadata, they warn, the statute could impose sweeping liability without giving businesses a workable compliance roadmap.

The media amicus briefs add a First Amendment and public interest dimension to the debate. Advertising-supported journalism depends on technologies that deliver content, measure engagement and sustain subscription and advertising models. They argue that an expansive interpretation of CIPA could chill the ordinary infrastructure of digital publishing. The Association of Corporate Counsel has advanced a similar concern from the in-house perspective, contending that CIPA demand letters divert legal departments from core compliance responsibilities while producing a less predictable consumer protection regime than the framework established by the CCPA.

Plaintiffs view the issue differently. They contend that commonly used technologies are not necessarily benign, particularly when they transmit information to third parties in real time and allow that information to be combined with other data to identify, profile or target users. In cases involving health care websites, financial portals, video-viewing information and loan applications, courts have sometimes treated URLs, button clicks, form fields and other interaction data as more than neutral metadata. The more revealing the information transmitted, the more likely a court may be to view the claim as involving protected communication content. Plaintiffs also argue that the existence of modern privacy statutes does not eliminate the role of older wiretapping laws when data collection practices resemble real-time interception of communications.

This uncertainty helps explain why many of these cases are well suited for early neutral evaluation, phased mediation or the appointment of a special master. Such processes can help parties understand the underlying technology before briefing positions harden or settlement discussions break down.

A national privacy patchwork

The Variety Media case in California is unfolding simultaneously with a broader national trend. In the absence of a comprehensive federal privacy law, states across the country have enacted consumer privacy statutes. Although these laws vary in important respects, most share a common structure. They require privacy notices, grant consumers rights to access and delete personal information, provide opt-outs from targeted advertising and data sales, impose heightened protections for sensitive data and require assessments for higher-risk processing activities. Most rely primarily on attorney general enforcement. California remains distinctive because it has both a dedicated privacy agency and a limited private right of action for certain data breaches.

Those differences have significant compliance and litigation consequences. States vary in their coverage thresholds, cure periods, definitions of sensitive information, children's privacy requirements, geolocation restrictions, profiling obligations, data-broker regulations and universal opt-out mechanisms. California's framework is generally broader and more relevant to private litigation, whereas many other states follow a Virginia- or Connecticut-style model emphasizing consumer rights, opt-outs, risk assessments and regulatory enforcement. The result is a growing patchwork that provides businesses with a modern privacy-compliance architecture while increasing the operational complexity of collecting and processing data across state lines.

The evolving state-law landscape also strengthens a central defense argument in data-tracking litigation: Modern privacy statutes are better suited than legacy surveillance laws to regulate commercial data processing. The CCPA and similar statutes directly address notice, consent, opt-outs, vendor restrictions, targeted advertising, sensitive information and data-sharing practices. On the other hand, CIPA was not designed to instruct publishers, retailers, hospitals or financial institutions on how to configure analytics tools, advertising technologies or website pixels. The result is an increasing tension between modern privacy statutes that expressly regulate data practices and older laws that plaintiffs invoke to challenge similar conduct.

The path forward

ADR is well positioned to assist litigants because data-tracking disputes will likely continue to evolve. Such disputes require interpretation of statutes drafted for older communications systems in the context of modern digital ecosystems that process information in milliseconds. A mediator or neutral evaluator with experience in privacy, cybersecurity, technology and class actions can help parties separate legal issues from factual and technological disputes.

Key questions often include what information was captured, when it was transmitted, who received it, whether the website operator or vendor was a party to the communication, whether the information reflected protected content rather than routing information and whether users provided meaningful consent. Clarifying those issues early can narrow disputes and focus the parties on the questions that matter most.

A structured dispute resolution process can substantially reduce uncertainty. Through confidential technology tutorials, targeted information exchanges and neutral-led issue framing, parties can determine whether a case concerns a bare IP address, a URL revealing sensitive subject matter, a loan application field, a video title or a broader identity-resolution ecosystem. A first-party website using analytics solely for internal measurement may present a materially different case from an independent data broker receiving cross-site information for behavioral advertising. Without a structured process, those distinctions can be obscured by generalized allegations about tracking technologies or equally generalized defenses about routine analytics practices.

Experienced neutrals can also help parties design a procedural path that matches the dispute. Some cases may warrant early mediation following limited discovery focused on consent banners, privacy policies, vendor agreements and data-flow logs. Others may benefit from a special master who can oversee technical discovery, protect trade secrets and help define the information necessary to evaluate liability and damages. In putative class actions, mediators can assist parties in assessing class certification risk, statutory damages exposure, injunctive relief, business practice changes and claims administration realities before litigation costs exceed the practical settlement value.

Building practical settlements

The most durable resolutions in privacy-tracking disputes will likely combine monetary, procedural and operational terms. Monetary relief may be significant, particularly where statutory damages create substantial exposure. At the same time, many disputes involve forward-looking commitments, such as revising consent mechanisms, narrowing vendor permissions, filtering sensitive information, honoring opt-out signals, improving privacy disclosures, limiting data retention and documenting restrictions on vendor use and onward disclosure.

Businesses may be willing to modify practices without conceding that existing technologies violate CIPA, whereas plaintiffs may place greater value on meaningful privacy protections than on prolonged motion practice. ADR provides a framework for exploring those interests and identifying practical solutions.

Mediators can add value by helping parties navigate the legal, technical and operational dimensions of privacy disputes derived from case experience involving data privacy, cybersecurity, cloud services, software, digital platforms and regulatory compliance obligations. These capabilities are particularly well suited to CIPA and broader data-tracking disputes because they allow parties to address complex evidence confidentially, engage with neutrals who understand both the legal and business implications of the technology and pursue practical resolutions while appellate courts continue to define the statute's reach.

Ultimately, the future of CIPA data-tracking litigation may depend on whether courts can draw a principled and administrable line between unlawful surveillance and the routine exchange of information that powers modern digital commerce. Until greater clarity emerges, ADR offers a practical bridge, enabling parties to evaluate risk, protect sensitive information and craft solutions that advance both privacy interests and legitimate business objectives.

Disclaimer: The content is intended for general informational purposes only and should not be construed as legal advice. If you require legal or professional advice, please contact an attorney.

#1935

Submit your own column for publication to Diana Bosetti


Related Tests for Privacy law


self-study/Privacy Law

Eavesdropping Liability