CIPA, a relatively little-known law from 1967, has resurfaced in many conversations between legal and marketing teams over the past year. Many companies struggle to understand what is at stake, and what they can do to adapt. Here, marketers have a vital role to play, by providing business and technical explanations, in order to ensure that any privacy-focused solution both fits legal obligations and limits marketing impacts.
(note: we are not legal professionals, we’ll leave any legal analysis to lawyers and attorneys, and this article should not be understood as legal advice in any way)
CIPA (California Invasion of Privacy Act) is a Cold War era law enacted in 1967. The goal of the law was to punish “eavesdropping upon private communications” (California Penal Code §630). At the time, this primarily meant fighting against wiretaps and similar privacy violating techniques.
The law was framed using obscure and somewhat dated terms like “pen register” (“a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, but not the contents of a communication [...]”) and “track and trace device” (“a device or process that captures the incoming electronic or other impulses that identify the originating number or other dialing, routing, addressing, or signaling information [...]” (California Penal Code §630.50). The wording reflects the era when the law was enacted, and many lawyers have expressed that it makes applying it today more challenging.
Violators risk civil penalties of up to $5,000 per violation per day (or 3 times the plaintiff’s actual damages, whichever is greater). Anyone has a private right of action and can press charges against companies that would have illegally invaded their privacy; class actions are also possible. And much like the CCPA/CPRA, CIPA may be a California state law, but its practical impact can extend beyond California's borders. Companies located outside the state may still be subject to CIPA when their activities involve communications with California residents.
CIPA was relatively little used at the time it was enacted. But it is making a surprise comeback during the digital era: some Internet users are suing websites that collected data during their visit, claiming that CIPA also applies to digital tracking. To oversimplify, usual tracking mechanisms (tags, SDKs, pixels, fingerprinting, cookies, session replay…) would amount to intercepting traffic, and would be illegal under CIPA. And, as anyone can take private action, this has led to a multitude of US companies receiving CIPA-related complaints.
Initially, most marketers and specialized lawyers rebuked the argument that tracking could be covered by CIPA. The online ad trade association IAB (the Internet Advertising Bureau) even released a Defense Toolkit detailing how advertisers can counter CIPA allegations.
But more and more companies began to settle, as early rulings denied motions to dismiss, and even suggested these claims may have some merit. At this date, and to our knowledge, no definite ruling has been made. Consequently, the situation remains unclear.
In this context, more and more legal departments are asking their marketing departments to implement new tools to improve compliance. How can marketers adapt?
(note: as stated earlier, we are not lawyers, so please contact appropriate counsel for any legal analysis)
Your number 1 priority should be to keep constant, open communication with your legal department: they are the ones equipped to make rulings and determine compliance. But this does not mean you should stay inactive – your team should focus on providing the right technical and business information (e.g. what data is critical to your operations, how you collect it, which tools you use and how you can customize their setup) to inform your legal department’s decision.
The basic option, requested by many of our clients’ legal departments, is to block tracking until users have agreed to cookies / tracking, to ensure that consent was given prior to any alleged CIPA-type interception. However, this means losing out on a lot of data as consent rates typically hover around 60% - 80% with accept / reject banners.
But other solutions are quickly emerging to minimize data losses. One of them is server-side tracking, where data is sent via an intermediary server; some early rulings (Smith v. Rack Room Shoes (N.D. Cal., January 23, 2026) suggest CIPA would not apply in this case. You should bring this option and others (like Google Tag Gateway) to your legal department to examine how they may help.
Still, keep in mind that CIPA compliance does not eliminate complying with the CCPA. And there may even be some compounding factors. For example, cookie banners need to respect all the specifications warranted by the CCPA, like symmetry (CCPA § 7004 (a) (2) (amended 2026)).
More largely, the best strategy we can recommend is to invest in a broader data collection plan, paying particular attention to zero-party data (data given voluntarily by customers) and first-party data (data you own), as they have the best quality and they are the least vulnerable to challenges. Third-party data, on the other hand, has become among the most vulnerable to legal challenges and technical limitations. Rethinking how you collect and activate data will help you minimize CIPA-related impact, and even support sustainable, long-term performance.
The unexpected reemergence of CIPA has created much uncertainty throughout the US. Legal departments make decisions, but it’s up to marketers to provide business and technical explanations, and to detail the many options at hand, from technical tools to upgraded data collection plans. Because only a strong partnership between legal and marketing can enable your company to navigate the legal uncertainty while continuing marketing operations with as few restrictions as possible.
CIPA is also a reminder that data governance is now a key part of marketing operations. Well-planned data governance makes data more available throughout the organization, and, as a result, supports long-term activation and growth. Conversely, a lack of data governance can lead to legal jeopardy, and may erode customer trust in the event of public incidents, such as data leaks. Therefore, investing in data governance now needs to be part of all future-proof marketing plans.
Discover all the latest news, articles, webinar replays and fifty-five events in our monthly newsletter, Tea O'Clock.