The California Invasion of Privacy Act—commonly known as CIPA—was enacted in 1967, decades before websites, tracking pixels, artificial intelligence chatbots, and session-replay software became ordinary business tools. Nevertheless, plaintiffs increasingly rely on this California privacy law to challenge how businesses record telephone calls and collect information through websites and mobile applications.
These lawsuits are not limited to large technology companies or businesses physically located in California. A small or midsized business operating elsewhere may face a CIPA claim if it records communications involving California residents or deploys technology that allegedly intercepts communications from California website visitors.
Because CIPA authorizes statutory damages of $5,000 per violation under specified circumstances, businesses should evaluate their call-recording systems, analytics software, chat tools, and other monitoring technologies before deployment.


