A new wave of lawsuits targeting online businesses, including adult websites, has emerged under the California Invasion of Privacy Act (CIPA). These lawsuits allege improper monitoring of user communications and activity, prompting businesses to review their data collection practices and third-party vendor agreements.
Rising CIPA Lawsuits Target Online Businesses
The California Invasion of Privacy Act (CIPA), originally enacted in 1967 and codified in sections 630-638 of the California penal code, prohibits unauthorized monitoring of communications. While initially intended to address wiretapping, trap-and-trace devices, and "pen registers" for telephone calls, plaintiffs' lawyers are now applying CIPA to internet communications and activity. This interpretation is contested by defense attorneys, who argue that CIPA should not apply to websites as internet technology did not exist when the law was enacted.
The number of CIPA lawsuits is increasing, with some law firms reporting multiple clients being served or threatened with such actions in a single week. Plaintiffs and their lawyers appear to be targeting websites systematically. The sensitivity of information handled, such as records of searches for specific sex acts, may increase exposure, but generally, there is no way to predict who will be the next defendant.
Plaintiffs commonly assert that website owners violate CIPA by illegally wiretapping user communications with the website, and potentially beyond, to broader internet activities. They also allege that website tracking tools collecting user information, such as IP addresses, constitute illegal "pen registers" or "trap and trace" devices, which are prohibited without a court order or specific exceptions under CIPA Section 638.51. These lawsuits claim that third-party service providers intercept communications without user consent, with website owners assisting in this interception. Each CIPA violation carries a penalty of $5,000 or three times the actual damages. The law's reach extends beyond California-based businesses, allowing anyone in California to sue for an alleged violation if a business interacts with California residents.
Defense lawyers argue that CIPA, even with amendments over the past 20 years, has not specifically added websites to its scope. They also contend that most collected and shared information is not private, damaging, or embarrassing. The applicability of CIPA to websites remains unsettled, with some courts ruling against its application and others allowing lawsuits to proceed. This creates an uncertain legal landscape for defendants, where outcomes may depend on factors such as the trial judge and the lawsuit's filing location.
Settlement sums for these actions range from $10,000 to $50,000, making preventative measures a prudent strategy for businesses.
Safeguarding Adult Websites Against CIPA Claims
While there is no guaranteed way to prevent a CIPA lawsuit, several precautions can make it more difficult for plaintiffs to target businesses. These measures focus on obtaining explicit user consent for tracking and data collection.
- Consent for Tracking: Block all tracking, including pixels, cookie trackers, browser fingerprinting, embedded scripts, web beacons, session replay tools, analytics, advertising trackers, chat widgets, AI support or analysis widgets, and live chat widgets, until users explicitly consent.
- Policy Acceptance: Ensure all tracking is blocked until users accept terms of use, privacy policy, and a separate cookies policy if applicable. Provide hyperlinks to all policies on the initial pop-up screen.
- Transparency: If user information is not sold to third parties, state this above the "accept" button. Businesses may also explain that trackers and cookies enhance website operation and provide customized services to encourage user buy-in.
- Remove Unused Trackers: Consider removing tracking tools that are not actively used, as they can still lead to legal issues.
- Clear Consent Options: Make "accept" and "decline" buttons equally visible.
- Affirmative Action: Require deliberate, affirmative action from the user, such as checking an item and pressing a button. Passive language like "By continuing to browse or enter this website, you consent to our terms of use, privacy policy and other policies" is insufficient.
- Prominent Language: Avoid hiding important language within broader terms or policy documents. Use at least 12-point font and consider bolding specific consent provisions.
- Geoblocking: If the above steps are too difficult, consider blocking California visitors entirely.
After implementing these policies, businesses must ensure follow-through. When a user declines or does not opt-in, no information should be obtained. Users and lawsuit filers have access to reports detailing what a website has shared. Technical audits of every tracking tool and cookie should be performed after every tech or policy update. Businesses must be ready to provide proof of user consent interactions, including time-stamped logs, to demonstrate compliance in court.
It is also a business's duty to ensure third-party vendors are not tracking users without consent. Agreements with all third-party vendors, including those providing free trackers and analytics like Google and Meta, should be reviewed. Written confirmation from vendors that they are not tracking users without opt-in, and that their actions comply with the business's terms of use and other policies, is recommended. This includes third-party search functionality suppliers and other vendors.
Potential Legislative Changes to CIPA
A bill to update CIPA, SB 690, has passed California’s Senate and is currently undergoing the committee process in the state Assembly. As it stands, SB 690 would narrow the law's scope, allowing only the state attorney general to sue for CIPA violations. The bill would also be partially retroactive, applying to some pending claims. Many organizations support SB 690 to protect businesses, while plaintiff lawyers and some privacy rights activists oppose the proposed legislation.
Key Facts
- CIPA lawsuits are increasing, targeting online businesses for alleged improper monitoring of user communications.
- Plaintiffs' lawyers interpret CIPA's "pen register" and "trap-and-trace" provisions to apply to website tracking tools.
- Each CIPA violation carries a penalty of $5,000 or three times actual damages.
- The applicability of CIPA to websites is currently unsettled in courts.
- Preventative measures include blocking all tracking until explicit user consent is obtained and ensuring transparency in data collection.
- California Senate Bill 690 aims to narrow CIPA's scope, allowing only the state attorney general to sue for violations.